itm8
Denmark · owned by AX VI itm8 Holding III ApS (Denmark) · itm8.com · 56 vendors
ITM8 Holding A/S is a leading Northern European digital transformation partner that provides comprehensive IT solutions. The company specializes in cloud services, digital transformation, application services, ERP, and cybersecurity. They serve small, medium, and corporate businesses, as well as the public sector across Europe, with headquarters in Denmark.
Resilience scores
- Digital Sovereignty: 21
- Digital Resilience: 8
- Financial Resilience: 5
Disruption prediction
itm8 has an estimated 27% probability of disruption in the next 6 months.
23 of itm8's 56 vendors monitored for disruptions.
Technology vendors
- Anthropic, PBC — Technology — United States
- EasyDMARC Inc. — Cybersecurity — United States
- Netlify, Inc. — Technology — United States
- and 54 more
Services catalogue
12 services in catalogue across 5 categories; runs on 56 sub-vendors.
- Personal Data Processing
- Modern work
- Development & Integration
Insights
Last updated 2026-09-15 · revision 47
56 direct vendors, 432 subvendors
Direct vendors by controlling owner country (sample)
- United Kingdom: 1
- Australia: 1
- Germany: 3
Subvendors by controlling owner country (sample)
- Hong Kong: 1
- Canada: 11
- UK: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
itm8 exhibits high migration readiness (Score: 90), primarily driven by its deeply integrated cloud-native strategy and extensive expertise in digital transformation. The company's internal tech stack is heavily invested in modern Microsoft cloud platforms (Azure, Microsoft 365, Dynamics 365, Power Platform, Copilot technologies), which are inherently designed for scalability, flexibility, and migration. As a top-5 Microsoft Solutions Partner in Denmark, itm8 possesses profound knowledge and experience in migrating and modernizing client environments, including multi-cloud and hybrid IT infrastructure services, which directly translates to high internal readiness. Their "Application Services" and "Digital Transformation" offerings further underscore their capability in managing complex migrations, including database administration and application modernization. Financially, itm8 is very stable with substantial and growing revenue, providing ample resources to fund any internal migration or modernization initiatives. The regulatory environment, while complex with new directives like NIS2 and DORA, is well-understood and managed by itm8, as evidenced by their comprehensive GDPR, ISO 27001:2022, ISAE 3000, and ISAE 3402 certifications. These certifications ensure robust data protection and operational controls, which are crucial for secure and compliant migrations. Data residency requirements, particularly for GDPR and Danish public sector clients (SKI framework), are clearly defined and managed, with reliance on Microsoft's EU Data Boundary commitments and presumed EU-based data centers. This established framework simplifies data handling during migration. Regarding vendor relationships, the data indicates a strong reliance on the Microsoft ecosystem. While the "Total Vendors: 0" is ambiguous, the "Internal Tech Stack" clearly shows Microsoft as a primary vendor, alongside Oracle, PostgreSQL, and HubSpot. This strong focus on Microsoft could be seen as a form of vendor lock-in if a strategic shift away from Microsoft were ever contemplated for itm8's own core systems. However, for their current business model, this deep integration with Microsoft is a significant enabler for efficient migrations and modernization within that ecosystem. The "Vendor Geographic Diversity" across 7 countries suggests a broader vendor landscape for other services, which could offer flexibility. Overall, itm8's core business of enabling digital transformation for others positions it exceptionally well for its own migration readiness.
Compliance
7 in-scope frameworks identified; showing 3.
DORA (source) — Assessment Required
DORA applies to ICT third-party service providers that are critical to financial entities in the EU. As itm8 provides a wide range of IT services, it is likely they have clients in the financial sector.
If itm8 provides critical ICT services to the financial sector, non-compliance with DORA could lead to contractual penalties and loss of business. The risk is moderate as the extent of their financial sector clientele is not fully clear.
Evidence: https://www.fortra.com/resources/guides/ultimate-guide-dora-compliance-financial-sector, https://waterfront.law/dora-compliance-what-financial-firms-need-to-know-about-the-eu-digital-operational-resilience-act/, https://www.klgates.com/thought-leadership/Digital-Operational-Resilience-in-the-Financial-Services-Sector-EU-and-UK-Update-7-31-2024, https://workpoint365.com/partners/partner-overview/itm8/, https://copla.com/blog/compliance-regulations/dora-regulations-in-denmark-and-impact-for-all-industries/, https://businesslaw.no/articles/eu-s-dora-regulation-on-ict-security-in-finance-norwegian-implementation/
CRA — Assessment Required
The Cyber Resilience Act (CRA) applies to all products with digital elements placed on the EU market. itm8, as a provider of various IT solutions and potentially software, will likely fall under its scope.
