Schultz

Denmark · owned by J. H. SCHULTZ-FONDEN (Denmark) · schultz.dk · 29 vendors

Schultz creates intelligent digital solutions primarily for the public sector, including municipalities, regions, and government agencies. Their offerings focus on enhancing daily welfare through management systems and document handling. The company also provides courses and webinars related to the use of their solutions.

Resilience scores

Technology vendors

Services catalogue

6 services in catalogue across 1 category; runs on 29 sub-vendors.

Insights

Last updated 2026-09-13 · revision 7

29 direct vendors, 310 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Schultz's migration readiness is moderate, primarily benefiting from its existing adoption of modern cloud infrastructure. The internal tech stack is based on Microsoft Azure and Microsoft Cloud Platform, and key technologies include Cloud-based SaaS and API Integration, indicating a foundation that is not legacy on-premise. Strong revenue growth (+37% YoY) suggests the financial capacity to fund migration initiatives. However, significant challenges impede higher readiness. The regulatory environment is exceptionally complex and stringent, with 'High Risk' assessments for GDPR, NIS2, EU AI Act, Danish Data Protection Act, and Danish Public Sector IT Security Requirements. These regulations, particularly the EU AI Act for high-risk AI systems and the Danish Data Protection Act for CPR numbers, impose strict compliance obligations that must be meticulously addressed during any migration. Furthermore, data residency requirements are very demanding, mandating EU/EEA processing for sensitive citizen data (CPR numbers, health data), which severely limits options for cloud regions or alternative providers and adds considerable complexity and cost to any migration strategy. While there is vendor diversity, the existing reliance on Microsoft Cloud Platform implies a degree of platform lock-in, making a migration to a different major cloud provider a substantial and complex undertaking. The lack of public security certifications (ISO 27001, SOC 2, ISAE 3000/3402) could also complicate due diligence and assurance requirements when engaging new platforms or partners during a migration.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

ISO 27001 certification is highly relevant for Schultz given: (1) the company processes CPR numbers, health card data, and sensitive citizen welfare data for ~70% of Danish municipalities; (2) Schultz operates lovtidende.dk — critical national legal infrastructure; (3) Schultz provides AI-powered tools processing citizen data in employment and social welfare contexts; (4) the 2025 acquisition of Prisme from Fujitsu expands the IT estate and introduces integration security risks; (5) Danish public sector procurement increasingly expects or requires ISO 27001 or equivalent security certifications from IT suppliers. Risk is High because: the absence of ISO 27001 certification for a company of this scale and sensitivity profile represents a significant security governance gap; a cybersecurity incident affecting municipal employment or social welfare systems could have severe consequences for vulnerable citizens and public trust; NIS2 compliance (which likely applies) is substantially easier to demonstrate with ISO 27001 as a foundation; and Danish Datatilsynet and CFCS may scrutinize security measures given the critical nature of Schultz's systems.

Evidence: https://www.schultz.dk/, https://www.schultz.dk/om-schultz/nyheder/schultz-aarsregnskab-markerer-vigtig-transformation/, https://www.iso.org/isoiec-27001-information-security.html, https://www.ds.dk/da/standarder/it/informationssikkerhed/ds-en-iso-iec-27001

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific requirements, including stricter rules on processing CPR numbers (§ 11), special categories of data, and public authority data processing. Schultz processes CPR numbers extensively (health card scanning, MitID authentication in apps, citizen case management) — this is subject to strict Danish rules requiring specific legal authorization. Risk is High because: (1) CPR number processing requires explicit legal basis under Danish law beyond GDPR; (2) Schultz processes CPR numbers for a large proportion of the Danish population through municipal systems; (3) Datatilsynet actively enforces CPR number processing rules and has issued guidance and enforcement actions in this area; (4) the scale of processing (70% of municipalities) means any systemic non-compliance would have national impact.

Evidence: https://www.schultz.dk/privatlivspolitik/, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502, https://www.datatilsynet.dk/english/the-danish-data-protection-act

ISAE 3000 (source) — Assessment Required

ISAE 3000 (general assurance) and ISAE 3402 (assurance on controls at service organizations) are relevant for Schultz as a significant IT service provider to Danish public sector entities. ISAE 3402 reports are commonly used in Denmark as an alternative to SOC2 for demonstrating controls at service organizations. Given that Schultz processes sensitive citizen data on behalf of municipalities (acting as a data processor), municipal clients may require ISAE 3402 Type II reports as part of their own compliance and audit obligations. Risk is Medium because: (1) ISAE 3000/3402 is not legally mandated; (2) Danish public sector clients may contractually require such assurance; (3) the absence of any publicly disclosed assurance report for a company processing data for 70% of Danish municipalities is a notable gap; (4) consequences of non-compliance are primarily contractual/reputational rather than regulatory fines.

Evidence: https://www.schultz.dk/, https://www.schultz.dk/privatlivspolitik/, https://www.iaasb.org/publications/international-standard-assurance-engagements-isae-3000-revised-assurance-engagements-other-audits-or

Financials

Three-year financials

Financial Resilience Score: 7/10

Schultz (J.H. Schultz Information A/S) demonstrates solid financial resilience underpinned by a highly defensible niche position in Danish public-sector software. The company reports approximately 70% market share in municipal employment-case-handling software, which provides strong recurring revenue visibility and high switching costs due to deep integration with Danish municipal IT systems and legislation. Ownership by the Schultz Foundation offers a stable, long-term capital structure without external shareholder dividend pressure, allowing reinvestment in product development and strategic M&A. FY2025 was a transformation year with 37% revenue growth driven primarily by the June 2025 acquisition of the Prisme municipal ERP business from Fujitsu, which added over 40 employees and expanded the company into a second product leg. The year posted a negative net result due to one-off M&A and integration costs, but management guides FY2026 to 8-12% revenue growth and a return to profitability. The public-sector customer base (Danish kommuner, regioner, and styrelser) is highly creditworthy, further supporting resilience. Key risks include heavy concentration in a single country (Denmark) and a single customer type (public sector), competitive pressure from KMD, NNIT, Netcompany, and Systematic, integration execution risk from the Prisme acquisition, and structural risk from potential shifts toward common state-owned platforms via KOMBIT. The lack of international diversification and exposure to Danish municipal budget pressures also constrain the resilience score.

Key strengths: ~70% market share in Danish municipal employment case-handling software, Foundation ownership (Schultz-Fonden) provides long-term stable capital, High switching costs due to deep integration with Danish municipal IT and legislation, Creditworthy public-sector customer base (municipalities, regions, government agencies), Strategic diversification via Prisme acquisition (municipal ERP), Growing AI product traction (Dialogstøtte used by ~1 in 3 Danish municipalities), FY2025 revenue growth of 37% YoY, Management guidance for return to profit in FY2026

Risk factors: 100% revenue concentration in Denmark, Concentration in a single customer type (Danish public sector), Negative FY2025 net result due to acquisition and integration costs, Integration risk from Prisme acquisition (people and tech migration from Fujitsu), Competitive pressure from KMD, NNIT, Netcompany, and Systematic, Structural risk from potential consolidation onto common state platforms (e.g. KOMBIT), Exposure to Danish municipal budget efficiency and cost-savings pressures

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report