CIM Mobility A/S

Denmark · owned by CIM GRUPPEN A/S (Denmark) · www.cim-mobility.dk · 15 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 4 categories; runs on 15 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

15 direct vendors, 185 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CIM Mobility A/S shows moderate migration readiness, largely propelled by its recent modernization efforts but tempered by significant unknowns and inherent operational constraints. A major strength is the company's migration of all customers to a "Next Generation Delivery Platform" in 2022, which strongly suggests a modern, adaptable core infrastructure and an engineering team capable of large-scale platform transitions. The presence of a REST API/SDK, along with Zapier and Shopify integrations, indicates a modular, API-driven architecture that is generally well-suited for migration to cloud-native environments and easier integration with external services. Additionally, the company's commitment to GDPR-compliant software architecture simplifies a major regulatory hurdle often encountered during cloud migrations. Conversely, several factors present challenges. The implied data residency requirements within Denmark, stemming from integrations with Danish public sector systems (NemSMS, e-Boks) and the stated hosting location for key products, will likely restrict choices for cloud regions and providers, potentially increasing complexity and cost. A significant unknown is the vendor lock-in risk, as specific details on vendor contracts and dependencies are not provided. This lack of information makes it difficult to assess the ease of disentanglement from existing vendor relationships during a migration. The absence of financial data (revenue concentration, growth history) also introduces uncertainty regarding the company's capacity to fund a potentially large-scale migration project. While their current hosting is ISO 27001 and ISAE3000 certified, it appears to be a traditional datacenter setup rather than a public cloud-native environment, suggesting that a full cloud migration would require re-platforming or significant lift-and-shift efforts rather than a simple re-deployment. The management of 16 services across 9 geographically diverse vendors, while beneficial for resilience, could add complexity to migration coordination and vendor management during the transition.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the internationally recognised standard for information security management systems (ISMS). For a company like CIM Mobility that processes sensitive personal communications data (including counselling data for vulnerable individuals and children, crisis alert data for municipalities), ISO 27001 certification would be highly relevant and expected by enterprise/public sector clients. Risk is MEDIUM because: (1) no ISO 27001 certification has been found, representing a potential security assurance gap; (2) Danish public sector procurement guidelines increasingly reference ISO 27001 or equivalent; (3) without certification, the company's security posture cannot be independently verified; (4) however, ISO 27001 is not legally mandated, and smaller companies often rely on internal controls without formal certification.

Evidence: https://www.cim-mobility.dk, https://www.iso.org/isoiec-27001-information-security.html, https://www.ds.dk/da/standarder/it/informationssikkerhed/iso-27001

GDPR (source) — Partially Compliant

CIM Mobility A/S is headquartered in Denmark (EU) and operates as a data processor and controller for sensitive personal data. Their products — talkiing (counselling chat for vulnerable individuals including children), SMS2GO (SMS gateway handling personal contact data), and CMA (crisis alert system) — all involve processing personal data, including potentially special category data (e.g., mental health disclosures via talkiing used by Børns Vilkår). As a B2B SaaS/platform provider serving Danish municipalities and NGOs, they act as a data processor under GDPR Article 28, requiring robust Data Processing Agreements (DPAs) with all clients. Risk is HIGH because: (1) they process data of vulnerable individuals (children, crisis callers); (2) non-compliance fines can reach €20M or 4% of global annual turnover; (3) Danish DPA (Datatilsynet) is an active enforcement authority; (4) public sector clients impose strict GDPR obligations on their processors; (5) while a Persondatapolitik exists via ComplyCloud, full compliance posture (DPAs, DPIA, RoPA) cannot be confirmed from public sources alone.

Evidence: https://www.cim-mobility.dk, https://gdpr.complycloud.com/externaldocument?id=59048da013865c5a413392dbe631f3cde5976374908296108674108249, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Danish E-Communications Act — Assessment Required

CIM Mobility operates SMS gateways and communications platforms (SMS2GO, NemSMS) that transmit electronic communications. The Danish E-Communications Act (implementing the EU Electronic Communications Code, Directive 2018/1972) regulates providers of electronic communications networks and services. If CIM Mobility is classified as an electronic communications service provider (rather than purely a software/application layer provider), they may be subject to registration requirements with the Danish Business Authority (Erhvervsstyrelsen) and obligations around network security, lawful interception, and emergency communications. Risk is MEDIUM due to the regulatory uncertainty around their classification.

Evidence: https://www.cim-mobility.dk/loesninger/, https://www.retsinformation.dk/eli/lta/2011/169, https://www.erhvervsstyrelsen.dk/tele

Financials

Three-year financials

Financial Resilience Score: 6/10

CIM Mobility A/S is a small, long-established Danish software company (founded ~2004) operating in niche communication and safety software markets. As a registered A/S, it has at least the minimum DKK 400,000 share capital and approximately 20 years of continuous operation, suggesting underlying business stability. The company serves a sticky public-sector customer base including Danish municipalities (e.g., Esbjerg Kommune) and NGOs (e.g., Børns Vilkår/BørneTelefonen), with mission-critical products that have high switching costs. However, the company faces meaningful risks due to its small size, geographic concentration (effectively 100% Denmark), and likely customer concentration among a limited number of municipalities and NGOs. The SMS gateway business is commoditising and faces pressure from larger global CPaaS providers like Twilio, Bird, LINK Mobility, and CM.com. Additionally, there has been limited public visibility since September 2023, which could indicate a quiet period, restructuring, or strategic shift that warrants investigation. Without access to actual financial figures from CVR filings, a definitive resilience score cannot be established, but the qualitative factors suggest moderate resilience typical of a small niche software vendor.

Key strengths: ~20 years of continuous operation since ~2004, Sticky public-sector customer base (Danish municipalities, NGOs), Mission-critical products with high switching costs, Three diversified product lines (SMS2GO, CMA, talkiing) within communication/safety domain, A/S legal structure with minimum DKK 400,000 share capital, Successful technical re-platforming to NGDP completed in 2022

Risk factors: Small company size with concentrated Denmark-only market, Customer concentration risk on a few municipalities and NGOs, SMS gateway business commoditising against global CPaaS competitors (Twilio, Bird, LINK Mobility, CM.com), Limited public visibility/news since September 2023, Key-person risk due to small headcount (~10-25 employees), No geographic diversification or foreign subsidiaries

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report