Danish e-Infrastructure Cooperation
Denmark · owned by Danish Ministry of Higher Education and Science (Denmark) · www.deic.dk · 10 vendors
The Danish e-Infrastructure Cooperation (DeiC) is the national agency that develops and operates the Danish national digital research infrastructure. This includes services in the fields of network, high-performance computing (HPC), and data management.
Resilience scores
- Digital Sovereignty: 50
- Digital Resilience: 8
- Financial Resilience: 8
Disruption prediction
Danish e-Infrastructure Cooperation has an estimated 27% probability of disruption in the next 6 months.
2 of Danish e-Infrastructure Cooperation's 10 vendors monitored for disruptions.
Technology vendors
- HostNordic A/S — Technology — Denmark
- i2r A/S — Denmark
- WebPros International GmbH — Technology — Switzerland
- and 7 more
Services catalogue
5 services in catalogue across 2 categories; runs on 10 sub-vendors.
- DNS Hosting
- DNS
- Network Infrastructure / Web Hosting
Insights
Last updated 2026-05-18 · revision 10
10 direct vendors, 159 subvendors
Direct vendors by controlling owner country (sample)
- Australia: 1
- Switzerland: 1
- United States: 3
Subvendors by controlling owner country (sample)
- China: 2
- United States: 120
- France: 5
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
DeiC exhibits high migration readiness, primarily driven by its advanced technological adoption and strategic approach to cloud services. A significant strength is the strong adoption of containerization technologies (Singularity/Apptainer, Cotainr), which makes workloads highly portable and simplifies deployment across different environments, including cloud platforms. The organization's engagement with commercial cloud providers through the OCRE framework (e.g., AWS, Azure, Google Cloud) demonstrates a clear strategy and experience in leveraging external cloud infrastructure. The internal tech stack is modern, with no apparent legacy systems that would typically hinder migration. DeiC's internal expertise in compliance (DeiC Compliance, DPO-tjenesten) is a valuable asset for navigating complex regulatory requirements like GDPR and NIS2 during any migration process. Similar to resilience, despite the contradictory "Total Vendors: 0" in the data, the listed geographic diversity of vendor HQs (6 countries) suggests a less concentrated vendor ecosystem, which can reduce vendor lock-in and simplify migration efforts. However, challenges exist, notably the strict data residency requirements (primarily within Denmark, complying with EU regulations), which will necessitate careful planning for data placement and compliance in cloud environments. The lack of public financial data also prevents an assessment of the organization's capacity to fund potentially large-scale migration projects. Lastly, the "Vendor Lock-in Risk" remains unknown, which could present unforeseen hurdles.
Compliance
4 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
DeiC operates critical digital infrastructure for Danish research and education sector, including national research networks, supercomputing facilities, and cybersecurity services (DKCERT). As a provider of digital infrastructure services in the EU, they likely qualify as an Important Entity under NIS2. High risk due to potential significant penalties (up to €10M or 2% of annual turnover) and operational requirements. The organization appears to meet size thresholds and operates in digital infrastructure sector.
Evidence: https://www.deic.dk/da/sikkerhed, https://cert.dk/organisation, https://www.deic.dk/da/sikkerhed/tjenester/deic-compliance
ISO 27001 (source) — Assessment Required
DeiC operates critical digital infrastructure and handles sensitive research data, making information security management crucial. They provide cybersecurity services through DKCERT and compliance consulting, suggesting awareness of information security frameworks. Medium risk as ISO 27001 is important for demonstrating systematic information security management but non-compliance doesn't carry direct legal penalties.
Evidence: https://www.deic.dk/da/sikkerhed/tjenester/deic-compliance
GDPR (source) — Compliant
DeiC is located in Denmark (EU) and processes personal data through their services including employee data, researcher data, and institutional data. They have established DPO services and compliance frameworks. Risk is Medium due to the complexity of their data processing activities across multiple research institutions and the high penalties for non-compliance (up to 4% of annual turnover), but they demonstrate active compliance measures.
Evidence: https://www.deic.dk/da/sikkerhed/tjenester/dpo-tjenesten, https://www.deic.dk/da/sikkerhed/tjenester/deic-compliance
Financials
Three-year financials
- 2025: revenue DKK 150.6M
- 2024: revenue DKK 141.7M
- 2023: revenue DKK 133M
Financial Resilience Score: 8/10
DeiC demonstrates strong financial resilience due to its status as a Danish state-funded public-sector cooperation body with highly stable, multi-source funding. The organization receives an annual Finance Act grant (DKK 55.2M in 2025, rising to DKK 55.7M in 2026), matched 1:1 by the eight Danish universities (DKK 29.5M in 2025), plus user fees for Forskningsnettet (~DKK 58M), plus an annual Research Reserve quantum grant (DKK 39.4M in 2025, DKK 30M in 2026). This diversified funding structure significantly reduces dependency on any single revenue stream. DeiC maintains large accumulated reserves, with significant unspent funds rolled over each year (DKK 65.9M in main budget at start of 2025; DKK 62M on quantum). The board explicitly plans to spend these down over 2026-2031 on major investments including a new DeiC Interactive HPC contract (DKK 10M/yr + DKK 4M one-off GPU) and LUMI AI Systems co-financing of DKK 45.3M in 2027. Legal/political backing is defined in Executive Order BEK 615/2023, with the agreement between Ministry (UFS) and Rectors' College running at least to 2027. However, there is strategic uncertainty in 2025-2026 following the Rectors' College request in May 2025 for a 'new direction' for DeiC, leading to chairperson resignation and a mid-term evaluation underway in 2026. Additionally, the DeiC Storage project was wound down in October 2025, and the quantum grant is declining from DKK 39.4M to DKK 30M in 2026.
Key strengths: Stable multi-source funding from Finance Act, universities, user fees, and Research Reserve, Large accumulated reserves of DKK 120+ million across all ledgers, Legal backing via Executive Order BEK 615/2023, Agreement with Rectors' College runs through at least 2027, 13+ year institutional history with continuous annual reporting since 2012, Diversified activities across network, HPC, data management, security, and quantum
Risk factors: Strategic uncertainty from Rectors' College request for 'new direction' in May 2025, Mid-term evaluation underway in 2026 with results expected mid-2026, DeiC Storage project wound down in October 2025, Quantum grant declining from DKK 39.4M (2024-2025) to DKK 30M in 2026, Dependency on continued political/Rektorkollegiet agreement, Cost inflation in international participation (NORDUnet, LUMI AI, EuroCC3), Underutilisation risk on LUMI-G allocations vs actual researcher usage
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Forskningsnettet (network operations, DKCERT, WAYF, Zoom): 30%
- HPC (LUMI + national systems): 24%
- Quantum (Q-Algorithm, Q-Access, Q-Competence): 16%
- Other/Unallocated: 9%
- Administration, communication, common costs: 7%
- KOR (Register Research coordination): 6%
- Data Management (Dataverse, DMP, DataCite): 5%
- Co-financing of Nordic / NeiC / NT-1: 2%
- International co-funding (EuroCC2, EPICURE, LUMI AI): 1%
Workforce by country
- Denmark: 70
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.