Digitaliseringsstyrelsen
Denmark · owned by Independent (Denmark) · digst.dk · 54 vendors
The Danish Agency for Digital Government (Digitaliseringsstyrelsen) leads Denmark's ambitious digital development, creating value for citizens, businesses and public organizations. The agency develops and maintains national digital infrastructure including MitID, Digital Post, and other digital government services.
Resilience scores
- Digital Sovereignty: 48
- Digital Resilience: 7
- Financial Resilience: 10
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Mistral AI — Technology — France
- Usercentrics GmbH — Technology — Germany
- and 51 more
Services catalogue
2 services in catalogue across 2 categories; runs on 54 sub-vendors.
- DNS Hosting
- Email Service
Insights
Last updated 2026-07-12 · revision 138
54 direct vendors, 474 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 1
- Italy: 2
- Denmark: 14
Subvendors by controlling owner country (sample)
- UK: 1
- Belgium: 7
- Finland: 4
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Digitaliseringsstyrelsen exhibits moderate migration readiness. Strengths include a modern and interoperable tech stack, characterized by the use of REST APIs, mobile application development, and adherence to 'Open Standards & Interoperability Frameworks' and a 'Common Public-Sector Digital Architecture (FDA)'. The adoption of Generative AI also signals an organizational capacity for embracing new technologies. Financially, consistent revenue growth provides the necessary resources to fund potential migration initiatives. However, significant challenges temper their readiness. The most substantial hurdles are the extremely strict regulatory environment (GDPR, NIS2, AI Act, eIDAS, DSA) and stringent data residency requirements. As a Danish government agency, critical government data and personal data of Danish citizens must generally be processed within the EU/EEA, with specific safeguards for any transfers outside. These requirements severely limit the choice of cloud providers and migration strategies, increasing complexity and cost. The ambiguity surrounding vendor relationships, specifically the contradiction between 'Total Vendors: 0' and the listed 'Vendor HQ Countries', makes it difficult to accurately assess vendor lock-in risk. If vendors are indeed utilized, the geographic diversity (7 countries) could mitigate lock-in, but the actual number of vendors and contract complexities remain unknown. This uncertainty, combined with the high regulatory and data sovereignty constraints, places them in the medium readiness category, as extensive planning and potentially custom solutions would be required for any significant migration.
Compliance
13 in-scope frameworks identified; showing 3.
EU AI Act (source) — Assessment Required
The EU AI Act is directly applicable to Digitaliseringsstyrelsen on two levels: (1) DIGST is the designated national market surveillance authority and competent authority for the AI Act in Denmark, responsible for supervising AI system compliance across Danish public and private sectors; (2) DIGST itself deploys AI systems in public services — including a generative AI assistant on Borger.dk for citizen communications and AI-based solutions documented in its case catalogue. Risk is High because: the AI Act imposes strict obligations on deployers of high-risk AI systems (which public administration AI systems often qualify as under Annex III); DIGST's dual role as regulator and deployer creates governance complexity; non-compliance by a supervisory authority would be reputationally catastrophic; the AI Act's prohibited practices and high-risk system requirements are directly relevant to AI used in citizen-facing public services.
Evidence: https://digst.dk/tilsyn/ai-forordningen/, https://digst.dk/kunstig-intelligens/kommunikation-paa-borgerdk-med-generativ-ai-assistent/, https://digst.dk/kunstig-intelligens/casekatalog-ai-loesninger-med-dokumenteret-effekt/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
NIS2 (source) — Assessment Required
Digitaliseringsstyrelsen occupies a uniquely complex dual position under NIS2: (1) It is the designated NIS2 supervisory authority for the digital sector in Denmark, responsible for overseeing compliance of digital service providers — meaning it administers and enforces NIS2 for others; (2) As an operator of critical national digital infrastructure (MitID national identity system, Digital Post, NemLog-in, NemKonto, AltID, Borger.dk), it may itself qualify as an Essential Entity under NIS2 Annex I categories covering 'public administration' and/or 'digital infrastructure' / 'ICT service management.' Risk is rated High because: the services operated (national digital identity, mandatory digital communications, payment infrastructure) are systemically critical to Danish society; a cybersecurity incident affecting MitID or Digital Post would have cascading national impact; NIS2 imposes strict incident reporting (24-hour early warning, 72-hour notification), risk management measures, and management accountability requirements. The 'Assessment Required' status reflects that while NIS2 clearly applies to the digital sector entities DIGST supervises, the precise scope of DIGST's own obligations as an entity — versus its role as supervisor — requires formal legal determination under Danish implementing law (Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau, Lov nr. 434/2025).