The Cyber Resilience Act will impose cybersecurity requirements on products with digital elements. Non-compliance could prevent itm8 from placing certain products on the EU market and lead to fines.
Evidence: https://www.williamfry.com/knowledge/cyber-resilience-act-what-manufacturers-need-to-know/, https://www.avixa.org/explore/articles/cyber-resilience-act, https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act, https://tracxn.com/d/companies/itm8/__g7h4VRfI7_2drhASKfKFvECcvx2xeIzvyHzQtclZ788, https://itm8.com/newsuk/itm8-unites-13-companies-in-a-major-merger, https://expert.broadcom.com/partners/vcsp/itm8
ISAE 3000 (source) — Compliant
For a technology service provider like itm8, an ISAE 3000 report provides independent assurance to clients over the design and effectiveness of controls related to services and data processing.
The ISAE 3000 report provides assurance over non-financial information, which is important for building trust with clients, particularly regarding data protection and security processes. Failure to maintain this would be a competitive disadvantage.
Evidence: https://itm8.com/about-itm8/certifications, https://itm8.dk/om-itm8/certificeringer
Financials
Three-year financials
- 2025: revenue DKK 2.10B, EBIT DKK -12.3M, equity DKK 1.29B
- 2024: revenue DKK 1.99B, EBIT DKK 43.4M, equity DKK 1.40B
- 2023: revenue DKK 1.03B, EBIT DKK 108M, equity DKK 160M
Financial Resilience Score: 5/10
itm8 shows a mixed resilience profile. On the positive side, the company benefits from strong PE sponsorship (Axcel, Chr. Augustinus Fabrikker, Ares, Dansk Vækstkapital II), a solid equity base with a group solvency ratio of 35.8% at end-2024, and highly recurring revenue with ~70% derived from Managed Services across 5,000+ customers and 200,000+ daily IT users. Management explicitly confirms sufficient liquidity and covenant headroom based on 2025-2026 forecasts, and PwC issued a clean audit opinion on the FY 2024 group accounts. However, the group is loss-making at a consolidated level, with net losses of DKK 582m in 2024 and DKK 532m in 2023 driven by heavy amortisation of goodwill/customer relationships and DKK 417m in financial expenses tied to Axcel's leveraged buyout structure. The single Danish operating entity (CVR 27001092) swung to a DKK 29.5M net loss in 2025 after only modest 5.5% revenue growth, with EBIT turning negative. Headcount has been reduced significantly (from 1,345 to 1,134 average, now 1,016 registered), and the group missed its FY 2024 revenue guidance. Execution risk from the ongoing 'One itm8' integration program, floating-rate senior debt from Ares/Nykredit, and unhedged SEK translation exposure add further pressure. Overall, resilience is adequate but constrained by leverage and integration execution risk.
Key strengths: Strong PE sponsorship from Axcel, Chr. Augustinus Fabrikker, Ares and Dansk Vækstkapital II, Group solvency ratio of 35.8% at end-2024, ~70% of revenue from recurring Managed Services, 5,000+ customers and 200,000+ daily IT users providing revenue visibility, Clean PwC audit opinion on FY 2024 group accounts, Management-confirmed liquidity headroom and covenant compliance for 2025-2026, ISO/IEC 27001:2022, ISAE 3402 Type II, and ISAE 3000 Type II certifications
Risk factors: Persistent group-level net losses (DKK -582m in 2024, DKK -532m in 2023), Highly leveraged capital structure with floating-rate senior debt from Ares and Nykredit, Heavy amortisation burden from DKK 3.9B customer relationships and DKK 2.8B goodwill, Unhedged SEK translation exposure from Swedish subsidiaries, Execution risk from ongoing 'One itm8' integration program, Declining headcount (1,345 → 1,134 → 1,016) signals operational pressure, FY 2024 revenue miss vs. DKK 2,700-2,800m guidance, Operating entity swung to loss in FY 2025 (DKK -29.5M net, DKK -12.3M EBIT), CSRD preparations deprioritised
Revenue by geography
- Denmark: 75%
- Sweden: 23%
- Other: 2%
Revenue by product/service
- Managed Services: 70%
- Product Sales: 16%
- Professional Services: 14%
Workforce by country
- Denmark: 1016
- Sweden: 927
- Germany: 125
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.