Nordic RCC A/S

Denmark · owned by Independent (Denmark) · nordic-rcc.net · 17 vendors

Nordic Regional Coordination Centre (Nordic RCC) is an independent company that provides regional coordination services to the four Nordic electricity Transmission System Operators (TSOs) — Statnett (Norway), Svenska Kraftnät (Sweden), Fingrid (Finland), and Energinet (Denmark). It supports cross-border operational security of the Nordic power system around the clock and is one of six EU-mandated Regional Coordination Centres in Europe. Headquartered in Copenhagen, it plays a key role in enabling the green energy transition and the European internal energy market.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 20

17 direct vendors, 220 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nordic RCC A/S demonstrates medium migration readiness, leaning towards the lower end. On the positive side, the company's strong financial growth provides the necessary capital to fund a significant migration initiative. Their existing use of Microsoft Azure for identity management (Azure AD / Entra ID) suggests some familiarity with cloud environments and a foundation for further cloud adoption. However, several critical factors present substantial migration challenges. The core operational systems, such as those for Flow-based Capacity Calculation and Common Grid Model methodology, are likely complex and potentially monolithic, as indicated by the 'unforeseen complexity' in the FBCC project delay. This suggests a significant effort would be required to refactor or re-platform these systems for a cloud-native architecture. A major impediment is the extensive list of 'Assessment Required' and 'High Risk' regulatory compliance items (GDPR, NIS2, ISO 27001, SOC2), for which 'No audit evidence found'. Any migration would necessitate addressing these compliance gaps, adding considerable complexity, cost, and time to the project. Strict EU data residency requirements under GDPR and NIS2 further constrain cloud deployment options and data transfer strategies. The vendor landscape is ambiguous, with 'Total Vendors: 0' contradicting the presence of 'Vendor HQ Countries' and 'Vendor Geographic Diversity'. Assuming vendors exist, the 'Vendor Lock-in Risk: Unknown' represents a potential hurdle, as complex vendor relationships could complicate migration planning and execution.

Compliance

10 in-scope frameworks identified; showing 3.

CSRD (source) — Assessment Required

The EU Corporate Sustainability Reporting Directive (CSRD) requires companies meeting two of three thresholds (>250 employees, >€40M net turnover, >€20M total assets) to report on sustainability matters under European Sustainability Reporting Standards (ESRS) with limited assurance. Nordic RCC's Activity Report 2025 explicitly references 'sustainability reporting' as a key focus area, suggesting the company is preparing for or already subject to CSRD. Risk is Medium because: (1) the company is actively working on sustainability reporting; (2) CSRD applicability depends on size thresholds not publicly confirmed; (3) non-compliance with CSRD reporting requirements could result in regulatory action from the Danish Business Authority; (4) as an energy sector entity, Nordic RCC's sustainability reporting is of particular public interest.

Evidence: https://nordic-rcc.net/publication-of-nordic-rcc-annual-report-2025-and-activity-report-2025/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2464

NIS2 (source) — Assessment Required

Nordic RCC A/S operates squarely within the electricity sector — specifically as a Regional Coordination Centre (RCC) mandated by EU Regulation 2019/943 — which is explicitly classified as an Essential Entity under NIS2 Annex I (energy sector: electricity). The company provides 24/7 critical operational security services to four national Transmission System Operators (TSOs) across Finland, Norway, Sweden, and Denmark, making it a critical node in European energy infrastructure. NIS2 risk is rated High because: (1) the energy/electricity sector is an Essential Entity category under NIS2 with the most stringent obligations; (2) a cyberattack or operational failure at Nordic RCC could cascade across four Nordic countries' power grids; (3) NIS2 imposes significant obligations including incident reporting (within 24h/72h), supply chain security, management accountability, and potential fines up to €10M or 2% of global turnover for Essential Entities; (4) Denmark transposed NIS2 into national law (Lov om sikkerhed i net- og informationssystemer, L 107) effective October 2024; (5) no public evidence of NIS2 compliance certification or formal assessment was found. The Activity Report 2025 references 'information security' and 'resilience' as key focus areas, suggesting awareness but not confirmed compliance.

