IST Group AB
Sweden · owned by Independent (Sweden) · ist.com · 43 vendors
IST Group AB is Scandinavia's leading EdTech company, providing innovative software solutions for students, teachers, parents, and school administrators. Their unified platform covers administration, finance, scheduling, teaching tools, communication, and analytics, serving over 5 million users across Sweden, Norway, Denmark, and Germany. Founded in Växjö, Sweden in 1982, the company has grown to over 400 employees across 9 offices.
Resilience scores
- Digital Sovereignty: 9
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Hewlett Packard Enterprise — Technology — United States
- Stripe, Inc. — Financial Services — United States
- Veeam Software Group GmbH — Technology — United States
- and 45 more
Services catalogue
34 services in catalogue across 8 categories; runs on 43 sub-vendors.
- Association Administration System
- Database search
- Embedded Linux Platforms
Insights
Last updated 2026-08-10 · revision 12
43 direct vendors, 349 subvendors
Direct vendors by controlling owner country (sample)
- Japan: 1
- Czech Republic: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- UK: 1
- France: 8
- Portugal: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
IST Group AB shows good potential for migration readiness, primarily driven by its modern technological foundation. The company operates a 'Cloud-based Infrastructure (SaaS delivery model)' and utilizes 'REST APIs' and 'SOAP APIs', which suggests a modular architecture conducive to migration. The adoption of 'SS12000 Data Standard' and 'OneRoster Data Standard' for data exchange further facilitates interoperability and data portability. Existing compliance with ISO 27001 and ISAE 3000 indicates strong information security controls that would support a secure migration process. However, several factors introduce complexity. As an EU-based company operating across multiple countries, strict GDPR and national data residency requirements are paramount, necessitating careful planning for data location and transfer during any migration. The financial stability of the company is unknown due to a lack of revenue data, which makes it difficult to assess their capacity to fund a significant migration effort. The 'Total Vendors: 0' data point is ambiguous; if interpreted as having no vendors, it would imply minimal vendor lock-in. However, the presence of 'Total Services: 129' and 'Vendor HQ Countries' suggests external dependencies. The explicit 'Vendor Lock-in Risk: Unknown' is a significant gap in assessing migration flexibility. Pending assessments for NIS2 and SOC2 could also introduce new compliance requirements that would need to be factored into migration planning.
Compliance
9 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Compliant
IST Group AB holds a current ISO/IEC 27001 certificate, publicly available for download on their certifications page. This internationally recognized standard demonstrates that IST has implemented a systematic and structured Information Security Management System (ISMS) that has been independently audited and certified. Risk is Low because the certification is current and publicly evidenced, indicating active compliance with information security management requirements. Ongoing risk relates to maintaining certification through surveillance audits and recertification cycles.
Evidence: https://www.ist.com/certifications-and-audit-assurance, https://www.ist.com/hubfs/International/ISO-IEC_27001%20certificate.pdf, https://www.ist.com/en/news/we-are-iso14001-certified
ISO 14001 — Compliant
IST Group AB holds a current ISO 14001:2015 certificate (certificate no. 10000453832, issued by MSC, accredited by SWEDAC, dated 2024-12-23), publicly available on their certifications page. The company also published a news article announcing the ISO 14001 certification for the whole of IST Group. Risk is Low given the current and publicly evidenced certification status.
Evidence: https://www.ist.com/certifications-and-audit-assurance, https://www.ist.com/hubfs/International/2024-ISO_14001-ENG-10000453832-MSC-SWEDAC-SWE-1-20241223.pdf, https://www.ist.com/en/news/we-are-iso14001-certified
ISO 9001 — Compliant
IST Group AB holds a current ISO 9001:2015 certificate (certificate no. 10000320760, issued by MSC, accredited by SWEDAC, dated 2024-12-23), publicly available on their certifications page. ISO 9001 certification demonstrates a structured quality management system, which is relevant for a SaaS provider delivering mission-critical educational administration software to public sector clients. Risk is Low given the current and publicly evidenced certification status.
Evidence: https://www.ist.com/certifications-and-audit-assurance, https://www.ist.com/hubfs/International/2024-ISO_9001-ENG-10000320760-MSC-SWEDAC-SWE-3-20241223.pdf
Financials
Financial Resilience Score: 7/10
IST Group AB demonstrates solid qualitative financial resilience characteristics despite the absence of verified quantitative data in this session. The company benefits from a highly sticky, mission-critical software business serving Nordic public-sector customers (municipalities and school authorities), which typically provides predictable, recurring revenue with low credit risk. Multi-year contracts and high switching costs for student information systems, once embedded in a municipality, create meaningful revenue durability. With over 40 years of operating history, 5+ million users, and 400+ employees across 9 offices in 4 countries, IST has achieved meaningful scale relative to smaller Nordic EdTech peers. However, several factors constrain a higher resilience score. The company's heavy dependence on public-sector procurement exposes it to long, competitive tender cycles and pricing pressure. The ongoing legacy-to-cloud transition (migrating inherited on-prem systems like Extens/Procapita to modern SaaS) is capex-heavy and can pressure margins. Competition from Visma InSchool, TietoEVRY, Infomentor, Itslearning, and the encroaching Google/Microsoft ecosystems adds pressure. Historical private-equity ownership (Axcel reportedly involved) suggests a leveraged capital structure whose refinancing risk cannot be assessed without current filings. Without verified revenue, EBIT and equity figures, the resilience score reflects qualitative business-model strengths tempered by unknown balance sheet dynamics.
Key strengths: Sticky, mission-critical school administration software with high switching costs, Recurring revenue from low-credit-risk public-sector customers (municipalities), Multi-year contracts with predictable budget cycles, Nordic scale: 5+ million users, 400+ employees, 9 offices in 4 countries, 40+ year operating history and established brand, Geographic diversification across Sweden, Norway, Denmark, Germany, ISO 14001 certified
Risk factors: Heavy concentration on public-sector procurement and tender cycles, Currency exposure to SEK, NOK, DKK, EUR, Capex-heavy legacy-to-cloud SaaS transition pressuring margins, Competition from Visma InSchool, TietoEVRY, Infomentor, Itslearning, Google/Microsoft, Private equity-linked ownership with unknown debt/leverage structure, Regulatory dependence on GDPR and school data localization rules
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.