EG Danmark A/S
Denmark · owned by Lancelot UK Finco Limited (United Kingdom) · egsoftware.com · 31 vendors
EG develops industry-specific software that simplifies complexity, improves efficiency, and creates real value. The company serves public and private companies across multiple Nordic countries with specialized solutions for construction, healthcare, public sector, retail, utilities, and other industries.
Resilience scores
- Digital Sovereignty: 26
- Digital Resilience: 8
- Financial Resilience: 6
Technology vendors
- Anthropic, PBC — Technology — United States
- Usercentrics GmbH — Technology — Germany
- Veeam Software Group GmbH — Technology — United States
- and 29 more
Services catalogue
3 services in catalogue across 2 categories; runs on 31 sub-vendors.
- Business Software
- Personal Data Processing
- system for the processing
Insights
Last updated 2026-08-03 · revision 22
31 direct vendors, 380 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 3
- Norway: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- Netherlands: 5
- Spain: 1
- Germany: 11
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
EG Danmark A/S exhibits high migration readiness (score 75), primarily driven by its predominantly cloud-native tech stack. The company extensively uses Microsoft Azure, SaaS cloud delivery, and leverages REST APIs and integration middleware. Many of its products are already delivered as SaaS, indicating a mature understanding and implementation of cloud models, which significantly simplifies further migration efforts. Strong financial growth provides the necessary capital to fund significant migration initiatives. The company's robust GDPR compliance and existing 'GDPR-compliant European cloud infrastructure' directly address complex data residency and sovereignty requirements, particularly critical for their healthcare and public sector solutions. This pre-existing framework significantly de-risks data migration. The use of REST APIs suggests a modular architecture, which facilitates easier migration of individual components or services. The primary challenge for migration readiness is the 'Unknown' vendor lock-in risk. While vendor services are geographically diverse (9 countries), the extent of reliance on specific platforms (e.g., Microsoft Dynamics 365, Azure) and the complexity of existing vendor contracts are not detailed. This could introduce unforeseen complexities or costs during a migration to a completely different ecosystem. Additionally, the 'Assessment Required' status for NIS2, SOC2, and ISO 27001, while not direct blockers, would likely need to be addressed as part of a comprehensive migration strategy to maintain or enhance customer trust and compliance posture in new environments. Finally, with a vast portfolio of 45 services across diverse industries, a full-scale migration would be a complex undertaking requiring careful planning and execution, despite the modern tech stack.
Compliance
10 in-scope frameworks identified; showing 3.
Danish Health Data Act — Assessment Required
EG operates multiple electronic health record (EHR) and clinical management systems in Denmark (EG WinPLC, EG Clinea, EG ClinicCare, EG Sundhed, EG Mediconnect, EG Netforvaltning Sundhed) and Norway (EG Pasientsky, EG Infodoc, EG Hano Journalsystem, EG CheckWare). These products process highly sensitive patient health data and are subject to strict national health IT regulations beyond GDPR. Risk is High because: (1) Danish health IT systems must comply with the Danish Health Data Authority (Sundhedsdatastyrelsen) requirements, including integration with national health data infrastructure (FMK - Fælles Medicinkort, MedCom standards); (2) Norwegian EHR systems must comply with Norm for informasjonssikkerhet og personvern i helse- og omsorgssektoren (Normen) and Helsepersonelloven; (3) Non-compliance with health IT regulations can result in loss of certification/approval, preventing EG's products from operating in regulated healthcare markets; (4) Patient safety implications of non-compliant health IT systems are severe.
Evidence: https://egsoftware.com/global/healthcare, https://egsoftware.com/dk/sundhed/winplc, https://egsoftware.com/dk/sundhed/netforvaltning-sundhed, https://egsoftware.com/no/helse/eg-pasientsky
EU AI Act (source) — Assessment Required
EG Danmark A/S has a dedicated AI strategy ('Industry AI') and has launched AI-powered features embedded directly into products, including an AI assistant for healthcare (EG WinPLC AI for clinical documentation), AI in construction, and AI across multiple verticals. The EU AI Act, which entered into force August 2024 with phased applicability (high-risk provisions applying from August 2026), is directly relevant. Healthcare AI systems (clinical decision support, medical documentation AI) are classified as HIGH-RISK under EU AI Act Annex III (medical devices / AI in healthcare). Risk is High because: (1) EG's healthcare AI (AI assistant in EG WinPLC for clinical notes) likely qualifies as a high-risk AI system requiring conformity assessment, technical documentation, human oversight mechanisms, and registration in the EU AI database; (2) EG's public sector AI tools (citizen welfare, education) may also qualify as high-risk; (3) The EU AI Act imposes significant obligations on providers of high-risk AI systems including risk management systems, data governance, transparency, accuracy/robustness requirements, and post-market monitoring; (4) Non-compliance penalties reach €30M or 6% of global annual turnover.
