Enonic

Norway · enonic.com · 15 vendors

Enonic is a Norwegian tech company that develops and delivers the open-source digital platform Enonic XP. It offers a headless CMS, web application framework, and NoSQL storage solution, enabling users to build, manage, and deliver digital experiences like websites, applications, and APIs.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 15 sub-vendors.

Insights

Last updated 2026-08-16 · revision 2

15 direct vendors, 230 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Enonic exhibits very high migration readiness, largely driven by its highly modern and cloud-native oriented technology stack. The use of Kubernetes, Terraform, GraphQL, Headless CMS, and a composable architecture positions them well for flexible deployments and migrations. Their core product, Enonic XP, is available as SaaS, self-hosted, or on-premises, showcasing inherent platform flexibility. The existence of 'Enonic Experience Cloud (SaaS)' further underscores their expertise in managing and operating cloud-based solutions, indicating a strong internal capability for cloud adoption and migration. The open-source nature of Enonic XP significantly reduces platform-level vendor lock-in. While the 'Total Vendors: 0' data point is contradictory to other vendor information, assuming 'Total Services: 19' and 'Vendor Geographic Diversity: 5 unique countries' reflects their actual vendor landscape, this diversity generally supports easier migration by reducing reliance on a single vendor. Weaknesses include the lack of data on financial stability, which could impact the funding of large-scale migrations, and unspecified data residency requirements, which could introduce complexity. Vendor lock-in risk for their specific services is also unknown.

Compliance

8 in-scope frameworks identified; showing 3.

GDPR (source) — Compliant

Enonic explicitly self-declares full GDPR compliance on its official security page. The company has appointed a dedicated Data Privacy Officer (DPO) reachable at privacy@enonic.com, which is a formal GDPR requirement for many data processors. They publish a privacy policy and a Data Processing Agreement (DPA) for cloud customers. As a Norwegian company (Norway is EEA), GDPR applies universally. The presence of a DPO, a published DPA, and explicit compliance declaration significantly reduces residual risk. The company is small (~20 employees), limiting the complexity of data processing activities. Risk is Low given the strong documented compliance posture.

Evidence: https://enonic.com/platform/security, https://enonic.com/privacy-policy, https://enonic.com/cookie-policy, https://enonic.com/cloud/third-party-suppliers

ISO 27001 (source) — Compliant

Enonic holds a current ISO 27001:2022 certification (the latest edition of the standard), confirmed on its official security page. The certification is maintained through annual audits by a certified external auditor covering all 93 information security controls. This is the gold standard for information security management and directly addresses risks related to data breaches, unauthorized access, and operational security. Risk is Low because: (1) certification is confirmed and current; (2) annual external audits provide ongoing assurance; (3) the 2022 edition is the most current version; (4) a Statement of Applicability is available on request.

Evidence: https://enonic.com/platform/security, https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en, https://www.iso.org/standard/62085.html

Norwegian Personal Data Act — Compliant

The Norwegian Personal Data Act implements GDPR into Norwegian law and applies directly to Enonic as a Norwegian company. Given Enonic's confirmed GDPR compliance, DPO appointment, and published privacy policy and DPA, compliance with the Norwegian Personal Data Act is effectively demonstrated. The Norwegian Data Protection Authority (Datatilsynet) enforces this law. Risk is Low given the strong GDPR compliance posture which encompasses Norwegian data protection law.

Evidence: https://enonic.com/platform/security, https://enonic.com/privacy-policy, https://www.datatilsynet.no/en/

Financials

Three-year financials

Financial Resilience Score: 6/10

Enonic AS demonstrates qualitative financial resilience through its 25-year operating history, blue-chip Norwegian public-sector customer base (NAV, Norsk Tipping, SSB, HDIR, Forsvaret, Posten), and long-duration, sticky contracts that provide predictable revenue streams. The transition to recurring revenue models through Enonic Cloud (launched 2021) and enterprise subscription licensing supports revenue stability, while ISO 9001 certification since 2011 signals mature process controls that align with public procurement requirements. However, the company's small scale (~20 employees) significantly limits R&D velocity and international sales reach compared to well-funded global rivals like Optimizely, Contentful, and Sanity. Heavy geographic concentration in Norway and dependency on a small number of flagship public-sector accounts creates material customer concentration risk. Currency exposure (NOK-denominated revenue vs. USD-funded competitors) and competitive pressure from hyperscalers and VC-backed headless CMS vendors add further risk. Founder-led private ownership limits capital-raising flexibility. Actual three-year financial figures were not accessible in this session and would need to be pulled from Brønnøysundregistrene to confirm resilience quantitatively.

Key strengths: 25-year operating track record since 2000, Blue-chip Norwegian public-sector customer base (NAV, Norsk Tipping, SSB, HDIR, Forsvaret, Posten), Recurring revenue potential via Enonic Cloud SaaS (launched 2021), ISO 9001 certified since 2011, Ranked #1 in SoftwareReviews DXP category four years running, Open-source strategy reduces marketing spend, Sticky, long-duration public-sector contracts

Risk factors: Small scale with only ~20 employees limits R&D and international reach, Heavy geographic concentration in Norway, Customer concentration in Norwegian public sector, Currency exposure with NOK revenue vs USD-funded competitors, Competitive pressure from well-funded global DXP/headless CMS vendors, Founder-led private ownership limits capital-raising options, AI/DXP competitive pressure requires ongoing investment

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report