DinnerBooking

Denmark · owned by Independent (Denmark) · dinnerbooking.com · 19 vendors

DinnerBooking is a Danish SaaS company that provides online restaurant reservation and management software to over 1,400 restaurants across 13+ countries, primarily in the Nordic region and Europe. Founded in 2004 as SystemBook by Christian Thygesen and rebranded to DinnerBooking in 2008, the platform enables guests to discover restaurants, read reviews, and book tables online, while giving restaurant operators tools for reservation management, events, gift cards, and loyalty programmes. The company is headquartered in Copenhagen, Denmark.

Resilience scores

Disruption prediction

DinnerBooking has an estimated 11% probability of disruption in the next 6 months.

7 of DinnerBooking's 19 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 19 sub-vendors.

Insights

Last updated 2026-09-13 · revision 3

19 direct vendors, 217 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DinnerBooking demonstrates a moderate level of migration readiness, primarily driven by its modern technological foundation. The company transitioned to cloud hosting in 2008 and operates a SaaS platform with a RESTful API, indicating an architecture that is likely modular and less reliant on legacy on-premise infrastructure. This cloud-native approach, coupled with native iOS and Android applications, suggests a relatively straightforward technical migration path compared to companies with older, monolithic systems. However, several factors present challenges and reduce the overall readiness score. The most significant is the lack of publicly available financial data (revenue concentration, growth history), which makes it difficult to assess the company's capacity to fund a potentially complex and costly migration effort. Strict data residency requirements, mandating data storage within the EU/EEA, limit the choice of cloud providers and regions, adding complexity and potentially cost to any migration strategy. While the company is compliant with GDPR and NIS2, ensuring continued adherence during and after migration will require careful planning and execution, adding to the regulatory burden. The vendor landscape also introduces uncertainty: while there's geographic diversity among vendor HQs and owners, the 'Total Vendors: 0' data point is contradictory. Assuming there are vendors for the 16 services, the unknown number of distinct vendors and the explicitly stated 'Vendor Lock-in Risk: Unknown' are significant concerns. High vendor lock-in could complicate migration by making it difficult or expensive to switch providers or integrate new systems. The absence of specific details on containerization or microservices, while implied by a modern SaaS architecture, means the exact technical effort for re-platforming or re-architecting remains somewhat unclear.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 risk is Medium for DinnerBooking. The company operates a cloud-based SaaS platform (online marketplace/digital platform) across 13+ EU countries, which places it in the 'digital providers' category under NIS2 Annex II (Important Entities). Specifically, NIS2 covers 'online marketplaces', 'online search engines', and 'cloud computing services' as digital providers. DinnerBooking's platform functions as an online marketplace connecting restaurants and diners, and as a cloud SaaS booking system for restaurants. The size threshold (50+ employees OR €10M+ annual turnover) is uncertain from public sources — the company has 22+ years of operation and 1,400+ restaurant clients across 13 countries, suggesting it may meet the threshold, but exact employee count and revenue are not publicly disclosed. If thresholds are met, NIS2 compliance obligations (risk management measures, incident reporting within 24/72 hours, supply chain security, business continuity) would apply. The risk level is Medium rather than High because: (1) sector classification as 'digital provider' under NIS2 is plausible but not certain (it is not a pure cloud infrastructure provider); (2) size threshold is unconfirmed; (3) NIS2 enforcement is still being implemented across EU member states (Denmark's NIS2 transposition via 'Lov om net- og informationssikkerhed' came into force in late 2024). Non-compliance risk is real but dependent on threshold confirmation.

Evidence: https://biz.dinnerbooking.com/en-gb/about-us/, https://dinnerbooking.com/dk/en-US, https://www.nis2directive.eu/, https://www.cfcs.dk/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

SOC 2 (source) — Assessment Required

SOC 2 risk is Medium for DinnerBooking. While SOC 2 is a voluntary framework (not a legal mandate), it is increasingly expected by enterprise restaurant clients and B2B SaaS customers as evidence of security, availability, processing integrity, confidentiality, and privacy controls. DinnerBooking operates as a cloud SaaS provider processing sensitive personal data (including payment card data and dietary/allergy information) for 1,400+ restaurant clients across 13 countries. The absence of a publicly available SOC 2 report creates a competitive and reputational risk, particularly as restaurant chains and hospitality groups increasingly require SOC 2 Type II reports from their technology vendors. The risk is Medium rather than High because SOC 2 is not legally mandated and enforcement is market-driven rather than regulatory. However, failure to obtain SOC 2 certification could result in loss of enterprise clients and inability to participate in certain procurement processes.

