EG A/S
Denmark · eg.dk · 22 vendors
EG A/S is a Danish software company that develops and delivers proprietary, industry-specific software-as-a-service (SaaS) solutions. They serve various vertical markets in the Nordic region, including construction, healthcare, retail, and public administration. The company focuses on providing mission-critical software to simplify tasks and enhance business processes for its customers.
Resilience scores
- Digital Sovereignty: 86
- Digital Resilience: 8
Technology vendors
- Anthropic, PBC — Technology — United States
- Demandware — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 19 more
Services catalogue
7 services in catalogue across 3 categories; runs on 22 sub-vendors.
- EG Hosting
- EG SafetyNet
- Customer Portal
Insights
Last updated 2026-03-03 · revision 6
22 direct vendors, 316 subvendors
Direct vendors by controlling owner country (sample)
- Luxembourg: 1
- United States: 19
- Australia: 1
Subvendors by controlling owner country (sample)
- Belgium: 2
- UK: 1
- Spain: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
EG A/S exhibits a solid foundation for migration readiness, largely due to its modern and cloud-native technology stack. The extensive use of Microsoft Azure, SaaS delivery models, Next.js, and Microsoft Dynamics 365 positions them well for further cloud adoption and migration initiatives. Their existing compliance with GDPR, including established data privacy programs and data processing agreements, means they have critical processes in place to manage sensitive data during migration. However, significant challenges exist, primarily related to stringent data residency requirements. As a Danish company operating in the EU/EEA and serving sectors like public administration and utilities, EG A/S is subject to strict EU data sovereignty rules (GDPR and likely NIS2), which will necessitate careful planning for data localization and could limit choices of cloud regions or providers. The financial stability required to fund a large-scale migration is unknown, representing a potential constraint. Furthermore, the vendor landscape, while geographically diverse for service origins, presents an unknown vendor lock-in risk. With 66 services listed, there could be numerous underlying vendor dependencies. The reliance on Microsoft platforms (Azure, Dynamics 365) could be seen as a form of vendor lock-in, though these are generally well-supported for migration. The lack of clarity on specific vendor relationships and contract complexities makes it difficult to fully assess the ease of disentanglement or re-platforming during a migration. Uncertainty around NIS2 applicability for their clients also adds a layer of complexity for migration strategies in those specific sectors.
Compliance
5 in-scope frameworks identified; showing 3.
GDPR (source) — Compliant
EG is headquartered in Denmark (EU) and processes personal data across multiple sectors including healthcare, public sector, and membership organizations. While GDPR compliance is mandatory and EG demonstrates awareness through GDPR-secure solutions, the medium risk reflects the complexity of managing personal data across diverse industry verticals and the significant penalties for non-compliance (up to 4% of annual turnover).
Evidence: https://egsoftware.com/global/trust-center, https://egsoftware.com/global/compliances
ISO 27001 (source) — Partially Compliant
EG explicitly states that 'Selected EG products have ISO 27001 certifications,' indicating partial implementation rather than organization-wide certification. Medium risk reflects the importance of information security management in their software business and the competitive advantage of full ISO 27001 certification, though partial compliance suggests ongoing efforts.
Evidence: https://egsoftware.com/assets/1754979047-nis2-and-dora-compliance-in-eg-v-1-0.pdf
SOC 2 (source) — Assessment Required
EG provides cloud-based software solutions across multiple industries, which typically requires SOC2 compliance for US customers or those requiring SOC2 attestations. However, as a Nordic-focused company, SOC2 may not be mandatory but could be beneficial for international expansion. Medium risk reflects potential customer requirements and competitive disadvantage without SOC2, though not legally mandated.
Evidence: https://egsoftware.com/global/compliances
Financials
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.