Impero A/S
Denmark · owned by Independent (Denmark) · impero.com · 13 vendors
Impero A/S is a Danish Software-as-a-Service (SaaS) company that offers a cloud-based platform for governance, risk, and compliance (GRC). The platform helps organizations, especially finance, tax, and compliance teams, to proactively manage risks and internal controls, ensuring transparency and audit readiness.
Resilience scores
- Digital Sovereignty: 23
- Digital Resilience: 7
- Financial Resilience: 6
Disruption prediction
Impero A/S has an estimated 17% probability of disruption in the next 6 months.
8 of Impero A/S's 13 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- HubSpot, Inc. — Technology — United States
- SolarWinds — Technology — United States
- and 11 more
Services catalogue
1 service in catalogue across 1 category; runs on 13 sub-vendors.
- Compliance management
Insights
Last updated 2026-09-13 · revision 2
13 direct vendors, 219 subvendors
Direct vendors by controlling owner country (sample)
- France: 1
- Denmark: 2
- United States: 9
Subvendors by controlling owner country (sample)
- Romania: 1
- Germany: 6
- Switzerland: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Impero A/S exhibits a high level of migration readiness, primarily driven by its modern and cloud-native technology stack. The use of Microsoft Azure and a Cloud-based SaaS model indicates that the company is already operating in a flexible, scalable environment. The presence of REST APIs and Automated Workflow & Notifications suggests a modular, API-driven architecture, which significantly simplifies the process of migrating or re-platforming components. The modular nature of their Impero Platform products (e.g., Risk, Control, Reporting, Testing, Entities Modules) and the integration of an AI-assisted feature layer (Impero Assist) further support the idea of a non-monolithic, adaptable system. Despite these strengths, certain unknowns prevent a perfect score. Critical information regarding 'Data Residency Requirements' is not specified, which could introduce significant complexity and cost if strict requirements exist. The 'Regulatory Environment' is also unknown, meaning potential compliance hurdles during migration cannot be assessed. While 'Total Services: 19' suggests a number of dependencies, the 'Vendor Lock-in Risk' is explicitly stated as unknown, which could complicate a move to a different platform or vendor if dependencies are tightly coupled. Lastly, the financial stability (ability to fund a migration) is unknown due to missing revenue and growth data.
Compliance
8 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Compliant
Impero explicitly holds ISAE 3402 Type II certification, which is a specific application of the ISAE 3000 framework for service organizations reporting on controls relevant to user entities' financial reporting. This is directly relevant to Impero's business as a SaaS platform used by finance, tax, and compliance teams at enterprise organizations. ISAE 3402 Type II (the more rigorous variant) confirms that Impero's controls have been tested over a period of time and found to be operating effectively. Risk is Low because Impero has demonstrated active compliance with this framework, which is the primary assurance standard applicable to its business model in European markets. This certification directly supports customer trust and regulatory requirements for Impero's enterprise clients.
Evidence: https://impero.com/product/security-compliance, https://impero.com/resources/trust-center
SOC 2 (source) — Partially Compliant
Impero is a cloud-based SaaS provider, making SOC 2 highly relevant as enterprise customers increasingly require SOC 2 reports as part of vendor due diligence. Impero's security page explicitly references the SOC 2 report provided by Microsoft Azure (their cloud infrastructure provider), covering backup/restoration, infrastructure, firewall, patching, antivirus, and business continuity management. However, there is no evidence that Impero itself holds a direct SOC 2 Type I or Type II report for its own application and operations (as distinct from Azure's infrastructure SOC 2). The risk is Medium because enterprise customers in regulated industries (banking, pharmaceuticals, manufacturing) will likely require Impero's own SOC 2 attestation, and the absence of a direct report creates a vendor risk gap. The company does hold ISAE 3402 Type II, which is the European equivalent and partially mitigates this gap.
Evidence: https://impero.com/product/security-compliance, https://impero.com/resources/trust-center
ISO 27001 (source) — Partially Compliant
ISO 27001 is highly relevant for Impero as a SaaS provider handling sensitive enterprise compliance data. Impero's security page explicitly references ISO 27001 as a security measure provided by Microsoft Azure. However, there is no public evidence that Impero A/S itself holds a direct ISO 27001 certification for its own ISMS (Information Security Management System). The risk is Medium because enterprise customers — particularly in regulated industries — increasingly require their SaaS vendors to hold direct ISO 27001 certification. The absence of a direct Impero ISO 27001 certificate (as opposed to relying on Azure's certification) represents a gap that could affect enterprise sales and customer trust. The company's ISAE 3402 Type II and regular penetration testing partially compensate for this gap.
