Blue Control A/S

Denmark · owned by Schmidt Investment Holding ApS (Denmark) · bluecontrol.dk · 6 vendors

Blue Control A/S develops and supplies SCADA (Supervisory Control and Data Acquisition) systems for water supply plants, treatment plants, and industrial installations. The company provides electrical automation solutions for monitoring and controlling waterworks, encompassing supply, filtration, pumping, and reporting. They also offer communication, support, backup, and service agreements for their systems.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 6 sub-vendors.

Insights

Last updated 2026-09-13 · revision 1

6 direct vendors, 87 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Blue Control A/S demonstrates a medium-low level of migration readiness. A primary challenge is the deep integration with specific industrial components from vendors like Siemens and Atvise, which are foundational to their SCADA systems. The fact that Blue Control engineers exclusively install their own SCADA solutions suggests a highly customized and potentially monolithic architecture that would be complex and costly to migrate to a more agile, cloud-native environment. While a proprietary cloud solution exists for IoT data, its proprietary nature could lead to vendor lock-in to their own platform, complicating migration to other public cloud providers. The reliance on legacy 3G/2G for some remote devices also presents a migration hurdle as these networks are decommissioned. Critical information regarding the regulatory environment, data residency requirements, and financial stability (essential for funding a migration) is missing, introducing significant unknowns and risks to any migration planning. The 'unknown' vendor lock-in risk, combined with the deep integration of core vendor products, suggests a potentially high level of lock-in. While there is some existing cloud adoption and web-based access, the overall architecture appears to be more tightly coupled to specific industrial hardware and software than a truly cloud-native, containerized, or microservices-based approach, limiting inherent migration flexibility.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed into Danish law as 'Lov om sikkerhed i net- og informationssystemer') is highly likely to apply to Blue Control A/S with HIGH confidence for the following reasons: (1) SECTOR: Blue Control A/S provides SRO (control, regulation, monitoring) systems exclusively to drinking water utilities (vandværker). Under NIS2 Annex I, 'drinking water' is listed as an Essential Entity sector. Companies that supply critical technology to Essential Entity operators — particularly OT/SCADA/SRO control systems — are themselves subject to NIS2 as ICT service providers or digital infrastructure providers to critical sectors. (2) SUPPLY CHAIN RISK: NIS2 explicitly addresses supply chain security (Art. 21), meaning Blue Control's customers (water utilities) are required to assess and manage risks from suppliers like Blue Control, creating strong indirect compliance pressure. (3) SIZE THRESHOLD: The company's size (employee count and turnover) is not publicly confirmed, but they appear to be a small-to-medium enterprise. If they have 50+ employees or €10M+ turnover, they would qualify as a medium enterprise and be directly subject to NIS2. If below these thresholds, they may still be subject as a supplier to Essential Entities. (4) DANISH TRANSPOSITION: Denmark transposed NIS2 via 'Lov nr. 1655 af 27. december 2022' and subsequent amendments. The Danish Centre for Cyber Security (CFCS) oversees enforcement. Risk is HIGH because: non-compliance with NIS2 can result in fines up to €10M or 2% of global annual turnover for Essential Entities; the drinking water sector is explicitly listed; and Blue Control's OT/SCADA products are directly embedded in critical water infrastructure. Missing information: Exact employee count and annual turnover needed to confirm size threshold applicability.

Evidence: https://www.bluecontrol.dk/Om-Blue-Control, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/cybersecurity/nis2/, https://www.retsinformation.dk/eli/lta/2022/1655

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It is highly relevant to Blue Control A/S because: (1) they operate a remote monitoring platform (Bluewatch) for critical water infrastructure, making information security a core operational concern; (2) their SRO systems are embedded in drinking water utilities, which are classified as critical infrastructure under NIS2; (3) NIS2 compliance (which is likely applicable — see above) strongly aligns with ISO 27001 requirements, and certification would provide evidence of NIS2 Art. 21 compliance; (4) their customers (water utilities) are increasingly required to demonstrate supply chain security, creating demand for supplier ISO 27001 certification. Risk is Medium because: no certification has been found (a gap), but ISO 27001 is voluntary and the company may have equivalent internal controls. The absence of certification is a risk factor in the context of NIS2 supply chain requirements and customer due diligence.

Evidence: https://www.bluecontrol.dk/Om-Blue-Control, https://www.iso.org/standard/27001, https://iaf.nu/en/iaf-certsearch/

EU Radio Equipment Directive — Assessment Required

Blue Control A/S manufactures electronic control systems (BC 1000, BC 7000, BC 9000) and level sensors (Niveausonde, SGE-16, SGE-25) that are placed on the EU market. CE marking requirements under the Radio Equipment Directive (2014/53/EU), Low Voltage Directive (2014/35/EU), and EMC Directive (2014/30/EU) are applicable to electronic products sold in the EU. The company references a 'Serviceattest' (service certificate) and 'Patent' on their website, suggesting some product documentation exists. Risk is Medium because non-compliance with CE marking requirements can result in market withdrawal, but the company appears to be an established manufacturer with existing product documentation.

Evidence: https://www.bluecontrol.dk/Produkter, https://www.bluecontrol.dk/Serviceattest, https://ec.europa.eu/growth/single-market/ce-marking_en

Financials

Three-year financials

Financial Resilience Score: 5/10

Blue Control A/S is a small Danish industrial-automation company operating in a defensible niche (SRO/SCADA systems for Danish waterworks). The business model combines proprietary controllers (BC 1000, BC 7000, BC 9000), recurring service agreements, Bluewatch monitoring subscriptions, and reseller distribution of complementary industrial components. Mission-critical SCADA systems create high switching costs once installed, supporting recurring revenue and customer retention. Regulatory tailwinds in Danish drinking-water supply (quality reporting, cyber-security, remote monitoring) further support demand. However, verified financial figures (revenue, EBIT, equity, headcount) were not retrievable, limiting quantitative assessment. As a small class-B Danish A/S incorporated around 2019, the company likely files abbreviated accounts and may legally omit revenue disclosure. Risks include heavy concentration in the small and consolidating Danish waterworks market, project-based revenue lumpiness, reseller dependence on European suppliers (FX/EUR exposure), and limited transparency. The overall resilience is moderate: a defensible niche with recurring service revenue offset by very narrow geographic and end-market exposure.

Key strengths: Niche focus with high switching costs in mission-critical SCADA systems, Structural tailwind from Danish drinking-water regulation and cyber-security requirements, Standard-component strategy reduces obsolescence and inventory concentration, Distribution reach via co-marketing with Kamstrup and Thvilum, Recurring revenue from service agreements, Bluewatch monitoring, and spare-parts webshop, Proprietary IP (patent on SRO concept)

Risk factors: Small company with concentration in Danish waterworks market, Limited and consolidating customer base caps addressable market, Project-based revenue lumpiness from waterworks capex tenders, Reseller dependence on European suppliers with EUR FX exposure, Limited financial transparency as a small class-B A/S, No evidence of meaningful international revenue diversification

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report