Netnod AB

Sweden · owned by TU-stiftelsen (Stiftelsen för Telematikens utveckling) (Sweden) · www.netnod.se · 18 vendors

Netnod is a neutral, non-profit Swedish Internet infrastructure organisation that provides critical services including Internet Exchange (IX) operations, secondary DNS services, root name server operations (I-root), time services (NTP/PTP), and DWDM transport services. It operates the largest Internet Exchange in Northern Europe and has run i.root-servers.net since 2000, the first root server located outside the United States. Fully owned by the non-profit foundation TU-stiftelsen (Stiftelsen för Telematikens utveckling), Netnod reinvests its profits into building robust digital infrastructure for Sweden and beyond.

Resilience scores

Disruption prediction

Netnod AB has an estimated 27% probability of disruption in the next 6 months.

10 of Netnod AB's 18 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 18 sub-vendors.

Insights

Last updated 2026-08-19 · revision 12

18 direct vendors, 248 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Netnod's migration readiness is moderate, primarily constrained by the inherent nature of its core business as a critical internet infrastructure provider. Services like Internet Exchange Points (IXP), DNS root server operations, and DWDM transport are fundamentally tied to specialized physical hardware and network infrastructure, making a wholesale 'lift and shift' or a full transition to a public cloud-native, containerized, or microservices architecture highly complex and potentially impractical. While their internal tech stack includes modern networking protocols (BGP, IPv6, DNSSEC, Anycast), there is no explicit evidence of cloud-native architectural patterns such as containerization or microservices for their core services. The use of Drupal 10 for their website is modern, but this likely represents a smaller, more adaptable component of their overall infrastructure. The regulatory environment presents significant considerations for migration. As a Swedish company, GDPR compliance is mandatory, and their 'strictly on premise' data storage currently aligns with data residency requirements. However, the high-risk applicability of NIS2 means any migration would need meticulous planning to ensure continuous compliance with stringent cybersecurity and incident reporting obligations, potentially adding complexity and cost. Financial stability for funding a major migration is difficult to assess due to the absence of data on revenue concentration by product or geography. Furthermore, the 'Vendor Lock-in Risk' is unknown, and the contradictory vendor data ('Total Vendors: 0' vs. listed vendor HQs and services) makes it challenging to determine the extent of potential dependencies that could impede migration. If there are significant vendor dependencies, this could increase migration complexity and cost. The relatively small workforce (55 employees) might also limit the internal capacity to undertake a large-scale migration project while maintaining critical ongoing operations. Given these factors, while Netnod possesses modern technical components and regulatory awareness, the fundamental physical and specialized nature of its core infrastructure services, coupled with significant unknowns regarding financial capacity and vendor lock-in, places its migration readiness in the medium category, leaning towards the lower end for a transformative cloud-native shift.

Compliance

10 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

Netnod provides cloud-adjacent and critical infrastructure services including Internet Exchange, DNS, time services, and transport — services that are consumed by enterprises, public sector entities, and TLD operators who frequently require SOC 2 assurance from their service providers. SOC 2 is not legally mandated but is a market-driven assurance standard (AICPA Trust Services Criteria). The risk is Medium because: (1) Netnod's enterprise and public sector DNS clients, as well as IX members, may contractually require SOC 2 reports; (2) absence of SOC 2 could be a competitive disadvantage and a procurement barrier; (3) no public SOC 2 report or certification has been found, creating uncertainty about whether Netnod has undergone this assessment. As a non-profit focused on critical infrastructure rather than commercial cloud services, SOC 2 may be less prioritised, but the risk of customer-driven requirements remains.

