Danish Agency for Digitisation (via DAREnet)

Denmark · www.digst.dk · 19 vendors

The Danish Agency for Digital Government implements IT projects focused on digitizing Denmark to provide better services to businesses and citizens. It develops and operates national digital service solutions, forms IT policies, and drives cross-public sector cooperation for digital transformation.

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 3 categories; runs on 19 sub-vendors.

Insights

Last updated 2026-03-28 · revision 2

19 direct vendors, 272 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The agency exhibits several strengths that contribute to migration readiness. The presence of a "Common Public Digital Architecture (FDA)" and an "Orkestreringskomponenten" suggests a structured, modular approach to IT development, which is highly beneficial for refactoring and migrating systems. The adoption of modern technologies such as REST APIs, OAuth 2.0/OpenID Connect, and even Generative AI (in borger.dk) indicates a forward-thinking tech strategy and a willingness to embrace contemporary architectural patterns. The diverse vendor base, with partners from 6 different countries, could provide a broader range of expertise and options for migration support. Migration readiness is significantly challenged by the complex and evolving EU regulatory environment, including NIS2, DSA, AI Act, Single Digital Gateway, and Data Governance Act. These regulations impose stringent requirements on data sovereignty, security, and operational compliance, which can severely limit cloud provider choices and increase the complexity and cost of migration. The reliance on specific national standards like OIOSAML and OIOIDWS, alongside the use of SOAP Web Services, suggests a heterogeneous environment that may require significant refactoring or custom integration efforts when moving to more generic cloud-native platforms. Although not explicitly stated, it is highly probable that a national agency like this would have strict data residency requirements, further complicating cloud migration strategies. The lack of financial data prevents an assessment of the agency's capacity to fund a potentially large-scale migration effort. Finally, the unknown vendor lock-in risk means that dependencies on existing vendors or technologies could create unforeseen hurdles during a migration.

Compliance

8 in-scope frameworks identified; showing 3.

DSA — Compliant

The agency has established DSA supervision capabilities and complaint handling procedures, indicating compliance with their supervisory obligations under the Digital Services Act. Risk is low due to their established supervisory framework.

Evidence: https://digst.dk/om-os/privatlivspolitik/

ISAE 3000 (source) — Assessment Required

As a government agency providing assurance and oversight services for digital regulations (NIS2, AI Act, DSA), ISAE 3000 compliance could be relevant for their supervisory and assurance activities. The risk is medium as it would enhance credibility of their oversight functions but is not typically mandatory for government entities.

SOC 2 (source) — Assessment Required

While SOC2 is not mandatory, as a provider of critical digital services to Danish citizens and businesses (MitID, Digital Post, citizen portals), implementing SOC2 controls would demonstrate strong security and operational practices. Given their role in national digital infrastructure, stakeholders may expect SOC2-level controls even if not formally certified. The risk is medium as it's not legally required but could impact trust and service quality.

Financials

Three-year financials

Financial Resilience Score: 9/10

Digitaliseringsstyrelsen is a sovereign-backed Danish government agency funded entirely through the Danish state budget (Finansloven), approved annually by the Folketing. Its financial resilience is effectively equivalent to that of the Danish state itself, which carries a AAA sovereign credit rating. There is no meaningful risk of insolvency, liquidity crisis, or revenue shortfall in any conventional commercial sense. The agency operates on a near-zero net result by design, with expenditures broadly matched to appropriations each year, and any small surplus or deficit (estimated at ±DKK 10–30 million) is absorbed within state accounting rules. The agency holds a legally mandated monopoly over Denmark's core digital public infrastructure — including MitID (used by ~97% of Danes over 15, processing ~95 million transactions per month), Digital Post (~252 million messages per year), NemKonto (~102 million payments per year), NemLog-in (~25 million logins per month), and borger.dk (~111.5 million visits in 2024). These services are classified as critical national infrastructure with no commercial competition, ensuring sustained political and budgetary priority. EU co-funding through programmes such as Digital Europe and DAREnet provides supplementary income for innovation projects. The agency's budget has grown steadily since its establishment in 2011, with step-changes around major infrastructure projects such as the Digital Post mandate (~2014) and the MitID rollout (~2021–2022). The creation of a dedicated Digitaliseringsministeriet in 2023–2024 has elevated the agency's political profile further. With approximately 400 employees and a lean operational structure relative to the scale of infrastructure managed, the agency demonstrates efficient resource utilisation. User satisfaction metrics are strong (MitID 83%, Digital Post 76%, borger.dk 70%), reinforcing the agency's societal legitimacy and political support. The primary risks are operational and political rather than financial. These include IT project execution risk on large-scale programmes, cybersecurity exposure as operator of critical national infrastructure, growing regulatory scope (NIS 2, AI Act, DSA, eIDAS 2.0) without proportional headcount growth, vendor concentration in large IT contracts, and the theoretical risk of government restructuring or budget reallocation. None of these risks threaten the agency's financial existence, but they could affect operational capacity and delivery quality.

Key strengths: 100% sovereign state funding via Danish Finance Act (Finansloven) — effectively AAA-rated counterparty, Legally mandated monopoly on Denmark's core digital public infrastructure (MitID, Digital Post, NemKonto, NemLog-in, borger.dk), Critical national infrastructure status ensuring sustained political and budgetary priority, Massive operational scale: 95M MitID transactions/month, 252M Digital Post messages/year, 102M NemKonto payments/year, High user satisfaction scores (MitID 83%, Digital Post 76%, borger.dk 70%), EU co-funding supplementing state appropriations (Digital Europe Programme, DAREnet, eIDAS cross-border), Stable ~400-employee workforce with lean structure relative to infrastructure scope, Growing mandate (AI governance, NIS 2 supervision, DSA, eIDAS 2.0) ensuring long-term relevance, Established since 2011 with consistent budget growth trajectory

Risk factors: Full budget dependency on state appropriations — political decisions to cut public spending could affect resources, IT project execution risk on large-scale programmes (e.g., eIDAS 2.0, AI integration) — MitID rollout experienced challenges, High-value cybersecurity target as operator of critical national digital infrastructure, Vendor concentration risk from large IT contracts with small number of major suppliers, Scope expansion pressure — growing regulatory mandate (NIS 2, AI Act, DSA) without proportional headcount growth, No commercial revenue diversification — almost entirely dependent on state appropriations, Risk of government restructuring or ministerial reorganisation altering agency mandate, PDF annual reports not directly accessible for precise figure extraction — estimates carry uncertainty

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report