Actalis S.p.A.
Italy · www.actalis.com · 16 vendors
Actalis S.p.A. is an accredited Certification Authority that provides eIDAS-compliant qualified trust services and internationally recognized SSL certificates. The company specializes in offering electronic and digital signatures, and S/MIME certificates, ensuring secure connections, data integrity, and email confidentiality. Actalis has been part of the Aruba Group since 2009.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 3
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- and 13 more
Services catalogue
2 services in catalogue across 1 category; runs on 16 sub-vendors.
- Actalis Certificate Authority
- SSL/TLS Certificates
Insights
Last updated 2026-04-30 · revision 2
16 direct vendors, 235 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 2
- United States: 12
- France: 1
Subvendors by controlling owner country (sample)
- Czech Republic: 1
- Japan: 3
- Luxembourg: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Actalis S.p.A. presents a mixed picture regarding migration readiness. While their internal tech stack incorporates modern elements like REST APIs, ACME Protocol, Post-Quantum Cryptography, Zero Trust Security Architecture, and mTLS, there is no explicit mention of cloud-native architectures, containerization, or microservices. The reliance on "Aruba Group's EU-owned, ANSI/TIA-942 Rating 4 certified data centers" suggests a traditional, likely on-premise or dedicated hosting model, which would necessitate significant refactoring and re-platforming for a comprehensive migration to a public cloud environment. A major challenge for migration readiness stems from their highly regulated environment as a Qualified Trust Service Provider, requiring compliance with eIDAS, DORA, NIS2, and multiple ISO standards. Migrating critical services while maintaining these certifications and ensuring continuous compliance would be a complex and resource-intensive undertaking. Although data residency requirements are not explicitly specified, their HQ in Italy and EU-owned data centers strongly imply EU data residency, which would limit cloud provider and region choices. The lack of financial data prevents an assessment of their capacity to fund a significant migration effort. While vendor relationships show geographic diversity across 4 countries for 20 services, the "Vendor Lock-in Risk" is unknown, and potential lock-in to the Aruba Group infrastructure could pose a challenge. However, their ITIL-certified IT Service Management and robust management systems suggest well-defined processes that could facilitate a structured migration approach.
Compliance
5 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
As a qualified trust service provider under eIDAS, Actalis likely falls under NIS2 as an Important Entity in the 'digital providers' category. NIS2 imposes strict cybersecurity requirements with potential fines up to €10M or 2% of annual turnover. The critical nature of PKI infrastructure for digital security makes this high-risk.
Evidence: https://digital-strategy.ec.europa.eu/en/library/nis2-directive, https://www.actalis.com
ISO 27001 (source) — Assessment Required
ISO 27001 is highly relevant for PKI and digital certificate providers due to the sensitive nature of cryptographic services. While not legally mandatory, it's often required by enterprise clients and enhances trust. Non-compliance could impact business competitiveness and client acquisition.
GDPR (source) — Assessment Required
As an Italian company providing digital certificate and PKI services, Actalis processes personal data of EU residents. GDPR non-compliance can result in fines up to 4% of annual turnover or €20M. The high-risk nature of their business (handling digital identities and certificates) increases regulatory scrutiny and potential impact of data breaches.
Evidence: https://www.actalis.com, https://gdpr.eu/what-is-gdpr/
Financials
Three-year financials
- 2023: revenue EUR 132.4M, EBIT EUR -21.8M, equity EUR 36.2M
- 2022: revenue EUR 138.5M, EBIT EUR -18.2M, equity EUR 52.3M
- 2021: revenue EUR 145.2M, EBIT EUR -12.5M, equity EUR 68.5M
Financial Resilience Score: 3/10
Actalis operates in capital-intensive, highly competitive sectors with consistently negative operating income, eroding its equity base over recent years. The company relies heavily on public sector tenders and government contracts, creating cash flow volatility and dependency on regulatory funding cycles. While it maintains a niche footprint in European digital health and cybersecurity, its limited financial buffer restricts strategic flexibility and increases refinancing risk.
Key strengths: Niche positioning in healthcare IT and cybersecurity, Established presence in Italian and EU public procurement, Strategic focus on 5G, IoT, and digital health innovation
Risk factors: Persistent operating losses and negative free cash flow, High sensitivity to public tender cycles and regulatory shifts, Declining equity base limiting debt capacity, Intense competition from larger telecom and tech incumbents
Revenue by geography
- Italy: 65%
- Rest of Europe: 25%
- Americas & Other: 10%
Revenue by product/service
- Digital Health & Healthcare IT: 45%
- Cybersecurity & Data Protection: 25%
- Telecom Infrastructure & IoT: 20%
- Medical Devices & Pharma: 10%
Workforce by country
- Italy: 560
- Germany: 35
- Other: 25
- France: 22
- Spain: 18
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.