Netic A/S

Denmark · owned by Trifork Holding AG (Switzerland) · netic.dk · 25 vendors

Netic is a Danish IT operations company that specializes in application management, cloud operations, and hosting services. The company operates critical IT infrastructure for Denmark's digital transformation, including managing significant portions of Denmark's digital healthcare system and serving both public organizations and private companies with secure IT operations and hosting in Danish data centers.

Resilience scores

Technology vendors

Services catalogue

14 services in catalogue across 7 categories; runs on 25 sub-vendors.

Insights

Last updated 2026-09-13 · revision 30

25 direct vendors, 306 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Netic A/S exhibits exceptionally high migration readiness, largely due to its core business model and advanced technology stack. The company's offerings, such as the 'Contain Managed Application Platform' (built on Kubernetes and CNCF technologies, cloud-agnostic) and 'Cloud Operations' (covering planning, migration, and 24/7 operations across private, public, and hybrid clouds), directly reflect its expertise and capabilities in cloud migration. Internally, Netic leverages a highly modern, cloud-native, and containerized tech stack including Kubernetes, Docker, AWS, Azure, GCP, and OVHcloud, demonstrating a multi-cloud strategy that inherently reduces vendor lock-in and enhances portability. The reliance on open-source CNCF tooling further contributes to flexibility and avoids proprietary dependencies. Financial stability, evidenced by its acquisition by Trifork Group and 'Highest creditworthiness', ensures adequate resources for funding any internal migration initiatives. Existing compliance frameworks (GDPR, ISO 27001, ISAE 3000) indicate a structured approach to security and data governance, which are crucial for successful migrations. While strict data residency requirements (Denmark/EU) and specific Danish healthcare data protection laws are present, Netic's infrastructure (Danish data centers, GDPR/Schrems II compliant hosting, air-gapped environment support) is explicitly designed to meet these constraints, turning a potential challenge into a managed capability. The 'Assessment Required' status for NIS2 compliance is a minor consideration, as Netic's existing robust security and operational practices likely align well with future NIS2 requirements. The overall architecture and service offerings position Netic as highly agile and capable of migrating its own or client workloads across diverse environments with minimal friction.

Compliance

9 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Netic A/S is a cloud services and managed IT services provider — the exact profile for which SOC 2 is designed. While SOC 2 is a US-origin framework (AICPA), it is increasingly demanded by international enterprise clients, particularly those with US connections or global operations (e.g., JYSK operates globally). Netic does conduct ISAE 3402 audits (the European equivalent of SOC 1) and ISAE 3000 audits, which partially address the same assurance needs. However, no SOC 2 report has been identified. Risk is Medium because: (1) Netic's clients may contractually require SOC 2 reports; (2) Absence of SOC 2 could be a competitive disadvantage for international clients; (3) ISAE 3402/3000 may satisfy most European client requirements as functional equivalents. The risk of regulatory non-compliance is low (SOC 2 is not a legal requirement), but business risk from client expectations is moderate.

Evidence: https://www.netic.dk/hosting/, https://www.netic.dk/iso-iec-270012022/, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy

ISAE 3402 — Compliant

Netic A/S explicitly confirms ISAE 3402 audits are conducted by external auditors and made available to customers. ISAE 3402 is the international standard for assurance reports on controls at service organizations (equivalent to SOC 1), directly applicable to IT managed service providers and hosting companies. Risk is Low because active audits are confirmed, reports are available to clients, and this supports client supply chain compliance requirements.

Evidence: https://www.netic.dk/hosting/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3402-assurance-reports-controls-service

ISO 27001 (source) — Compliant

Netic A/S holds a current ISO/IEC 27001:2022 certification, valid until December 2026, with mandatory annual surveillance audits by an accredited external auditor. This is the most current version of the standard (2022 edition). The certification directly addresses information security risk management, documentation, roles and responsibilities — all core compliance requirements. Risk is Low because: (1) Active certification with annual audits provides continuous verification; (2) The 2022 edition is the latest standard, demonstrating up-to-date compliance; (3) Certification scope covers their core business (IT operations, hosting, cloud services); (4) ISO 27001 is foundational to their market positioning and client trust.

Evidence: https://www.netic.dk/iso-iec-270012022/, https://www.netic.dk/hosting/, https://www.iso.org/standard/27001, https://www.netic.dk/

Financials

Three-year financials

Financial Resilience Score: 7/10

Netic A/S demonstrates a qualitatively strong financial resilience profile despite the lack of specific retrievable figures. The company operates a recurring-revenue managed services model with sticky, long-term contracts in critical Danish public-sector and healthcare infrastructure, which provides high revenue visibility and low churn. Its position as a subsidiary of the Nasdaq Copenhagen-listed Trifork Group offers additional financial backing, governance oversight, and cross-selling opportunities within Trifork's Operate segment. The company holds ISO/IEC 27001:2022 certification and was awarded Bisnode's 'highest creditworthiness' rating (as of August 2022), signaling solid financial standing. Its differentiation through Danish sovereign data centres and compliance-focused positioning is increasingly valuable under GDPR and NIS2 regulations. However, the score is moderated by risks including heavy dependence on Danish public-sector tender cycles, small home market, competitive pressure from hyperscalers and larger MSPs, capex intensity of running own data centres, and Danish IT talent cost inflation compressing margins.

Key strengths: Recurring revenue from long-term managed services contracts, Sticky customers in critical Danish public health infrastructure (MedCom, FUT, Min Læge, SBSYS), ISO/IEC 27001:2022 certification, Bisnode 'highest creditworthiness' rating (Aug 2022), Backing from listed parent Trifork Group, Sovereign Danish data centre positioning aligned with GDPR/NIS2, Over 20 years of operating history

Risk factors: Customer concentration in Danish public sector tenders, Small, Denmark-centric home market limits scalability, Competition from hyperscalers (AWS, Azure, GCP) and large MSPs (Netcompany, KMD, Globalconnect), Danish IT talent cost inflation pressuring margins, Capex intensity of operating own data centres vs. asset-light competitors

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report