Posti Group Oyj

Finland · www.posti.fi · 17 vendors

Posti Group Oyj is the main Finnish postal and logistics service provider, offering a wide range of services including traditional postal services, parcel and e-commerce solutions, transport, warehousing, and fulfillment. The company operates in Finland and internationally, with a strong focus on expanding its e-commerce and logistics offerings. Posti Group aims to achieve fossil-free operations by 2030.

Resilience scores

Disruption prediction

Posti Group Oyj has an estimated 11% probability of disruption in the next 6 months.

10 of Posti Group Oyj's 17 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 17 sub-vendors.

Insights

Last updated 2026-08-03 · revision 1

17 direct vendors, 226 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Posti exhibits a solid foundation for migration readiness due to its significant adoption of cloud-native technologies, including a multi-cloud strategy (Microsoft Azure, Google Cloud Platform), container orchestration (Kubernetes, Docker), and Infrastructure as Code (Terraform). The use of Apache Kafka and PostgreSQL aligns with modern, scalable data architectures. These elements suggest a workforce and infrastructure capable of embracing further cloud migration and modernization initiatives. The primary challenge to migration readiness lies in the presence of complex, potentially monolithic enterprise systems such as SAP, Microsoft SQL Server, MuleSoft, and Workday. Migrating or refactoring these systems can be exceptionally complex, costly, and time-consuming, often requiring specialized strategies beyond simple lift-and-shift. The lack of information regarding specific regulatory environments, data residency requirements, and the company's financial stability (ability to fund large-scale migrations) introduces significant unknowns that could impact the scope and feasibility of migration projects. Additionally, while vendor geographic diversity is noted, the actual "Vendor Lock-in Risk" is unknown, which could pose a substantial hurdle if critical systems are tightly coupled to specific vendor platforms or contracts.

Compliance

11 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

Posti Group Oyj falls squarely within the NIS2 Directive's scope as a postal and courier services operator in the EU, explicitly listed as an 'Important Entity' under Annex II of NIS2 (Directive 2022/2555/EU). With approximately 13,700 employees and operations across five EU/EEA countries (Finland, Sweden, Estonia, Latvia, Lithuania), Posti far exceeds the medium enterprise threshold (50+ employees, €10M+ turnover). Finland transposed NIS2 into national law via the Cybersecurity Act (Kyberturvallisuuslaki, 1.4.2024). As Finland's national postal operator and critical logistics infrastructure provider, Posti is almost certainly registered with Traficom (Finnish Transport and Communications Agency) as a regulated entity. Non-compliance risk is High because: (1) NIS2 imposes mandatory incident reporting (24-hour initial notification, 72-hour detailed report), (2) security measure requirements are extensive (supply chain security, access controls, encryption, business continuity), (3) management liability provisions apply, and (4) supervisory fines for Important Entities can reach €7M or 1.4% of global annual turnover. The 'Assessment Required' status reflects that while applicability is near-certain, the specific compliance posture and registration status cannot be fully confirmed from public sources alone.

Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.traficom.fi/en/communications/cyber-security/nis2-directive, https://www.finlex.fi/fi/laki/alkup/2024/20240326, https://www.posti.com/corporate/posti-yrityksena

SOC 2 (source) — Assessment Required

Posti Group Oyj operates the OmaPosti digital platform, which processes personal data for millions of Finnish consumers (digital mailbox, parcel tracking, digital letters and invoices). Posti also provides B2B logistics and digital services to corporate customers who may contractually require SOC 2 assurance. While SOC 2 is a US-origin framework (AICPA), it is increasingly demanded by enterprise customers globally, including in Europe, as evidence of security, availability, processing integrity, confidentiality, and privacy controls. The risk is Medium because: (1) Posti's digital services platform handles sensitive consumer data at scale; (2) enterprise B2B customers may require SOC 2 Type II reports; (3) absence of SOC 2 could be a competitive disadvantage in enterprise sales. However, European companies often use ISO 27001 as the equivalent assurance framework, which may substitute for SOC 2 in practice.

