IT-Forsyningen

Denmark · it-forsyningen.dk · 11 vendors

IT-Forsyningen I/S provides IT service, operations, and support tasks for five Danish municipalities: Allerød, Ballerup, Egedal, Fredensborg, and Furesø. The company aims to deliver innovative, high-quality IT services that support the municipalities' business processes and reduce long-term IT costs.

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 11 sub-vendors.

Insights

Last updated 2026-06-24 · revision 2

11 direct vendors, 175 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

IT-Forsyningen's migration readiness is assessed as 25. The company's internal tech stack, featuring "HaloITSM," "MitID," and reliance on "Municipal network infrastructure," does not indicate a cloud-native, containerized, or microservices architecture. This suggests a potentially monolithic or tightly coupled environment, which would significantly increase the complexity and effort required for migration to modern cloud platforms. There is no available data regarding specific regulatory environments or data residency requirements, which are critical factors that could introduce substantial compliance challenges and costs during a migration. Similarly, the absence of financial data (revenue, growth) makes it impossible to assess the company's capacity to fund a potentially large-scale migration initiative. Regarding vendor relationships, the data presents a contradiction: "Total Vendors: 0" is stated, yet the use of specific products like HaloITSM and MitID implies external vendors. If we assume they rely on a few key external platforms, this could lead to significant vendor lock-in, especially with a national digital identity system like MitID, making it difficult and costly to switch or re-platform. The "Unknown" vendor lock-in risk further exacerbates this uncertainty. The combination of a traditional tech stack, significant data gaps on critical migration factors, and potential vendor lock-in points to low migration readiness.

Compliance

7 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

IT-Forsyningen provides cloud-adjacent and managed IT services to five municipalities, which may include hosting, infrastructure management, and digital service delivery. SOC 2 is increasingly expected by public sector clients as evidence of controls over security, availability, processing integrity, confidentiality, and privacy. While SOC 2 is not legally mandated in Denmark, the absence of a SOC 2 report (or equivalent ISO 27001 certification) may represent a gap in demonstrable assurance to the municipalities it serves. Risk is Medium rather than High because SOC 2 is a voluntary US framework and Danish public sector entities more commonly use ISO 27001 or ISAE 3402/3000 as assurance frameworks.

Evidence: https://www.it-forsyningen.dk, https://www.aicpa-cima.com/resources/landing/soc-2-engagements

ISAE 3000 (source) — Assessment Required

ISAE 3000 (and the related ISAE 3402 for service organizations) is commonly used in Denmark as an assurance framework for IT service providers serving public and private sector clients. As IT-Forsyningen provides IT operations and support services to five municipalities, the municipalities may require or benefit from an ISAE 3000/3402 assurance report to satisfy their own governance and audit obligations. Risk is Medium because while not legally mandated, the absence of such a report may create audit gaps for the municipalities' own financial and operational audits (e.g., by Rigsrevisionen or municipal auditors).

Evidence: https://www.it-forsyningen.dk, https://www.rigsrevisionen.dk, https://www.fsr.dk/faglige-standarder/revisionsstandarden/isae-3000

Danish Municipal Governance Law — Assessment Required

IT-Forsyningen is structured as an interessentskab (I/S) — a partnership/joint venture between five municipalities. This structure is governed by Danish municipal law (Kommunestyrelsesloven, LBK nr. 47 af 15/01/2019) and the rules on inter-municipal cooperation (§ 60 samarbejder). Compliance with these governance rules is essential for the legal validity of the entity. Risk is Medium as the entity has been operating since 2014 and has established vedtægter (bylaws), suggesting foundational governance compliance, but ongoing compliance with municipal law requirements must be maintained.

Evidence: https://www.it-forsyningen.dk/om-os/bestyrelse-og-ejerskab, https://www.retsinformation.dk/eli/lta/2019/47, https://www.ankestyrelsen.dk

Financials

Three-year financials

Financial Resilience Score: 7/10

IT-Forsyningen I/S is a Danish inter-municipal cooperative (§60-fællesskab) jointly owned by five municipalities, operating on a cost-recovery basis rather than as a commercial entity. Its financial profile is characterized by near-zero profit by design, with revenue derived entirely from contributions by its five owner-municipalities. This structure provides extremely high revenue visibility and essentially zero credit risk, as Danish municipalities are stable, publicly funded entities. Demand is contractually guaranteed via the I/S charter (vedtægter). The organisation has demonstrated steady growth through accession of new members (from three founding municipalities in 2014, to Allerød in 2018, to Fredensborg in 2023), creating economies of scale and a broader competence base. However, financial resilience is constrained by concentration risk (100% dependence on five Danish municipalities), political/governance risk tied to local elections, wage cost pressure from competition with the private IT labour market, and the absence of a typical equity buffer found in commercial firms. Financial transparency is limited compared to ApS/A/S entities, making external benchmarking difficult. Overall resilience is solid due to the public-sector backing but capped by the non-commercial, dependency-based structure.

Key strengths: Stable, public-sector funded customer base with five Danish municipalities, Cost-recovery model insulates from market competition, Contractually guaranteed demand via I/S charter (vedtægter), Growing scale through municipal accessions (2014, 2018, 2023), Strategic relevance from growing municipal digitalisation and cybersecurity needs, Zero credit risk from municipal customers

Risk factors: 100% revenue concentration in five Danish municipalities, Withdrawal risk from any single municipality could materially affect cost-sharing, Political/governance risk tied to Danish local elections (kommunalvalg), Wage cost pressure competing with private IT labour market for specialised competencies, No equity buffer typical of commercial firms, Limited financial transparency compared to listed or ApS/A/S companies

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report