ProISP AS
Norway · www.proisp.no · 13 vendors
Resilience scores
- Digital Sovereignty: 8
- Digital Resilience: 5
- Financial Resilience: 7
Technology vendors
- jQuery Foundation — Technology — United States
- Netlify, Inc. — Technology — United States
- WebPros International L.L.C. — Technology — United States
- and 10 more
Services catalogue
4 services in catalogue across 2 categories; runs on 13 sub-vendors.
- DNS
- Pro ISP Hosting
- Domain Registration
Insights
Last updated 2026-08-23 · revision 2
13 direct vendors, 170 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- United States: 8
- Japan: 1
Subvendors by controlling owner country (sample)
- Netherlands: 4
- Poland: 2
- Russia: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ProISP AS demonstrates low-to-medium migration readiness, primarily due to its traditional infrastructure and implicit data residency requirements. The company's core offerings, Web Hosting and Virtual Private Servers (VPS), are based on conventional server infrastructure (SSD storage, MySQL, PHP, root/administrator access for VPS) hosted in specific Norwegian data centers. This architecture is not indicative of a cloud-native, containerized, or microservices approach, which would make a direct migration to modern public cloud environments complex, potentially costly, and require significant re-architecting rather than a simple 'lift and shift'. Another significant challenge is the strong implicit data residency requirement. The explicit mention of services being hosted on 'Norwegian SSD servers' and in 'Norwegian data centers' strongly suggests a need to keep customer data within Norway. This could severely limit the choice of global cloud providers or require intricate architectural solutions to ensure compliance, potentially increasing migration complexity and cost. On the positive side, the use of widely supported open-source technologies like WordPress, MySQL, and PHP means that the application layer is built on platforms that are generally portable, which could facilitate application-level migration once an infrastructure strategy is defined. The presence of multiple vendors (Microsoft, Sectigo, Atlassian, Zendesk, Google) suggests that the company is not entirely locked into a single vendor ecosystem, which could offer some flexibility in choosing new cloud partners, although the 'Vendor Lock-in Risk: Unknown' prevents a definitive assessment. Being a reseller of Microsoft 365 Business indicates some familiarity with cloud-based services, though this pertains to customer offerings rather than ProISP's own core infrastructure. Key missing data points include financial stability (revenue concentration, growth history) and specific regulatory requirements, which are crucial for assessing the company's ability to fund and navigate a significant migration effort. The traditional infrastructure and implicit data residency are the most significant hurdles to achieving high migration readiness.
Compliance
8 in-scope frameworks identified; showing 3.
EU Regulation 2021 — Assessment Required
ProISP AS explicitly references EU Regulation 2021/784 (Terrorist Content Online Regulation) in its Privacy Policy, providing a dedicated contact point (requestblock@group.one) for communications under this regulation. This demonstrates awareness and a compliance posture. The TCO Regulation requires hosting service providers to remove or disable access to terrorist content within one hour of receiving a removal order from a competent authority. Risk is Low-Medium: the company has established a contact point, but as a web hosting provider, it could receive removal orders and must have operational procedures to comply within the one-hour deadline.
Evidence: https://www.proisp.no/om-oss/personvern/
PCI DSS (source) — Partially Compliant
ProISP AS accepts credit/debit card payments from customers but has outsourced payment processing to Adyen N.V., which is PCI DSS certified. The company explicitly states it does not store any card number data in its own systems — only a transaction reference to Adyen's systems. This outsourcing model significantly reduces ProISP's PCI DSS scope. Risk is Low because: (1) the company does not store, process, or transmit cardholder data directly; (2) Adyen N.V. is a major PCI DSS-certified payment processor; (3) the company's liability is limited to ensuring its integration with Adyen is secure. The company may still need to complete a PCI DSS Self-Assessment Questionnaire (SAQ A or SAQ A-EP) depending on its integration method.
Evidence: https://www.proisp.no/om-oss/personvern/
NIS2 (source) — Assessment Required
ProISP AS operates as a digital infrastructure and ISP provider (web hosting, VPS, domain registration, email services) — a sector explicitly listed under NIS2 as 'Digital Infrastructure' (Annex I, Essential Entities) and 'Digital Providers' (Annex II, Important Entities). Norway, as an EEA member, is expected to implement NIS2 through the EEA Agreement process (Norway's NIS2 implementation is in progress as of 2024-2025). The company serves 50,000+ customers and is part of the Group.One group, which operates across multiple European countries (Denmark, Sweden, Netherlands, Norway), suggesting it likely meets or approaches the medium/large enterprise thresholds (50+ employees or €10M+ turnover at group level). Risk is Medium rather than High because: (1) Norway's NIS2 transposition timeline is still being finalised; (2) the exact employee count and turnover of GROUP.ONE NORWAY AS specifically (vs. the wider Group.One group) is not publicly confirmed; (3) classification as Essential vs. Important Entity requires formal regulatory determination. Non-compliance risk includes significant fines (up to €10M or 2% of global turnover for Important Entities; €7M or 1.4% for Essential Entities under Norwegian implementation).
Evidence: https://www.proisp.no/om-oss/databehandleravtale/, https://www.proisp.no/om-oss/personvern/, https://www.proisp.no
Financials
Financial Resilience Score: 7/10
ProISP AS operates in the Norwegian web hosting and domain name market with an established brand of approximately 20 years and a claimed customer base of around 50,000. As part of Group.One, a pan-European hosting consolidator backed by private equity investor Cinven, the company benefits from access to capital, procurement scale, and shared technical platforms across the Nordic region. The subscription-based business model provides recurring, high-margin revenue with typically low churn characteristics of the hosting industry. However, specific financial figures (revenue, EBIT, equity) could not be retrieved in this research session, as the Norwegian company registries (Brønnøysund Regnskapsregisteret) and business databases (Proff.no) were not accessible. The company appears to have been consolidated into GROUP.ONE NORWAY AS based on the website footer, which may reduce standalone financial visibility. Qualitatively, the diversified product ladder from budget shared hosting to Enterprise VPS tiers, combined with Microsoft 365 reselling, supports resilience. Risks include intense price competition in Nordic hosting from players like Domeneshop, One.com, and Loopia; heavy first-year discounting pressuring new customer economics; platform migration execution risk; SMB/consumer customer concentration with price sensitivity; and FX exposure on Microsoft licensing costs resold in NOK. The score reflects strong strategic backing and business model quality, offset by lack of verified financials and competitive pressures.
Key strengths: Ownership by Group.One, backed by private equity investor Cinven, Recurring subscription revenue model with sticky customer base, 20-year established brand with ~50,000 customers, Diversified product portfolio from shared hosting to Enterprise VPS, Access to pan-European scale in procurement and technical platforms
Risk factors: Intense price competition in Nordic hosting market, Heavy first-year discounting pressures new customer economics, Platform migration execution risk mentioned in support pages, Customer concentration in price-sensitive SMB/consumer segment, FX exposure to USD/EUR licensing costs (Microsoft 365) resold in NOK, Reduced standalone financial visibility due to Group.One consolidation
Revenue by geography
- Norway: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.