Evidence: https://www.posti.fi/en/customer-service/terms-and-statements/data-protection, https://www.posti.com/en/corporate/posti-business

GDPR (source) — Compliant

Posti Group Oyj is headquartered in Finland (EU member state) and processes extensive personal data including customer names, addresses, phone numbers, delivery data, digital mailbox content metadata, and employee data across Finland, Sweden, Estonia, Latvia, and Lithuania. The scale of personal data processing — covering millions of Finnish consumers, business customers, and employees across the Baltic region — creates inherently elevated GDPR exposure. However, Posti demonstrates active compliance measures: a dedicated data protection team (tietosuoja@posti.com), published privacy notices (tietosuojaselosteet), data subject rights mechanisms (access, correction, deletion requests), and explicit references to lawful bases for processing (e.g., postal law for address data). The Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) actively enforces GDPR, and fines can reach €20M or 4% of global annual turnover. Risk is Medium rather than Low because of the breadth of personal data processing and cross-border Baltic operations, but the company shows clear compliance infrastructure.

Evidence: https://www.posti.fi/asiakaspalvelu/ehdot-ja-selosteet/tietosuoja, https://www.posti.fi/asiakaspalvelu/ehdot-ja-selosteet/tietosuoja/tietosuojaselosteet, https://www.posti.fi/asiakaspalvelu/ehdot-ja-selosteet/kayttoehdot, https://www.posti.fi/en/customer-service/terms-and-statements/data-protection

Financials

Three-year financials

Financial Resilience Score: 6/10

Posti Group demonstrates moderate financial resilience underpinned by its dominant Finnish market position, nearly 400-year history, and continued majority state ownership post-IPO. The company has achieved 10 consecutive years of adjusted EBITDA margin improvement (13.6% in 2024), maintains strong operating cash flow (€148.6m in 2024), and has access to €180m in committed credit lines plus a €200m commercial paper program. Net debt to adjusted EBITDA remains conservative at 1.2x. Diversification is improving, with 61% of 2024 revenue now coming from parcels/logistics rather than traditional mail. However, several structural challenges temper this resilience. Revenue has declined for three consecutive years due to the secular decline of letter mail (addressed letters -14% in 2024), weak Nordic consumer demand, and divestments. The 2023 result included €57.4m in goodwill impairments at Swedish subsidiary Aditro Logistics, highlighting execution risk in international expansion. The equity ratio dropped sharply from 41.5% in 2022 to 25.2% in 2024, largely due to a €150m special dividend, reducing balance-sheet buffer. Ongoing regulatory risks include a Finnish Competition Authority investigation that could theoretically result in fines up to 10% of group turnover, plus environmental remediation liabilities of ~€12.4m.

Key strengths: Market leader in Finland across all three segments with nearly 400-year history, 10 consecutive years of adjusted EBITDA margin improvement (13.6% in 2024), Strong operating cash flow of €148.6m in 2024, Conservative net debt/adjusted EBITDA of 1.2x, €180m unused committed credit lines plus €200m commercial paper program, Diversified revenue mix with 61% from parcels/logistics, Continued Finnish state majority ownership post-IPO, Universal postal service obligation provides franchise stability

Risk factors: Structural decline of letter mail (-14% addressed letters in 2024), Three consecutive years of revenue decline, €57.4m goodwill impairment at Swedish Aditro Logistics in 2023, Equity ratio dropped from 41.5% (2022) to 25.2% (2024) after €150m special dividend, Finnish Competition Authority (KKV) investigation into alleged abuse of dominance, €2.4m data-protection fine (Netposti) under appeal, Excess warehouse capacity in Sweden and weak Nordic consumer demand, Intense competition from new entrants in parcels/e-commerce delivery, Labor union exposure with political strikes affecting Q1 2024, €12.4m environmental remediation liability for Southern Postipuisto

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report