CPSMS

Denmark · www.cpsms.dk · 8 vendors

CPSMS.DK, operated by Compaya A/S, provides an online SMS gateway service for businesses and individuals. It facilitates sending bulk SMS, two-way communication, and integration with other IT systems via a well-documented API. The service emphasizes secure and GDPR-compliant messaging solutions.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 8 sub-vendors.

Insights

Last updated 2026-07-03 · revision 6

8 direct vendors, 124 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

CPSMS exhibits low migration readiness. While the company benefits from a modern, API-driven architecture (RESTful API, JSON) and a strong historical financial performance that could fund a migration, several factors significantly impede readiness. The most substantial challenge is the strict data residency requirement under GDPR, mandating data processing and storage within EU/EEA boundaries. This severely limits the choice of cloud providers and geographic regions for migration, adding complexity and potentially increasing costs. The pending 'Assessment Required' status for NIS2 compliance also introduces uncertainty, as any migration would need to ensure adherence to these evolving cybersecurity directives, potentially requiring additional effort and investment. Furthermore, the lack of explicit cloud-native technologies such as containerization or microservices in the internal tech stack suggests a more traditional deployment model, which typically requires greater refactoring effort during a cloud migration. Finally, the 'Vendor Lock-in Risk' is 'Unknown', which is a critical impediment. Without clarity on vendor dependencies, contract complexities, and the number of distinct vendors (especially given the 'Total Vendors: 0' anomaly in the data, which makes assessing vendor relationships difficult), the potential for high lock-in could significantly complicate and delay any migration efforts.

Compliance

9 in-scope frameworks identified; showing 3.

Danish Marketing Practices Act — Assessment Required

CPSMS explicitly offers SMS marketing and customer club services, which are directly subject to the Danish Marketing Practices Act (Markedsføringsloven) and the EU ePrivacy Directive (implemented in Denmark via the Marketing Practices Act and the Executive Order on Information Security). These rules govern consent requirements for commercial electronic communications, opt-out mechanisms, and sender identification. As a data processor enabling SMS marketing for business customers, CPSMS must ensure its platform supports customers' compliance with these rules. The risk is Medium because: (1) SMS marketing is a high-scrutiny area for Danish regulators (Forbrugerombudsmanden); (2) violations can result in fines and injunctions; (3) the company's responsibility as a processor is limited but reputational risk from facilitating non-compliant marketing exists.

Evidence: https://www.cpsms.dk/sms-markedsfoering.php, https://www.cpsms.dk/sms-kundeklub.php, https://www.cpsms.dk/persondatapolitik.php

ISAE 3402 — Compliant

CPSMS explicitly states its platform is operated in an ISAE 3402-certified datacenter. ISAE 3402 provides assurance on the design and operating effectiveness of controls at service organizations. This certification of the hosting infrastructure reduces operational and financial reporting risk for CPSMS's customers. The risk level is Low as this is a confirmed, third-party-verified control environment for the underlying infrastructure.

Evidence: https://www.cpsms.dk, https://www.cpsms.dk/gdpr.php

GDPR (source) — Compliant

GDPR is universally applicable as Compaya A/S is headquartered in Denmark (EU) and processes personal data of EU residents both as a data controller (employee/customer data) and as a data processor (SMS recipient data on behalf of clients). The risk level is Medium rather than Low because CPSMS processes personal data at scale on behalf of many business customers — including mobile numbers and potentially names of end-recipients — which creates ongoing processor obligations. However, the company has demonstrably invested in compliance: it publishes an annual ISAE 3000 declaration, maintains a formal Data Processing Agreement (DPA) framework, and has a published Privacy Policy. Enforcement by the Danish Datatilsynet is active and credible, but the company's documented compliance posture reduces residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover, maintaining a Medium risk profile.

Evidence: https://www.cpsms.dk/gdpr.php, https://www.cpsms.dk/persondatapolitik.php, https://www.cpsms.dk/files/COMPAYA-ISAE-3000.pdf, https://www.datatilsynet.dk

Financials

Financial Resilience Score: 6/10

CPSMS (operated by Compaya A/S) demonstrates qualitative signs of financial resilience despite the absence of retrievable hard financial data in this session. The company has a long operating history (~20 years since 2006) in the Danish A2P SMS gateway niche, and earned the Børsen Gazelle award four consecutive years (2013-2016), which requires at least doubling of revenue over four years combined with positive earnings each year. This is strong evidence of a historically profitable, growing business. The company benefits from an asset-light, transactional pay-per-SMS model with recurring revenue characteristics and blue-chip Danish customer references including YouSee, TDC, Fullrate, and DagliBrugsen. High customer satisfaction (Trustpilot 4.7/5 across ~600 reviews) and compliance posture (ISAE 3402 data centre, GDPR, SSL, 99.99% uptime) reduce operational risk. However, the score is tempered by structural headwinds: OTT messaging (WhatsApp, RCS, push notifications) pressures SMS volumes long-term; rising A2P SMS termination fees from mobile operators squeeze gateway margins; customer concentration among a few large telcos/retailers creates single-client exposure; and the business is ~100% concentrated in Denmark (DKK) with no geographic diversification. Competition from larger, better-capitalised players (GatewayAPI, LinkMobility, Sinch, CM.com) is intensifying. Actual three-year revenue, EBIT and equity figures were not retrievable from CVR/Proff in this session, so the score reflects qualitative signals only.

Key strengths: ~20 years operating history (founded 2006), Børsen Gazelle award 2013, 2014, 2015, 2016 (four consecutive years of doubled revenue with positive earnings), Blue-chip Danish customer base: YouSee, TDC, Fullrate, DagliBrugsen, Trustpilot rating 4.7/5 across ~600+ reviews, Asset-light pay-per-SMS transactional model with recurring revenue, ISAE 3402-certified data centre, 99.99% uptime, GDPR/SSL compliance, D&B/Bisnode Live Rating indicating active credit rating

Risk factors: Structural pressure on SMS from OTT messaging (RCS, WhatsApp Business, push, email), Rising wholesale A2P SMS termination fees squeezing gateway margins, Customer concentration risk among a few large telcos and retail chains, ~100% revenue concentration in Denmark / DKK with no geographic diversification, Intense competition from larger players (GatewayAPI, LinkMobility, Sinch, CM.com), Small private company with limited financial transparency, Post-2016 growth likely matured with no further Gazelle recognitions

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report