e-nettet A/S
Denmark · owned by Independent (Denmark) · www.e-nettet.dk · 36 vendors
E-nettet A/S is a Danish financial infrastructure company owned by all Danish financial and mortgage institutions. It develops and operates shared IT systems and digital solutions for the financial sector and real estate market in Denmark. The company facilitates complex processes such as bank changes, digital property transfers, and pension payments, aiming to strengthen Denmark's position as a highly digitalized society.
Resilience scores
- Digital Sovereignty: 39
- Digital Resilience: 4
- Financial Resilience: 8
Disruption prediction
e-nettet A/S has an estimated 27% probability of disruption in the next 6 months.
11 of e-nettet A/S's 36 vendors monitored for disruptions.
Technology vendors
- Netlify, Inc. — Technology — United States
- NNIThosting — Technology — Denmark
- Rain-Task Limited — Technology — United Kingdom
- and 37 more
Services catalogue
2 services in catalogue across 2 categories; runs on 36 sub-vendors.
- Digital Infrastructure
- Digital Signatures
Insights
Last updated 2026-09-13 · revision 19
36 direct vendors, 342 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 2
- Australia: 1
- Nepal: 2
Subvendors by controlling owner country (sample)
- Poland: 4
- Unknown: 1
- Singapore: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
e-nettet A/S exhibits a medium level of migration readiness, facing significant challenges primarily due to stringent regulatory and data residency requirements. A major constraint for any cloud migration is the strict EU/Danish data residency requirements for sensitive financial data, which will limit cloud provider options to EU-based data centers and potentially require specific Danish localization, adding complexity and cost. The pending high-risk NIS2 assessment means that any migration must incorporate stringent cybersecurity and resilience measures from the outset, further increasing the scope and effort. The data presents a contradiction with 'Total Vendors: 0' while also listing vendor geographic diversity. Assuming vendor relationships exist, the 'Vendor Lock-in Risk: Unknown' poses an uncertainty for migration planning, as potential dependencies and contract complexities are not clear. If 'Total Vendors: 0' were strictly true, it would imply no external vendor dependencies, which could simplify migration, but also mean a lack of external expertise. While key technologies like API-based financial sector integration suggest a modular architecture that could facilitate migration, there is no explicit data confirming a cloud-native, containerized, or microservices architecture for their core financial systems, which might necessitate significant re-platforming efforts. On the positive side, e-nettet's stable financial position provides the capacity to fund a migration initiative. Their demonstrated GDPR compliance also indicates a strong foundation in data governance and privacy, which is crucial for managing sensitive data during a migration. Overall, while financially stable and having good data governance, the stringent regulatory environment, data residency requirements, and architectural unknowns present significant challenges for a smooth and rapid migration.
Compliance
10 in-scope frameworks identified; showing 3.
eIDAS Regulation — Assessment Required
e-nettet A/S operates digital identity and consent management services (e-samtykke) and digital mortgage registration (tinglysning) that involve electronic identification and trust services. The company also references MitID (Denmark's national eID system) with a dedicated Manager for MitID (Michael Busk-Jepsen). Risk is Medium because: (1) The company's digital services rely on electronic identification (MitID) for user authentication; (2) The e-samtykke product manages digital consent for financial data sharing, which may involve qualified electronic signatures or seals; (3) Digital mortgage registration (tinglysning) involves legally binding electronic transactions requiring trust services; (4) eIDAS 2.0 (applicable from 2026) introduces new requirements for digital identity wallets and trust services that may affect e-nettet's authentication infrastructure.
Evidence: https://www.e-nettet.dk/om-e-nettet/organisation/, https://www.e-nettet.dk/privatlivspolitik/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183
Danish Data Protection Act — Partially Compliant
The Danish Data Protection Act supplements GDPR with national-specific provisions and is directly applicable to e-nettet A/S as a Danish company. Risk is Medium because: (1) The company processes property data including CPR-adjacent data (owner names, birth dates) from public registers, which may trigger specific Danish provisions on CPR number processing; (2) The company explicitly states in its privacy policy that it does not process CPR numbers as a rule, suggesting awareness of the stricter Danish rules on CPR processing (Section 11 of the Danish Data Protection Act); (3) The company has a Privacy Officer and Compliance team indicating active management; (4) Datatilsynet (the Danish DPA) has been increasingly active in enforcement, including against financial sector companies. Risk is not High because the company has demonstrated compliance awareness and has appropriate governance structures.
