NCC-DK (Nationalt Koordinationscenter for Cybersikkerhed i Danmark)
Denmark · owned by Independent (Denmark) · ncc-dk.dk · 9 vendors
NCC-DK is Denmark's National Coordination Centre for Cybersecurity, bringing together companies, public authorities, and research environments within the Danish cybersecurity ecosystem. It provides services including a professional network, grant funding pools, and EU funding advisory to strengthen collaboration and innovation in cybersecurity. The organisation is co-funded by the EU and supported by partners including the Danish Business Authority (Erhvervsstyrelsen) and the European Cybersecurity Competence Centre (ECCC).
Resilience scores
- Digital Sovereignty: 33
- Digital Resilience: 4
- Financial Resilience: 7
Disruption prediction
NCC-DK (Nationalt Koordinationscenter for Cybersikkerhed i Danmark) has an estimated 17% probability of disruption in the next 6 months.
2 of NCC-DK (Nationalt Koordinationscenter for Cybersikkerhed i Danmark)'s 9 vendors monitored for disruptions.
Technology vendors
- Consently — Denmark
- The Apache Software Foundation — Technology — United States
- Trimble Inc. — Technology — United States
- and 6 more
Insights
Last updated 2026-09-14 · revision 7
9 direct vendors, 129 subvendors
Direct vendors by controlling owner country (sample)
- United States: 5
- Denmark: 1
- Israel: 1
Subvendors by controlling owner country (sample)
- Germany: 1
- Sweden: 1
- Netherlands: 3
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
NCC-DK demonstrates low migration readiness. The primary challenges stem from its internal tech stack, which consists of WordPress, Elementor, and B2Match. These platforms are generally not considered cloud-native, containerized, or microservices-based, suggesting a potentially monolithic architecture that would require significant re-engineering for a modern cloud migration. The complex regulatory environment presents another major hurdle; 'Assessment Required' or 'Partially Compliant' statuses for NIS2, GDPR, ISO 27001, and Databeskyttelsesloven mean any migration would necessitate meticulous planning to ensure continuous compliance, adding substantial overhead and risk. Data residency requirements, mandating transfers outside the EU/EEA to use valid mechanisms, further constrain migration options. A significant concern is the 'Unknown' vendor lock-in risk across 14 services. This lack of clarity on vendor dependencies, contract terms, and data portability could severely impede migration efforts, leading to unforeseen costs and delays. While grant funding is available, the flexibility to allocate substantial resources specifically for a complex migration project is unclear. The only minor opportunity is the absence of specific data localization mandates beyond general GDPR requirements for EU/EEA transfers, offering some flexibility in choosing cloud regions within the EU.
Compliance
6 in-scope frameworks identified; showing 3.
Forvaltningsloven — Assessment Required
The Danish Public Administration Act (Forvaltningsloven) applies to all parts of the public administration. NCC-DK is a public sector entity performing public administration functions.
As a public administration body, non-compliance with the Danish Public Administration Act could lead to legal challenges and reputational damage. The risk is medium as compliance is a standard requirement for public entities in Denmark.
Evidence: https://cybersecurity-centre.europa.eu/nccs_en, https://www.nis-2-directive.com/Transposition/Denmark.html, https://www.rti-rating.org/wp-content/uploads/Denmark.pdf, https://plesner.com/en/news/access-to-documents-in-public-files-is-a-key-consideration-when-sharing-information-with-public-authorities
ISO 27001 (source) — Assessment Required
ISO 27001 is a voluntary information security standard. However, for a national cybersecurity coordination center, it is a highly relevant framework for demonstrating best practices in information security management.
While not mandatory, ISO 27001 certification is a strong indicator of cybersecurity maturity. For a national cybersecurity center, its absence could be a reputational risk. The NCC group strives to implement security measures in accordance with the ISO 27000 series.
Evidence: https://www.ncc.com/contact-us/about-the-website/data-protection-policy/
NIS2 (source) — Assessment Required
The NIS2 Directive applies to public administration entities. NCC-DK is a public sector body. Denmark has transposed NIS2 into national law, and it applies to both public and private entities in critical sectors.
As a central coordinating body for cybersecurity in Denmark, NCC-DK is likely to be considered a public administration entity under NIS2. Non-compliance would undermine its credibility and conflict with its mission to enhance national cybersecurity.
Evidence: https://www.nccgroup.com/media/ipvjhh1i/ncc-group-nis2-e-guide-2024.pdf, https://cybersecurity-centre.europa.eu/nccs_en, https://www.nis-2-directive.com/Transposition/Denmark.html, https://www.nccgroup.com/campaign/nis2-prepare-your-organisation-for-compliance/, https://digital-strategy.ec.europa.eu/en/policies/nis2-directive-denmark
Financials
Financial Resilience Score: 7/10
NCC-DK is not a commercial entity but a public-sector coordination center jointly anchored in two Danish government agencies (Styrelsen for Samfundssikkerhed and Erhvervsstyrelsen) and operated by the CenSec and DigitalLead cluster consortium. Its financial resilience therefore rests entirely on public budget appropriations rather than commercial revenue. Funding stability is supported by dual sources: Danish national budget allocations and EU co-financing via Horizon Europe and the Digital Europe programme. Its existence is embedded in EU regulation as part of a 27-country ECCC network, giving multi-year structural visibility. However, the mandate is time-limited: the current operator agreement with CenSec and DigitalLead runs only until end-2025, and continuation depends on renewed tender awards and political appropriations. The total programme budget for 2024-2025 is modest at DKK 17.3-17.8 million across three grant pools. Because NCC-DK has no independent legal entity, balance sheet, or equity buffer, it cannot absorb shocks independently and is fully dependent on its sponsoring agencies and operator clusters. No successor programme budget for the post-2025 period has been publicly disclosed as of the analysis date.
Key strengths: Institutional backing from two Danish government agencies (Styrelsen for Samfundssikkerhed and Erhvervsstyrelsen), EU co-financing via Horizon Europe and Digital Europe programme, Structural mandate embedded in EU cybersecurity regulation as part of 27-country ECCC network, Established operator consortium (CenSec + DigitalLead) with existing cluster infrastructure, Active grant programme of DKK 17.3-17.8M for 2024-2025
Risk factors: Time-limited operator mandate expiring end-2025 with no publicly disclosed renewal, Full dependence on Danish state budget appropriations and EU funding envelope, No independent legal entity, balance sheet or equity buffer, Operator continuity risk if CenSec or DigitalLead cluster funding weakens, No separate CVR registration or published annual accounts, limiting financial transparency
Revenue by geography
- EU co-financing: 0%
- Denmark (national budget): 0%
Revenue by product/service
- EU funding facilitation: 0%
- Professional network (150+ members): 0%
- Grant administration (three national pools): 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.