Opoura A/S
Denmark · owned by Scorpio HoldCo A/S (Denmark) · scada-international.com · 22 vendors
Opoura A/S (formerly SCADA International) is a Danish company specialising in energy management software, power plant control, hardware engineering, and digital services for the renewable energy sector. The company provides SCADA software, power plant controllers, and energy trading platforms for wind, solar PV, BESS, and hybrid energy parks. Headquartered in Silkeborg, Denmark, Opoura serves customers across Europe and North America, supporting the energy transition through intelligent data acquisition, processing, and asset control.
Resilience scores
- Digital Sovereignty: 27
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Anthropic, PBC — Technology — United States
- Netlify, Inc. — Technology — United States
- Opoura A/S — Energy & Utilities — Denmark
- and 19 more
Insights
Last updated 2026-09-13 · revision 11
22 direct vendors, 308 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 2
- Australia: 2
- United States: 12
Subvendors by controlling owner country (sample)
- New Zealand: 1
- Czech Republic: 2
- Japan: 3
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Opoura A/S exhibits medium migration readiness, primarily driven by significant regulatory and data residency complexities. The company operates in a highly regulated sector (energy & utilities) with numerous 'Assessment Required' and 'High risk' obligations (NIS2, IEC 62443, EU Network Code on Cybersecurity, GDPR). These regulations, particularly those pertaining to critical infrastructure and data protection, impose stringent requirements that will necessitate extensive planning, validation, and potential re-architecture during any migration. The multi-jurisdictional data residency landscape across 9 countries, with specific requirements for Ukraine, the US, and national energy sectors (Germany, Poland, Denmark), further complicates data architecture and migration strategy. While Opoura has existing 'Cloud-based SCADA hosting options' and utilizes Machine Learning/AI, indicating some modern tech adoption and cloud experience, the presence of 'PLC-based control' and traditional web CMS (WordPress/Elementor) suggests a mixed tech stack that may require varied migration approaches. The 'Unknown' vendor lock-in risk for 24 services also presents a potential challenge, as deep integrations could complicate disentanglement. On the positive side, Opoura's strong financial stability, evidenced by Børsen Gazelle awards and private equity backing, provides the necessary capital and strategic support to fund complex migration initiatives. The ISO 27001:2022 certification also offers a robust security and governance framework to guide a secure migration. However, the substantial regulatory and data residency hurdles place Opoura in the lower-to-mid range of migration readiness.
Compliance
9 in-scope frameworks identified; showing 3.
NERC CIP — Assessment Required
Opoura explicitly references NERC CIP on their OT Solutions page, listing a case study where they assisted a 'large international utility company' in becoming NERC CIP compliant for operating plants in North America, including gap analysis, procedure development, and staff training. Opoura also lists 'Nerc-CIP' as a compliance standard in their compliance service offering. This indicates active engagement with NERC CIP requirements for US-based customers. Risk is Medium because: (1) NERC CIP applies to Opoura's US customers (bulk electric system operators) rather than directly to Opoura as a technology vendor; (2) however, as a technology supplier to NERC CIP-regulated entities, Opoura's products and services must meet NERC CIP supply chain security requirements (CIP-013); (3) Opoura's US operations (confirmed in Privacy Policy) may involve direct engagement with NERC CIP-regulated facilities; (4) non-compliance by Opoura's products could expose US customers to NERC CIP violations.
Evidence: https://opoura.com/operational-technology-solutions/, https://opoura.com/about-us/
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (CRA) was published in the Official Journal on 20 November 2024 and entered into force on 10 December 2024, with most obligations applying from 11 December 2027. It imposes mandatory cybersecurity requirements on manufacturers and suppliers of 'products with digital elements' (PDEs) placed on the EU market. Opoura's SCADA software (OneView®), power plant controllers (OneView® Energy Control Unit), and energy trading software are all PDEs under the CRA. Risk is High because: (1) Opoura is a manufacturer/supplier of software and hardware products with digital elements sold to EU customers; (2) the CRA introduces conformity assessment requirements, CE marking obligations, and vulnerability disclosure requirements; (3) critical products (Class I/II) face stricter requirements — SCADA and industrial control systems for energy infrastructure may be classified as Class II (important products); (4) penalties reach €15M or 2.5% of global annual turnover; (5) the 2027 deadline requires immediate preparation given the complexity of conformity assessment.
