Nets A/S
Denmark · www.nets.eu · 12 vendors
Nets A/S is a leading provider of digital payment services and related technology solutions across the Nordic region and other parts of Europe. The company operates a network that connects merchants, enterprises, financial institutions, and consumers, enabling them to make and receive payments and utilize value-added services. Nets offers solutions for in-store, online, and mobile payment acceptance, as well as payment processing services for card issuers and e-security solutions.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 7
- Financial Resilience: 7
Disruption prediction
Nets A/S has an estimated 11% probability of disruption in the next 6 months.
8 of Nets A/S's 12 vendors monitored for disruptions.
Technology vendors
- Adobe Inc. — Technology — United States
- Meta Platforms, Inc. — Technology — United States
- Statuspage (an Atlassian company) — Australia
- and 10 more
Services catalogue
10 services in catalogue across 6 categories; runs on 12 sub-vendors.
- Transaction Processing
- Nets eID Broker
- Dankort
Insights
Last updated 2026-09-13 · revision 14
12 direct vendors, 203 subvendors
Direct vendors by controlling owner country (sample)
- United States: 10
- Australia: 2
Subvendors by controlling owner country (sample)
- United Kingdom: 3
- Germany: 3
- China: 6
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Nets A/S exhibits high migration readiness, largely due to its highly modern and cloud-native internal tech stack. The extensive use of Java, Kotlin, Python, Go, Microsoft Azure, AWS, Kubernetes, Docker, Apache Kafka, PostgreSQL, Microservices Architecture, and REST APIs positions Nets well for further cloud adoption and modernization initiatives. The company's existing presence on both Azure and AWS indicates a multi-cloud strategy and established cloud operational capabilities. However, migration readiness is significantly challenged by a complex and stringent regulatory environment. Compliance with GDPR, PSD2, DORA, NIS2, and PCI DSS imposes strict requirements on data handling, security, and operational continuity that must be meticulously maintained throughout any migration. Specifically, DORA (applicable from January 2025) introduces stringent ICT risk management, incident reporting, and third-party risk management requirements, while NIS2 (transposed by October 2024) mandates robust cybersecurity measures. Data residency requirements are also a major constraint, with a primary need for EU/EEA data residency for personal data, specific Danish financial sector data requirements, and EBA Cloud Outsourcing Guidelines demanding regulatory access to data held by cloud providers. These factors limit the choice of cloud regions and providers and necessitate careful architectural planning. The declining revenue trend could also impact the financial capacity to fund large-scale migration projects. Similar to resilience, the vendor data is ambiguous. Assuming '3 unique countries' implies a limited number of key vendors, this could indicate a higher risk of vendor lock-in, which would add complexity and potential cost to migration efforts. Despite these significant regulatory and data residency hurdles, the advanced technical architecture and existing cloud footprint provide a strong foundation for successful migration, allowing Nets to navigate these complexities effectively.
Compliance
11 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
Nets A/S provides payment processing, card acquiring/issuing, and digital infrastructure services to banks, merchants, and public sector clients across Europe. Many of these clients — particularly large banks and multinational merchants — contractually require SOC 2 Type II reports as part of vendor due diligence. Risk is Medium because: (1) absence of SOC 2 reporting could create commercial friction with enterprise clients; (2) SOC 2 is not a legal/regulatory requirement in the EU (unlike PCI DSS or GDPR), so non-compliance does not carry regulatory penalties; (3) Nets' existing PCI DSS certification and ISO 27001 certification (if held) partially address the same control domains; (4) as a B2B financial infrastructure provider, client contractual requirements drive SOC 2 relevance more than regulatory mandates.
