Arbeids- og velferdsetaten (NAV)

Norway · owned by Norwegian Ministry of Labour and Social Inclusion (Norway) · nav.no · 29 vendors

NAV (Arbeids- og velferdsetaten) is the Norwegian Labour and Welfare Administration, a Norwegian government agency responsible for administering a range of social welfare services including employment support, sickness benefits, pensions, family benefits, and social assistance. It operates under the Norwegian Ministry of Labour and Social Inclusion and serves both private individuals and employers across Norway. NAV is one of Norway's largest public agencies, managing approximately one-third of the national budget.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-08 · revision 3

29 direct vendors, 250 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

NAV exhibits very high migration readiness, primarily driven by its advanced and cloud-native oriented tech stack. The extensive use of containerization (Docker, Kubernetes, Nais), microservices architecture, and cloud platforms (GCP) significantly reduces technical barriers to migration, enabling flexible and incremental shifts. The proficiency with open-source technologies like Kotlin, React, PostgreSQL, and Kafka minimizes proprietary technology lock-in, offering greater portability. NAV's existing compliance with stringent regulations such as GDPR and NIS2 demonstrates established processes for data governance and security, which are critical for managing compliance throughout a migration project. As a government agency, NAV benefits from stable financial backing, providing the necessary resources to fund strategic modernization and migration initiatives. The main constraint is the strict data residency requirement (Norway/EEA preference), which limits the choice of cloud regions and providers; however, NAV is already operating within these constraints using GCP. The presence of Oracle Database suggests some legacy components that might require specific migration strategies or refactoring, but this is balanced by the widespread adoption of modern databases like PostgreSQL. The 'Total Vendors: 0' data point is ambiguous regarding the exact number of vendors, making it difficult to assess vendor-related contractual lock-in, but the technological choices strongly indicate low technical lock-in. The 'Vendor Lock-in Risk: Unknown' is a neutral factor.

Compliance

11 in-scope frameworks identified; showing 3.

Arbeidsmiljøloven — Compliant

The Working Environment Act governs employment conditions, including employee monitoring and data processing in the workplace. NAV, as an employer of ~22,000 employees, must comply with provisions on employee data processing, monitoring, and workplace surveillance. Risk is Low because: (1) NAV has established HR and legal compliance functions; (2) employee data processing is a standard compliance area for large Norwegian employers; (3) no specific enforcement actions related to employee data have been publicly identified; (4) the consequences of non-compliance, while significant, are less severe than those for citizen data processing failures.

Evidence: https://lovdata.no/dokument/NL/lov/2005-06-17-62, https://www.nav.no/sok-jobb-i-nav

SOC 2 (source) — Assessment Required

SOC 2 is an American Institute of CPAs (AICPA) framework primarily relevant for cloud service providers and technology companies serving US clients. NAV itself is not a cloud service provider and would not typically be required to obtain SOC 2 certification. However, NAV is a major consumer of cloud and SaaS services (it uses Microsoft Azure, AWS, and other cloud platforms as part of its digital transformation programme), and its vendors/processors may hold SOC 2 certifications. The risk is Medium because: (1) NAV's procurement of cloud services means it should be evaluating SOC 2 reports from its vendors as part of due diligence; (2) NAV's own digital services platform (nav.no) serves millions of users; (3) there is no regulatory mandate for NAV itself to obtain SOC 2, but vendor SOC 2 compliance is relevant to NAV's supply chain risk management under NIS2 and GDPR.

Evidence: https://www.nsm.no/grunnprinsipper-for-ikt-sikkerhet/, https://www.nav.no/personvern-sikkerhet-navno

NAV-loven — Compliant

The NAV Act is the primary enabling legislation for NAV's existence and operations. As the organisation established by and operating under this Act, NAV is structurally compliant with its foundational legal framework. Risk is Medium because: (1) the Act defines NAV's mandate, powers, and obligations; (2) non-compliance with specific provisions (e.g., the 2019 EEA scandal involved misapplication of rules under this Act) can result in significant legal and political consequences; (3) ongoing parliamentary scrutiny and Riksrevisjonen audits monitor compliance; (4) the Act is regularly amended, requiring continuous legal monitoring.

Evidence: https://lovdata.no/dokument/NL/lov/2006-06-16-20, https://www.regjeringen.no/no/dokumenter/nou-2020-9/id2760080/, https://www.nav.no/annet/om-nav

Financials

Three-year financials

Financial Resilience Score: 10/10

NAV is a Norwegian government agency (Arbeids- og velferdsetaten), not a corporate entity, and therefore benefits from full sovereign backing by the Kingdom of Norway (AAA-rated). It is funded directly through the state budget and administers roughly one-third of the Norwegian national budget, making its financial resilience effectively equivalent to that of the Norwegian state itself. Total appropriations grew 8.5% from 2023 to 2024, reaching NOK 673.4 billion, and benefit disbursements grew 8.9% to NOK 659.8 billion, reflecting stable and expanding funding. Operationally, NAV faces pressures typical of a large public administration: growing case backlogs on AAP, sick pay, disability and international cases; only 6 of 16 national benefits met their processing-time norms in 2024; and none of the 9 international benefits did. A NOK 315 million overspend (~4%) on labour-market measures and elevated misdisbursement risk on AAP and dagpenger indicate operational strain, but these do not threaten solvency given sovereign backing. Structural risks include demographic pressures (7 of 10 additional inhabitants by 2035 expected to be 67+), rising consulting spend (NOK 1,028M in 2024, +8% YoY), high internal sick leave (8.5%), and legacy IT complexity. However, modernisation programmes such as Prosjekt 4 (NOK 1.166 bn framework) and the new sick-pay system (Speil) are underway. User satisfaction remains strong at 78% overall and 86% among employers.

Key strengths: Full sovereign backing by the Kingdom of Norway (AAA-rated), Stable, growing state appropriations (+8.5% YoY in 2024), Administers ~1/3 of Norwegian national budget (NOK 673.4B), Strong user satisfaction: 78% overall, 86% among employers, Active modernisation programmes (Prosjekt 4, Speil sick-pay system)

Risk factors: Growing case backlogs; only 6 of 16 national benefits met processing-time norms in 2024, NOK 315M overspend (~4%) on labour-market measures (Kap. 634/76), Elevated misdisbursement risk on AAP and dagpenger, Datatilsynet NOK 20M fine in March 2024 (overturned Dec 2024, possible reconsideration), High internal sick leave (8.5% in 2024, above national average), Legacy IT complexity - only 72% of sickness cases in new system (target was 85%), Rising consulting spend (NOK 1,028M, 9.5% of wage costs), Demographic pressure: 7 of 10 new inhabitants by 2035 expected to be 67+, Cumulative efficiency cuts 2017-2024 of NOK ~990M real

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report