Evidence: https://digst.dk/tilsyn/nis-2/, https://www.retsinformation.dk/eli/lta/2025/434, https://www.retsinformation.dk/eli/lta/2025/620, https://eur-lex.europa.eu/legal-content/DA/TXT/?uri=CELEX:32022L2555, https://www.cfcs.dk/da/opgaver/nis2/nis2-vejledninger/, https://nis2tjek.sikkerdigital.dk/
Data Governance Act — Assessment Required
Digitaliseringsstyrelsen is the designated supervisory authority for the Data Governance Act (DGA) in Denmark and actively promotes re-use of public sector data. Risk is Medium because: (1) DIGST supervises DGA compliance for data intermediaries and data altruism organizations in Denmark; (2) DIGST operates Datavejviser (data directory) and promotes open public data re-use, which must comply with DGA requirements for protected data categories; (3) DIGST's own data sharing activities must comply with DGA provisions on re-use of protected public sector data. The DGA is relatively new (applicable from September 2023) and compliance frameworks are still maturing.
Evidence: https://digst.dk/tilsyn/datastyringsforordningen/, https://digst.dk/data/datastyringsforordningen-og-beskyttede-data/, https://digst.dk/data/datavejviser/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R0868
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 10/10
Digitaliseringsstyrelsen is a Danish central-government agency, not a commercial entity. Its counterparty risk is effectively Kingdom of Denmark sovereign risk (AAA), meaning there is no going-concern risk. Funding is set annually through the Finanslov approved by Folketinget, providing stable and predictable financial backing. The agency operates critical national digital infrastructure (MitID, Digital Post, NemLog-in, NemKonto, borger.dk) with near-universal adoption, making it structurally essential to the Danish state. Digitalisation is a top political priority in Denmark, and the agency's scope has been consistently expanding with new regulatory responsibilities (AI Act, NIS2, DSA supervision transferred in 2024-2025). Some solutions like MitID and NemLog-in are partly co-financed by user-organisations (private-sector service providers and public authorities), providing a semi-commercial funding leg alongside appropriations. The scale and criticality of its operations (94 million MitID transactions/month, 253 million Digital Post messages in 2025) make the agency essentially 'too critical to defund'. Risks are largely operational and political rather than financial. Vendor concentration risk exists with a small number of external suppliers (e.g., Nets/Nexi Group historically for the eID stack). The agency has moved between ministries multiple times, creating budget-line discontinuities. Cyber and operational risks are significant given the national criticality of MitID and Digital Post. Dependence on US hyperscale cloud raises digital sovereignty concerns that could force costly re-platforming.
Key strengths: Sovereign backing from Kingdom of Denmark (AAA), Annual appropriations set in Finansloven by Folketinget, Owns critical national digital infrastructure with near-universal adoption, Co-financing from user-organisations for MitID and NemLog-in, Structurally growing scope and transaction volumes, Strategic political priority for Danish government
Risk factors: Vendor concentration risk with small number of external suppliers, Political/organisational risk from repeated ministry reorganisations, Cyber and operational risk on nationally critical systems, Digital sovereignty exposure to US hyperscale cloud providers, Growing regulatory workload outpacing headcount expansion, Contract-renewal cycles causing spending volatility
Revenue by geography
- Denmark: 100%
Revenue by product/service
- MitID (citizen eID): 30%
- Digital Post: 20%
- NemLog-in: 18%
- NemKonto: 10%
- borger.dk: 10%
- MitID Erhverv: 5%
- Other apps (Sundhedskort, Kørekort, AltID, Digital Fuldmagt, NemSMS): 4%
- Regulatory supervision (AI Act, NIS2, DSA, eIDAS): 3%
Workforce by country
- Denmark: 400
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.