Evidence: https://www.netnod.se/dns/dns-enterprise-services, https://www.netnod.se/dns/dns-for-public-sector, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services

Cyber Resilience Act (source) — Assessment Required

The EU Cyber Resilience Act (CRA), adopted in 2024 and applying from 2027, imposes cybersecurity requirements on products with digital elements placed on the EU market. Netnod has actively engaged with CRA consultations (COM(2022)454, I2022/01758, Fi2026/00065 on complementary provisions). Risk is Medium because: (1) Netnod primarily provides services rather than products, which may limit direct CRA applicability; (2) however, if Netnod develops or distributes software/hardware components (e.g., for IX, DNS, or time services), CRA obligations may apply; (3) Netnod's response to Fi2026/00065 on complementary provisions to the EU Cyber Resilience Regulation confirms ongoing monitoring of obligations; (4) full applicability depends on whether Netnod's offerings qualify as 'products with digital elements' under CRA definitions.

Evidence: https://www.netnod.se/netnod-and-internetstiftelsen-responds-to-the-eu-commissions-proposed-adoption-of-the-cyber-resilience-act, https://www.netnod.se/cybersecurity/netnod%27s-response-on-provisions-complementing-the-eu-cyber-resilience-regulation, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847

EECC — Assessment Required

The EECC (implemented in Sweden via LEK SFS 2022:482) directly applies to providers of public electronic communications networks and services. Netnod's transport (DWDM), IX, and potentially DNS services qualify as electronic communications services. Netnod has extensively engaged with EECC implementation consultations (I2019/02319/D, PTS dnr 22-1480, 22-1477, 22-1342, 20-3324). Risk is High because: (1) EECC imposes network security, incident reporting, and end-user protection obligations; (2) PTS actively supervises EECC compliance; (3) Netnod's transport and IX services are core electronic communications infrastructure.

Evidence: https://www.netnod.se/netnod-responds-to-pts-proposals-on-the-implementation-of-the-european-code-of-electronic-communications-directive, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018L1972, https://www.pts.se/en/

Financials

Three-year financials

Financial Resilience Score: 7/10

Netnod AB benefits from a highly stable ownership and mission structure via TU-Stiftelsen (Stiftelsen för Telematikens Utveckling), which removes shareholder dividend pressure and enables retention of earnings for reinvestment. This foundation-ownership model typically produces a strong equity base relative to revenue and low financial leverage, supporting resilience through economic cycles. The company operates critical Internet infrastructure including I-root (one of the 13 global DNS root servers), the largest IXPs in the Nordics, and Sweden's national time distribution service, generating sticky, long-tenure customer relationships with ISPs, TLD registries, and governments. Revenue is largely recurring and subscription-based (IX port fees, DNS anycast subscriptions, time-service contracts), and the company has a 20+ year track record of 100% DNS uptime, reinforcing brand strength. Public-sector alignment with PTS, RISE, and Swedish national digital resilience programs (Robusthetskollen, FORT training) provides steady demand and a reputational moat. However, Netnod is small in absolute size (historically low-hundreds of MSEK revenue), meaning single customer losses or capex cycles can materially move margins. Capex intensity is significant given ongoing equipment refresh cycles (100GE to 400GE and beyond) across multiple sites. Competitive pressure from larger European IXPs (DE-CIX, AMS-IX) and private peering / cloud on-ramps partly substitutes for public IX peering, and the non-profit mandate limits access to equity capital for large expansion since there is no IPO route available.

Key strengths: Foundation ownership (TU-Stiftelsen) removes dividend pressure and enables earnings retention, Critical-infrastructure position operating I-root DNS server and largest Nordic IXPs, Recurring subscription-based revenue model across IX, DNS, and time services, Long-standing public-sector alignment with PTS and Swedish national digital resilience, 20+ years of 100% DNS uptime and strong brand reputation since 1996, Sticky, long-tenure customer relationships with ISPs, TLD registries, and governments

Risk factors: Small absolute size means single customer loss or capex cycle can significantly move margins, Capex intensity from ongoing equipment refresh (100GE to 400GE) across multiple sites, Competitive pressure on IX pricing from DE-CIX, AMS-IX and private peering / cloud on-ramps, FX exposure with international DNS/anycast customers paying in EUR/USD while cost base is SEK, Non-profit mandate limits access to equity capital for large expansion (no IPO route), Geographic concentration in Nordics limits scale relative to pan-European competitors

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report