FAB IT ApS

Denmark · owned by Independent (Denmark) · fab-it.dk · 4 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 4 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

4 direct vendors, 82 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

FAB IT ApS exhibits medium migration readiness, leaning towards the lower end due to several significant challenges. The company's core business revolves around traditional infrastructure services such as custom co-location, dedicated hosting, and tailored private cloud solutions hosted exclusively in their Danish datacenter. This indicates a predominantly on-premise/private cloud architecture, which typically presents substantial hurdles for migration to modern public cloud environments, often requiring extensive re-architecture due to potential monolithic structures and a lack of cloud-native patterns (e.g., containerization, microservices). While FAB IT offers 'Public Cloud (advisory/consulting)', there is no evidence that their *own* internal systems are designed with public cloud migration in mind. 'Data Residency Requirements: Not specified' for FAB IT itself, but their services explicitly state hosting in Denmark, implying client data residency requirements that could significantly complicate any migration involving moving data out of Denmark. The 'Vendor Lock-in Risk: Unknown' is a critical barrier, as unassessed vendor dependencies can substantially increase migration complexity, cost, and time. Financial stability is also unknown, which impacts the ability to fund a potentially costly and resource-intensive migration. Opportunities for migration include their internal expertise in public cloud advisory and the use of a modern static site generator (Hugo) for their website, but these are minor compared to the challenges posed by their core infrastructure model.

Compliance

7 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3402 (Assurance Reports on Controls at a Service Organisation) is the international equivalent of SOC 2 and is the standard most commonly used in Denmark and the EU for service organisation assurance reporting. As a provider of hosting, private cloud, and managed IT outsourcing services, FAB IT ApS acts as a service organisation whose controls are relevant to its clients' own financial reporting and compliance obligations. The risk level is Medium because: (1) ISAE 3402 is not legally mandated; (2) however, Danish and EU enterprise clients — particularly those subject to financial audit requirements — may request ISAE 3402 Type II reports from their IT service providers; (3) the absence of such a report may limit FAB IT's addressable market among larger, compliance-mature Danish companies; (4) NIS2 supply chain security requirements are increasing demand for formal assurance from IT service providers across the EU.

Evidence: https://fab-it.dk/service/hosting/, https://fab-it.dk/service/private-cloud/, https://fab-it.dk/service/outsourcing/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3402-assurance-reports-controls-service

GDPR (source) — Assessment Required

FAB IT ApS is headquartered in Denmark, an EU member state, making GDPR unconditionally applicable. As an IT services provider offering hosting, private cloud, IT outsourcing, and managed services, FAB IT processes personal data in multiple capacities: (1) as a Data Controller for its own employee and customer/supplier data, and (2) critically, as a Data Processor on behalf of its SMB clients whose data resides in FAB IT's Danish datacenter and private cloud infrastructure. This dual role significantly elevates risk. Non-compliance can result in fines up to €20 million or 4% of global annual turnover. The Danish Data Protection Authority (Datatilsynet) is an active enforcement body with a track record of investigations and fines. No public evidence of a formal GDPR compliance program, DPO appointment, or privacy policy was found on the website, which is itself a potential compliance gap for a company processing client data at scale.

Evidence: https://fab-it.dk, https://fab-it.dk/about/, https://fab-it.dk/service/hosting/, https://fab-it.dk/service/private-cloud/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679, https://www.datatilsynet.dk/english

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary framework developed by the AICPA, but it has become a de facto market requirement for cloud service providers and managed service providers (MSPs) serving enterprise or security-conscious clients. FAB IT ApS provides private cloud, hosting/co-location, and managed IT outsourcing services — all service categories where clients routinely request SOC 2 Type II reports as evidence of security controls. The risk level is Medium because: (1) SOC 2 is not legally mandated, so there is no regulatory penalty for non-compliance; (2) however, the absence of a SOC 2 report may represent a significant commercial risk, limiting FAB IT's ability to win contracts with larger or more compliance-mature clients; (3) as a smaller Danish IT firm primarily serving local SMBs, the immediate commercial pressure for SOC 2 may be lower than for larger cloud providers, but this is evolving as Danish SMBs increasingly face their own compliance requirements (GDPR, NIS2) and demand assurance from their IT suppliers.

Evidence: https://fab-it.dk/service/hosting/, https://fab-it.dk/service/private-cloud/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Financials

Three-year financials

Financial Resilience Score: 5/10

Fab:IT ApS is a small Danish private limited company (anpartsselskab) operating in the IT services sector with over 20 years of operating history. While specific financial figures from filed annual reports could not be retrieved, the qualitative profile suggests moderate resilience. The company's long operating tenure (~20+ years since approximately 2003-2004) indicates it has successfully weathered multiple IT industry cycles, including the 2008-09 financial crisis and the 2020 pandemic downturn. Its business model, centered on recurring-revenue services like hosting, private cloud, and managed services/outsourcing, typically produces sticky customer relationships and predictable cash flow, which is favorable for an SMB-focused IT services firm. However, several factors constrain the resilience score. As a small ApS, Fab:IT likely has limited capital buffers, with equity bases at small Danish IT ApS firms typically in the low single-digit million DKK range. The hosting and private cloud segments require ongoing capital expenditure for datacenter infrastructure, which can stress cash flow if customer growth slows. Additionally, the company faces intense competition from hyperscalers (Microsoft Azure, AWS, Google Cloud) that continue to compress margins for independent Danish hosters. Talent dependency in the consulting-heavy business model and elevated cybersecurity liability typical of MSPs add further risk. Without verified financial data, a mid-range score reflects the balance between long operating history and small-scale vulnerabilities.

Key strengths: Long operating history of 20+ years indicating ability to weather industry cycles, Recurring-revenue service mix (hosting, private cloud, managed services) producing sticky customer relationships, Diversified service portfolio across hosting, networking, security, and consulting, SMB customer base likely broad and fragmented, reducing single-customer concentration risk

Risk factors: Small scale with limited capital buffers typical of small Danish ApS firms, Capital intensity in hosting/private cloud requiring ongoing capex, Talent dependency on small number of key technical staff, Hyperscaler competition (Azure, AWS, Google Cloud) compressing margins, Elevated cybersecurity/breach liability risk typical of MSP sector

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report