DLX A/S

Denmark · owned by MAKS Holding Herning ApS (Denmark) · www.dlx.dk · 7 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 2 categories; runs on 7 sub-vendors.

Insights

Last updated 2026-09-13 · revision 3

7 direct vendors, 118 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DLX A/S exhibits moderate migration readiness. The company's strong financial stability, indicated by an AAA credit rating, provides a solid foundation to fund potential migration initiatives. Their existing ISAE 3402 assurance report demonstrates a mature control environment, which can be leveraged to ensure security and compliance in a new cloud setting. Furthermore, DLX's experience in managed IT services and IT consulting, coupled with their resale of Microsoft Office 365, indicates some familiarity with cloud operations and the ability to manage complex IT projects. However, several factors present significant challenges to migration. DLX's core infrastructure, including datacenter operations, virtual servers built on VMware, and web hosting on FreeBSD, represents a traditional, on-premises architecture. A full migration to a cloud-native environment would likely require substantial re-platforming and re-architecture rather than a simple lift-and-shift, increasing complexity and cost. Strict data residency requirements, mandating data storage within Denmark/EU, significantly limit the choice of cloud providers and specific regions, adding a layer of complexity to planning and execution. Moreover, the identified regulatory compliance gaps, particularly concerning GDPR, NIS2, and ePrivacy, would need to be thoroughly addressed and re-validated in any new cloud environment to avoid legal and financial penalties. Finally, reliance on key vendor platforms like VMware, Acronis, and Veeam suggests a moderate level of vendor lock-in, which could complicate transitioning to alternative cloud-native services or require significant integration efforts.

Compliance

10 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is the general framework for assurance engagements other than audits or reviews of historical financial information. ISAE 3402 (which DLX holds) is a specific application of ISAE 3000 principles. DLX may also be subject to ISAE 3000 in the context of ESG reporting assurance (they publish an ESG report) or other non-financial assurance engagements. Risk is Low as this is not a legally mandated framework and DLX's ISAE 3402 already demonstrates engagement with the ISAE assurance family.

Evidence: https://www.dlx.dk/revisionserklaering, https://dlx.dk/DLX_ISAE3402_2026.pdf, https://dlx.dk/esg

Danish IT Security Act — Assessment Required

Denmark has implemented EU NIS and NIS2 directives through national legislation. As a Danish IT infrastructure and managed services provider, DLX A/S may be subject to sector-specific cybersecurity obligations under Danish law. The Danish Business Authority (Erhvervsstyrelsen) and the Centre for Cyber Security (CFCS) are the primary enforcement bodies. Risk is Medium pending size threshold confirmation.

Evidence: https://www.erhvervsstyrelsen.dk/nis2, https://www.cfcs.dk/en/, https://www.dlx.dk

GDPR (source) — Partially Compliant

DLX A/S is headquartered in Denmark (EU member state) and operates as a cloud/IT services provider that acts as both a data controller (for its own customer and employee data) and a data processor (processing personal data on behalf of its customers via hosted services, virtual servers, online backup, hosted desktop, etc.). As a data processor for potentially many Danish and EU businesses, DLX carries elevated GDPR risk: any breach or non-compliance could affect multiple downstream data subjects. The Danish Data Protection Authority (Datatilsynet) is an active enforcement body. While DLX publicly offers a Data Processing Agreement (Databehandleraftale) — a positive compliance signal — the absence of a publicly visible privacy policy, DPO appointment disclosure, or Records of Processing Activities (RoPA) on their website introduces residual risk. Fines under GDPR can reach €20M or 4% of global annual turnover.

Evidence: https://www.dlx.dk/databehandleraftale, https://dlx.dk/DLXDatabehandleraftale.pdf, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Financials

Three-year financials

Financial Resilience Score: 7/10

DLX A/S displays several qualitative indicators of financial solidity despite the absence of retrievable quantitative data in this session. The company holds a AAA credit-rating badge (typically issued by Bisnode/Dun & Bradstreet), which in the Danish rating system requires multi-year profitable trading, positive equity, and no payment remarks. This signals strong creditworthiness at the time of rating. Additionally, DLX maintains an ISAE 3402 assurance report, a recurring third-party audit standard for service organisations, implying mature internal controls and stable operations required by enterprise customers. The business model itself supports resilience: hosting, virtual servers, Microsoft 365, backup, and cloud PBX services are subscription-based, producing predictable recurring cash flow and high customer stickiness. Ownership of a physical datacenter in Herning provides a defensible operational moat versus resellers, and a diversified multi-product portfolio (compute, storage, collaboration, telephony, web, advisory) reduces single-product dependence. As an A/S, DLX also meets higher governance and disclosure obligations, with minimum share capital of DKK 400,000. However, risks include exposure to a small, competitive Danish IT-hosting market dominated by larger players (GlobalConnect, Zitcom, Interxion) and hyperscalers (Azure, AWS, GCP). Capex intensity from owning a datacenter, energy-cost volatility (2022-2024), potential customer concentration, key-person risk typical of owner-managed A/S companies, and hyperscaler substitution risk for M365/IaaS workloads all temper the resilience score.

Key strengths: AAA credit-rating badge displayed on corporate website, ISAE 3402 assurance report indicating mature internal controls, Recurring subscription-based revenue model with high stickiness, Owned datacenter infrastructure in Herning as defensible moat, Diversified multi-product portfolio across hosting, M365, telephony, advisory, VMware Partner and Microsoft Partner certifications, A/S legal structure with minimum DKK 400,000 share capital and governance requirements

Risk factors: Small Danish IT-hosting market with structural price pressure, Competition from larger players (GlobalConnect, Zitcom, Interxion) and hyperscalers (Azure, AWS, GCP), Capex intensity from datacenter ownership including depreciation and hardware refresh, Energy-price volatility impacting datacenter operations, Potential customer concentration risk typical of small B2B IT providers, Key-person risk typical of owner-managed Danish A/S companies, Hyperscaler substitution risk for Office 365 and virtual server workloads

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report