NHC A/S

Denmark · owned by PVL HOLDING ApS (Denmark) · nhc.dk · 16 vendors

NHC is a Danish IT managed services provider that delivers IT outsourcing, support, hosting, security, and compliance solutions to Danish businesses. Founded in 2006, the company operates under the motto 'Leave IT to us,' taking full responsibility for clients' IT infrastructure so they can focus on their core business. NHC serves companies ranging from 10 to 200+ employees and operates from offices in Silkeborg and Taastrup, Denmark.

Resilience scores

Disruption prediction

NHC A/S has an estimated 17% probability of disruption in the next 6 months.

8 of NHC A/S's 16 vendors monitored for disruptions.

Technology vendors

Insights

Last updated 2026-09-13 · revision 9

16 direct vendors, 226 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

NHC A/S exhibits high migration readiness. This is primarily driven by its highly modern, cloud-native internal tech stack, with extensive adoption of Microsoft Azure, Microsoft 365, Microsoft Intune, and other related Microsoft cloud services. This positions them well for further cloud migrations and digital transformations. Their strong focus on IT compliance, including NIS2 and GDPR, is a significant advantage for navigating the regulatory and data governance aspects of migrations. The presence of their own NHC Datacenter also provides flexibility for hybrid cloud strategies. The main challenge to migration readiness is the significant vendor lock-in within the Microsoft ecosystem. While this facilitates migrations *within* Microsoft's cloud offerings, it would present a substantial challenge and cost if NHC were to consider migrating away from Microsoft to another major cloud provider. Data residency requirements are not specified, which could introduce complexity if strict requirements emerge, and explicit details on containerization or microservices adoption are not provided.

Compliance

6 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 was transposed into Danish law via 'Lov om foranstaltninger til sikring af et højt fælles cybersikkerhedsniveau' (effective October 2024). NHC A/S operates as a Managed Service Provider (MSP) and IT hosting provider in Denmark. Under NIS2 Annex I and II, 'ICT service management (B2B)' is explicitly listed as an Important Entity sector — this directly covers MSPs providing IT outsourcing, hosting, and security services to other businesses. The size threshold for NIS2 is medium enterprises (50+ employees OR €10M+ annual turnover). NHC's website states it serves companies from 10 to 200+ employees and describes itself as growing, but exact employee count and turnover are not publicly disclosed. The ISAE-3402 report references an insurance policy of DKK 10M (professional liability) and DKK 10M (product liability), suggesting a company of meaningful scale. If NHC meets the medium enterprise threshold (likely given its multi-office presence, datacenter operations, and customer base), it would qualify as an Important Entity under NIS2. Risk is Medium rather than High because: (1) the size threshold is not publicly confirmed; (2) NHC actively markets NIS2 compliance services to customers, suggesting awareness but not confirmed self-compliance; (3) Danish NIS2 enforcement is still maturing post-October 2024 transposition.

Evidence: https://nhc.dk/it-compliance, https://nhc.dk/hubfs/Dokumenter/NHC-ISAE-3402-Erklaering-2024.pdf, https://www.cfcs.dk/da/cybersikkerhed/nis2/, https://erhvervsstyrelsen.dk/nis2, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

ISAE 3402 — Compliant

NHC A/S has obtained a full ISAE 3402 Type II declaration for the period 1 January – 31 December 2024, issued by an independent, state-authorised auditor (Per Jensen, Statsautoriseret revisor, Revisionshuset Tal & Tanker, CVR: 37 31 56 64). The auditor concluded with no significant remarks across all tested controls. This is the highest level of assurance available under ISAE 3402 and directly addresses the company's role as a hosting and IT services provider. Risk is Low because: (1) the declaration is current (covering full year 2024, signed February 2025); (2) the auditor found no material deficiencies; (3) the declaration covers all key control domains relevant to NHC's hosting services; (4) NHC has a documented process for annual renewal. The only residual risk is that ISAE 3402 covers hosting services specifically and may not cover all NHC service lines (e.g., IT support, security services, compliance advisory).

Evidence: https://nhc.dk/hubfs/Dokumenter/NHC-ISAE-3402-Erklaering-2024.pdf, https://nhc.dk/forretningsdokumenter, https://nhc.dk/it-hosting, https://nhc.dk/nhc-datacenter

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). NHC A/S explicitly states in its ISAE-3402 2024 declaration that it has organised its IT security according to DS/ISO/IEC 27002:2022 and has implemented controls across all four domains (organisational, people, physical, technological). However, implementing ISO 27002 controls does not equate to ISO 27001 certification — ISO 27001 requires a formal ISMS with documented scope, risk treatment plan, Statement of Applicability, and third-party certification audit by an accredited certification body. No ISO 27001 certificate was found in public sources. Risk is Medium because: (1) NHC's customers (Danish SMEs) increasingly require ISO 27001 or equivalent assurance from their IT providers; (2) NIS2 compliance (if applicable) strongly encourages ISO 27001 alignment; (3) the absence of formal certification may be a competitive disadvantage and a gap in demonstrable security governance. The ISAE-3402 partially mitigates this risk by providing independent third-party assurance.

Evidence: https://nhc.dk/hubfs/Dokumenter/NHC-ISAE-3402-Erklaering-2024.pdf, https://nhc.dk/it-sikkerhed, https://nhc.dk/nhc-security-service, https://www.ds.dk/da/certificering/iso-27001

Financials

Three-year financials

Financial Resilience Score: 7/10

NHC A/S appears to have a resilient business model built on recurring revenue streams from managed IT services, outsourcing at fixed monthly pricing, and hosting contracts. These service categories typically produce high-visibility, contract-based recurring revenue, which is the most stable revenue profile in the IT services sector. The company's diversified customer base across retail, industrial, professional services, and rights-management sectors reduces single-industry concentration risk, and its two Danish office locations provide reach across Denmark's main commercial regions. The reference to a D&B AAA rating on the company website, if current, indicates historically low default risk among Danish SMEs. Multi-vendor competency with Microsoft, Citrix, Fortinet, Veeam, and Kaseya reduces dependence on any single platform. However, actual financial figures (revenue, EBIT, equity) could not be retrieved from CVR/virk.dk in this session, so quantitative resilience metrics remain unverified. The Danish mid-market MSP space is highly competitive with consolidation pressure from larger players like Atea, itm8, Fellowmind, and EG, which could pressure margins. Additionally, wage inflation and talent scarcity for security and Azure engineers in Denmark pose ongoing cost risks, and as an MSP handling client infrastructure, cybersecurity liability is a material concern.

Key strengths: Recurring revenue model from managed services and hosting contracts, Diversified customer base across retail, industrial, and professional services sectors, Two Danish office locations (Silkeborg HQ and Taastrup) providing national reach, Multi-vendor competency reducing platform dependence, Referenced D&B AAA rating on company website, NIS2 regulatory tailwind driving demand for security services

Risk factors: Highly competitive Danish mid-market IT services space with margin pressure, Wage inflation and talent scarcity for security and Azure engineers, Cybersecurity liability as an MSP handling client infrastructure and hosting, Potential customer concentration risk from large contracts (unverified), NIS2 compliance raises operational cost bar for NHC itself, Financial figures not publicly verified in this session

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report