IT Confidence A/S
Denmark · owned by B36 ApS (Denmark) · itconfidence.dk · 15 vendors
IT Confidence A/S is a Danish IT company that provides stable IT operations, strong IT security, and flexible solutions for businesses. They function as an external IT department, managing services from servers and networks to backup, cloud, and support, ensuring reliable and secure IT environments.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 4
- Financial Resilience: 6
Technology vendors
- MailChannels Corporation — Cybersecurity — Canada
- Netlify, Inc. — Technology — United States
- SPFProtect (MailChannels) — Cybersecurity — Canada
- and 12 more
Services catalogue
1 service in catalogue across 1 category; runs on 15 sub-vendors.
- DNS Hosting
Insights
Last updated 2026-09-13 · revision 8
15 direct vendors, 247 subvendors
Direct vendors by controlling owner country (sample)
- United States: 10
- Japan: 1
- Israel: 1
Subvendors by controlling owner country (sample)
- United States: 178
- Poland: 3
- Unknown: 1
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The company demonstrates medium migration readiness. Strengths: The company exhibits good migration readiness due to its existing hybrid cloud strategy, leveraging Microsoft Azure and S3 Object Lock for immutable storage. Their "Virtual Datacenter Platform" combines local Danish hosting with public cloud, indicating familiarity with cloud environments and the ability to manage diverse infrastructure. Proactive awareness and emphasis on "Danish hosting" and "Danish datacenters" directly address critical data residency requirements, which is a significant advantage for planning migrations within the EU/EEA regulatory framework. While the data states "Total Vendors: 0", which contradicts the presence of "Vendor HQ Countries" and "Vendor Geographic Diversity", the implied geographic diversity of vendor HQs (6 unique countries) suggests a potentially diversified supply chain, reducing single-vendor dependency from a geographic perspective, assuming vendors do exist. Weaknesses: The complex regulatory environment, particularly GDPR and the likely applicability of NIS2, poses significant challenges. While aware, the lack of formal certifications (e.g., ISO 27001, SOC2, ISAE 3000/3402) means that establishing or proving compliance during a migration could add considerable overhead and risk. The financial stability, being 100% concentrated in Denmark, could impact the ability to fund large-scale migrations if the local market experiences a downturn. The contradictory "Total Vendors: 0" data point makes a precise assessment of vendor lock-in difficult; however, their reliance on specific platforms like Microsoft Azure and S3 Object Lock implies some level of platform-specific dependency that would need to be managed during any significant migration.
Compliance
7 in-scope frameworks identified; showing 3.
EU Data Act — Assessment Required
IT Confidence A/S explicitly references the EU Data Act on its homepage alongside NIS2: 'Vi hjælper dig med at leve op til kravene i blandt andet NIS2 og Data Act' (We help you comply with requirements including NIS2 and Data Act). The EU Data Act entered into force on 11 January 2024 and applies from 12 September 2025. As a cloud and managed services provider, IT Confidence A/S may be subject to Data Act obligations as a 'data holder' or 'data recipient' in the context of cloud switching and data portability requirements. Risk is Medium because: (1) the Data Act is newly applicable (from September 2025); (2) IT Confidence A/S provides cloud and hosting services that fall within scope; (3) the company has demonstrated awareness by referencing it publicly; (4) specific obligations around data portability, cloud switching, and interoperability will need to be implemented.
Evidence: https://itconfidence.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R2854, https://digital-strategy.ec.europa.eu/en/policies/data-act
ISAE 3000 (source) — Assessment Required
IT Confidence A/S explicitly references ISAE 3402 on its homepage: 'Processer der understøtter ISAE 3402' (Processes that support ISAE 3402). This is a significant and specific compliance signal — the company is actively positioning its processes as supporting ISAE 3402 assurance reporting. ISAE 3402 (Assurance Reports on Controls at a Service Organisation) is the international standard used by service organisations to demonstrate the effectiveness of their internal controls to clients and their auditors. As an IT MSP, IT Confidence A/S would be a 'service organisation' under ISAE 3402. Risk is Medium because: (1) the company has explicitly referenced ISAE 3402, indicating awareness and intent; (2) however, 'processes that support ISAE 3402' does not confirm that an actual ISAE 3402 Type I or Type II report has been issued; (3) without a formal report from an accredited auditor, clients cannot rely on ISAE 3402 assurance; (4) if clients are relying on IT Confidence's ISAE 3402 positioning without a formal report, this creates a misrepresentation risk.