Evidence: https://impero.com/product/security-compliance, https://7269527.fs1.hubspotusercontent-na1.net/hubfs/7269527/Website%20Documentation%202025/Impero-security-whitepaper.pdf
Financials
Three-year financials
- 2025: revenue DKK 42.0M, EBIT DKK -6.72M, equity DKK 15.4M
- 2024: revenue DKK 35.4M, EBIT DKK -11.7M, equity DKK 6.16M
- 2023: revenue DKK 27.6M, EBIT DKK -13.1M, equity DKK 15.0M
Financial Resilience Score: 6/10
Impero A/S demonstrates improving financial resilience driven by a highly recurring SaaS revenue model with excellent retention metrics (1% churn, 106% NRR in 2025) and consistent double-digit ARR growth from DKK 30.4M (2023) to DKK 46.2M (2025). The EBITDA loss has narrowed substantially from -DKK 10.6M in 2023 to -DKK 3.1M in 2025, with 2025 cash burn from ordinary operations at only DKK 1.3M, indicating a credible path toward profitability. A December 2025 directed share issue of DKK 15M replenished the balance sheet, leaving the company with DKK 18.9M cash and no interest-bearing debt entering 2026. However, the company remains cash-flow negative on a recurring basis, and management has formally deferred the previous target of positive recurring cash flow by end-2026 to prioritize commercial investment. The equity base of DKK 15.4M is small relative to accumulated operating losses, and further capital raises may be needed if growth investments do not quickly translate into ARR. ARR growth has decelerated from 34% (2023) to 19% (2025), CAC has risen sharply from DKK 222K to DKK 371K, and CAC payback has lengthened to 22 months. Deloitte issued a clean audit opinion with no going-concern qualification, and the diversified blue-chip customer base (Volkswagen, Mercedes-Benz, Commerzbank, Maersk) and reduced top-10 customer concentration (20% of ARR) support resilience.
Key strengths: Highly recurring SaaS revenue with 1% churn and 106% Net Revenue Retention in 2025, ARR grew from DKK 30.4M (2023) to DKK 46.2M (2025), a 52% cumulative increase, EBITDA loss narrowed from -DKK 10.6M (2023) to -DKK 3.1M (2025), DKK 15M directed share issue in Dec 2025 restored cash to DKK 18.9M with no interest-bearing debt, Blue-chip enterprise customers including Volkswagen, Mercedes-Benz, Commerzbank, Maersk, Top-10 customer concentration reduced from 37% (2020) to 20% (2025), Big-4 partner channel (Deloitte, KPMG, PwC, Grant Thornton) generates 37% of ARR, Clean Deloitte audit opinion with no going-concern qualification, DKK 19.5M deferred income provides forward-revenue visibility, Unrecognized deferred tax asset of DKK 20.2M could benefit future earnings
Risk factors: Still cash-flow negative on a recurring basis; break-even target formally deferred, Small equity base of DKK 15.4M relative to ongoing operating losses, ARR growth decelerating (34% → 28% → 19%) with 2026 guidance of only 15-23%, CAC rose sharply from DKK 222K to DKK 371K; payback lengthened to 22 months, Geographic concentration: 88% of ARR from Denmark and DACH only, Small headcount (~40) creates key-person and execution risk, Recent executive turnover (CFO changed Aug-Oct 2025; new CCO Jan 2026), Small-cap First North listing with limited free float; share price 27% below IPO, Concentrated ownership limits liquidity (Kolind >25%, Profound Partners >20%), Rising competition from AI-first GRC vendors and potential market consolidation
Revenue by geography
- Denmark: 44%
- DACH (Germany/Austria/Switzerland): 44%
- Other (UK, Benelux, Nordics ex-DK, US, South Africa): 12%
Revenue by product/service
- Impero SaaS Platform (Risk, Control, Reporting, Testing, Entity Management, Impero Assist AI): 100%
Workforce by country
- France: 0
- Denmark: 0
- Germany: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.