Cystotech ApS

Denmark · owned by Independent (Denmark) · cystotech.com · 7 vendors

Cystotech ApS is a Danish medtech company based in Aarhus that develops AI-assisted clinical decision support software for cystoscopy, focused on improving bladder cancer detection and care. Their flagship product, CystoAID®, is a CE/MDR-certified Class IIb Software as a Medical Device that integrates with existing cystoscopy systems to provide real-time AI-assisted support to clinicians during bladder cancer procedures. The company was founded by clinicians and software engineers with the mission to reduce missed tumors, false positives, and the overall burden of bladder cancer care across Europe and beyond.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 7 sub-vendors.

Insights

Last updated 2026-09-13 · revision 14

2 direct vendors, 83 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Cystotech ApS demonstrates low migration readiness, primarily due to the fundamental architecture of its core product, CystoAID®. The product is explicitly designed for 'On-premise Edge Computing' with 'no cloud dependency' and '3G-SDI Video Integration'. This design choice, while beneficial for current data residency compliance, means the core business is not cloud-native, making a migration to a cloud environment a significant and complex undertaking. Furthermore, migrating the processing of sensitive patient health data to the cloud would likely increase, rather than decrease, regulatory complexity under GDPR, the Danish Data Protection Act, and the EU AI Act, particularly concerning data residency and international transfer mechanisms, which are currently simplified by the on-premise model. The company's unproven financial stability (early-stage, no revenue data) suggests limited resources to fund a major re-architecture and migration effort. A 'Medium' vendor lock-in risk also exists. While internal tools like Atlassian and Wix are cloud-based, they do not represent the core product's architecture. The specialized nature of the 3G-SDI integration also presents a technical challenge for cloud migration. Therefore, the company faces substantial technical, financial, and regulatory hurdles for any significant migration of its core offering.

Compliance

8 in-scope frameworks identified; showing 3.

ISO 13485 — Compliant

Risk is Low because: (1) Cystotech explicitly states their QMS is based on ISO 13485:2016 on their published policies page; (2) ISO 13485 certification is a prerequisite for CE marking under EU MDR, and Cystotech has achieved MDR Class IIb CE marking (April 2025), providing strong indirect evidence of ISO 13485 compliance; (3) the quality policy, risk management policy, and vulnerability disclosure policy are all published and dated, indicating an active and documented QMS; (4) ongoing clinical trials and post-market surveillance activities are consistent with ISO 13485 requirements for continual improvement and monitoring.

Evidence: https://www.cystotech.com/policies, https://www.cystotech.com/about, https://www.iso.org/standard/59752.html

EU Cybersecurity Act — Assessment Required

Risk is Medium because: (1) CystoAID® is a connected medical device (interfaces with hospital cystoscopy systems via 3G-SDI) and cybersecurity is a mandatory MDR requirement; (2) MDCG 2019-16 guidance on cybersecurity for medical devices applies to Cystotech's product; (3) the EU Cybersecurity Act establishes ENISA's role and cybersecurity certification schemes that may apply to medical AI systems; (4) the published vulnerability disclosure policy and cybersecurity references in the risk management policy indicate awareness but formal cybersecurity certification is not confirmed; (5) hospital IT security teams will scrutinize CystoAID®'s cybersecurity posture during procurement.

Evidence: https://www.cystotech.com/policies, https://www.enisa.europa.eu/, https://health.ec.europa.eu/system/files/2020-09/md_mdcg_2019_16_guidance_cybersecurity_en_0.pdf

GDPR (source) — Partially Compliant

Risk is High because: (1) Cystotech processes special category health data (live cystoscopy video of bladder cancer patients) under Article 9 GDPR, which carries the strictest obligations and highest fines (up to €20M or 4% of global annual turnover); (2) as a medical AI SaMD vendor, Cystotech's customers (hospitals) are data controllers and Cystotech likely acts as a data processor, requiring formal Data Processing Agreements (DPAs) under Article 28; (3) the on-premise architecture reduces but does not eliminate GDPR exposure — patient video data is processed in real time on hospital premises using Cystotech software; (4) Denmark's Datatilsynet is an active enforcement authority; (5) the company is early-stage with a published GDPR statement covering only support-site data, with no evidence of a formal DPO appointment, comprehensive privacy policy, or Article 28 DPA framework publicly disclosed; (6) AI systems processing health data may require Data Protection Impact Assessments (DPIAs) under Article 35.

Evidence: https://www.cystotech.com/policies, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Financials

Three-year financials

Financial Resilience Score: 4/10

Cystotech ApS is a young, Aarhus-based clinical-AI medtech founded around 2022, currently in a pre-commercial/early-commercialization phase. Its financial profile is characteristic of an early-stage medtech: revenue is likely negligible, operating results likely loss-making due to R&D-heavy burn (multiple clinical studies RAISE01/02/03, regulatory work, and AI development), and financing is via equity from founders and likely seed/venture rounds. Specific årsrapport figures for revenue, EBIT, and equity could not be retrieved and should be verified through datacvr.virk.dk. Despite the weak financial disclosure and pre-revenue status, the company has meaningful qualitative strengths: strong clinical validation with two peer-reviewed studies (96.2% sensitivity, 88.1% PPV), clinician-founder leadership, KOL endorsements including Prof. Ashish M. Kamat, and a large addressable market (~$12B annually in EU+US for bladder cancer care). The device-agnostic, on-premise, plug-and-play product design reduces hospital IT/procurement friction. However, resilience is constrained by typical early-medtech risks: cash-burn runway dependent on continued fundraising, regulatory dependency on CE-MDR and eventual FDA clearances, long hospital sales cycles for AI software adoption, and competition from established players like Olympus/Medtronic partnerships and incumbent blue-light cystoscopy solutions (Cysview/Hexvix). The small ApS structure also limits financial transparency for outside stakeholders.

Key strengths: Clinically validated technology with two peer-reviewed studies (RAISE01 and RAISE02), Clinician-founded with strong domain credibility (Co-founder/CMO Jacob Elmose Jensen, MD), KOL endorsements including Prof. Ashish M. Kamat (President, International Bladder Group), Large addressable market (~$12B annually in EU + US bladder cancer care), Device-agnostic, plug-and-play, on-premise product design reduces adoption friction, Transitioning from R&D/clinical-evidence phase into early-commercialization phase

Risk factors: Pre-revenue / early-revenue stage with typical medtech cash-burn risk, Runway depends on continued fundraising, Regulatory dependency on CE-MDR and eventual FDA clearances, Long hospital sales cycle for capital equipment / AI software in urology, Competition from Olympus/Medtronic partnerships and incumbent blue-light cystoscopy (Cysview/Hexvix), Small ApS structure with limited financial disclosure to outside investors

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report