SAC-IT A/S
Denmark · owned by EPICO GROUP ApS (Denmark) · www.sac-it.dk · 31 vendors
SAC-IT A/S provides stable, secure, and efficient IT operations for both private and public companies. Their services encompass IT consulting, planning, implementation, installation, operation, monitoring, and support for servers, PCs, printers, and cloud solutions.
Resilience scores
- Digital Sovereignty: 32
- Digital Resilience: 5
- Financial Resilience: 6
Disruption prediction
SAC-IT A/S has an estimated 27% probability of disruption in the next 6 months.
13 of SAC-IT A/S's 31 vendors monitored for disruptions.
Technology vendors
- Broadcom Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Netlify, Inc. — Technology — United States
- and 30 more
Services catalogue
2 services in catalogue across 2 categories; runs on 31 sub-vendors.
- DNS Hosting
- Personal Data Processing
Insights
Last updated 2026-09-13 · revision 19
31 direct vendors, 318 subvendors
Direct vendors by controlling owner country (sample)
- China: 1
- Poland: 1
- United States: 19
Subvendors by controlling owner country (sample)
- Australia: 4
- Czech Republic: 1
- India: 3
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
SAC-IT A/S demonstrates medium migration readiness. Its internal tech stack is modern and heavily cloud-oriented, utilizing Microsoft Azure, Microsoft 365, and VMware Cloud Foundation. The company also lists AWS and Google Cloud as key technologies and offers various cloud solutions (Private, Hybrid, Public), indicating multi-cloud familiarity and the technical capability to migrate between or integrate diverse cloud environments. The presence of an AI Automation Platform further suggests advanced operational capabilities that can streamline migration processes. However, significant challenges exist. The primary hurdles stem from the complex regulatory environment and potential vendor lock-in. The high-risk status for NIS2 (EU and Danish implementations) means any migration must meticulously adhere to stringent cybersecurity, supply chain security, and incident reporting requirements, adding significant complexity and cost. Similarly, DORA (if applicable to their customer base) will impose strict third-party risk management and contractual obligations. Data residency requirements under GDPR and the Danish Bookkeeping Act necessitate careful planning to ensure data remains within the EEA or is transferred with appropriate safeguards. While SAC-IT's multi-cloud offerings suggest flexibility, its internal reliance on the Microsoft ecosystem (Azure, M365, Intune, SharePoint) could lead to some vendor lock-in, potentially complicating migrations away from or between Microsoft services. The absence of public ISO 27001, SOC 2, or ISAE 3000 certifications may also require additional effort to demonstrate control effectiveness and assurance during a migration project to customers and auditors.
Compliance
9 in-scope frameworks identified; showing 3.
ISAE 3000 (source) — Assessment Required
ISAE 3000 is an international assurance standard used for non-financial assurance engagements, often applied in the context of IT service providers issuing assurance reports to clients (e.g., ISAE 3402 for service organization controls, analogous to SOC 1). As a cloud, managed services, and datacenter provider, SAC-IT may be expected by certain clients — particularly those in regulated industries (financial services, public sector) — to provide ISAE 3402 or ISAE 3000 assurance reports. Risk is Low because: (1) ISAE 3000/3402 is not legally mandated; (2) it is primarily relevant for financial sector clients under DORA or audit requirements; (3) no evidence of such a report has been found; (4) many Danish SME IT providers do not issue ISAE reports unless specifically required by enterprise clients.
Evidence: https://www.sac-it.dk/48/compliance, https://www.sac-it.dk/42/managed-services
ISO 27001 (source) — Assessment Required
ISO 27001 is the internationally recognized standard for Information Security Management Systems (ISMS). SAC-IT A/S explicitly offers ISO 27001/2 consulting and implementation services to clients, and their compliance page lists it as a core framework. However, no public ISO 27001 certification for SAC-IT's own operations has been found. For an IT security and managed services provider, the absence of ISO 27001 certification for their own organization represents a credibility and competitive risk — clients seeking a certified IT partner may prefer providers with their own certification. Risk is Medium because: (1) the company clearly has deep ISO 27001 expertise (they sell it as a service); (2) it is plausible they are pursuing or have obtained certification without public disclosure; (3) ISO 27001 is not legally mandated in Denmark but is a strong market expectation for IT security providers.
