Nordlo AB

Sweden · www.nordlo.com · 18 vendors

Resilience scores

Disruption prediction

Nordlo AB has an estimated 27% probability of disruption in the next 6 months.

8 of Nordlo AB's 18 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 1 category; runs on 18 sub-vendors.

Insights

Last updated 2026-08-10 · revision 1

18 direct vendors, 202 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 8/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Nordlo AB exhibits a good level of migration readiness. **Strengths:** The company's internal tech stack includes significant cloud components like Microsoft Azure and Microsoft 365, along with IaaS, indicating existing experience and infrastructure for cloud environments. Their product offerings highlight "DevOps practices" and "custom application development," suggesting capabilities in modern software development and deployment methodologies that facilitate migration. While specific regulatory environments are not detailed, Nordlo's offering of "ISO 27001-certified environments" and "incident management for regulated industries" implies a strong understanding and capability in managing compliance requirements, which is crucial for successful migrations. The presence of vendors from 7 unique countries suggests experience in managing diverse vendor relationships, which can be beneficial in navigating complex migration projects involving multiple technologies and providers. As a provider of "Full-Service Partnership (Helhetsåtagande)" and "Managed Services," Nordlo's core business involves managing and transforming client IT environments, including potentially migrating them. This internal expertise is a significant asset for their own migration readiness. **Weaknesses:** The lack of information on revenue concentration and growth history makes it difficult to assess the financial capacity to fund significant migration initiatives. The "Vendor Lock-in Risk: Unknown" is a potential hurdle. While vendor geographic diversity is good, the actual level of lock-in with key platforms (e.g., Microsoft Azure, Microsoft 365) could impact the ease and cost of future migrations. While cloud-adopted, there's no explicit mention of containerization or microservices, which are key indicators of advanced cloud-native readiness. The conflicting vendor data ("Total Vendors: 0" vs. other detailed vendor information) makes it challenging to precisely evaluate the number and nature of vendor relationships, which are critical for assessing migration complexity and lock-in.

Compliance

10 in-scope frameworks identified; showing 3.

ISO 14001 — Compliant

Risk is rated Low because Nordlo has confirmed ISO 14001:2015 certification. This demonstrates a formal environmental management system, reducing regulatory and reputational risks related to environmental compliance. Nordlo also has SBTi (Science Based Targets initiative) approved climate targets, further evidencing environmental commitment.

Evidence: https://nordlo.com/om-oss, https://nordlo.com/om-oss/hallbarhet, https://nordlo.com/pressmeddelanden/nordlos-vetenskapsbaserade-mal-godkanda-av-globala-klimatinitiativet-sbti

ISO 27001 (source) — Compliant

Risk is rated Low because Nordlo has confirmed ISO 27001:2022 certification — the most current version of the standard — as publicly stated on their official 'About Us' page. This is the highest level of assurance available for information security management. ISO 27001:2022 certification requires: (1) a formal ISMS scope definition; (2) risk assessment and treatment; (3) implementation of Annex A controls; (4) internal audits; (5) management review; and (6) annual surveillance audits plus triennial recertification by an accredited certification body. The certification directly mitigates information security risks and demonstrates a mature security posture appropriate for an IT managed services provider of Nordlo's scale.

Evidence: https://nordlo.com/om-oss, https://www.iso.org/standard/27001, https://nordlo.com/tjanster/sakerhet

ISO 9001 — Compliant

Risk is rated Low because Nordlo has confirmed ISO 9001:2015 certification on their official website. This demonstrates a formal quality management system is in place, reducing operational and service delivery risks. ISO 9001 is a widely adopted standard for IT service providers and supports consistent service quality across Nordlo's decentralized organization.

Evidence: https://nordlo.com/om-oss

Financials

Three-year financials

Financial Resilience Score: 6/10

Nordlo Group AB demonstrates moderate financial resilience underpinned by a high-quality recurring revenue base from managed services and full IT outsourcing (helhetsåtagande) contracts, which are typically multi-year and SLA-based. The company has a diversified customer base spread across resilient verticals including retail, real estate, construction, public sector, and industrial/logistics, limiting single-customer concentration risk. It holds strong certifications (ISO 9001, 14001, 45001, 27001, 27701) and was named Microsoft SMB Partner of the Year in Sweden in 2024, supporting eligibility for public-sector procurement and Microsoft-ecosystem revenue. However, resilience is tempered by the classic risks of a PE-backed roll-up. Nordlo has completed roughly 20 acquisitions in seven years, which creates significant goodwill on the balance sheet, integration risk, and obscures underlying organic growth. As a PE-backed platform owned by FSN Capital since 2018, the group almost certainly carries meaningful acquisition-financing debt, though leverage and interest coverage are not publicly disclosed. Additional risks include Nordic wage inflation and consultant utilization sensitivity, competition from larger players (Tietoevry, CGI, Advania, Iver), geographic concentration in just Sweden and Norway, and an approaching likely ownership transition given typical PE hold periods of 5-7 years.

Key strengths: Recurring revenue from managed services and multi-year outsourcing contracts, Diversified customer base across resilient verticals (retail, real estate, public sector, industrial), Strong certifications (ISO 9001/14001/45001/27001/27701), Microsoft SMB Partner of the Year Sweden 2024, PE sponsor (FSN Capital) provides capital access and governance discipline, 13 consecutive years top of Radar's customer satisfaction survey, Self-reported ~SEK 2.5B revenue and ~1,000 employees scale

Risk factors: Acquisition-heavy growth creating goodwill and integration risk, Undisclosed leverage typical of PE-backed roll-ups, Talent and wage inflation pressure on consultant margins, Geographic concentration limited to Sweden and Norway, Ownership transition risk as FSN Capital approaches typical exit horizon, Organic growth not disclosed and difficult to disentangle from M&A, Competition from larger Nordic IT services players (Tietoevry, CGI, Advania, Iver)

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report