Evidence: https://opoura.com/scada-software/, https://opoura.com/power-plant-control/, https://opoura.com/operational-technology-solutions/, https://opoura.com/about-us/
IEC 62443 — Assessment Required
IEC 62443 is the primary international cybersecurity standard for Industrial Automation and Control Systems (IACS), directly applicable to SCADA systems, power plant controllers, and OT environments — the core of Opoura's product and service portfolio. Opoura explicitly lists IEC 62443 as a compliance standard in their OT Solutions page ('Security Standards: NIS2, EC62443, ISO2700X, Nerc-CIP'). As a SCADA software and OT solutions provider to critical energy infrastructure, Opoura's customers (utilities, TSOs, IPPs) increasingly require IEC 62443 compliance from their technology suppliers. Risk is High because: (1) IEC 62443 is becoming a de facto requirement for energy sector OT suppliers in the EU, reinforced by NIS2 supply chain security obligations; (2) the EU Cyber Resilience Act (CRA), entering into force in 2024-2027, will mandate cybersecurity requirements for products with digital elements, directly impacting Opoura's SCADA and control products; (3) non-compliance creates commercial risk with enterprise customers and regulatory risk under NIS2 supply chain provisions.
Evidence: https://opoura.com/operational-technology-solutions/, https://opoura.com/about-us/, https://opoura.com/wp-content/uploads/2025/04/DK017260-3-Opoura-AS-ISO-27001-2022-ENG-2025-v3.pdf
Financials
Three-year financials
- 2025: gross profit DKK 108B, EBIT DKK 10.3B, equity DKK 89.2B
- 2024: gross profit DKK 119B, EBIT DKK 23.4B, equity DKK 84.8B
- 2023: gross profit DKK 89.1B, EBIT DKK 38.4B, equity DKK 55.2B
Financial Resilience Score: 7/10
Opoura A/S (formerly SCADA International A/S) demonstrates strong qualitative financial resilience despite the absence of retrievable line-item DKK figures in this session. The company has earned Børsen Gazelle awards in both 2024 and 2025, which by definition requires at least a doubling of revenue over a rolling four-year period with consecutive profitable årsrapporter. This provides externally verified evidence of sustained top-line growth combined with continuous profitability, a rare combination for a mid-sized private energy-tech firm. The business model blends recurring software revenue (OneView SCADA platform, PPC support, OT/cyber managed services) with project-based hardware and engineering, providing a stabilising base of multi-year contracts. ISO 27001, 9001, 14001 and 45001 certifications position the company well for NIS2-driven demand and large utility procurement. The independent, vendor-agnostic positioning is structurally advantageous as IPPs build hybrid wind/solar/BESS portfolios. Risks that temper the score include customer concentration among a handful of large named accounts, working-capital swings from project-based hardware delivery, FX exposure (EUR/USD/GBP revenue vs. DKK cost base), and execution risk associated with the late-2024 rebrand from SCADA International to Opoura. As a private A/S there is no public credit rating, and leverage/interest cover can only be assessed via the årsrapport.
Key strengths: Two consecutive Børsen Gazelle awards (2024, 2025) evidencing >100% four-year revenue growth with sustained profitability, Recurring software and managed-services revenue base (SCADA, PPC, OT/cyber), ISO 27001:2022, 9001:2015, 14001:2015, 45001:2018 certifications, Independent, hardware-agnostic positioning across wind, solar, BESS, hybrid and PtX, Diversified service ladder from software through hardware, engineering and on-site O&M, Structural tailwinds from EU energy transition and NIS2 regulation, International footprint across 45+ countries with offices in DK, DE, PL, UK, US, ES
Risk factors: Customer concentration among a few large named accounts (Siemens Gamesa, DTE Energy, Deutsche Windtechnik, Goldbeck Solar, World Kinect), Working-capital swings from project-based hardware/WIP business, FX exposure — EUR/USD/GBP revenue against DKK cost base, Execution and marketing cost risk from the 2024 rebrand to Opoura, Talent scarcity for OT/SCADA engineers across Europe, No public credit rating; leverage visibility limited to annual filings, No public segment reporting — limited transparency on product/geography revenue mix
Revenue by geography
- Iberia: 0%
- Poland: 0%
- Germany: 0%
- North America: 0%
- United Kingdom: 0%
- Nordics (DK/SE): 0%
Revenue by product/service
- On-site services: 0%
- Hardware & engineering: 0%
- Energy trading software: 0%
- Power engineering studies: 0%
- OT & cybersecurity services: 0%
- Power plant controllers (PPC): 0%
- SCADA software (OneView platform): 0%
Workforce by country
- Spain: 0
- Poland: 0
- Denmark: 0
- Germany: 0
- United States: 0
- United Kingdom: 0
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.