Napatech A/S
Denmark · owned by Independent (Denmark) · napatech.com · 41 vendors
Napatech is the leading provider of programmable Smart Network Interface Cards (SmartNICs) and Data Processing Units (DPUs) solutions that accelerate AI, network, storage, and security workloads for cloud, enterprise, and telecom datacenters worldwide. The company specializes in high-speed packet capture, network acceleration, and FPGA-based solutions.
Resilience scores
- Digital Sovereignty: 17
- Digital Resilience: 5
- Financial Resilience: 6
Disruption prediction
Napatech A/S has an estimated 11% probability of disruption in the next 6 months.
12 of Napatech A/S's 41 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- EasyDMARC Inc. — Cybersecurity — United States
- Kontron — Germany
- and 38 more
Services catalogue
2 services in catalogue across 2 categories; runs on 41 sub-vendors.
- NAPA Fleet Intelligence
- Performance Monitoring
Insights
Last updated 2026-09-13 · revision 22
41 direct vendors, 306 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 3
- China: 1
- Denmark: 1
Subvendors by controlling owner country (sample)
- South Korea: 1
- Ireland: 2
- Portugal: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Napatech A/S exhibits low migration readiness, primarily due to the highly specialized and hardware-dependent nature of its core products. Its offerings, such as SmartNICs and DPUs built on Intel Altera and AMD Xilinx FPGAs, are deeply integrated with specific hardware and low-level network processing. Migrating these core functionalities to a generic cloud-native environment would be extremely challenging, likely requiring significant re-engineering or reliance on specialized, potentially costly, cloud services that may not fully replicate their on-premise performance. Data residency requirements, stemming from GDPR and potential customer-specific demands in critical infrastructure sectors (telecom, financial services, defense), further complicate migration by restricting data processing locations and requiring robust compliance mechanisms. The company's fluctuating financial performance could also limit its ability to fund a large-scale, complex migration project. While its internal tech stack (e.g., WordPress, Act-On) might be more readily migratable, the fundamental dependency on specific FPGA vendors represents a form of technology lock-in for its core product development. The lack of public SOC2 and ISO 27001 certifications could also be a barrier, as many cloud providers and enterprise customers expect these for vendor assurance. The geographic diversity of vendors is a positive for general supply chain, but does not directly mitigate the technical challenges of migrating their specialized hardware-centric solutions.
Compliance
8 in-scope frameworks identified; showing 3.
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into Danish law via the Danish NIS2 Act effective October 2024) may apply to Napatech A/S on two potential grounds: (1) As a manufacturer of ICT hardware (SmartNICs and DPUs) used in critical digital infrastructure, telecom networks, financial services, and defense — NIS2 Annex II covers 'manufacturing of computers and electronic and optical products' (NACE C26) as an Important Entity sector; (2) Napatech's products are used by entities in Essential sectors (telecom, financial services, digital infrastructure), which may trigger supply chain security obligations. Size threshold: Napatech is a publicly listed company on Oslo Stock Exchange with annual revenues likely exceeding €10M (medium enterprise threshold), making it subject to NIS2 if sector classification applies. Risk is Medium because: the manufacturing sector classification under NIS2 is confirmed for ICT hardware manufacturers; however, the precise Danish NIS2 transposition thresholds and whether Napatech has self-registered with the Danish Centre for Cyber Security (CFCS) as required is unknown. Non-compliance risk includes fines up to €7M or 1.4% of global annual turnover for Important Entities.
Evidence: https://www.napatech.com/about/certifications/, https://www.napatech.com/solutions/infrastructure-and-defense/, https://www.napatech.com/solutions/telecom/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/en/
EU Export Control — Assessment Required
Napatech's SmartNICs and DPUs are high-performance network processing hardware used in telecom, financial services, and explicitly in 'Infrastructure and Defense' applications. Such hardware may qualify as dual-use items under EU Regulation 2021/821 (recast Dual-Use Regulation) and/or US Export Administration Regulations (EAR) given the involvement of US-origin technology (Intel/Altera FPGA components). Risk is High because: (1) Napatech explicitly markets products for defense and government use; (2) High-performance FPGAs and network processing hardware are frequently subject to export controls (ECCN classifications); (3) Sales to non-EU/non-US customers may require export licenses; (4) US re-export controls apply to products containing US-origin technology (Intel Agilex FPGAs); (5) Violations can result in severe penalties including criminal prosecution and loss of export privileges. The company's global customer base (worldwide datacenter and telecom markets) amplifies this risk.
