Cortex Consult A/S

Denmark · owned by Advania AB (publ) (Sweden) · cortexconsult.dk · 12 vendors

Cortex Consult A/S is a Danish-owned IT company that provides IT solutions, infrastructure management, cloud services, and cybersecurity to small and medium-sized businesses. The company offers services including IT outsourcing, Microsoft 365 / Modern Workplace solutions, datacenter hosting, network management, and IT security. With over 25 years of experience and approximately 60 employees, it is recognized as one of Denmark's leading IT companies in outsourcing, hosting, and operations.

Resilience scores

Disruption prediction

Cortex Consult A/S has an estimated 17% probability of disruption in the next 6 months.

6 of Cortex Consult A/S's 12 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 14

12 direct vendors, 200 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Cortex Consult A/S demonstrates a medium-to-high level of migration readiness, scoring 65. **Strengths:** * **Extensive Cloud Adoption & Expertise:** The company's core business and internal tech stack are deeply integrated with Microsoft Azure and Microsoft 365. They offer "Managed public cloud services primarily on Microsoft Azure," "Azure Virtual Desktop (AVD)," and "Hybrid Cloud Management." This existing expertise and infrastructure in modern cloud platforms significantly enhance their readiness for further cloud migrations or optimizations within the Microsoft ecosystem. * **Modern Tech Stack:** The reliance on cloud-native services like Azure AD, Intune, and Microsoft Defender for Office 365 indicates a modern, agile tech environment, reducing the complexity typically associated with migrating legacy, monolithic systems. * **Compliance Framework Experience:** Experience with ISO 27001, SOC 2, and ISAE 3402 (for datacenter operations) suggests a foundational understanding of security and compliance requirements, which is crucial for planning secure migrations. **Weaknesses & Challenges:** * **Significant Regulatory & Data Residency Constraints:** As a Danish company and SKI supplier, Cortex Consult A/S must comply with strict "GDPR data residency requirements" and "Danish government data residency requirements," mandating data storage within the EU/EEA or Denmark. This significantly limits the choice of cloud regions and providers for any migration, adding complexity and potential cost. The "High" risk for GDPR and "Medium" risk for NIS2 (both "Assessment Required") highlight ongoing compliance burdens that must be addressed during migration planning. * **High Vendor Lock-in (Microsoft Ecosystem):** While their deep integration with Microsoft Azure and Microsoft 365 is a strength for migrations *within* that ecosystem, it represents a significant vendor lock-in if the company were to consider migrating to a different major cloud provider (e.g., AWS, GCP). Such a migration would involve substantial re-platforming, data transfer, and retraining costs. * **Missing Financial Data:** The absence of "Revenue Concentration by Product", "Revenue Concentration by Geography", and "Growth History" makes it impossible to assess the financial capacity to fund potentially large-scale or complex migrations. * **Unknown Vendor Lock-in Risk:** The "Vendor Lock-in Risk" is explicitly "Unknown", which is a critical missing piece for a full assessment of migration flexibility and cost.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). For an IT managed services provider, cloud services provider, and IT security services company like Cortex Consult A/S, ISO 27001 certification is highly relevant and increasingly expected by enterprise and public sector clients. Risk is Medium because: (1) Cortex provides IT security services (vulnerability scanning, phishing training, security analysis) — operating without ISO 27001 while selling security services creates a credibility and reputational risk; (2) their SKI 02.22 public sector contracts may require or prefer ISO 27001 certification; (3) NIS2 compliance (which is likely applicable) is significantly facilitated by ISO 27001 certification, as the standard's controls map closely to NIS2 Article 21 requirements; (4) the Advania merger may bring ISO 27001 requirements as part of group-level security governance. Risk is not High because ISO 27001 remains voluntary in Denmark, and many Danish SMEs operate without it.

