EDORA

Denmark · owned by Hedegaard Holding 2017 ApS (Denmark) · edora.dk · 22 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 3 categories; runs on 22 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

22 direct vendors, 224 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

EDORA exhibits high migration readiness due to its modern, open-source, and cloud-native oriented internal tech stack. The extensive use of OpenStack, Kubernetes, Docker, Terraform, and a microservices architecture signifies a highly portable and agile infrastructure. Their strong expertise in NIS2 and GDPR compliance, along with a focus on data sovereignty and hosting within Danish/EU jurisdiction, means they are well-equipped to handle complex regulatory and data residency requirements during any migration. The provision of 'IT Consulting & System Development' and 'AI & Data Services' also points to internal capabilities for managing and executing complex system modernizations and integrations. The main limitation in fully assessing migration readiness is the absence of data regarding EDORA's financial stability (revenue concentration, growth history), which could influence the funding and prioritization of large-scale migrations. While their core technologies are open-source, the specific 'Vendor Lock-in Risk' remains unknown, and the exact number of unique vendors is ambiguous (given 'Total Vendors: 0' vs. detailed vendor geographic data). However, the inherent nature of their open-source stack generally reduces vendor lock-in for their own platform.

Compliance

8 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 risk is assessed as High for two compounding reasons. First, Edora itself is highly likely to qualify as an Important Entity or Essential Entity under NIS2 in its own right: it provides ICT services and digital infrastructure to critical public sector entities (courts, national employment systems, health data authorities, emergency preparedness/defence), operates a cloud IaaS platform (Edora Cloud) serving government clients, and manages society-critical systems like NemRefusion (2.7M+ annual transactions). ICT service management providers and digital infrastructure providers are explicitly listed NIS2 sectors. Second, Edora actively markets NIS2 compliance advisory services to its clients, meaning it must itself demonstrate compliance to maintain credibility and contractual obligations. The company explicitly states 'NIS2-kompatibel' for Edora Cloud and offers NIS2 compliance consulting. Non-compliance would risk: regulatory fines up to €10M or 2% of global turnover (for Important Entities), loss of public sector contracts (which constitute the core of Edora's business), and reputational damage. The Danish NIS2 implementation (Lov om sikkerhed i net- og informationssystemer, in force October 2024) is enforced by the Danish Centre for Cyber Security (CFCS) and sector-specific authorities.

Evidence: https://edora.dk/cloud/edora-cloud/, https://edora.dk/services/security-compliance/, https://edora.dk/industrier/beredskab-forsvar/, https://edora.dk/industrier/energi-forsyning/, https://cfcs.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions, including stricter rules for processing of CPR numbers (Danish civil registration numbers), special category data, and processing by public authorities. Edora processes data on behalf of Danish public authorities and likely handles CPR numbers in systems like NemRefusion, EESSI, and municipal citizen services. Risk is Medium because: (1) CPR number processing requires specific legal basis and security measures beyond standard GDPR; (2) Edora acts as data processor for public authorities subject to the Act's stricter provisions; (3) no specific compliance documentation for CPR handling was found publicly. The Danish DPA (Datatilsynet) actively enforces these requirements.

Evidence: https://edora.dk/persondatapolitik/, https://edora.dk/case/nemrefusion-kombit/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502

ISO 27001 (source) — Partially Compliant

ISO 27001 risk is Medium because Edora explicitly states on its Edora Cloud product page that 'ISO 27001 under implementering' (ISO 27001 is under implementation). This means the company has initiated the certification process but has not yet achieved formal certification. Given that Edora manages critical public sector IT infrastructure — including court systems, national employment platforms, health data systems, and emergency preparedness cloud — the absence of a completed ISO 27001 certification represents a meaningful gap. However, the active implementation effort, combined with the published Information Security Policy and NIS2-aligned security practices, demonstrates substantive progress. Risk is Medium rather than High because: (1) the company is actively pursuing certification; (2) it has implemented foundational security controls evidenced by its security service offerings and published policies; (3) Danish public sector contracts (SKI framework agreements) may require ISO 27001 or equivalent, creating commercial pressure to complete certification.

Evidence: https://edora.dk/cloud/edora-cloud/, https://edora.dk/wp-content/uploads/2026/06/Informationsssikkerhedspolitik-Edora.pdf, https://edora.dk/services/security-compliance/

Financials

Three-year financials

Financial Resilience Score: 7/10

Edora A/S demonstrates solid qualitative financial resilience despite the absence of verified financial figures in this research session. The company benefits from a sticky public-sector customer base including central Danish government agencies (KOMBIT, Domstolsstyrelsen, STAR, Danmarks Statistik, Sundhedsdatastyrelsen), long-cycle contracts, and six SKI framework agreements that provide multi-year revenue visibility. Its solutions are embedded in national infrastructure (e.g., NemRefusion processing ~2.7 million transactions/year), creating high switching costs and mission-critical positioning. With 25+ years of continuous operation since 2000, the company has weathered multiple technology cycles. The revenue mix combines recurring SaaS products (Lets Talk, WorkForce Planner, Leverandørplatformen), Edora Cloud hosting, and consulting services, providing a balanced recurring + project revenue profile. Regulatory tailwinds from Danish/EU data sovereignty requirements and NIS2 directly favor Edora's sovereign Danish cloud positioning. However, resilience is tempered by significant concentration risks: near-total dependence on the Danish public sector, geographic concentration in Denmark only, a consultant-heavy cost base (125+ specialists) where utilization drives margins, and ongoing capex requirements for cloud and datacentre buildout. Competition from Netcompany, KMD (NEC), Systematic, Trifork, and international consultancies (Accenture, Capgemini) for the same public contracts is intense. Without access to verified revenue, EBIT, and equity figures from the CVR filings, the score reflects qualitative strengths balanced against concentration risks.

Key strengths: Sticky public-sector customer base with long-cycle contracts, Six SKI framework agreements providing multi-year revenue visibility, Mission-critical embedded position in Danish national infrastructure, 25+ years of continuous operation since 2000, Mixed recurring SaaS + consulting + cloud revenue model, Regulatory tailwind from data sovereignty and NIS2 requirements, High switching costs on core systems (NemRefusion, court systems)

Risk factors: Heavy customer concentration in Danish public sector, Geographic concentration - Denmark only, no international diversification, Consultant-heavy cost base with utilization-driven margins, Ongoing capex requirements for sovereign cloud and datacentre buildout, Intense competition from Netcompany, KMD, Systematic, Trifork, Accenture, Capgemini, Exposure to Danish public IT budget and procurement cycles

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report