Braathe Gruppen AS

Norway · braathe.no · 20 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 2 categories; runs on 20 sub-vendors.

Insights

Last updated 2026-08-04 · revision 2

20 direct vendors, 242 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Braathe Gruppen AS exhibits a high level of migration readiness. **Strengths:** * **Core Business in Cloud & Digital Transformation:** The company's primary offerings revolve around 'Skytjenester & Infrastruktur' (Cloud Services & Infrastructure), 'Digital Arbeidsplass' (Digital Workplace), and 'Digital Transformasjon' (Digital Transformation consulting). This indicates deep internal expertise, processes, and a strategic focus on cloud adoption and migration. * **Modern, Cloud-Native Tech Stack:** Their internal tech stack heavily features Microsoft Azure and Microsoft 365, which are cloud-native platforms. This suggests that their own operations are already largely optimized for cloud environments, making further migrations or transitions within the cloud ecosystem highly feasible. * **Consulting and Development Capabilities:** Offering 'Konsulenter & Utviklere' (Consultants & Developers) for Microsoft Power Platform and custom application development, along with 'Digital Transformasjon' services, means they possess the internal skills and resources to plan, execute, and manage complex migrations, including application modernization. * **Experience with Virtualization:** The use of Citrix (Virtual Desktop / DaaS) indicates experience with virtualized environments, which can be a stepping stone or a component of cloud migration strategies. **Weaknesses & Unknowns:** * **Potential Vendor Lock-in:** While their strong alignment with Microsoft technologies (Azure, M365, Power Platform, Teams) is a strength for migrations *within* the Microsoft ecosystem, it could present a challenge if a migration *away* from these specific platforms were desired. The 'Vendor Lock-in Risk' is explicitly stated as 'Unknown,' but the heavy reliance on a few key technology providers suggests a moderate level of platform-specific lock-in. * **Unknown Regulatory and Data Residency Requirements:** The absence of data on 'Regulatory Environment' and 'Data Residency Requirements' is a significant unknown. These factors can introduce complex compliance hurdles and dictate architectural choices during migration, potentially increasing cost and complexity. * **Unknown Financial Capacity:** Missing data on 'Revenue Concentration' and 'Growth History' means the financial capacity to fund large-scale or complex migration projects is unknown. * **Monolithic vs. Microservices:** While they use modern cloud platforms, it's not explicitly stated if their internal applications are architected using microservices or containerization, which would further enhance migration flexibility and readiness. However, their consulting services suggest an understanding of these modern approaches.

Compliance

11 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Compliant

Braathe Gruppen AS holds a current, publicly available ISO/IEC 27001 certification, confirmed directly from the company's official website. The certificate was issued by an accredited certification body (UKAS-accredited, as indicated by the certificate filename 'UKAS-6'). ISO 27001 is the international standard for information security management systems (ISMS) and is directly relevant to Braathe's business as an IT services and cloud provider. Risk is Low because: (a) the certification is confirmed and publicly evidenced; (b) ISO 27001 requires annual surveillance audits and triennial recertification, providing ongoing assurance; (c) the certification directly supports GDPR Article 32 compliance (appropriate technical and organisational measures); (d) the company's virksomhetspolicy explicitly references ISO 27001 as a foundational framework. The main residual risk is ensuring the certification scope covers all relevant services and that the iteam acquisition in 2024 has been incorporated into the ISMS scope.

Evidence: https://braathe.no/wp-content/uploads/2024/04/ISOIEC-27001-258108-2018-AIS-NOR-UKAS-6-no-NO-20240403-20240403143517.pdf, https://braathe.no/om-oss/var-virksomhetspolicy/, https://braathe.no/vi-leverer/sikkerhet/, https://braathe.no

Norwegian Transparency Act — Partially Compliant

The Norwegian Transparency Act (Åpenhetsloven, effective July 2022) applies to larger Norwegian enterprises and requires due diligence on human rights and decent working conditions in supply chains, with mandatory annual reporting. Braathe Gruppen AS explicitly references Åpenhetsloven compliance on their official website and has a dedicated page for it. With 400+ employees and revenues likely exceeding the NOK 70M threshold (given the scale of operations), the Act applies. Risk is Medium because: (a) the company demonstrates awareness and has published compliance information; (b) however, the depth of supply chain due diligence for a technology company with global hardware/software suppliers (Microsoft, Dell, Citrix, etc.) is complex; (c) failure to conduct adequate due diligence or publish required reports can result in orders from the Consumer Authority (Forbrukertilsynet) and fines. Risk is not High because the company has proactively addressed this obligation publicly.

Evidence: https://braathe.no/om-oss/var-virksomhetspolicy/apenhetsloven/, https://braathe.no/om-oss/var-virksomhetspolicy/, https://www.forbrukertilsynet.no/apenhetsloven

eIDAS Regulation — Assessment Required

eIDAS (EU Regulation 910/2014, updated by eIDAS 2.0) governs electronic identification and trust services in the EU/EEA. Norway, as an EEA member, applies eIDAS. Braathe provides digital workplace and IT solutions that may involve electronic signatures, authentication services, or identity management. Risk is Low because: (a) eIDAS primarily applies to trust service providers (TSPs) offering qualified electronic signatures, seals, or timestamps — Braathe does not appear to be a qualified TSP; (b) however, as a Microsoft partner offering Azure AD/Entra ID and identity services, eIDAS-compliant authentication may be relevant to customer solutions; (c) no evidence of Braathe operating as a qualified trust service provider.

Evidence: https://braathe.no/vi-leverer/digital-arbeidsplass/, https://braathe.no/vi-leverer/

Financials

Financial Resilience Score: 6/10

Braathe Gruppen AS operates a business model with structurally attractive financial characteristics: a large share of recurring revenue from managed cloud services, Microsoft 365 licensing, network-as-a-service, and cybersecurity subscriptions. This annuity-like revenue base typically supports predictable cash flows and reduces earnings volatility. The company benefits from a broad service portfolio spanning digital workplace, infrastructure, security, ERP, and consulting, which reduces dependency on any single technology cycle. Vendor certifications (Microsoft Solution Partner in Security and Modern Work, Citrix Gold) support enterprise deal eligibility and licensing margins. The 2024 acquisition by iteam AS provides additional financial backing, scale advantages, consolidated procurement leverage with key vendors (Microsoft, Dell, Citrix), and access to group financing. The nationwide Norwegian footprint of 40+ offices creates a competitive moat in the mid-market segment. However, actual financial statements (revenue, EBIT, equity for FY2021-FY2023) could not be retrieved during this research, limiting the ability to verify liquidity, profitability, and leverage metrics. A moderate score reflects the qualitatively sound business model tempered by unverified financial data and integration risks from the recent acquisition.

Key strengths: High share of recurring revenue from managed services, licensing, and subscriptions, Broad service portfolio reducing technology cycle dependency, Microsoft Solution Partner and Citrix Gold certifications, Nationwide Norwegian footprint with 40+ offices, Strategic backing from iteam AS post-2024 acquisition, Group scale of 400+ employees enabling procurement leverage

Risk factors: Integration risk from 2024 iteam acquisition (cultural, systems, go-to-market), Wage inflation and consultant utilization sensitivity in high-cost Norwegian labor market, Customer concentration in Norwegian SMB/mid-market with limited international diversification, Vendor dependency on Microsoft licensing economics and partner program changes, Cybersecurity liability exposure as a managed service provider, Competition from larger Nordic MSPs (Advania, Atea, Crayon, Sopra Steria, TietoEVRY) and hyperscaler-direct offerings, Financial statements not verified in this research session

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report