I2 A/S

Denmark · www.i2.dk · 17 vendors

I2 A/S is a Danish company that provides IT infrastructure and operations services. It offers network, hosting, and data communication solutions, and operates Denmark's largest internet exchange point (DIX). The company, an independent division within the Technical University of Denmark (DTU), has over 40 years of experience in its field.

Resilience scores

Technology vendors

Services catalogue

8 services in catalogue across 4 categories; runs on 17 sub-vendors.

Insights

Last updated 2026-03-12 · revision 2

17 direct vendors, 234 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

I2 A/S exhibits low migration readiness. The company's core business revolves around physical infrastructure services such as an Internet Exchange (DIX), co-location, and traditional hosting (web, mail), which inherently suggests a legacy or on-premise-centric technology stack. There is no indication of cloud-native technologies, containerization, or microservices in their internal tech stack or key technologies, implying that a significant re-architecture and refactoring effort would be required for a successful migration to modern cloud platforms. The lack of specified data residency requirements and unknown financial stability to fund such a large-scale transformation are significant challenges. While the company has good vendor geographic diversity, the 'Total Services: 29' suggests a potentially complex ecosystem of interconnected services, which could lead to high vendor lock-in risk, especially given their infrastructure-heavy offerings. The 'Vendor Lock-in Risk: Unknown' is a critical missing piece of information, but the nature of their business points towards potential infrastructure-level lock-in. While ISO 27001 certification provides a strong security foundation, it does not directly translate to architectural readiness for cloud migration.

Compliance

5 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

As a service provider offering hosting and facility management, ISAE 3000 assurance reports could be valuable for demonstrating control effectiveness to customers. While not mandatory, lack of such assurance could limit business opportunities with larger enterprise customers who require third-party assurance. Risk is moderate as it affects competitive positioning rather than regulatory compliance.

GDPR (source) — Assessment Required

As a Danish company providing IT services including hosting, email services, and facility management, I2 A/S inevitably processes personal data of employees, customers, and potentially end-users of their services. GDPR violations can result in fines up to 4% of annual turnover or €20 million. Given their location in Denmark (EU) and service offerings, GDPR compliance is mandatory and non-compliance carries severe financial and reputational risks.

Evidence: https://www.i2.dk/, https://www.i2.dk/da/content/iso-27001-hos-i2

NIS2 (source) — Assessment Required

I2 A/S provides digital infrastructure services including hosting, datacenter services, and operates DIX (Denmark's largest internet exchange point). This likely qualifies them as a 'digital infrastructure' provider under NIS2's Important Entities category. NIS2 has significant cybersecurity requirements and incident reporting obligations. Non-compliance can result in fines up to €10 million or 2% of annual turnover, plus potential business disruption from regulatory actions.

Evidence: https://www.i2.dk/, https://www.i2.dk/da/content/iso-27001-hos-i2

Financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report