Evidence: https://itconfidence.dk/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3402-assurance-reports-controls-service, https://www.fsr.dk/
NIS2 (source) — Assessment Required
IT Confidence A/S explicitly references NIS2 on its website as a framework it helps customers comply with, demonstrating awareness. As an IT Managed Services Provider (MSP), IT Confidence A/S may itself fall under NIS2 as an 'Important Entity' in the category of 'ICT service management (B2B)' (Annex II of NIS2 Directive). MSPs providing managed IT services to other businesses are specifically called out in NIS2 as a category of digital providers subject to the directive. However, NIS2 applies to medium and large enterprises (50+ employees OR €10M+ annual turnover). IT Confidence A/S was founded in April 2020 and appears to be a small company based on its founding story (4 founders, growing to multiple offices). If the company is below the 50-employee and €10M turnover thresholds, it would generally be exempt — unless it is identified as a critical entity by Danish authorities regardless of size. Risk is Medium because: (1) the sector match (ICT managed services) is strong; (2) the size threshold is uncertain and could be met; (3) non-compliance with NIS2 carries fines up to €7M or 1.4% of global annual turnover for Important Entities; (4) Denmark has transposed NIS2 and the Danish Centre for Cyber Security (CFCS) is actively enforcing it. The company's own marketing of NIS2 compliance assistance to clients creates reputational risk if they themselves are non-compliant.
Evidence: https://itconfidence.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/, https://www.en.digst.dk/policy-and-strategy/nis2/
Financials
Three-year financials
- 2025: gross profit DKK 8.41M, EBIT DKK -10.2M, equity DKK -7.40M
- 2024: gross profit DKK 16.5M, EBIT DKK -2.34M, equity DKK 900K
- 2023: gross profit DKK 12.1M, EBIT DKK 1.93M, equity DKK 3.35M
Financial Resilience Score: 6/10
IT Confidence A/S demonstrates a business model with structural strengths typical of managed service providers (MSPs), including recurring monthly retainer revenue from IT operations, support, backup, and security monitoring. This provides predictable cash flow and high customer lifetime value. The company is well-positioned to benefit from Danish SME compliance-driven IT outsourcing tailwinds through 2024-2026, driven by NIS2 and Data Act obligations, and differentiates through Danish-hosted infrastructure and ISAE 3402-aligned processes. A self-reported NPS of 62.7 for 2024 supports low churn assumptions and customer loyalty. However, the company faces meaningful scale-related risks. As a small-to-mid-sized Danish MSP, it competes against much larger integrators (Fujitsu, itm8, Globeteam, Netcompany, Atea) and dozens of regional MSPs, creating pricing pressure and talent competition. Its 'no lock-in' marketing policy, while trust-building, reduces contractual revenue visibility. Customer concentration risk is elevated given a modest reference customer list, and heavy dependence on the Microsoft ecosystem (M365, Azure) exposes gross margin to licensing and partner-program changes. Operational/cyber risk is existential for an MSP running client environments, and NIS2 compliance costs will rise. Without verified financials (revenue, EBIT, equity, headcount) from the CVR annual reports, a definitive resilience score cannot be established; the score reflects a qualitative mid-range assessment based on business model and market positioning.
Key strengths: Recurring-revenue managed services business model with predictable cash flow, Compliance-forward positioning aligned with NIS2 and Data Act tailwinds, Danish-hosted infrastructure differentiation for SME customers, Two-office national footprint (Kongens Lyngby and Silkeborg), High self-reported NPS of 62.7 (2024) indicating customer loyalty, ISAE 3402-aligned processes and Microsoft 365 hardening capabilities
Risk factors: Scale disadvantage versus larger Danish IT integrators (Fujitsu, itm8, Atea, Netcompany), Customer concentration risk with modest reference customer base, No lock-in policy reduces contractual revenue visibility and churn protection, Heavy dependence on Microsoft ecosystem (M365, Azure) licensing and partner programs, Cyber/operational risk as a hosting provider - security incident could be existentially damaging, Rising NIS2 compliance costs, Talent competition and pricing pressure in Danish MSP market
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Backup & Recovery: 0%
- Netværk & Sikkerhed (Network & Security): 0%
- IT Drift & Support (Managed Services/Helpdesk): 0%
- Cloud & Infrastruktur (including Danish hosting): 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.