Evidence: https://www.napatech.com/solutions/infrastructure-and-defense/, https://www.napatech.com/products/f3076x-dpu/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021R0821, https://www.napatech.com/about/certifications/
SOC 2 (source) — Assessment Required
SOC 2 is a voluntary framework developed by the AICPA applicable to service organizations that store, process, or transmit customer data in the cloud. Napatech A/S primarily manufactures and sells hardware (SmartNICs, DPUs) and associated software. However, the company operates cloud-connected portals (Support Portal, Documentation Portal, Download Center) and provides software products (Link-Capture, Link-Inline, Link-Virtualization, Link-Storage, Link-Security) that may involve cloud service components. Napatech's customers include financial institutions, telecom operators, and defense entities — sectors that frequently require SOC 2 attestation from technology vendors as part of their own compliance programs and vendor due diligence. Risk is Medium because: (1) Napatech's enterprise customers in regulated sectors (financial services, telecom, defense) are likely to contractually require SOC 2 reports; (2) No SOC 2 report or certification has been publicly evidenced; (3) Absence of SOC 2 could be a commercial barrier in regulated-sector sales. The risk is not High because Napatech is primarily a hardware manufacturer, not a cloud service provider.
Evidence: https://www.napatech.com/about/certifications/, https://supportportal.napatech.com/, https://docs.napatech.com/, https://www.napatech.com/solutions/financial-services/
Financials
Three-year financials
- 2025: revenue DKK 147M, EBIT DKK -80.7M, equity DKK 205M
- 2024: revenue DKK 116M, EBIT DKK -116M, equity DKK 153M
- 2023: revenue DKK 183M, EBIT DKK -32.9M, equity DKK 112M
Financial Resilience Score: 6/10
Napatech A/S presents a mixed financial resilience profile. On the positive side, the company has a very strong balance sheet with cash of DKK 127.5M at year-end 2025, an equity ratio of approximately 75%, and a current ratio of 457%. Management explicitly states that 2026 operations are fully funded. The company operates a differentiated high-margin business (~70% gross margin) with meaningful IP in SmartNIC/DPU technology and secular tailwinds from AI infrastructure demand. Return to growth in 2025 (+26% DKK, +33% USD) and 27 new design wins support the outlook. However, resilience is undermined by persistent operating losses (EBIT negative every year 2022-2025), significant negative free cash flow (DKK -42.2M in 2025), and accumulated losses of DKK -452.8M. The company has funded losses through repeated dilutive equity raises (DKK 145.6M in 2024 and DKK 130.7M in 2025), with share count up ~22% over two years. Customer concentration is elevated (top 2 customers = 35% of revenue), geographic concentration in the US is high (69%), and all revenue is USD-denominated creating FX exposure. Management's 2026 guidance still implies negative EBITDA (~DKK -25M at midpoint), meaning profitability remains uncertain in the near term.
Key strengths: Strong liquidity: DKK 127.5M cash at YE 2025, High equity ratio (~75%) with low interest-bearing debt (~DKK 28M), Excellent current ratio of 457%, High gross margin business (~70%), Return to growth in 2025 (+26% DKK / +33% USD), 27 unique design wins in 2025 feeding pipeline, 2026 operations fully funded per management, Strategic exposure to AI infrastructure demand
Risk factors: Persistent operating losses every year 2022-2025, Accumulated losses of DKK -452.8M at YE 2025, Negative free cash flow of DKK -42.2M in 2025, Repeated dilutive equity raises (~22% share count growth over 2 years), Customer concentration: top 2 customers = 35% of revenue, Geographic concentration: 69% of revenue from USA, FX exposure: all revenue in USD vs. DKK functional currency, 2026 guidance still implies negative EBITDA (~DKK -25M midpoint), Competition against much larger silicon players, DKK 40M floating charge on assets securing bank facilities
Revenue by geography
- Americas: 69%
- Rest of World (EMEA + APAC): 31%
Revenue by product/service
- SmartNIC Products: 97%
- Engineering Services: 3%
Workforce by country
- Denmark: 76
- United States: 10
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.