Kramse.org ApS

Denmark · kramse.org · 16 vendors

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-06-19 · revision 8

16 direct vendors, 245 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Kramse.org ApS exhibits moderate migration readiness. The company's internal tech stack, characterized by a strong reliance on open-source tools (Linux, OpenBSD, Git, Ansible) and a lean approach (Jekyll for static sites, REST API for ScanLab), provides a solid foundation for potential migration to modern cloud environments. This tech stack is generally flexible and less prone to proprietary lock-in, which can ease the technical aspects of migration. However, the migration process would face significant challenges primarily due to the complex regulatory environment. The company has "Assessment Required" statuses for GDPR, NIS2, SOC2, and ISO 27001. Ensuring compliance with these frameworks during and after migration, especially regarding data protection by design, incident reporting, and supply chain security, would add substantial complexity, cost, and time. GDPR's data residency requirements, while currently managed by operating within Denmark, would need careful consideration if migrating to cloud providers with data centers outside the EU/EEA. The lack of financial stability data makes it impossible to assess the company's capacity to fund a potentially costly migration effort. The ambiguity surrounding vendor relationships ("Total Vendors: 0" contradicting other vendor data) also creates uncertainty regarding potential vendor lock-in risks or dependencies that could complicate migration. While the tech stack offers opportunities, the regulatory burden and data gaps present considerable hurdles, positioning the company in the medium readiness category.

Compliance

6 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 (Directive (EU) 2022/2555) includes 'digital providers' and 'ICT service management' as covered sectors, and managed security service providers (MSSPs) / cybersecurity consultancies may fall under its scope as Important Entities. Kramse.org ApS / Zencurity ApS explicitly markets NIS2 implementation services to clients, demonstrating deep familiarity with the directive. However, the risk level is Medium rather than High because: (1) the size threshold for NIS2 is medium enterprises (50+ employees OR €10M+ annual turnover) — Kramse.org ApS appears to be a micro-enterprise well below these thresholds; (2) Denmark's NIS2 implementing legislation (Lov om sikkerhed i net- og informationssystemer) may provide micro-enterprise exemptions; (3) if the entity is below the size threshold, NIS2 does not apply unless it is identified as a critical sole provider. The primary uncertainty is the exact legal size classification of Kramse.org ApS.

Evidence: https://zencurity.com, https://www.cfcs.dk/en/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.retsinformation.dk/eli/lta/2024/639

SOC 2 (source) — Assessment Required

SOC 2 (AICPA Trust Services Criteria) is a US-origin voluntary framework primarily relevant to cloud service providers and SaaS companies serving US enterprise clients. Kramse.org ApS / Zencurity ApS does operate a Port Scan API service (app.scanlab.dk) which could be considered a cloud/SaaS offering, and serves clients with high security requirements. However, the risk level is Low because: (1) SOC 2 is not legally mandated in Denmark or the EU; (2) the company's primary market is Danish/EU organisations, where ISO 27001 and ISAE 3402 are more commonly required than SOC 2; (3) there is no evidence that clients are contractually requiring SOC 2 reports; (4) the company is a micro-enterprise where the cost-benefit of a SOC 2 audit may not be justified.

Evidence: https://zencurity.com, https://app.scanlab.dk, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

GDPR (source) — Assessment Required

GDPR is universally applicable to Kramse.org ApS as a Denmark-registered entity operating within the EU. As a cybersecurity consultancy/freelance operation, it almost certainly processes personal data of clients, suppliers, and potentially employees or contractors (names, emails, contact details, IP addresses, etc.). The risk level is assessed as Medium rather than High because: (1) the company appears to be a micro-enterprise (sole trader / very small team), which reduces the volume and sensitivity of personal data processed; (2) there is no evidence of processing special category data (health, biometric, etc.); (3) Denmark's Datatilsynet (the supervisory authority) actively enforces GDPR but focuses enforcement resources on larger organisations and systemic violations; (4) however, as a cybersecurity firm, any non-compliance would be reputationally damaging and inconsistent with the services it sells to clients. The absence of a visible privacy policy on kramse.org itself is a notable gap.

Evidence: https://kramse.org, https://www.datatilsynet.dk/english, https://gdpr-info.eu/, https://www.datatilsynet.dk/english/regulations-and-directives/the-danish-data-protection-act

Financials

Three-year financials

Financial Resilience Score: 4/10

No financial statements could be located for an entity named 'Kramse.org ApS' in publicly accessible Danish sources during the research session. The kramse.org domain is publicly presented as the personal website of Henrik Kramselund, a Danish IT security professional, with commercial activity explicitly routed through a separate company called Zencurity rather than through 'Kramse.org ApS.' This raises uncertainty about whether the named entity is an active operating company, a dormant/holding vehicle, or simply not registered. Without confirmed CVR registration, annual reports, revenue, EBIT, equity, or headcount, quantitative resilience cannot be assessed. If the entity exists, it is most likely a micro-ApS filing abbreviated accounts under Danish regnskabsklasse B, with only gross profit, profit/loss, and equity typically disclosed. Inferred strengths include low overhead typical of a personal freelance vehicle, the owner's long-standing professional identity in IT security (a growing Danish market segment), and an established online presence including security course material on GitHub. However, these are offset by significant risks: heavy key-person dependency on a single individual, very small scale typical of micro-ApS entities, limited equity buffers, and the fact that commercial activity appears to flow through Zencurity rather than this entity. The absence of a public financial track record means counterparty risk cannot be quantitatively measured, warranting a below-average resilience score.

Key strengths: IT security is a growing market segment in Denmark, Low overhead typical of a personal freelance vehicle, Owner has long-standing professional identity as security trainer, Established online presence including GitHub security course material

Risk factors: Heavy key-person dependency on a single individual (Henrik Kramselund), Likely very small scale (micro-ApS) with limited equity buffers, Commercial activity appears routed through separate company Zencurity, Entity may be dormant/holding/personal vehicle with limited operating activity, No public financial track record retrievable, Existence of registered entity 'Kramse.org ApS' could not be confirmed in CVR

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report