Aeven A/S
Denmark · owned by New Nordic IT Topco ApS (Denmark) · aevengroup.com · 38 vendors
Aeven is a Danish IT infrastructure company that helps organizations build and run adaptive digital infrastructure, combining local Danish data center reliability with hybrid cloud capabilities. The company was formed from part of NNIT, bringing over 30 years of experience supporting industries where IT cannot fail, including life science, healthcare, finance, energy, and the public sector. Its services span application services, hybrid cloud, SAP services, cybersecurity, data centers, digital workplace, and consulting.
Resilience scores
- Digital Sovereignty: 29
- Digital Resilience: 5
- Financial Resilience: 6
Technology vendors
- Alchemer — Technology — United States
- Cohesity — Cybersecurity — United States
- Zscaler, Inc. — Cybersecurity — United States
- and 35 more
Services catalogue
2 services in catalogue across 2 categories; runs on 38 sub-vendors.
- Hosting e-Boks’ platform.
- Personal Data Processing
Insights
Last updated 2026-09-13 · revision 25
38 direct vendors, 356 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Sweden: 2
- Luxembourg: 1
Subvendors by controlling owner country (sample)
- Netherlands: 5
- Japan: 3
- Australia: 4
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Aeven A/S exhibits a strong foundation for migration readiness due to its modern, cloud-oriented tech stack, including extensive use of Microsoft Azure, Hybrid Cloud Services, and SAP HANA. The company's offerings like 'Cloud Delivery Framework' and 'Digital Estate Transformation Advisor' suggest internal expertise and structured approaches to cloud adoption and digital transformation. Its ISO 27001 certification and GDPR compliance provide a solid security and data governance baseline crucial for secure migrations. Vendor diversity, with key technology vendors and vendor HQs in 5 unique countries, generally reduces single-vendor lock-in and offers flexibility. However, the company's migration readiness is severely hampered by its significant financial instability in 2023, marked by a drastic reduction in revenue and employees. This financial constraint will critically impact the ability to fund and execute complex, large-scale migration projects, which often require substantial investment and sustained resources. Furthermore, the 'Assessment Required' status for NIS2 and SOC2 compliance introduces potential regulatory complexities and unforeseen requirements that could emerge during a migration, adding costs and delays. GDPR data residency requirements, coupled with their Danish data centers, necessitate careful planning for any data movement outside the EU/EEA. The specific level of vendor lock-in remains unknown, which could present challenges in migrating away from certain systems or vendors. While the tech stack is modern, the presence of 'business-critical applications' for regulated industries may imply a mix of legacy systems that could complicate migration efforts.
Compliance
11 in-scope frameworks identified; showing 3.
Danish Data Protection Act — Compliant
The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions, including stricter rules for processing sensitive personal data, employee data, and criminal records. As a Danish company, Aeven is directly subject to this Act. Risk is Medium because Aeven processes employee data across multiple jurisdictions (Denmark, Czech Republic, Hungary, Philippines) and serves clients in regulated sectors where special category data (health data, financial data) may be processed. The appointment of a DPO and published Privacy Notice indicate active compliance, but the complexity of cross-border employee data processing and client data processing increases residual risk.
Evidence: https://www.aevengroup.com/privacy-notice/, https://www.datatilsynet.dk/english
ISAE 3000 (source) — Assessment Required
ISAE 3000 (and its IT-specific variant ISAE 3402) is commonly used by IT service providers and data processors in Denmark and the Nordic region to provide third-party assurance to clients on internal controls. As a major managed IT services provider serving regulated industries (life sciences, healthcare, finance, public sector), Aeven's clients — particularly in financial services and public administration — may contractually require ISAE 3000/3402 assurance reports. Risk is Medium because: (1) absence of an ISAE 3000 report may create contractual gaps with Danish financial sector or public sector clients who are themselves subject to ISAE requirements; (2) the Danish financial regulator (Finanstilsynet) and public procurement rules often require ISAE 3402 reports from IT outsourcing providers; (3) Aeven's ISO 27001 provides some overlapping assurance but is not a substitute for ISAE 3402 in financial sector outsourcing contexts.
