Kongsberg Maritime

Norway · www.kongsberg.com/maritime · 24 vendors

Resilience scores

Technology vendors

Services catalogue

10 services in catalogue across 4 categories; runs on 24 sub-vendors.

Insights

Last updated 2026-08-14 · revision 1

24 direct vendors, 242 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Kongsberg Maritime exhibits good migration readiness, scoring 75. The company has a strong foundation for cloud migration and modernization, with significant adoption of cloud platforms (Microsoft Azure, AWS), containerization technologies (Docker, Kubernetes), and modern development practices (Azure DevOps, Git, Jenkins, Kafka, REST APIs). This indicates a capability to move towards cloud-native architectures and microservices. The absence of specified data residency requirements is a positive factor, offering flexibility in choosing cloud regions. However, migration readiness is tempered by the likely presence of legacy systems. The tech stack includes Microsoft SQL Server, Windows Server, and SAP (ERP), which often require more complex migration strategies or re-platforming efforts. Integration with industrial protocols like OPC-UA also suggests critical operational technology (OT) systems that may have specific constraints for cloud migration due to performance, security, or regulatory considerations. The data states "Total Vendors: 0", which is inconsistent with other vendor data; assuming vendors exist, the "Vendor Lock-in Risk" is unknown, which could be a significant factor. While vendor geographic diversity is noted across 7 countries, the specific nature and complexity of these vendor relationships and potential lock-in are not detailed. Furthermore, information on the regulatory environment and financial stability (which impacts funding for migration) is missing, preventing a comprehensive assessment of potential challenges and opportunities.

Compliance

12 in-scope frameworks identified; showing 3.

IACS Unified Requirements E26 & E27 — Assessment Required

The International Association of Classification Societies (IACS) Unified Requirements E26 (Cyber Resilience of Ships) and E27 (Cyber Resilience of On-board Systems and Equipment) became mandatory for newbuild vessels contracted on or after July 1, 2024. As a major supplier of onboard systems and equipment to newbuild vessels, Kongsberg Maritime must ensure its products comply with UR E27 requirements. Risk is High because: (1) non-compliant equipment cannot be installed on newbuild vessels subject to IACS class rules; (2) this directly affects Kongsberg Maritime's ability to supply systems to the newbuild market; (3) the requirements cover the entire product lifecycle including design, development, testing, and maintenance; (4) Kongsberg Maritime supplies systems to virtually all major shipyards globally.

Evidence: https://www.iacs.org.uk/publications/unified-requirements/ur-e/, https://www.kongsberg.com/maritime/products-and-systems/systems/km-cyber/, https://www.dnv.com/services/cyber-security-for-ships-and-offshore-units-3897/

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (Regulation 2024/2847), adopted in October 2024, introduces mandatory cybersecurity requirements for products with digital elements sold in the EU market. Kongsberg Maritime manufactures and sells a wide range of products with digital elements — including ECDIS systems, dynamic positioning systems, automation controllers, sensors, and connected maritime equipment — to EU/EEA customers. Risk is High because: (1) Kongsberg Maritime's products are likely classified as 'Important' or 'Critical' products under CRA given their safety-critical maritime applications; (2) the CRA requires conformity assessments, CE marking for cybersecurity, vulnerability handling processes, and security updates for the product lifecycle; (3) non-compliance can result in market access restrictions (products cannot be sold in EU) and fines up to €15M or 2.5% of global turnover; (4) the CRA applies from 2027, giving limited time for compliance preparation.

Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847, https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act, https://www.kongsberg.com/maritime/products-and-systems/systems/km-cyber/

NIS2 (source) — Assessment Required

Kongsberg Maritime is a critical supplier to the maritime transport sector — one of the explicitly listed Essential Entity sectors under NIS2 (transport, specifically maritime transport). The company provides navigation systems, dynamic positioning, propulsion control, automation, and digital infrastructure to over 34,000 vessels worldwide. As a large enterprise (Kongsberg Group reported revenues of approximately NOK 35+ billion and employs over 12,000 people globally, with Kongsberg Maritime being the largest division), it far exceeds the NIS2 size thresholds (50+ employees or €10M+ turnover). The risk level is High because: (1) maritime transport is an Essential Entity sector under NIS2 Annex I; (2) as a technology provider to critical maritime infrastructure, Kongsberg Maritime may qualify as an ICT service provider or digital infrastructure provider; (3) NIS2 supply chain security requirements mean even if Kongsberg Maritime itself is not directly regulated, its customers (shipping companies, port operators) will impose NIS2-derived contractual obligations; (4) Norway, as an EEA member, is expected to implement NIS2 equivalent legislation; (5) non-compliance penalties can reach €10M or 2% of global turnover for Important Entities, and €7M or 1.4% for others.

Evidence: https://www.kongsberg.com/maritime/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-new, https://www.nkom.no/internett/informasjonssikkerhet/nis

Financials

Three-year financials

Financial Resilience Score: 8/10

Kongsberg Maritime demonstrates strong financial resilience as a segment of Kongsberg Gruppen ASA, a publicly listed Norwegian industrial technology group with investment-grade balance sheet metrics. The segment benefits from a large installed base of 34,000+ vessels, generating recurring aftermarket/service revenue that comprises ~35-40% of segment revenue at high margins. Year-end 2023 order backlog of approximately NOK 32 billion provides multi-year revenue visibility. Diversified end-markets (merchant, offshore, offshore wind, naval, cruise, fishing, subsea) help offset cyclicality in any single vertical. Revenue has approximately tripled over the past decade (2013-2023), driven by the Rolls-Royce Commercial Marine acquisition (2019) and organic growth from decarbonization and offshore wind demand. However, exposure to shipbuilding cyclicality, Asian shipyard concentration, FX risk, and energy transition risk on legacy oil & gas exposure limit the score from being higher.

Key strengths: Backed by strong listed parent Kongsberg Gruppen ASA (OSE: KOG) with investment-grade metrics, Large installed base of 34,000+ vessels generating recurring aftermarket revenue, Record order backlog of ~NOK 32 billion at year-end 2023 provides multi-year visibility, Diversified end-markets across merchant, offshore, naval, cruise, fishing and subsea, Technology leadership in dynamic positioning, propulsion, automation and autonomous shipping, Revenue tripled over past decade with expanding EBIT margins into double digits by 2023

Risk factors: Cyclicality of shipbuilding tied to freight rates and offshore capex, Concentration in Asian shipyards with FX exposure (KRW, CNY, EUR, USD vs NOK), Integration and restructuring costs from Rolls-Royce Commercial Marine acquisition, Supply-chain inflation (electronics, semiconductors, steel) creating margin headwinds, Energy-transition risk on legacy oil-and-gas exposure

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report