Evidence: https://nordic-rcc.net/about/, https://nordic-rcc.net/publication-of-nordic-rcc-annual-report-2025-and-activity-report-2025/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019R0943, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1366, https://www.retsinformation.dk/eli/lta/2024/639

EU Network Code on Cybersecurity — Assessment Required

EU Regulation 2024/1366 (Network Code on Cybersecurity for the electricity sector) entered into force in June 2024 and directly applies to TSOs, DSOs, and RCCs including Nordic RCC. This is a sector-specific cybersecurity regulation that supplements NIS2 with electricity-sector-specific requirements. Risk is High because: (1) it directly names RCCs as regulated entities; (2) it requires cybersecurity risk assessments, incident reporting, supply chain security, and ISMS implementation aligned with IEC 62351 and ISO 27001; (3) implementation timelines are phased (2024-2026), meaning Nordic RCC is currently in active implementation; (4) non-compliance could trigger regulatory action from national energy regulators and ACER; (5) the Activity Report 2025 references 'information security' and 'resilience' as key focus areas, suggesting active implementation work but no confirmed completion.

Evidence: https://nordic-rcc.net/publication-of-nordic-rcc-annual-report-2025-and-activity-report-2025/, https://nordic-rcc.net/about/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1366, https://www.acer.europa.eu/electricity/network-codes/cybersecurity

Financials

Three-year financials

Financial Resilience Score: 8/10

Nordic RCC A/S demonstrates exceptionally strong financial resilience for a young company, underpinned by a highly stable and regulatorily protected business model. Revenue is generated under a cost-plus contract with a 5% mark-up on costs, billed to its four state-owned TSO shareholders (Energinet, Statnett, Fingrid, Svenska Kraftnät). This structure virtually eliminates market and pricing risk while guaranteeing a small positive margin. The company's existence and tasks are mandated by EU Regulation 2019/943, providing a regulatory moat with effectively no competitive threat. The balance sheet is very strong, with equity of DKK 352M representing approximately 80% of total assets (DKK 440M), no interest-bearing external debt beyond lease liabilities of DKK 29M, and DKK 114.7M in cash. Operating cash flow was DKK 62.8M in 2025 (DKK 110.8M in 2024). Credit risk is minimal given that customers are effectively sovereign entities, and no impairment has been recognised on trade receivables. EY issued an unqualified audit opinion for 2025. Key risks include extreme customer concentration (93% of revenue from the four TSO owners), heavy dependence on a single intangible asset (NorCap platform, 51% of total assets), and cybersecurity exposure as critical energy infrastructure under NIS2. However, these are largely mitigated by the cost-plus contract structure and the regulatory framework. The company has been profitable every year since its start-up loss in 2022.

Key strengths: Cost-plus contract with 5% mark-up guarantees positive margin, Four state-owned TSO shareholders as customers (ultra-low credit risk), Equity ratio of ~80% (DKK 352M equity vs DKK 440M total assets), DKK 114.7M cash position at year-end 2025, Regulatory moat under EU Regulation 2019/943, Unqualified EY audit opinion, Profitable every year since 2023 (post start-up phase), Strong revenue growth: 3.7x in three years (DKK 97.7M to DKK 364.2M)

Risk factors: Customer concentration: 93% of revenue from four TSO shareholders, Single-asset concentration: NorCap platform is 51% of total assets, Cybersecurity/critical infrastructure exposure under elevated geopolitical threat, Heavy reliance on consultants (DKK 112.2M in 2025, exceeding wages of DKK 84.6M), Retained earnings deficit of DKK -95M from historical R&D reserve treatment, Rapid headcount growth (44 to 111 in three years) creates execution risk, Technological obsolescence risk on NorCap platform over longer term

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report