Pointsharp AB
Sweden · owned by Main Capital Partners (Netherlands) · www.pointsharp.com · 11 vendors
Pointsharp is a European cybersecurity company headquartered in Stockholm, Sweden, that provides advanced Multi-Factor Authentication (MFA), Identity and Access Management (IAM), and Secure Information Exchange solutions. The company serves large enterprise organizations and governmental institutions across sectors such as finance, defense, and government, supporting on-premises, cloud, and hybrid infrastructures. Founded in 2006, Pointsharp has grown through acquisitions including SecMaker, Cryptshare, SIVIS, and Vemendo, and employs approximately 200 people with offices in Sweden, Germany, Denmark, the Netherlands, and Switzerland.
Resilience scores
- Digital Sovereignty: 36
- Digital Resilience: 9
- Financial Resilience: 6
Technology vendors
- Google LLC — Technology — United States
- Loopia AB — Technology — Sweden
- Mandrill (an Intuit company) — United States
- and 8 more
Insights
Last updated 2026-04-13 · revision 2
11 direct vendors, 180 subvendors
Direct vendors by controlling owner country (sample)
- Germany: 1
- Denmark: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Spain: 1
- Switzerland: 1
- Luxembourg: 1
Migration Readiness: 8/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Pointsharp AB exhibits high migration readiness. Their existing internal tech stack includes Microsoft Azure, indicating a strong foundation and experience with cloud infrastructure. Their product offerings further reinforce this, with solutions like PKI-as-a-Service (Pointsharp Secure Cloud) and SAP-certified components for SAP S/4HANA Cloud (private edition), demonstrating a clear commitment to cloud adoption and hybrid deployment models. The availability of Java and .NET APIs for product integration suggests a service-oriented architecture, which facilitates migration efforts. While the data on "Total Vendors: 0" is contradictory to the listed "Vendor HQ Countries" across 7 unique countries, the implied vendor geographic diversity suggests they are not heavily locked into a few concentrated vendors, which generally reduces migration complexity. Key challenges for migration readiness stem from their strict regulatory environment (GDPR, NIS2 applicable) and data residency requirements (EU/EEA). These necessitate careful planning to ensure compliance, data sovereignty, and security during any migration, potentially adding complexity and cost. The absence of financial stability data (revenue concentration, growth history) also means the ability to fund a significant migration cannot be fully assessed.
Compliance
5 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
As a cybersecurity company handling sensitive customer data and providing security services, ISO 27001 certification would be expected industry standard. Medium risk due to lack of evidence of certification despite being in cybersecurity industry.
Evidence: https://www.pointsharp.com/en/certifications
GDPR (source) — Compliant
Company is headquartered in Sweden (EU member state) and processes personal data of employees, customers, and website visitors. They have a comprehensive privacy notice, appointed DPO (Patrik Jonasson), and demonstrate GDPR compliance awareness. Risk is low due to established compliance framework and EU location.
Evidence: https://www.pointsharp.com/en/privacy-notice, https://www.pointsharp.com/en/certifications
NIS2 (source) — Assessment Required
As a cybersecurity/IAM provider in the EU with 200+ employees, Pointsharp likely falls under NIS2 as an 'Important Entity' providing digital services. The company explicitly mentions NIS2 compliance support for customers, indicating awareness. Medium risk due to potential applicability but unclear formal compliance status.
Evidence: https://www.pointsharp.com/en/certifications, https://www.pointsharp.com/en/about
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 6/10
Pointsharp AB operates in a structurally attractive and high-growth segment of the cybersecurity market — Identity and Access Management (IAM), Identity Governance & Administration (IGA), PKI, and Secure Information Exchange. The company was explicitly described as profitable and growing autonomously at the time of Main Capital's acquisition in November 2020, indicating a sound underlying business model prior to the PE-backed expansion phase. Its software and SaaS-oriented product portfolio is consistent with high gross margins and recurring, predictable revenue streams, which are hallmarks of financial resilience in the software sector. Strong regulatory tailwinds from EU mandates including NIS2 (October 2024), DORA (January 2025), eIDAS 2, and the Cyber Resilience Act create durable structural demand for exactly the solutions Pointsharp provides, reducing the risk of revenue cyclicality. However, the company's financial resilience is materially constrained by a lack of public financial transparency. No audited revenue, EBIT, equity, or leverage figures are available from accessible sources, making it impossible to independently verify profitability, debt serviceability, or balance sheet strength. PE-backed buy-and-build strategies of the type pursued by Main Capital typically involve acquisition financing that introduces leverage onto the consolidated balance sheet, and the interest burden associated with four acquisitions completed between 2021 and 2025 is entirely unknown. Additionally, the rapid pace of M&A — four deals in approximately four years across two countries and multiple product stacks — creates meaningful integration risk that could weigh on margins and management bandwidth. The company's customer base in defense, finance, industrial, and government sectors provides high switching costs and long contract cycles, supporting revenue retention. Its 'Made in Europe' positioning is a genuine differentiator for data-sovereignty-sensitive public-sector and regulated-industry clients. With approximately 200 employees and a multi-country footprint, Pointsharp is a credible mid-market player, though it remains small relative to global IAM incumbents such as Microsoft Entra, Okta, and CyberArk, which limits pricing power and R&D scale. The PE ownership cycle also introduces exit-timing uncertainty, with a potential exit window estimated at 2024–2027 based on Main Capital's typical hold period.
Key strengths: Recurring software/SaaS revenue model with high gross margin characteristics, Confirmed organic profitability at time of PE entry in November 2020, Strong regulatory tailwinds: NIS2, DORA, eIDAS 2, Cyber Resilience Act driving structural demand, High switching costs and long contract cycles in defense, finance, government, and industrial customer base, PE backing from Main Capital Partners (~€1B AUM) providing acquisition capital and strategic support, Diversified product portfolio post-acquisitions covering IAM, IGA, PKI, and Secure Information Exchange, 'Made in Europe' data sovereignty positioning as competitive differentiator for regulated sectors, Approximately 200 employees across Sweden, Germany, Netherlands, and Denmark
Risk factors: Financial leverage and debt load entirely unknown — PE-backed serial acquisitions typically carry significant acquisition debt, No public financial statements accessible — revenue, EBIT, equity, and margins cannot be independently verified, Integration risk from four acquisitions (2021–2025) across two countries and multiple product stacks, Likely large goodwill and intangible asset balances on balance sheet; impairment risk unquantifiable, Small absolute scale (~200 employees) relative to global IAM competitors limits R&D and sales leverage, PE exit timing uncertainty (estimated 2024–2027 window) could affect strategy and investment levels, No country-level or product-level revenue breakdown available to assess concentration risk, Multi-currency exposure across SEK, EUR, and DKK, though largely intra-European
Revenue by geography
- Germany / DACH: 0%
- Outside Europe: 0%
- Rest of Europe: 0%
- Sweden / Nordics: 0%
- Netherlands / Benelux: 0%
Revenue by product/service
- Secure Information Exchange (Cryptshare): 0%
- Identity Governance and Administration (IGA, SIVIS, Vemendo): 0%
- Access Management (PKI, NetiD, MFA, SSO, Passwordless, FIDO2, eID): 0%
Workforce by country
- Total: 200
- Sweden: 0
- Denmark: 0
- Germany: 0
- Netherlands: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.