Danova A/S

Denmark · owned by JAN BIDSTED HOLDING ApS (Denmark) · danova.dk · 12 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 12 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

12 direct vendors, 167 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Danova A/S demonstrates medium migration readiness. A key strength is that their core 'Danova Data Cloud' is already a proprietary online data platform, ISO/IEC 27001 certified and NIS2 compliant, indicating existing experience with cloud infrastructure and a strong understanding of compliance requirements. This foundation means a significant portion of their data and services are already in a cloud environment. The WordPress website is also generally portable. However, a notable challenge is the reliance on the 'Microtronics myDatanet Platform' as the backend for their core data cloud. This proprietary platform could introduce significant vendor lock-in, making migration to a different cloud provider or a custom-built solution complex and potentially costly. The assessment is also limited by the absence of data on specific data residency requirements, which could impact migration strategies, and financial stability, which is crucial for funding a migration. There is no explicit mention of modern cloud-native practices like containerization or microservices, which would typically indicate higher readiness.

Compliance

9 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC 2 is a US-origin voluntary auditing framework developed by the AICPA, applicable to service organizations that store, process, or transmit customer data in the cloud. Danova operates a cloud-based Data Cloud platform (data.danova.dk) used by water utilities and municipalities to access operational measurement data. While SOC 2 is not legally mandated in Denmark or the EU, it is increasingly requested by enterprise customers (especially those with international operations or US-linked procurement requirements) as evidence of security controls. Risk is Medium because: (1) Danova's utility customers may request SOC 2 reports as part of vendor due diligence; (2) the company has pursued ISO 27001 instead, which is the European equivalent and generally preferred in the EU market; (3) absence of SOC 2 could be a commercial barrier if Danova pursues export markets (mentioned as a strategic ambition). No evidence of SOC 2 audit was found.

Evidence: https://danova.dk/serviceydelser/data-cloud/, https://danova.dk/om-os/

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (CRA), entered into force December 2024 with phased compliance deadlines (most requirements apply from December 2027), introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market. Danova manufactures and sells hardware products with digital connectivity (data loggers, level sensors, flow meters with IoT/cloud connectivity feeding into the Danova Data Cloud). These products likely qualify as 'products with digital elements' under the CRA. Risk is Medium because: (1) the CRA will apply to Danova as a manufacturer of connected measurement devices; (2) compliance deadlines are 2027, giving time to prepare; (3) Danova's existing ISO 27001 certification provides a foundation; (4) however, CRA introduces new conformity assessment, vulnerability disclosure, and software update obligations that go beyond ISO 27001.

Evidence: https://danova.dk/serviceydelser/data-cloud/, https://danova.dk/produkter/dataloggere/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847

NIS2 (source) — Partially Compliant

NIS2 applicability to Danova ApS is nuanced and requires careful analysis. Danova is a supplier of measurement equipment and a cloud data platform to the water/wastewater utility sector — a sector explicitly listed under NIS2 Annex I (Essential Entities: 'drinking water' and 'wastewater'). However, Danova itself is not a water utility operator; it is a technology/engineering supplier to those operators. Under NIS2, direct applicability depends on whether Danova qualifies as a 'digital infrastructure' or 'ICT service management' provider, or whether it falls under supply chain obligations imposed on its utility customers. Critically, Danova's own Data Cloud page explicitly states their platform has 'ISO/IEC 27001 certification that fulfills NIS2,' indicating the company is actively positioning itself as NIS2-compliant — suggesting they have self-assessed NIS2 as applicable or relevant to their business. Risk is Medium because: (1) if Danova is classified as an ICT service provider to critical infrastructure operators, direct NIS2 obligations may apply; (2) even if not directly subject, their utility customers (Essential Entities under NIS2) will impose NIS2 supply chain security requirements on Danova; (3) the company appears to have proactively addressed this via ISO 27001 certification. Size threshold (50+ employees or €10M+ turnover) is unconfirmed from public sources.

Evidence: https://danova.dk/serviceydelser/data-cloud/, https://danova.dk/it-sikkerhed-for-data-og-nis2-danova-data-cloud-i-frontlinjen/, https://danova.dk/om-os/, https://www.cfcs.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Financials

Three-year financials

Financial Resilience Score: 6/10

Danova ApS operates in a stable, non-cyclical niche serving Danish municipal water/wastewater utilities and industrial process customers, providing a degree of demand resilience. The company has a 30+ year operating history, suggesting durability through multiple economic cycles. Recurring revenue components from annual calibration/verification contracts, equipment rental, and the Data Cloud subscription platform likely provide cash flow visibility beyond one-off hardware sales. Regulatory tailwinds from EU and Danish focus on wastewater overflow monitoring and climate adaptation support ongoing demand. However, the ApS legal form and single Danish office indicate a small-scale operation with limited financial buffer. Geographic concentration in Denmark (likely >90% of revenue), reliance on foreign OEM brand distribution (e.g., UWT), and typical SME key-person risk temper the resilience assessment. No verified financial figures were available in this research session, so the score reflects qualitative business model assessment only. A definitive score would require review of årsrapport filings from datacvr.virk.dk.

Key strengths: 30+ year operating history in specialized instrumentation niche, Recurring revenue from calibration, rental, and Data Cloud subscription services, Non-cyclical regulated end market (Danish municipal water/wastewater utilities), ESG and regulatory tailwinds for wastewater and emissions monitoring, High switching costs and local application expertise with utility customers

Risk factors: Small company scale (ApS) with limited financial buffer, Geographic concentration in Denmark with minimal export diversification, Distribution dependency on foreign OEM brands (UWT and others), Key-person and small ownership group risk typical of Danish SME ApS, Competition from larger instrumentation players (Endress+Hauser, Krohne, Siemens, VEGA), Single Danish location creates operational concentration risk

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report