Nexus Group
Sweden · www.nexusgroup.com · 15 vendors
Nexus Group, a part of IN Groupe, is an innovative identity management company. It secures society by enabling trusted identities for people and things, offering comprehensive identity and security solutions for workforce, workplace, and the Internet of Things (IoT). The company's headquarters are located in Stockholm, Sweden.
Resilience scores
- Digital Sovereignty: 20
- Digital Resilience: 8
- Financial Resilience: 7
Disruption prediction
Nexus Group has an estimated 21% probability of disruption in the next 6 months.
9 of Nexus Group's 15 vendors monitored for disruptions.
Technology vendors
- Demandware — Technology — United States
- Netlify, Inc. — Technology — United States
- Salesforce, Inc. — Technology — United States
- and 12 more
Services catalogue
1 service in catalogue across 1 category; runs on 15 sub-vendors.
- Personal Data Processing
Insights
Last updated 2026-08-11 · revision 1
15 direct vendors, 182 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 2
- Germany: 1
- Japan: 1
Subvendors by controlling owner country (sample)
- Germany: 7
- Italy: 1
- Japan: 3
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Nexus Group's migration readiness is assessed as medium, largely due to significant data gaps and a lack of explicit indicators for cloud-native architecture. While the internal tech stack includes 'REST API,' suggesting some modularity and integration capabilities, there is no explicit mention of cloud-native components like containerization or microservices, which are key facilitators for modern migrations. The presence of 'WordPress' might also indicate some traditional web components that could complicate a full-scale cloud migration. Crucially, 'Regulatory Environment' and 'Data Residency Requirements' are not specified; these are vital considerations that profoundly impact migration strategies, compliance, and costs, especially for a global cybersecurity firm. The absence of data on 'Revenue Concentration by Product,' 'Revenue Concentration by Geography,' and 'Growth History' makes it impossible to assess the company's financial capacity to fund a potentially extensive migration effort. Regarding vendor relationships, the 'Total Vendors: 0' is inconsistent with other vendor data. Assuming there are vendors, 'Vendor Lock-in Risk: Unknown' means the complexity of disentangling from existing vendor contracts or technologies during a migration cannot be determined. While 'Vendor Geographic Diversity: 4 unique countries' is positive for resilience, it does not directly reduce vendor lock-in. The 'Total Services: 17' suggests a moderate number of external dependencies that would need careful consideration during any migration planning.
Compliance
10 in-scope frameworks identified; showing 3.
Common Criteria — Compliant
Risk is rated Low because Nexus Group explicitly displays Common Criteria certification on its About page, indicating active compliance with this international IT security evaluation standard. Common Criteria certification is a rigorous, third-party evaluated standard required for security products used in government and critical infrastructure environments. Maintaining this certification demonstrates a mature security evaluation program. Risk is Low as the certification appears to be actively maintained and is a core business requirement for Nexus's government and critical infrastructure customer base.
Evidence: https://nexus.ingroupe.com/about-in-groupe-nexus/, https://ingroupe.com/integrity-and-compliance/, https://www.commoncriteriaportal.org/, https://www.fmv.se/verksamhet/csec/
eIDAS Regulation — Assessment Required
Risk is rated High because: (1) Nexus Group provides PKI, digital certificate issuance, and identity management services that directly overlap with eIDAS-regulated trust services (electronic signatures, electronic seals, time stamps, website authentication certificates, electronic registered delivery services); (2) Nexus explicitly offers 'GO Workforce LoA3' services — Level of Assurance 3 under eIDAS — and references DIGG (Swedish Agency for Digital Government) compliance, indicating direct eIDAS engagement; (3) Nexus serves Inera (Swedish healthcare) for LoA3-compliant eIDs, which is an eIDAS-regulated activity; (4) If Nexus acts as a Qualified Trust Service Provider (QTSP) or provides services to QTSPs, it is subject to strict eIDAS requirements including supervisory body oversight, security audits every 24 months, and conformity assessment by accredited CABs; (5) eIDAS 2.0 (EU Digital Identity Wallet regulation, effective 2024) introduces new requirements for wallet providers and trust service providers that Nexus's services directly address; (6) Non-compliance with eIDAS for trust service providers can result in removal from EU Trusted Lists and loss of qualified status, which would be commercially devastating.
