3Shape
Denmark · owned by 3SHAPE HOLDING A/S (Denmark) · www.3shape.com · 14 vendors
Resilience scores
- Digital Sovereignty: 21
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Abion AB (formerly Ports Group) — Technology — Sweden
- Anthropic, PBC — Technology — United States
- TeamViewer AG — Technology — Germany
- and 11 more
Services catalogue
1 service in catalogue across 1 category; runs on 14 sub-vendors.
- TRIOS
Insights
Last updated 2026-09-13 · revision 1
14 direct vendors, 198 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Spain: 1
- Canada: 1
Subvendors by controlling owner country (sample)
- South Korea: 1
- Germany: 4
- Norway: 2
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
3Shape exhibits medium migration readiness, characterized by a mixed technology landscape and significant data gaps. On the positive side, the existing use of Microsoft Azure and Power Apps, coupled with the cloud-based 3Shape Unite platform, demonstrates some experience and infrastructure for cloud adoption, providing a foundation for further migration efforts. The company's engagement with AI/ML and other advanced technologies could also drive the need for scalable cloud infrastructure, presenting an opportunity for strategic migration. However, significant challenges exist due to the presence of legacy technologies such as Delphi, C++, C#, and Sitecore CMS, along with a primary focus on Windows for desktop software. This suggests that core applications may be monolithic and require substantial refactoring for a cloud-native migration. The absence of explicit mention of containerization or microservices architecture implies a potentially traditional software development approach. Crucially, there are significant gaps in information regarding the regulatory environment, data residency requirements, and financial stability, all of which are critical for planning, funding, and executing a comprehensive migration strategy. The 'Vendor Lock-in Risk: Unknown' and the ambiguous 'Total Vendors: 0' also introduce uncertainties regarding vendor dependencies and potential migration complexities.
Compliance
11 in-scope frameworks identified; showing 3.
HIPAA (source) — Partially Compliant
HIPAA is directly applicable to 3Shape's US operations. 3Shape explicitly references HIPAA compliance for electronic Protected Health Information (ePHI) in its Communicate and LMS cloud services, which are used by US dental clinics and labs. As a Business Associate (BA) under HIPAA, 3Shape must execute Business Associate Agreements (BAAs) with covered entities (dental practices). Risk is High because: (1) dental scan data constitutes ePHI under HIPAA; (2) 3Shape explicitly acknowledges ePHI handling in its GDPR FAQ, confirming HIPAA scope; (3) HIPAA violations carry civil penalties up to $1.9M per violation category per year and potential criminal liability; (4) OCR (HHS Office for Civil Rights) has actively enforced HIPAA against healthcare technology vendors; (5) 3Shape's US data center (Azure US) stores ePHI for American customers. Status is 'Partially Compliant' because while 3Shape references HIPAA safeguards and has a BAA with Microsoft Azure, no publicly available BAA template for customers, HIPAA audit report, or OCR compliance certification has been found.
Evidence: https://www.3shape.com/en/gdpr, https://support.3shape.com/en_US/privacy-compliance-center/privacy-policy
Danish Data Protection Act — Assessment Required
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions and is directly applicable to 3Shape as a Danish company. Risk is Medium because: (1) the Act includes specific provisions on processing of sensitive data (including health data) that go beyond GDPR minimum requirements; (2) the Datatilsynet (Danish DPA) is an active enforcement authority that has issued fines and reprimands to Danish companies; (3) 3Shape's processing of patient dental health data (special category) requires specific legal bases under both GDPR and the Danish Act; (4) the Act includes specific rules on employee monitoring and processing of employee data. Risk is not High because 3Shape's documented GDPR compliance program likely addresses most Danish Act requirements, and the Danish Act largely mirrors GDPR.
Evidence: https://www.3shape.com/en/gdpr, https://www.datatilsynet.dk/english
ISAE 3000 (source) — Assessment Required
ISAE 3000 (Revised) is a framework for assurance engagements other than audits or reviews of historical financial information, commonly used in Europe as the basis for service organization control reports (similar to SOC 2 in the US context). Risk is Low because: (1) ISAE 3000 is not legally mandated for 3Shape's industry; (2) it is primarily relevant if 3Shape's enterprise customers (particularly in Scandinavia and Europe) require third-party assurance reports on internal controls; (3) 3Shape's primary regulatory obligations (GDPR, HIPAA, EU MDR) do not specifically require ISAE 3000 reporting; (4) the absence of an ISAE 3000 report is less commercially impactful than SOC 2 absence in 3Shape's primary markets. However, large Danish institutional customers (hospitals, public dental services) may request ISAE 3402 (controls at service organizations) reports.
Evidence: https://www.3shape.com/en/gdpr
Financials
Three-year financials
- 2025: revenue DKK 1.72B, EBIT DKK 654M, equity DKK 998M
- 2024: revenue DKK 1.82B, EBIT DKK 1.10B, equity DKK 1.30B
- 2002: revenue DKK 1.73B, equity DKK 820M
Financial Resilience Score: 7/10
3Shape is a scaled, profitable, founder-controlled Danish medtech champion in digital dentistry with a defensible IP position and global reach. The company has category leadership through its TRIOS intraoral scanner platform, which is one of two dominant global platforms in digital dentistry, yielding pricing power and recurring software/service revenue. Its founder-controlled structure enables a long investment horizon and the ability to fund R&D through downturns without listed-equity pressure. However, the company faces material risks including ongoing litigation exposure with Align Technology (iTero/Invisalign) which has produced significant legal costs and market injunctions. Competitive pressure from Align, Dentsply Sirona, Medit, and Chinese entrants is compressing scanner ASPs. The company is also exposed to the dental capex cycle and FX movements. Historically profitable and cash-generative based on Danish press reporting, though exact figures could not be verified from primary filings.
Key strengths: Category leadership in digital dentistry with TRIOS intraoral scanner, Global installed base creating recurring software/maintenance revenue, R&D-heavy with large patent portfolio, Founder-controlled with long investment horizon, Historically profitable and cash-generative, Global reach across ~25 offices
Risk factors: Ongoing litigation with Align Technology (patent and antitrust disputes), Customer concentration in dental capex cycle, FX exposure with sales in USD/EUR vs DKK cost base, Competitive pressure from Align, Dentsply Sirona, Medit, and Chinese entrants compressing ASPs, Private ownership limits transparency for counterparties, Ukraine R&D operations exposed to ongoing war
Workforce by country
- Denmark: 800
- Ukraine: 400
- China: 0
- Italy: 0
- Japan: 0
- Spain: 0
- Brazil: 0
- France: 0
- Poland: 0
- Germany: 0
- Singapore: 0
- South Korea: 0
- United States: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.