Optimum IT
Denmark · owned by Independent (Denmark) · www.optimumit.dk · 14 vendors
Optimum IT is a Danish independent IT consultancy that helps public authorities and private companies with the development and digitalisation of their businesses. The company offers services spanning digital strategy, IT and business architecture, public procurement processes, and organisational implementation of digital initiatives. Its clients include major Danish public sector organisations such as Rigspolitiet, KOMBIT, and various municipalities and regions, as well as private sector companies.
Resilience scores
- Digital Sovereignty: 14
- Digital Resilience: 4
- Financial Resilience: 7
Disruption prediction
Optimum IT has an estimated 17% probability of disruption in the next 6 months.
6 of Optimum IT's 14 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- VeronaLabs — Technology — Estonia
- and 11 more
Insights
Last updated 2026-09-13 · revision 7
14 direct vendors, 216 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- United Kingdom: 1
- Egypt: 1
Subvendors by controlling owner country (sample)
- Poland: 5
- Ireland: 2
- Japan: 3
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Optimum IT's migration readiness is assessed as medium-low. The internal tech stack, primarily WordPress and Elementor, is not inherently cloud-native, containerized, or microservices-based. Migrating these systems to a modern cloud environment would likely necessitate significant re-platforming or re-architecture, thereby increasing the complexity, cost, and duration of any migration effort. The regulatory landscape poses substantial challenges, with GDPR, NIS2, SOC2, and ISO 27001 all marked as 'Assessment Required' with high or medium risks. Addressing these compliance requirements meticulously during migration will add significant overhead and potential delays, as they must be factored into architectural and operational decisions. Strict data residency requirements, stemming from GDPR (EU/EEA or adequacy countries) and potential additional localization for Danish government clients, further complicate migration planning. These requirements will limit cloud provider choices and dictate specific architectural patterns, adding complexity and potentially increasing costs. The absence of financial stability data makes it difficult to ascertain the company's capacity to fund a potentially complex and costly migration. Regarding vendor lock-in, the data is ambiguous, stating 'Total Vendors: 0' while also providing details on vendor geographic diversity. If there are underlying vendor dependencies for their current tech stack, the lack of a detailed vendor lock-in assessment is a weakness. While the geographic diversity of vendor HQs (6 unique countries) *could* imply a broader market for potential new vendors or less reliance on a single vendor ecosystem, offering some flexibility, the actual number of vendors and the extent of lock-in remain unknown. The non-cloud-native tech stack combined with stringent and unaddressed regulatory and data residency requirements are the primary factors contributing to a lower migration readiness score.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
GDPR is mandatory for all EU companies processing personal data. As a Danish company serving both public and private clients, Optimum IT processes employee data, customer data, and client personal information. Non-compliance can result in fines up to 4% of annual turnover or €20 million. The company has a privacy policy indicating GDPR awareness, but full compliance status requires detailed assessment.
Evidence: https://www.optimumit.dk/privatlivs-politik/
SOC 2 (source) — Assessment Required
SOC2 is voluntary but increasingly expected for IT service providers, especially those serving enterprise clients. As an IT consulting firm handling client data and systems, SOC2 certification would demonstrate security controls. Risk is moderate as it's not legally required but may be contractually expected by clients.
NIS2 (source) — Assessment Required
NIS2 applies to Important Entities including digital service providers in the EU. As an IT consulting company providing digital transformation and IT services to critical sectors (government, healthcare, transport), Optimum IT may qualify as a digital service provider. Size threshold appears met based on client portfolio. Assessment needed to determine exact classification and requirements.
Evidence: https://www.optimumit.dk/, https://www.optimumit.dk/om-os-2/
Financials
Three-year financials
- 2025: gross profit DKK 27.7M, EBIT DKK 2.58M, equity DKK 3.62M
- 2024: gross profit DKK 22.1M, EBIT DKK 2.17M, equity DKK 3.31M
- 2023: gross profit DKK 21.4M, EBIT DKK 2.45M, equity DKK 4.94M
Financial Resilience Score: 7/10
Optimum IT A/S demonstrates qualitative financial resilience grounded in a sticky Danish public-sector client base and a diversified roster of critical public agencies including Rigspolitiet, KOMBIT, Erhvervsstyrelsen, Vejdirektoratet, Lægemiddelstyrelsen, Banedanmark, Region Hovedstaden, Region Midtjylland and several universities. Recurring framework agreements (SKI, KOMBIT) and recent re-awards (e.g. KOMBIT 'Igen!' in April 2025) suggest stable, multi-year revenue streams that buffer against economic cycles. The firm positions itself as an independent, vendor-neutral advisor with senior consultants (high average years of experience), which supports premium day rates and credibility in public procurement. Active recruitment in 2024-2025 (welcoming Helena, Helle) indicates net headcount expansion and management confidence. However, financial transparency is limited because, as a small Danish A/S likely reporting under regnskabsklasse B, revenue is not required to be disclosed. The business model is headcount-driven and exposed to Danish IT wage inflation, utilisation swings and bench cost during slow tender periods. Heavy public-sector dependency ties results to political budget cycles and procurement law changes, and the small absolute size means loss of a few key partners or large engagements would have outsized impact.
Key strengths: Sticky public-sector client base with recurring framework agreements (SKI, KOMBIT), Diversified roster of critical Danish public agencies reducing single-customer risk, Vendor-neutral independent advisor positioning attractive for public procurement, Senior consultant mix supporting premium day rates, Repeat awards (KOMBIT 'Igen!' April 2025) signal sustained client retention, Active hiring in 2024-2025 indicates growth and management confidence, Approximately 15 years of trading history (CVR registered ~2009-2010)
Risk factors: Headcount-driven model exposed to utilisation rates and Danish IT wage inflation, Heavy public-sector dependency tied to political budget cycles and procurement law, Small absolute size — loss of key partners or large engagements has outsized impact, Limited public financial transparency (small A/S filings typically omit revenue), Geographic concentration: effectively 100% Denmark, Bench cost exposure during slow tender periods
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Strategy: 0%
- Architecture: 0%
- Implementation: 0%
- Procurement/Udbud: 0%
Workforce by country
- Denmark: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.