LEVEL7 ApS
Denmark · owned by Baco Holding ApS (Denmark) · l7consulting.dk · 8 vendors
LEVEL7 ApS is a Danish cybersecurity and transformation consulting firm specializing in critical infrastructure protection, helping organizations meet regulatory requirements and strengthen security resilience. Their services include national security advisory, cyber leadership, governance, risk & compliance, program management, and executive cyber search. They serve clients across the Nordic region and Germany.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 4
- Financial Resilience: 6
Disruption prediction
LEVEL7 ApS has an estimated 17% probability of disruption in the next 6 months.
6 of LEVEL7 ApS's 8 vendors monitored for disruptions.
Technology vendors
- HubSpot, Inc. — Technology — United States
- Looker — Technology — United States
- Netlify, Inc. — Technology — United States
- and 5 more
Insights
Last updated 2026-09-15 · revision 30
8 direct vendors, 159 subvendors
Direct vendors by controlling owner country (sample)
- United States: 7
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- Australia: 3
- Czech Republic: 2
- Austria: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
LEVEL7 ApS's deep expertise in a wide array of regulatory compliance frameworks (NIS2, DORA, GDPR, CER Directive, NIST CSF, CIS Controls, ISO standards) is a significant asset for navigating the complex legal and compliance requirements inherent in any migration project. Their internal tech stack includes modern SaaS solutions (Squarespace, Cal.com, Confluence), which are already cloud-based, simplifying some aspects of cloud adoption. The 'flexible deployment (self-hosted or hosted)' option for their proprietary FITS platform *could* indicate architectural adaptability, though specific details on its cloud-nativeness (e.g., containerization, microservices) are not provided. However, the most critical challenge to migration readiness is the projected financial instability for 2025, with a significant drop in gross profit and employee count. This severely limits the financial capacity to fund and execute a complex migration initiative. 'Data Residency Requirements' are 'Not specified,' which is a major unknown that could introduce significant constraints and complexity, particularly for their self-hosted FITS platform. 'Vendor Lock-in Risk' is 'Unknown,' but the use of specific SaaS platforms and a moderately diverse vendor base (2-3 unique countries for 18 services) suggests a moderate level of vendor dependency that could complicate switching providers. The 'self-hosted' nature of FITS, while offering control, might also imply a more monolithic or tightly coupled architecture that would require substantial refactoring for a truly cloud-native migration.
Compliance
7 in-scope frameworks identified; showing 3.
EU Cybersecurity Act — Assessment Required
The Act establishes an EU-wide certification framework for ICT products, services, and processes. A proposed amendment specifically targets 'managed security services', including consultancy, making it directly relevant to the company's operations.
The risk is currently low as certification schemes for cybersecurity services are still emerging. However, this will become a key market access requirement, and failure to certify in the future could hinder business.
Evidence: https://lvl7.dk/about, https://www.scrut.io/post/eu-compliance-regulations, https://certification.enisa.europa.eu/about-eu-cyber-certification/eu-regulatory-context/cybersecurity-act_en
NIS2 (source) — Assessment Required
The company provides cybersecurity services and states it supports 'critical infrastructure operators'. This could classify it as an 'Important Entity' under the ICT service management category. However, with only 5 employees, it falls below the 50-staff threshold.
If applicable, non-compliance could result in significant fines and reputational damage, especially for a cybersecurity firm. The risk is medium as applicability is uncertain due to the company's small size.
GDPR (source) — Partially Compliant
The company is established in Denmark, within the EU, and its website has a privacy policy acknowledging the processing of personal data. This brings it directly into the scope of the GDPR.
As a Danish company, non-compliance can lead to significant fines (up to 4% of global turnover). The risk is elevated as their privacy policy lacks a named Data Protection Officer, a specific requirement for some organizations.
Financials
Three-year financials
- 2025: gross profit DKK 6.05M, EBIT DKK 2.74M, equity DKK 7.03M
- 2024: gross profit DKK 10.8M, EBIT DKK 6.54M, equity DKK 11.0M
- 2023: gross profit DKK 10.1M, EBIT DKK 4.92M, equity DKK 7.89M
Financial Resilience Score: 6/10
LEVEL7 ApS demonstrates consistent profitability across all four disclosed fiscal years (2022-2025) with no reported loss years. Even in the weak FY2025, the company maintained an EBIT margin of ~45% on gross profit and net margin of ~35%. The firm operates debt-light with DKK 7.03M in equity supporting a ~4-person operation, representing roughly 2-3 years of the current cost base as a safety cushion. Its positioning in a structurally growing cybersecurity market (NIS2, DORA, GDPR, CER, NIST CSF, ISO 27001) provides regulatory tailwinds, and the launch of FITS, an AI-powered GRC SaaS platform, introduces potential recurring revenue diversification beyond consulting. However, FY2025 showed a sharp contraction with gross profit falling ~44%, EBIT and net profit both down ~58%, and average headcount dropping from 6 to 4. Equity fell by DKK 3.97M despite DKK 2.13M of net profit, implying ~DKK 6M in owner distributions that reduced the safety buffer. As a boutique with only 4-5 employees and two named partners, the firm carries significant key-person and customer concentration risk. The absence of revenue disclosure (permitted under Danish accounting-class B rules) limits external verification of pricing power and utilisation. Overall, resilience is moderate: strong profitability history and equity cushion, but material recent contraction and small-firm scale risks temper the score.
Key strengths: Consistent profitability across all four disclosed years (2022-2025) with no loss years, Strong EBIT margins (~45% on gross profit even in weak FY2025), Debt-light balance sheet with DKK 7.03M equity supporting ~4-person operation, Positioned in structurally growing cybersecurity/regulatory compliance market (NIS2, DORA, GDPR), Product diversification underway via FITS AI-powered GRC SaaS platform, Public-sector and critical-infrastructure exposure provides sticky engagements
Risk factors: Sharp FY2025 downturn: gross profit -44%, EBIT/net profit ~-58%, Equity drawdown of ~DKK 6M in distributions reducing safety buffer, Key-person concentration with only two named partners and 4-5 total employees, Small-firm scale risk: losing one significant retainer materially reshapes P&L, No revenue disclosure limits external assessment of pricing power and customer concentration, Headcount decline from 8 (FY2023) to 4 (FY2025) suggests capacity contraction
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 5
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.