Arosii
Denmark · owned by Independent (Denmark) · arosii.dk · 9 vendors
Arosii is a Danish IT solutions company focused on developing and scaling businesses through technology. Based in Denmark, the company offers IT services tailored to help organizations grow and optimize their operations. Their website is presented in Danish, indicating a primary focus on the Danish market.
Resilience scores
- Digital Sovereignty: 11
- Digital Resilience: 4
- Financial Resilience: 7
Disruption prediction
Arosii has an estimated 17% probability of disruption in the next 6 months.
3 of Arosii's 9 vendors monitored for disruptions.
Technology vendors
- Fortinet, Inc. — Technology — United States
- Google LLC — Technology — United States
- Umbraco A/S — Technology — Denmark
- and 6 more
Insights
Last updated 2026-09-13 · revision 4
9 direct vendors, 163 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- United Kingdom: 2
- Sweden: 1
Subvendors by controlling owner country (sample)
- Moldova: 1
- Denmark: 6
- Germany: 6
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Arosii's migration readiness is assessed as moderate (Score: 35), primarily due to significant data gaps. The most critical missing information is Arosii's internal tech stack and key technologies, which are fundamental to determining the complexity and feasibility of any migration (e.g., cloud-native vs. legacy, containerization). Similarly, the lack of public financial data makes it impossible to assess Arosii's capacity to fund a migration initiative. Regulatory requirements, including GDPR and Danish national regulations, along with the likely EU/EEA data residency requirements, will impose constraints on migration strategies, potentially limiting choices for cloud providers or requiring specific regional deployments. The NIS2 assessment requirement further adds a layer of complexity, as migration plans would need to ensure ongoing compliance. Regarding vendor relationships, the data states "Total Vendors: 0" but then lists "Total Services: 16" from vendors with HQ/Owner countries in the United States, Denmark, and the United Kingdom. Assuming these services are indeed provided by vendors, the "Vendor Lock-in Risk: Unknown" and the unspecified number of unique vendors make it difficult to assess potential migration challenges related to vendor dependencies and contract complexity. The geographic diversity of vendor HQs is a positive, but without knowing the number of unique vendors or specific lock-in clauses, the overall impact on migration readiness remains uncertain.
Compliance
7 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is an assurance framework relevant for service organizations that handle customer data. While not a legal requirement, it is a common customer expectation in the technology sector.
SOC 2 is more commonly required by US-based clients. As Arosii's client base appears to be primarily Danish and European, the immediate risk of not having a SOC 2 report is low.
GDPR (source) — Partially Compliant
Arosii is established in Denmark (an EU member state) and processes personal data of EU citizens, including sensitive health data through its work with the Danish Health Data Authority and regional health authorities.
Arosii processes health data, which is a special category of personal data. Non-compliance can lead to significant fines and reputational damage. The lack of a publicly named DPO is a compliance gap.
NIS2 (source) — Assessment Required
Arosii's 2025 profit of 24.3 million DKK strongly suggests a turnover exceeding the €10 million threshold. As a provider of digital services to the public administration and health sectors, it qualifies as an 'Important Entity'.
As a key IT supplier to the Danish healthcare sector, a security incident at Arosii could have significant societal impact. Non-compliance with NIS2 can result in substantial fines and reputational damage.
Financials
Three-year financials
- 2025: gross profit DKK 12.3M, EBIT DKK 2.06M, equity DKK 26.8M
- 2024: gross profit DKK 10.9M, EBIT DKK 1.51M, equity DKK 9.51M
- 2023: gross profit DKK 9.71M, EBIT DKK 302K, equity DKK 6.76M
Financial Resilience Score: 7/10
Arosii A/S demonstrates solid financial resilience for a small, founder-owned Danish IT services firm. Gross profit has grown consistently every year from DKK 9.11M in FY 2021/22 to DKK 12.3M in FY 2024/25 (~35% cumulative on stable headcount), indicating rising productivity and pricing power. EBIT recovered from near break-even in FY 2022/23 (DKK 302K) to DKK 2.06M in FY 2024/25, and equity nearly quadrupled to DKK 26.8M, providing a substantial buffer relative to the ~15-18 person operation and the paid-in share capital of only DKK 500K. The company benefits from long-standing (~20 year) relationships in regulated healthcare-IT and clean-tech verticals, with sticky customers such as Sundhedsdatastyrelsen (Danish Health Data Authority), Nordex, Eniig and Suzlon. Founder ownership (Morten Kvistgaard Nielsen 48%, Claus Leth Gregersen) provides continuity, and the group structure with parent Arosii Information Systems Holding A/S and the Mobilize Me subsidiary offers additional cushioning. However, resilience is constrained by very small scale (~18 employees at a single Aarhus site), unquantified customer concentration among a handful of large accounts, and exposure to public-sector procurement and wind-industry capex cycles. The DKK 24.3M net profit spike in FY 2024/25 is non-recurring and appears driven by a non-operating financial gain (likely a subsidiary revaluation/divestment) rather than trading, so underlying operating profitability remains modest. Revenue is not disclosed under Danish small-company rules, limiting transparency.
Key strengths: Consistent gross profit growth (~35% cumulative over 4 years) on stable headcount, Strong equity buffer of DKK 26.8M vs. DKK 500K share capital, Long-standing (~20 year) customer relationships in regulated healthcare-IT and clean-tech verticals, Blue-chip customer base including Sundhedsdatastyrelsen, Nordex, Eniig, Suzlon, Founder-owned with continuity of management, Group backing from Arosii Information Systems Holding A/S and Mobilize Me subsidiary, EBIT recovery from DKK 302K to DKK 2.06M over three years
Risk factors: Very small scale (~15-18 employees) exposes company to key-person risk, Unquantified customer concentration among a few large accounts, Revenue not publicly disclosed, limiting transparency for lenders and counterparties, FY 2024/25 net profit spike (DKK 24.3M) is non-recurring and not operational, Exposure to public-sector procurement cycles via health-authority customers, Exposure to volatile wind-industry capex cycles (Nordex, Suzlon), Loss year experienced in 2021 (DKK -1.49M) shows historical vulnerability
Workforce by country
- Denmark: 18
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.