Evidence: https://nexus.ingroupe.com/go-workforce-loa3-digg/, https://nexus.ingroupe.com/inera-enables-loa3-compliant-eids-via-remote-id-verification-with-in-groupe/, https://www.digg.se/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32014R0910, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1183
SOC 2 (source) — Assessment Required
Risk is rated Medium because: (1) Nexus Group operates multiple cloud/SaaS services (GO IoT, GO Workforce, GO Workplace, GO MDM, GO Authentication, GO Cards) that process customer data, making SOC 2 highly relevant as a trust assurance framework; (2) Nexus serves large enterprise and government clients (Volkswagen, Siemens, Electrolux, Banque de France, Skanska) who typically require SOC 2 Type II reports as part of vendor due diligence; (3) No SOC 2 report or certification was found in public sources; (4) The absence of SOC 2 could represent a competitive and contractual risk, particularly for US-market customers or multinational enterprises with US operations; (5) However, Nexus holds ISO 27001 certification (evidenced by certification logos on the About page), which is the European equivalent and may satisfy many customer requirements that SOC 2 would otherwise address. Risk is not High because ISO 27001 provides substantial overlap and may be the preferred framework for Nexus's primarily European customer base.
Evidence: https://nexus.ingroupe.com/about-in-groupe-nexus/, https://nexus.ingroupe.com/solutions/online-services/, https://ingroupe.com/integrity-and-compliance/, https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Nexus Group's financial resilience is materially strengthened by its 2021 acquisition by IN Groupe, the French state-owned identity and secure documents company. This ownership structure provides long-term capital backing, sovereignty credentials, and cross-selling access into government identity programs, which is a distinct advantage over VC-funded cybersecurity peers. IN Groupe reports group revenue in the range of €400-450M with ~2,000 employees, of which Nexus is one business unit. The business benefits from sticky enterprise and government customer relationships in PKI and workforce identity, which typically involve multi-year contracts with high switching costs. A growing SaaS/subscription mix through Smart ID GO services builds recurring ARR, while regulatory tailwinds from NIS2, eIDAS 2.0, post-quantum cryptography migration, and the EU Cyber Resilience Act support demand. Blue-chip references including Volkswagen, Siemens, Electrolux, and Banque de France reduce sales-cycle risk. However, resilience is tempered by scale disadvantages versus global IAM/PKI leaders (Microsoft Entra, Okta, Ping, Entrust, DigiCert, Thales), PKI commoditization pressure from cloud-native CA services, and concentration risk on a few large contracts (VW V2X, ID06, national eID programs) given the estimated SEK ~500M revenue scale. Historical profitability was thin, with reported operating losses in several pre-IN Groupe years during cloud platform investment. Sustained EBIT profitability remains a key watch-item.
Key strengths: Strategic ownership by IN Groupe (French state-backed) providing long-term capital, Sticky enterprise and government PKI/identity contracts with high switching costs, Growing SaaS recurring revenue mix via Smart ID GO services, Regulatory tailwinds (NIS2, eIDAS 2.0, post-quantum, EU Cyber Resilience Act), Blue-chip customer references (Volkswagen, Siemens, Electrolux, Banque de France), Long operating history since 1984 with focused identity/PKI positioning
Risk factors: Scale disadvantage vs. global IAM/PKI leaders (Microsoft, Okta, Entrust, Thales), PKI commoditization pressure from cloud-native CA services, Concentration risk on large deals (VW V2X, ID06, national eID programs), FX exposure: EUR/USD/CHF revenue vs. SEK reporting, Integration and restructuring risk within IN Groupe post-2021 acquisition, Historically thin profitability with prior operating losses
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.