Evidence: https://biz.dinnerbooking.com/en-gb/about-us/, https://terms.dinnerbooking.com/en-us/privacy/, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

ISO 27001 (source) — Assessment Required

ISO 27001 risk is Medium for DinnerBooking. As a cloud SaaS provider processing personal data for 1,400+ restaurants across 13 countries, information security management is critical. ISO 27001 certification is increasingly expected by enterprise clients and is relevant to demonstrating GDPR compliance (particularly Art. 32 on security of processing). The absence of publicly available ISO 27001 certification creates reputational and competitive risk. The risk is Medium because: (1) ISO 27001 is voluntary (not legally mandated in Denmark for this sector); (2) the company may have equivalent internal security controls without formal certification; (3) GDPR Art. 32 requires 'appropriate technical and organisational measures' which ISO 27001 would help demonstrate. Non-certification does not automatically mean non-compliance with security requirements, but it increases the difficulty of demonstrating compliance to regulators and clients.

Evidence: https://biz.dinnerbooking.com/en-gb/about-us/, https://terms.dinnerbooking.com/en-us/privacy/, https://www.iso.org/isoiec-27001-information-security.html, https://www.ds.dk/en

Financials

Three-year financials

Financial Resilience Score: 6/10

DinnerBooking demonstrates meaningful qualitative resilience despite the absence of verified financial figures in this session. The company has a 20+ year operating history (founded 2004), an entrenched B2B SaaS base of 1,400+ restaurants, and a two-sided marketplace generating 20+ million guest bookings annually. Revenue is diversified across SaaS subscriptions, event ticketing, gift cards, prepayment handling, and a loyalty programme (DinnerPoints), with a geographic footprint spanning 13+ countries. Sticky, recurring subscription revenue from restaurant management software—which is deeply embedded in operational workflows—provides predictable ARR and high switching costs. However, the company faces material risks. It competes against well-capitalised global players (TheFork, OpenTable, SevenRooms, Quandoo, Resy, Tock) with much larger marketing budgets. As a Danish ApS, it is likely bootstrapped/founder-controlled with limited access to growth capital versus VC-backed rivals. Its exposure to hospitality-sector cyclicality (COVID-19, cost-of-living, energy shocks) has historically caused churn. Revenue is likely concentrated in Denmark/Nordics despite the 13-country footprint, and financial transparency is limited due to small ApS disclosure rules. Key-person/family-ownership risk (Thygesen brothers) is also present. Overall, the profile suggests a stable, mature niche player with moderate resilience, rather than a high-growth or highly defensible market leader.

Key strengths: 20+ years of continuous operation (founded 2004), Entrenched B2B SaaS base of 1,400+ restaurants with high switching costs, Two-sided network effects with 20M+ annual bookings, Diversified revenue streams (SaaS, ticketing, gift cards, prepayment, loyalty), Geographic diversification across 13+ countries, Sticky recurring subscription revenue (predictable ARR), Mature product depth with POS integrations and APIs, Founder/family continuity providing strategic stability

Risk factors: Intense competition from well-capitalised global players (TheFork, OpenTable, SevenRooms, Quandoo, Resy, Tock), Exposure to restaurant-sector cyclicality and macro shocks (COVID-19, energy, cost-of-living), Capital constraints as a small Danish ApS versus VC-backed multinationals, Likely revenue concentration in Denmark/Nordics despite multi-country presence, Limited traction in expansion markets (France, Poland, Hungary) against local leaders, Key-person / family-ownership governance risk (Thygesen brothers), Limited public financial transparency under Danish ApS Class B disclosure rules

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report