SagaLabs ApS

Denmark · owned by Independent (Denmark) · sagalabs.dk · 5 vendors

SagaLabs is a Danish cybersecurity company that delivers realistic, scenario-based cybersecurity training, cyber ranges, workshops, and advisory services to businesses and educational institutions. Founded in November 2023 in Aarhus by four founders with backgrounds in the Danish military cyber programme, the company applies a 'Train As You Fight' philosophy to prepare organisations for real-world cyber threats. Their offerings include hands-on incident response simulations, team-based exercises for SOC, IT, and management, and a cloud-based cyber range platform.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 2

5 direct vendors, 127 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SagaLabs ApS exhibits a high level of migration readiness. A primary strength is their core business as a 'cloud-based cyber range platform,' which inherently implies strong internal cloud expertise, a modern architectural approach, and a workforce skilled in cloud infrastructure, automation, and scenario development. Their internal tech stack includes modern cloud-native components like Framer, Cloudflare Pages, and GitHub. The absence of specified data residency requirements is a potential advantage, as it removes a common and complex barrier to cloud migration. However, some challenges and unknowns exist. The 'proprietary SagaLabs Cloud platform' could introduce complexity during migration if it is highly customized and not built on easily portable, standard cloud primitives, potentially leading to internal technical lock-in. Critical data regarding their specific regulatory environment, financial stability (which impacts the ability to fund a migration), and explicit vendor lock-in risk for their 6 services is missing, making a complete assessment of these factors difficult. While vendor geographic diversity is moderate (3 countries), the specific nature of vendor contracts and potential lock-in for these services is 'Unknown.' Despite these unknowns, their fundamental cloud-centric business model and internal technical capabilities position them strongly for future migrations.

Compliance

7 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It is highly relevant for SagaLabs given: (1) the company operates cloud infrastructure hosting customer security environments; (2) it serves public-sector and critical infrastructure clients who frequently require ISO 27001 certification from their IT/security vendors; (3) as a cybersecurity company, the reputational expectation of strong information security practices is particularly high — a cybersecurity firm without ISO 27001 faces credibility risk. Risk is Medium rather than High because ISO 27001 is voluntary (no direct legal penalty for non-certification), and the company is a small startup where the cost/benefit of full certification is still maturing. However, the risk of losing enterprise contracts due to lack of certification is real and growing.

Evidence: https://sagalabs.dk, https://sagalabs.dk/about/company, https://www.iso.org/standard/27001, https://www.ds.dk/da/standarder/it/informationssikkerhed/ds-en-iso-iec-27001

Danish Bookkeeping Act — Assessment Required

The Danish Bookkeeping Act (modernised in 2022, with digital bookkeeping requirements phasing in from 2024-2026) requires Danish companies to maintain digital accounting records and use approved digital bookkeeping systems. As a Danish ApS, SagaLabs is subject to these requirements. Risk is Low because: (1) this is a standard business compliance requirement applicable to all Danish companies; (2) the consequences of non-compliance are primarily administrative; (3) the company is likely using standard accounting software that meets requirements. This is included for completeness as a Danish-specific regulatory obligation.

Evidence: https://www.erhvervsstyrelsen.dk/bogfoeringsloven, https://www.retsinformation.dk/eli/lta/2022/700

NIS2 (source) — Assessment Required

NIS2 (EU Directive 2022/2555, transposed in Denmark via the NIS2 Act effective October 2024) applies to Essential Entities and Important Entities operating in listed sectors. SagaLabs ApS is a cybersecurity training and cyber range provider — it is NOT itself an operator in the NIS2-listed sectors (energy, transport, banking, health, water, digital infrastructure, etc.). However, NIS2 does include 'managed security service providers' (MSSPs) and 'digital providers' as Important Entities under Annex II. SagaLabs provides cybersecurity services (training, incident response advisory, cyber ranges) to critical infrastructure operators, which may bring it within scope as a managed security service provider depending on the nature of its contractual relationships. The size threshold (50+ employees OR €10M+ annual turnover) is the primary limiting factor: SagaLabs was founded in November 2023, had its first full-time employee only in May 2025, and currently appears to be a micro-enterprise well below the 50-employee threshold. This strongly suggests NIS2 does NOT currently apply based on size. Risk level is Low because the size threshold is almost certainly not met for a company of this age and stage, though this should be formally verified as the company grows. The risk would escalate to Medium/High if the company crosses the 50-employee or €10M turnover threshold.

Evidence: https://sagalabs.dk/about/company, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/da/cybertruslen/nis2/, https://www.retsinformation.dk/eli/lta/2024/639

Financials

Three-year financials

Financial Resilience Score: 4/10

SagaLabs ApS is an early-stage Danish cybersecurity training company incorporated in November 2023, with its first full-time employee joining only in May 2025. As a small Danish ApS with abbreviated reporting obligations, no specific revenue, EBIT, or equity figures are publicly retrievable at this time. Financial resilience must therefore be viewed through a startup lens rather than through traditional financial metrics. On the positive side, the company has assembled an unusually strong customer roster for its age, including Norlys, itm8, Statens IT, Erhvervsstyrelsen, Aarhus Kommune, CBS, UCL, Forsvaret, Hjemmeværnet, SektorCERT, TRUESEC, PROSA, and Dansk IT. The founders' background in Denmark's Cyberværnepligt (cyber conscription) program provides strong domain credibility, and the market is supported by favorable macro tailwinds from NIS2, DORA, and rising Nordic cyber threat activity. The company has also won recognition including the Danish National Startup Championship. However, significant risks remain. The entity is essentially seed-stage with only one full-time employee beyond founders as of mid-2025. It faces key-person dependence, lumpy project-based revenue, likely high customer concentration, and limited financial cushion (Danish micro-ApS typically start with the DKK 40,000 minimum share capital). No public information on venture financing is available.

Key strengths: Strong customer references across Danish enterprise, defence, public sector, and academia, Founders' credibility from Danish Cyberværnepligt (cyber conscription) program, Favorable market tailwinds from NIS2, DORA, and Nordic cyber threat landscape, Won Danish National Startup Championship and other startup awards, Four service lines: scenario training, cyber range platform, workshops, and advisory

Risk factors: Very early stage - incorporated Nov 2023, first full-time employee May 2025, Founder-dependence and key-person risk, Project-based revenue creates cash flow lumpiness, Likely high customer concentration given small size and short history, Limited financial cushion; no disclosed external funding, ~100% geographic concentration in Denmark

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report