KOMBIT A/S
Denmark · owned by KL (Denmark) · kombit.dk · 17 vendors
KOMBIT (Kommunernes it-fællesskab) is a Danish shared IT organisation owned by the Danish municipalities (KL – Local Government Denmark). It develops and manages a modern IT infrastructure and approximately 30 nationwide IT solutions to support digital transformation across all Danish municipalities. Its focus areas include data support, digital welfare, IT infrastructure, green transition, and cybersecurity.
Resilience scores
- Digital Sovereignty: 47
- Digital Resilience: 7
- Financial Resilience: 9
Technology vendors
- Adobe Inc. — Technology — United States
- Kruso — Technology — Denmark
- UXmail — Technology — Denmark
- and 23 more
Services catalogue
6 services in catalogue across 1 category; runs on 17 sub-vendors.
- Fælleskommunal Datafordeler
- Kommunernes Ydelsessystem
- NemRefusion 3.0
Insights
Last updated 2026-09-13 · revision 17
17 direct vendors, 267 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Germany: 2
- Denmark: 5
Subvendors by controlling owner country (sample)
- Moldova: 1
- Sweden: 9
- Denmark: 10
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
KOMBIT A/S exhibits a medium level of migration readiness. On the positive side, their financial stability, evidenced by strong revenue growth, provides the necessary capital to fund significant migration initiatives. The tech stack includes modern elements such as Microsoft Azure adoption, extensive use of REST APIs across infrastructure components, and an event-driven messaging system (Beskedfordeler), which indicates a modular architecture conducive to migration. The presence of a central integration platform (Serviceplatformen) and robust identity and access management components can facilitate phased migrations and secure integration of new systems. However, several significant challenges hinder higher migration readiness. The regulatory environment imposes strict constraints: NIS2 compliance is a 'High Risk' and 'Assessment Required,' meaning any migration must meticulously address these requirements, potentially adding complexity and cost. Similarly, formal ISO 27001 certification and SOC2/ISAE 3000 assurance reports are 'Assessment Required,' which would likely be prerequisites for demonstrating security and control to municipal clients during and after migration. Data residency requirements are stringent, with a strong preference for data processing within Denmark/EU, limiting the choice of cloud providers and potentially increasing infrastructure costs. Vendor lock-in is a considerable concern; while KOMBIT works with multiple vendors, critical core systems like KY, KSD, SAPA, BBR, DUBU, and FLIS are primarily handled by Netcompany, and Støttesystemerne by KMD. This concentration with a few key vendors for essential services suggests high vendor lock-in, which could complicate contract negotiations, data migration, and re-platforming efforts. The presence of legacy integration technologies like Webservices/SOAP on the Serviceplatformen and SFTP also indicates that a full migration would involve modernizing or re-architecting these components, adding to the complexity and duration of the migration process.
Compliance
9 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a US-origin voluntary framework (AICPA) for service organisations managing customer data, assessing controls around Security, Availability, Processing Integrity, Confidentiality, and Privacy. While not legally mandated in Denmark, KOMBIT operates as a shared IT service provider for 98 municipalities and manages 30+ critical IT systems. Its municipal clients and IT vendors may require SOC 2 or equivalent assurance. KOMBIT references 'revisionserklæringer' (audit declarations) on its security page, which may be ISAE 3402 (the European equivalent of SOC 2) reports rather than SOC 2 specifically. Risk is Medium because the absence of SOC 2 or equivalent assurance could affect vendor trust and procurement eligibility, though it is not a legal requirement in Denmark.
Evidence: https://kombit.dk/fokusomraader/sikkerhed, https://dok.kombit.dk/sikkerhed
ISAE 3000 (source) — Partially Compliant
ISAE 3402 (assurance on controls at service organisations) and ISAE 3000 (general assurance engagements) are the European standard equivalents of SOC 2, widely used in Denmark for IT service providers. KOMBIT explicitly references 'revisionserklæringer' (audit/assurance declarations) as a core part of its information security framework, stating these create 'transparency and trust.' This strongly suggests ISAE 3402 or ISAE 3000 reports are produced for KOMBIT's IT solutions. Risk is Medium because while assurance reporting appears to be in place, the scope, frequency, and specific ISAE standard applied are not publicly confirmed, and gaps in coverage could affect municipal clients' own compliance obligations.
Evidence: https://kombit.dk/fokusomraader/sikkerhed, https://dok.kombit.dk/sikkerhed
EU Cybersecurity Act — Assessment Required
The EU Cybersecurity Act establishes ENISA's mandate and a framework for ICT product/service/process certification. As KOMBIT procures and manages ICT solutions for all Danish municipalities, it may be subject to EU cybersecurity certification requirements for specific products or services, particularly as the EU rolls out certification schemes (e.g., EUCS for cloud services). KOMBIT's role in managing critical municipal IT infrastructure also intersects with broader EU cybersecurity policy. Risk is Medium as mandatory certification schemes are still being developed and implemented.
Evidence: https://kombit.dk/fokusomraader/sikkerhed, https://www.enisa.europa.eu, https://kombit.dk/fokusomraader/it-infrastruktur
Financials
Three-year financials
- 2025: revenue DKK 1.11B, EBIT DKK 124M, equity DKK 713M
- 2024: revenue DKK 1.02B, EBIT DKK 36.1M, equity DKK 633M
- 2023: revenue DKK 934M, EBIT DKK -178M, equity DKK 624M
Financial Resilience Score: 9/10
KOMBIT A/S operates a structurally low-risk, pass-through cost-recovery model that effectively eliminates most conventional financial risks. As a wholly owned subsidiary of KL (Local Government Denmark), the company serves a captive customer base of all 98 Danish municipalities, which are themselves funded by national taxation. This results in extremely low counterparty and credit risk, with demand essentially guaranteed by the ownership structure. Revenue is generated through municipal prepayments during development phases and per-citizen/per-municipality usage fees once systems go into operations, ensuring predictable cash flow. The company's near-zero EBIT and modest equity (~DKK 50-70M) are by design rather than indicators of weakness. KOMBIT bills municipalities at cost plus a modest buffer for risk/reserves, meaning profitability is not the operational objective. Capital adequacy is maintained through the relationship with parent KL and prepayments from municipalities, providing a stable financial foundation despite the thin equity base. However, the company faces meaningful execution risks on large IT programs, with historical examples like KY experiencing multi-year delays and cost overruns. While these costs can ultimately be passed to municipalities, they create political friction. Additionally, heavy supplier concentration—particularly on Netcompany and KMD—introduces vendor lock-in and pricing pressure risks. Despite these operational challenges, the financial resilience remains very high due to the public-sector backing and guaranteed demand.
Key strengths: Captive customer base of all 98 Danish municipalities, 100% ownership by KL (Local Government Denmark) providing public-sector backing, Cost-recovery model with prepayments and usage fees ensuring predictable revenue, Long-term framework agreements with suppliers and municipalities, Indirect support from municipal sector funded by national taxation, Extremely low counterparty/credit risk
Risk factors: Project execution risk on large IT programs (e.g., KY multi-year delays), Heavy supplier concentration on Netcompany and KMD, No commercial diversification possible due to mandate, Political friction from cost overruns passed to municipalities, Geographic concentration in Denmark only, Increasing political attention to public IT cost control and vendor dependency, Modest equity base relative to revenue
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 175
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.