Nordicway ApS

Denmark · owned by Independent (Denmark) · nordicway.dk · 13 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 13 sub-vendors.

Insights

Last updated 2026-09-13 · revision 6

13 direct vendors, 172 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nordicway ApS exhibits medium migration readiness, primarily due to a combination of architectural dependencies and significant regulatory compliance debt. The core hosting architecture, relying on cPanel, LiteSpeed, and a traditional LAMP/LEMP-like stack, while utilizing modern versions of these tools, is not inherently cloud-native, containerized, or microservices-based. This traditional setup makes a direct 'lift-and-shift' to modern cloud platforms more complex and costly than for more agile, containerized applications. A major challenge for any migration is the need to simultaneously address the existing 'Partially Compliant' and 'Assessment Required' statuses for GDPR, Danish Data Protection Act, ePrivacy, PCI DSS, NIS2, SOC 2, and ISO 27001. This substantial regulatory compliance debt would add significant complexity, cost, and risk to any migration project. Furthermore, there is a degree of vendor lock-in due to dependencies on specific software vendors like cPanel, Imunify360, and JetBackup for core hosting functionalities, and infrastructure provider Hetzner. Migrating away from these established systems would necessitate considerable re-architecture, data migration, and operational changes. The company's financial capacity to fund a potentially large-scale migration project is also unknown, as revenue figures are listed as null. On the positive side, the explicit commitment to EU-only data storage (except for Stripe with SCCs) provides clear boundaries for migration planning, simplifying the selection of compliant target environments within the EU. Additionally, the internal tech stack's mention of modern development languages (Node.js, Python, Ruby, Next.js, React, Angular) suggests potential internal capabilities to adapt to more modern, cloud-native solutions if a strategic decision is made to evolve the core hosting model.

Compliance

8 in-scope frameworks identified; showing 3.

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act supplements GDPR with national-specific provisions and is enforced by Datatilsynet, which has demonstrated active enforcement including issuing fines and reprimands to Danish companies. Risk is High because the same gaps identified under GDPR (cookie consent, DPO appointment, RoPA) apply equally under the Danish Act. Datatilsynet has issued guidance specifically on web hosting providers acting as data processors and has sanctioned companies for inadequate DPA arrangements.

Evidence: https://nordicway.dk/handelsbetingelser/, https://nordicway.dk/privatlivspolitik/, https://www.retsinformation.dk/eli/lta/2018/502

Danish E-Commerce Act — Partially Compliant

Risk is Low because Nordicway is a Danish e-commerce/digital services provider and the E-Commerce Act requirements are relatively straightforward. The company publishes its CVR number, address, and contact information as required. The main risk area is ensuring all mandatory pre-contractual information is provided in the ordering process, which cannot be fully verified without accessing the customer portal.

Evidence: https://nordicway.dk/, https://nordicway.dk/handelsbetingelser/

ISO 27001 (source) — Assessment Required

ISO 27001 risk is Medium for similar reasons to SOC 2. As a web hosting provider processing data for 30,000+ websites, Nordicway has significant information security responsibilities. ISO 27001 certification is not legally required but is a strong market expectation for hosting providers and would strengthen their GDPR Article 32 compliance posture (requirement for 'appropriate technical and organisational measures'). The absence of ISO 27001 certification means Nordicway cannot demonstrate to customers or regulators that it has a formally audited and certified Information Security Management System (ISMS). For a small SME, the cost and complexity of ISO 27001 certification may be prohibitive, but the risk of a security incident without a certified ISMS is a genuine concern given the scale of customer data hosted.

Evidence: https://nordicway.dk/, https://nordicway.dk/handelsbetingelser/

Financials

Three-year financials

Financial Resilience Score: 5/10

Nordicway ApS is a young Danish private limited company (founded 2019) operating in the competitive web hosting and domain registration market. The business model benefits from recurring subscription revenue (monthly/annual hosting and domain renewals), low operational complexity through a deliberately simplified single-product strategy, and an asset-light infrastructure based on shared cPanel/LiteSpeed hosting. The company self-reports hosting 30,000+ websites, which would indicate meaningful customer scale for a micro-business in the Danish market. However, the company faces significant risks including its short operating history without exposure to a full economic cycle, intense competition from larger and better-capitalised players (Simply.com, One.com, Curanet, DanDomain, UnoEuro, team.blue), and margin pressure from its price-led positioning (introductory 9.50 DKK/month). As a small ApS, the equity base is likely modest (Danish ApS minimum capital is 20,000 DKK), and the business has concentration risk in a single product line, a single country (Denmark), and likely a very small team with key-person dependency. Detailed financial figures (revenue, EBIT, equity) could not be retrieved from the Danish CVR register in this session, limiting the resilience assessment.

Key strengths: Recurring subscription revenue model providing predictable cash flow, Low operating complexity with simplified single-product strategy, Asset-light infrastructure (shared cPanel/LiteSpeed hosting), Stable pricing held flat since founding, supporting retention, Stated scale of 30,000+ websites hosted

Risk factors: Very young company (founded 2019) with limited track record, Intense competition from larger, better-capitalised Danish and international hosting providers, Price-led positioning compressing margins, Exposure to energy and infrastructure cost inflation, Likely modest equity base typical of small ApS, Concentration in single product line and single country (Denmark), Key-person dependency from small team size

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report