Evidence: https://www.aicpa-cima.com/resources/landing/soc-2, https://www.nets.eu/
ISAE 3000 (source) — Assessment Required
Nets A/S provides payment processing and financial infrastructure services to banks and financial institutions across Europe. These clients frequently require ISAE 3000 or ISAE 3402 assurance reports as part of their own regulatory compliance (e.g., under EBA outsourcing guidelines, DORA, and national banking regulations). Risk is Medium because: (1) absence of ISAE 3000/3402 reporting could impair Nets' ability to serve regulated financial institution clients; (2) EBA Guidelines on Outsourcing (EBA/GL/2019/02) require banks to obtain assurance over outsourced critical functions — Nets' payment processing services qualify; (3) ISAE 3000 is not a direct regulatory requirement for Nets itself but is commercially critical for client relationships.
Evidence: https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised, https://www.eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-outsourcing-arrangements, https://www.nets.eu/
EBA Guidelines on Outsourcing Arrangements — Compliant
Risk is Medium because: (1) Nets A/S is both subject to EBA outsourcing guidelines as a regulated payment institution (for its own outsourcing arrangements) and is itself a critical outsourced service provider to banks subject to these guidelines; (2) EBA outsourcing guidelines require robust contractual arrangements, audit rights, and business continuity planning; (3) non-compliance could trigger supervisory action by Finanstilsynet; (4) DORA (effective January 2025) largely supersedes and strengthens EBA outsourcing requirements for ICT services, so the transition to DORA compliance is the primary current focus.
Evidence: https://www.eba.europa.eu/regulation-and-policy/internal-governance/guidelines-on-outsourcing-arrangements, https://www.finanstilsynet.dk/
Financials
Three-year financials
- 2025: revenue EUR 1.49B, EBIT EUR 112M, equity EUR 2.34B
- 2024: revenue EUR 1.42B, EBIT EUR 36.1M, equity EUR 1.63B
- 2023: revenue EUR 1.32B, EBIT EUR -45.0M, equity EUR 1.59B
Financial Resilience Score: 7/10
Nets A/S benefits from its position as a near-utility payment infrastructure provider in Denmark and the broader Nordic region, operating critical systems such as the Dankort scheme and Betalingsservice direct debit platform. This entrenched infrastructure creates very high switching costs and provides recurring, transaction-volume-linked revenue with strong cash conversion. As part of Nexi Group following the 2021 merger, Nets benefits from a diversified European footprint across the Nordics, DACH, and Italy, plus access to European debt and equity markets through its well-capitalised parent. However, the 2018 take-private by Hellman & Friedman and subsequent Nexi merger left the combined group with substantial multi-billion EUR debt, creating refinancing risk in a rising interest rate environment. Regulatory pressures from EU PSD2/PSD3, interchange-fee caps, and the potential digital euro challenge card-scheme economics, while competitive disruption from account-to-account payments, mobile wallets (Apple Pay, MobilePay/Vipps), and BNPL players erode traditional card processing volumes. Integration risk from the ongoing Nexi-Nets-SIA three-way merger and concentration in mature, low-growth European markets further temper the resilience profile.
Key strengths: Near-utility status in Denmark via Dankort and Betalingsservice, High switching costs and entrenched infrastructure, Recurring transaction-volume-linked revenue with strong cash conversion, Nordic + DACH + Italian geographic diversification via Nexi Group, Backed by well-capitalised parent Nexi Group with capital markets access
Risk factors: Substantial multi-billion EUR debt from 2018 take-private and Nexi merger, Rising interest rates increase refinancing risk, EU regulatory pressure (PSD2/PSD3, interchange caps, digital euro), Competitive disruption from A2A payments, mobile wallets, BNPL, Concentration in mature European markets with limited volume growth, Integration risk from Nexi-Nets-SIA three-way merger
Revenue by geography
- Denmark: 38%
- Norway: 22%
- Germany/DACH: 18%
- Rest of Nordics (Sweden, Finland): 18%
- Other Europe: 4%
Revenue by product/service
- Merchant Services: 48%
- Issuer & eSecurity Services: 33%
- Financial & Network Services: 19%
Workforce by country
- Denmark: 1750
- Norway/Sweden/Finland: 1000
- Germany/DACH: 650
- Estonia/Poland: 400
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.