Evidence: https://www.aevengroup.com/about-us/our-certificates-and-partners/, https://www.aevengroup.com/what-we-do/
DORA (source) — Assessment Required
DORA (applicable from January 17, 2025) directly impacts ICT third-party service providers (ICT TPPs) that provide services to EU financial entities. Aeven explicitly serves the finance and banking sector and provides managed IT, cloud, data center, and security services. Under DORA, Aeven may qualify as a 'critical ICT third-party service provider' (CTPP) subject to direct oversight by EU supervisory authorities (EBA, ESMA, EIOPA), or at minimum as an ICT TPP subject to contractual DORA requirements imposed by its financial sector clients. Risk is High because: (1) DORA imposes stringent contractual, audit, and resilience requirements on ICT providers to financial entities; (2) financial sector clients must ensure their ICT providers meet DORA standards or face their own regulatory sanctions; (3) non-compliance could result in loss of financial sector contracts; (4) DORA's oversight framework for critical ICT TPPs includes direct supervisory powers including on-site inspections and fines.
Evidence: https://www.aevengroup.com/about-us/our-certificates-and-partners/, https://www.aevengroup.com/about-us/
Financials
Three-year financials
- 2025: revenue DKK 1.82B, EBIT DKK -55.5M, equity DKK 581M
- 2024: revenue DKK 1.59B, EBIT DKK -86.2M, equity DKK 662M
- 2023: revenue DKK 904M, EBIT DKK -21.1M, equity DKK 717M
Financial Resilience Score: 6/10
Aeven A/S presents a mixed financial resilience profile as a recently carved-out entity from NNIT A/S, now owned by Nordic Capital. The company benefits from significant strengths including backing by an experienced Nordic private-equity sponsor, long-term anchor customer contracts (typically 3-7 years) providing high revenue visibility, and a scaled Danish operating footprint with owned data centers—a differentiator in the current EU sovereign cloud environment. With approximately DKK 1.7-1.8 billion in annual revenue and 1,100-1,200 employees at separation, Aeven is one of the larger domestic IT infrastructure operators in Denmark. However, meaningful risks temper this assessment. Heavy customer concentration on Novo Nordisk creates material exposure to renegotiation or loss of that master services agreement. As a carve-out, Aeven faces execution risk in standing up standalone corporate functions, which typically depresses margins in years 1-2. The traditional infrastructure-outsourcing market is contracting as customers migrate to hyperscalers (AWS, Azure, GCP), creating structural headwinds. PE ownership likely implies a leveraged capital structure with associated interest burden. Without verified access to the filed årsrapport, precise leverage, profitability, and equity figures cannot be confirmed, warranting a moderate score.
Key strengths: Backed by Nordic Capital private-equity sponsor, Long-term anchor customer contracts (3-7 years) with high revenue visibility, Owned data-center footprint in Denmark supporting EU sovereign cloud positioning, Scale as one of the larger domestic Danish IT infrastructure operators, Broad service portfolio enabling cross-sell (hybrid cloud, SAP, security, digital workplace), ~30 years of operating heritage inherited from NNIT
Risk factors: Heavy customer concentration on Novo Nordisk, Carve-out execution risk depressing margins in years 1-2, Competitive pressure from hyperscalers (AWS, Azure, GCP) and larger IT services rivals, Traditional infrastructure-outsourcing market contracting in favor of public cloud, Likely leveraged capital structure under PE ownership, Offshore delivery dependence (Czech Republic, Philippines) exposing P&L to wage inflation and FX
Revenue by geography
- Denmark: 90%
- International: 10%
Workforce by country
- Denmark: 715
- Czech Republic: 250
- Philippines: 150
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.