Evidence: https://www.sac-it.dk/48/compliance, https://www.sac-it.dk/39/it-sikkerhed, https://www.sac-it.dk/33/om-sac-it
NIS2 (source) — Assessment Required
SAC-IT A/S operates in the ICT/digital services sector in Denmark (EU), providing Managed Services, Cloud hosting, IT Security (Security-as-a-Service), Backup-as-a-Service, and datacenter services. Under NIS2 Directive (EU 2022/2555), 'ICT service management' (B2B) is listed as an Essential Entity sector, and 'digital providers' (including managed service providers and cloud computing service providers) are listed as Important Entities. SAC-IT's service portfolio — particularly Managed Services, Cloud, and Security-as-a-Service — strongly aligns with these categories. The risk level is Medium because: (1) the sector match is strong but the precise NIS2 classification (Essential vs. Important Entity) depends on Danish national implementation specifics and SAC-IT's exact revenue/employee count; (2) SAC-IT itself offers NIS2 compliance consulting to clients, indicating awareness of the regulation; (3) Denmark transposed NIS2 via the 'Lov om sikkerhed i net- og informationssystemer' (NIS2-loven), effective October 2024; (4) non-compliance penalties can reach €10M or 2% of global annual turnover for Important Entities. Size threshold (50+ employees or €10M+ turnover) is unconfirmed from public sources, which prevents a definitive High confidence assessment.
Evidence: https://www.sac-it.dk/48/compliance, https://www.sac-it.dk/39/it-sikkerhed, https://www.sac-it.dk/33/om-sac-it
Financials
Three-year financials
- 2025: gross profit DKK 24.5M, EBIT DKK -1.54M, equity DKK 3.18M
- 2024: gross profit DKK 25.4M, EBIT DKK -1.68M, equity DKK 2.80M
- 2023: gross profit DKK 22.7M, EBIT DKK 1.13M, equity DKK 6.18M
Financial Resilience Score: 6/10
SAC-IT A/S appears to operate a resilient business model centered on recurring-revenue managed services, cloud, and IT security offerings. These service lines typically generate predictable subscription-based cash flows and healthy gross margins, providing structural stability. The company is strategically positioned to benefit from rising regulatory demand in Denmark (NIS2, DORA, GDPR), which drives sustained need for compliance and security services. Established mid-market customer references such as BabyDan and Sv. Michelsen Chokolade suggest a stable B2B account base. However, without access to actual financial filings from CVR/virk.dk, a definitive resilience score cannot be assigned. Danish MSPs of this profile typically operate in the DKK 30-150M revenue range with limited buffers against churn of large accounts. The company faces meaningful risks from talent dependency in a tight Danish IT labor market, vendor concentration on Microsoft and VMware, cyber-liability exposure inherent to security/backup providers, and consolidation pressure from larger players like itm8, Fellowmind, and Globeteam. The midrange score reflects a qualitatively sound business model tempered by small-company scale risk and undisclosed financials.
Key strengths: Recurring-revenue business model via Managed Services, Cloud, and subscription offerings, Strategic positioning around IT security and compliance (NIS2, DORA, GDPR tailwinds), Established mid-market Danish customer references (BabyDan, Sv. Michelsen Chokolade), Vendor alignment with dominant enterprise stacks (Microsoft 365, Azure, VMware VCF), Active portfolio expansion into AI platform and GRC tooling
Risk factors: Small-company scale risk with limited buffers against large account churn, Talent dependency on certified engineers in a tight Danish IT labor market, Vendor concentration risk on Microsoft and VMware licensing/margin changes, Cyber-liability exposure as a security and backup provider, Consolidation pressure from larger Danish MSPs (itm8, Fellowmind, Globeteam)
Revenue by geography
- Denmark: 100%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.