Evidence: https://egsoftware.com/global/industry-ai, https://egsoftware.com/global/compliances, https://egsoftware.com/dk/sundhed/winplc/ai, https://egsoftware.com/global/ai
SOC 2 (source) — Assessment Required
EG Danmark A/S is a large SaaS/cloud software provider serving 44,000+ customers across critical industries. SOC 2 (Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy) is highly relevant for cloud service providers. However, EG has not publicly disclosed a SOC 2 Type I or Type II report. Instead, EG conducts annual ISAE 3000 and ISAE 3402 audit statements, which are the European equivalents of SOC 2/SOC 1 respectively. Risk is Medium because: (1) EG's enterprise customers in regulated industries (healthcare, public sector, utilities) increasingly require SOC 2 or equivalent assurance; (2) The absence of a publicly disclosed SOC 2 report may create procurement friction with international customers; (3) EG's ISAE 3402 reports provide comparable assurance for European customers but may not satisfy US-based or globally-oriented customers requiring SOC 2 specifically. The risk is not High because EG has equivalent European audit frameworks in place.
Evidence: https://egsoftware.com/global/compliances, https://egsoftware.com/global/audit-statements, https://egsoftware.com/global/trust-center
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
EG Danmark A/S benefits from a highly diversified vertical software portfolio spanning 13+ industries, strong recurring SaaS revenue, and deep entrenchment with 44,000+ customers across regulated Nordic verticals such as municipalities, GP clinics, housing associations, and utilities. The Nordic public-sector exposure provides revenue stability through long procurement cycles and stable payers, while ongoing SaaS migration supports predictable ARR and higher valuation multiples. Backing from Francisco Partners since 2019 has provided capital and M&A discipline, enabling 20+ acquisitions and roughly doubling group revenue to an estimated DKK 2.5-2.7B and headcount to 3,000+. However, resilience is tempered by structural risks typical of PE-owned platforms: high leverage that compresses net earnings, a goodwill/intangibles-heavy balance sheet with impairment risk if segment growth stalls, and integration risk from rapid bolt-on acquisitions across 5+ countries. Exact revenue, EBIT, equity, and debt figures could not be verified from primary CVR filings in this session, limiting definitive quantitative assessment. Public-sector procurement losses in large municipal or EHR tenders and Nordic talent competition present additional risks. Overall, the business model is resilient but leverage and integration execution remain key watch items.
Key strengths: Diversified vertical portfolio across 13+ industries cushions cyclical downturns, High recurring/SaaS revenue share supports predictable ARR, 44,000+ customers with high switching costs in regulated Nordic verticals, Strong PE backing from Francisco Partners with M&A discipline, Nordic public-sector exposure provides revenue stability, 20+ acquisitions since 2019 driving scale and geographic diversification
Risk factors: High leverage typical of PE-owned platforms compressing net earnings, Goodwill/intangibles-heavy balance sheet with impairment risk, Integration risk from rapid bolt-on acquisitions across 5+ countries, Nordic public-sector procurement risk on large municipal/GP-clinic tenders, Talent competition in Nordic software labour markets, Product portfolio overlap from acquisitive strategy
Revenue by geography
- Denmark: 55%
- Norway: 25%
- Sweden: 10%
- Finland: 10%
Revenue by product/service
- Citizen Welfare & Utility: 30%
- Construction, Property & Asset Management: 30%
- Healthcare & Beauty: 22%
- Retail & Supply Chain: 18%
Workforce by country
- Denmark: 1425
- Norway: 600
- Other (Poland, India, Spain, Estonia, Iceland): 375
- Sweden: 300
- Finland: 300
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.