Comparison Overview

ShipMonk

VS

CMA CGM

ShipMonk

201 NW 22nd Ave, Unit 100, Fort Lauderdale, Florida, US, 33311
Last Update: 2026-04-04
Between 750 and 799

Since 2014, ShipMonk has operated with a singular guiding principle: help ecommerce brands scale through technology-driven fulfillment solutions that enable entrepreneurs to devote more time to the things that matter most in their businesses. Put simply, here at ShipMonk we help ecommerce brands STRESS LESS and GROW MORE. Headquartered in Fort Lauderdale, FL, ShipMonk proudly employs 2,000+ team members across a network of 11 state-of-the-art facilities located throughout the US, Canada, and Europe. We are America’s fastest-growing third-party logistics provider (3PL) for DTC, B2B, and retail fulfillment, specializing in the facilitation of sustained growth for ecommerce brands of all sizes across all verticals. Our enterprise-level fulfillment services stand out amongst other 3PLs thanks to our seamless integrations, superior shipping rates and services, and powerful order, inventory, and warehouse management technology. Each year, ShipMonk is recognized by ecommerce industry leaders and publications for our commitment to innovation. For example: The Inc. 5000 List of America’s Fastest-Growing Private Companies for eight consecutive years, Deloitte’s Technology Fast 500™️, and Entrepreneur Magazine’s 360 List of Best Entrepreneurial Companies in America. Most recently ShipMonk was recognized as a Business Intelligence Group “Company of the Year” for the third year in a row, and ShipMonk founder Jan Bednar was named a National Winner in Ernst & Young’s Entrepreneur of the Year®️ Awards.

NAICS: 47
NAICS Definition: Transportation and Warehousing
Employees: 1,171
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

CMA CGM

4, Quai d'arenc, Marseille, 13002, FR
Last Update: 2026-04-02
Between 750 and 799

The CMA CGM Group is a global player in sea, land, air and logistics solutions, true to its corporate Purpose, "We imagine better ways to serve a world in motion". Present in 177 countries, it employs 160,000 people, of which nearly 6,000 in Marseilles where its head office is located. The world's 3rd largest shipping company, CMA CGM serves more than 420 ports across 5 continents with a fleet of over 650 vessels. In 2024, CMA CGM carried over 23 million TEU (twenty-foot equivalent unit) containers. Its subsidiary CEVA Logistics, one of the world's top five players, operates 1,000 warehouses and handled 15 million shipments in 2024. CMA CGM AIR CARGO, the Group's air freight division, will operate a fleet of 6 cargo aircraft by 2025. CMA Media, France's 3rd largest private media group, includes RMC-BFM and several national and regional press titles (La Tribune Dimanche, La Tribune, La Provence and Corse Matin). Committed to energy transition, the CMA CGM Group is aiming for Net Zero Carbon by 2050. The CMA CGM Foundation provides humanitarian aid in crisis situations, and is committed to education for all and equal opportunities throughout the world. To date, the CMA CGM Foundation has transported 63,000 tons of humanitarian aid to 97 countries and supported over 550 educational projects.

NAICS: 47
NAICS Definition: Transportation and Warehousing
Employees: 30,339
Subsidiaries: 12
12-month incidents
0
Known data breaches
0
Attack type number
2

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/shipmonk.jpeg
ShipMonk
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/cma-cgm.jpeg
CMA CGM
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
ShipMonk
100%
Compliance Rate
0/4 Standards Verified
CMA CGM
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Transportation, Logistics, Supply Chain and Storage Industry Average (This Year)

No incidents recorded for ShipMonk in 2026.

Incidents vs Transportation, Logistics, Supply Chain and Storage Industry Average (This Year)

No incidents recorded for CMA CGM in 2026.

Incident History — ShipMonk (X = Date, Y = Severity)

ShipMonk cyber incidents detection timeline including parent company and subsidiaries

Incident History — CMA CGM (X = Date, Y = Severity)

CMA CGM cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/shipmonk.jpeg
ShipMonk
Incidents

No Incident

https://images.rankiteo.com/companyimages/cma-cgm.jpeg
CMA CGM
Incidents

Date Detected: 9/2021
Type:Ransomware
Attack Vector: ransomware (Ragnar Locker)
Motivation: financial gain, data theft
Blog: Blog

Date Detected: 9/2020
Type:Ransomware
Motivation: financial gain
Blog: Blog

Date Detected: 2/2017
Type:Cyber Attack
Attack Vector: remote hacking, navigation system compromise
Motivation: financial gain (piracy), physical seizure of vessel, ransom
Blog: Blog

FAQ

CMA CGM company demonstrates a stronger AI Cybersecurity Score compared to ShipMonk company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

CMA CGM company has historically faced a number of disclosed cyber incidents, whereas ShipMonk company has not reported any.

In the current year, CMA CGM company and ShipMonk company have not reported any cyber incidents.

CMA CGM company has confirmed experiencing a ransomware attack, while ShipMonk company has not reported such incidents publicly.

Neither CMA CGM company nor ShipMonk company has reported experiencing a data breach publicly.

CMA CGM company has reported targeted cyberattacks, while ShipMonk company has not reported such incidents publicly.

Neither ShipMonk company nor CMA CGM company has reported experiencing or disclosing vulnerabilities publicly.

Neither ShipMonk nor CMA CGM holds any compliance certifications.

Neither company holds any compliance certifications.

CMA CGM company has more subsidiaries worldwide compared to ShipMonk company.

CMA CGM company employs more people globally than ShipMonk company, reflecting its scale as a Transportation, Logistics, Supply Chain and Storage.

Neither ShipMonk nor CMA CGM holds SOC 2 Type 1 certification.

Neither ShipMonk nor CMA CGM holds SOC 2 Type 2 certification.

Neither ShipMonk nor CMA CGM holds ISO 27001 certification.

Neither ShipMonk nor CMA CGM holds PCI DSS certification.

Neither ShipMonk nor CMA CGM holds HIPAA certification.

Neither ShipMonk nor CMA CGM holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Description

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Description

Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.

Description

A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.