Norlys Energy A/S

Denmark · owned by Independent (Denmark) · norlys.dk · 39 vendors

Norlys is Denmark's largest energy and telecommunications cooperative, offering electricity, natural gas, internet, and TV services to Danish consumers and businesses. The company was formed through the merger of Eniig and SE (Syd Energi), combining energy distribution and supply with fiber internet and TV services. It operates as a customer-owned cooperative headquartered in Denmark.

Resilience scores

Technology vendors

Services catalogue

5 services in catalogue across 4 categories; runs on 39 sub-vendors.

Insights

Last updated 2026-08-02 · revision 25

39 direct vendors, 402 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Norlys Energy A/S demonstrates a high degree of migration readiness, driven by its modern technological landscape and potential for low vendor lock-in. **Strengths:** The company's internal tech stack is highly conducive to migration, featuring extensive use of Microsoft Azure (including CDN and Blob Storage), REST APIs, and OpenID Connect (OAuth 2.0). These components facilitate cloud-native development and seamless integration, making it easier to re-platform or re-architect services. Key technologies like 5G Network Technology, IoT Device Management, and Energy Trading & Spot Price Integration are inherently modern and often designed for flexible, cloud-based deployments. Financially, Norlys is well-positioned, with substantial and generally growing revenue (DKK 24B in 2023), providing ample resources to fund significant migration initiatives. A critical advantage for migration flexibility is the reported "Total Vendors: 0". If interpreted as a lack of direct external vendor relationships, this implies extremely low vendor lock-in, granting the company maximum autonomy to choose new platforms, providers, and architectures without being constrained by complex vendor contracts or dependencies. **Challenges & Opportunities:** While the overall tech stack is modern, the presence of "Umbraco CMS" might require specific migration strategies, as it may not be fully containerized or microservices-based by default, potentially adding complexity to certain application migrations. The absence of specified data residency requirements or detailed regulatory compliance information means these factors cannot be fully assessed, but their current lack of explicit mention does not present an immediate barrier. The opportunity lies in leveraging the existing Azure footprint and modern APIs to further adopt cloud-native patterns, containerization, and microservices architectures, enhancing agility, scalability, and cost efficiency during future migrations.

Compliance

11 in-scope frameworks identified; showing 3.

EU AI Act (source) — Assessment Required

Norlys operates an IoT platform, Crowd Insights analytics service, and digital infrastructure that may incorporate AI/ML components. The EU AI Act entered into force in August 2024 with phased implementation. For Norlys, AI Act applicability depends on whether they deploy AI systems in regulated categories (e.g., AI for critical infrastructure management could be high-risk under Annex III). Risk is currently Low because the AI Act's main obligations for high-risk AI systems apply from August 2026, and Norlys's AI use cases are not clearly in prohibited or high-risk categories based on publicly available information.

Evidence: https://norlys.dk/erhverv/digitalisering/iot/iot-platform/, https://norlys.dk/erhverv/digitalisering/crowd-insights/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689

ISO 27001 (source) — Assessment Required

Norlys operates critical digital infrastructure (fiber networks, 5G, IoT platforms) and energy systems that are high-value targets for cyberattacks. ISO 27001 certification would provide a structured ISMS framework and is increasingly expected by regulators (including NIS2 supervisory authorities) and enterprise customers. The absence of publicly disclosed ISO 27001 certification is a gap for a company of Norlys's scale and critical infrastructure profile. However, risk is Medium rather than High because ISO 27001 is voluntary (though NIS2 compliance may effectively require equivalent controls), and the company may have internal security programs not publicly disclosed. The Danish energy sector has historically been targeted by state-sponsored cyber actors, elevating the importance of formal ISMS certification.

Evidence: https://norlys.dk/om-norlys/ansvarlighed/certificeringer-og-governance/, https://norlys.dk/erhverv/internet/it-sikkerhed/

Danish Electronic Communications Act — Assessment Required

Norlys operates as a significant electronic communications provider in Denmark, offering fiber internet, 5G mobile, cable TV, and business telephony services. The Danish Telecom Act (implementing the EU EECC) imposes obligations on providers of electronic communications networks and services, including network security, lawful interception, emergency services access, number portability, and consumer protection. The Danish Business Authority (Erhvervsstyrelsen) and the Danish Telecommunications Agency regulate this sector. Non-compliance risks include license revocation and significant fines. Risk is High because telecom is a core business line.

Evidence: https://norlys.dk/om-norlys/netvaerk/5g/, https://norlys.dk/erhverv/internet/, https://www.erst.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32018L1972

Financials

Three-year financials

Financial Resilience Score: 7/10

Norlys Group demonstrates solid financial resilience underpinned by its unique cooperative ownership structure (Norlys A.m.b.a. with 500,000+ member-owners), which provides patient capital and a long-term investment horizon. The company benefits from significant scale as Denmark's largest integrated energy and telecommunications player, with diversified revenue streams across electricity retail, gas, fiber broadband, mobile, TV, EV charging, B2B ICT, and renewables. This diversification reduces single-market risk and provides multiple growth vectors. The group's infrastructure ownership—including co-ownership of TDC NET and extensive cable/fiber networks from the legacy SE/Eniig/Stofa operations—creates a durable competitive moat. A strong equity base (~DKK 15B) built up through retained earnings, particularly during the 2022 energy-price boom, provides balance sheet strength. However, the 2022 energy crisis exposed vulnerabilities to commodity price swings, trading margin volatility, and counterparty margining risk in Nordic power markets. Heavy capex requirements for fiber, 5G, and EV charging rollouts, combined with regulatory risks (windfall taxes, price caps) and intense competition in both energy retail and telecom, moderate the overall resilience score.

Key strengths: Cooperative ownership with 500,000+ member-owners providing patient capital, Denmark's largest integrated energy and telecom group with scale advantages, Diversified revenue streams across energy, telecom, renewables, and EV charging, Infrastructure ownership including TDC NET co-ownership and fiber/cable networks, Strong equity base (~DKK 15B) bolstered by retained earnings from 2022 price boom, Renewables portfolio providing commodity hedge and ESG positioning

Risk factors: Commodity price exposure causing revenue and working capital volatility, Regulatory risk including EU/Danish price caps and windfall taxes, Intense competition in energy retail (Andel, OK, Ørsted) and telecom (TDC/Nuuday, Telenor, YouSee), Heavy capex requirements for fiber, 5G, and EV charging buildout, Trading counterparty and margining risk exposed during 2022 Nordic power market stress, Geographic concentration with 95%+ revenue from Denmark

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report