Evidence: https://cortexconsult.dk, https://cortexconsult.dk/it-sikkerhed-generelt/, https://cortexconsult.dk/saerbarhedsscanninger/, https://www.iso.org/standard/27001, https://www.danak.dk/en/

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA, but it has become a de facto market requirement for cloud service providers, managed service providers, and IT outsourcing companies. Cortex Consult A/S provides cloud services (Microsoft Azure, M365), datacenter/hosting, IT infrastructure management, and IT security services — all service categories where enterprise and public sector clients increasingly demand SOC 2 Type II reports as evidence of security controls. Risk is Medium because: (1) without SOC 2 certification, Cortex may lose competitive bids, particularly for larger enterprise or public sector contracts; (2) their SKI 02.22 public sector framework agreement may increasingly require evidence of security assurance; (3) as they grow (and following the Advania merger), customer due diligence requirements will intensify. However, SOC 2 is not legally mandated in Denmark, so the risk is commercial/reputational rather than regulatory.

Evidence: https://cortexconsult.dk, https://cortexconsult.dk/datacenter-hosting/, https://cortexconsult.dk/public-cloud/, https://cortexconsult.dk/it-infrastrukturdrift/

NIS2 (source) — Assessment Required

Cortex Consult A/S is a strong candidate for NIS2 classification as an 'Important Entity' under the 'Digital Providers' or 'ICT Service Management (B2B)' categories. Specifically: (1) They provide managed IT services, cloud services, datacenter/hosting, and IT security services — activities that fall squarely within Annex I (Essential Entities: digital infrastructure) or Annex II (Important Entities: digital providers, managed service providers) of NIS2; (2) With ~60 employees, they meet the 'medium enterprise' threshold (50+ employees) required for NIS2 applicability; (3) They operate in Denmark, an EU member state that transposed NIS2 via the Danish NIS2 Act (Lov om sikkerhed i net- og informationssystemer, in force October 2024); (4) Their SKI 02.22 public sector IT services contract further elevates their risk profile as a supplier to critical public administration entities. Risk is High because: non-compliance with NIS2 can result in fines up to €10M or 2% of global annual turnover for Important Entities; the Danish Centre for Cyber Security (CFCS) and the Danish Business Authority are active supervisory bodies; and as an IT managed services provider, a security incident at Cortex could cascade to dozens of SME and public sector clients, making them a high-value regulatory target.

Evidence: https://cortexconsult.dk, https://cortexconsult.dk/om-cortex/, https://cortexconsult.dk/it-infrastrukturdrift/, https://cortexconsult.dk/datacenter-hosting/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/, https://www.erhvervsstyrelsen.dk/nis2

Financials

Three-year financials

Financial Resilience Score: 7/10

Cortex Consult A/S demonstrates strong qualitative financial resilience despite the absence of retrievable årsrapport figures in this research session. The company has operated continuously since 1998 (27+ years) and has maintained an AAA credit rating from Bisnode/Soliditet uninterrupted since 2002, which is a rare and sustained external signal of solvency, timely payment behavior, and consistent profitability across multiple economic cycles including the dot-com bust, 2008 financial crisis, and COVID-19 pandemic. The business model is anchored in recurring-revenue services (managed IT operations, hosting, Microsoft 365 licensing) that provide strong revenue visibility. Access to the Danish public-sector SKI 02.22 framework agreement adds a layer of predictable, low-credit-risk government/municipal revenue. Strategic alignment with top-tier vendors (Microsoft, Cisco, HPE, Veeam) and the May 2026 combination with Advania further reduce standalone scale and funding risk. However, resilience is capped by the company's small scale (~60 FTE), SMB customer concentration exposing it to macro cycles, heavy dependency on the Microsoft ecosystem, and Danish IT-consultant wage inflation pressuring people-based service margins. Post-merger integration risk into Advania is a new 2026-onward consideration.

Key strengths: AAA credit rating (Bisnode/Soliditet) maintained continuously since 2002, 27+ years of continuous operation since 1998, Recurring-revenue mix from managed IT operations, hosting, and M365 licensing, Approved supplier on Danish public-sector SKI 02.22 framework agreement, Strategic vendor partnerships with Microsoft, Cisco, HPE, and Veeam, May 2026 combination with Advania removes standalone scale/funding risk

Risk factors: SMB customer concentration sensitive to macro slowdowns, Heavy dependency on Microsoft ecosystem (M365, Azure) licensing changes, Small scale (~60 FTE) relative to Nordic MSP consolidators, Danish IT-consultant wage inflation pressures margins, Post-merger integration risk with Advania (brand, customers, staff retention), Effectively 100% Denmark geographic concentration

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report