Evidence: https://www.e-nettet.dk/privatlivspolitik/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502
ISO 27001 (source) — Assessment Required
ISO 27001 certification is highly relevant for e-nettet A/S given its role as the financial sector's shared digital infrastructure provider. Risk is Medium because: (1) The company handles sensitive financial data for the entire Danish banking and mortgage sector; (2) The company's annual report explicitly prioritizes 'robustness, security, and high operational stability' as strategic objectives; (3) The company has a dedicated CTO/Security Director, Senior Security Advisor, DevSecOps Engineer, and Business Continuity Specialist — suggesting security management maturity; (4) However, no ISO 27001 certificate has been found in public sources; (5) NIS2 compliance (which is highly likely applicable) requires risk management measures that substantially overlap with ISO 27001 requirements, creating regulatory pressure toward certification; (6) Institutional customers (major Danish banks) may require ISO 27001 or equivalent as a supplier requirement. Risk is not High because the company clearly has security management infrastructure in place, even if formal certification is unconfirmed.
Evidence: https://www.e-nettet.dk/om-e-nettet/organisation/, https://www.e-nettet.dk/om-e-nettet/aarsrapport/, https://www.iso.org/isoiec-27001-information-security.html
Financials
Three-year financials
- 2025: revenue DKK 275M, EBIT DKK 1.87M, equity DKK 135M
- 2024: revenue DKK 258M, EBIT DKK 10.9M, equity DKK 133M
- 2023: revenue DKK 237M, EBIT DKK 4.69M, equity DKK 124M
Financial Resilience Score: 8/10
e-nettet A/S is a sector-owned utility company providing critical shared IT and data infrastructure to the Danish financial sector. Its financial resilience is structurally strong because it is co-owned by essentially all major Danish banks and mortgage-credit institutions, meaning demand for its services is non-discretionary and embedded in national payment, mortgage, and property-transaction infrastructure. The company supports approximately 70% of all Danish home sales, giving it an extraordinarily deep competitive moat. Regulatory tailwinds from CSRD, DORA, and TARGET expand its role as a shared infrastructure layer. Headcount has been stable at 101-106 FTE for at least five years (2021-2025), suggesting revenue is also broadly stable in real terms. Historically, revenue has been in the range of ~180-220 MDKK with modest, positive net results. The cooperative ownership model with a very low CEO-to-employee pay ratio (~4x) reduces incentive-driven risk-taking. High operational uptime is a headline KPI, indicating disciplined operations. Key risks include customer concentration on a small set of Danish financial institutions, 100% single-country exposure to Denmark, structurally capped growth due to the utility pricing model, rising employee turnover to 21% in 2025 (well above the internal <15% target), and housing-market sensitivity for volume-based revenue components. Danish banking consolidation could reduce the number of paying customers over time.
Key strengths: Sector-utility status with co-ownership by Danish financial sector, ~70% market share in Danish home sales transactions, Non-discretionary demand embedded in national infrastructure, Stable workforce of 101-106 FTE over 5 years, High employee satisfaction (96%) and high operational uptime, Regulatory tailwinds from CSRD, DORA, and TARGET, Cooperative governance model with low CEO pay ratio (~4x)
Risk factors: Customer concentration on small set of Danish financial institutions, 100% single-country exposure to Denmark, Structurally capped growth due to utility pricing model, Employee turnover rose to 21% in 2025 vs <15% target, Housing-market cyclical sensitivity, Danish banking consolidation reducing customer count, Reliance on external platforms and policy-driven migrations
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Ancillary/new products: 0%
- ESG/climate data services: 0%
- Bank-switching services (bankskifte): 0%
- Payments infrastructure services (Kronos2/TARGET): 0%
- Housing transaction data and workflow services (bolighandel): 0%
Workforce by country
- Denmark: 101
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.