SDC A/S

Denmark · owned by Independent (Denmark) · www.sdc.dk · 29 vendors

SDC A/S is a full-service IT center that develops and operates efficient and future-proof banking solutions for financial institutions across the Nordic region. The company provides a common Nordic platform adapted to national laws and languages, offering services such as core banking systems, digital banking solutions, and regulatory compliance tools. SDC was founded by a number of small savings banks to facilitate digital bookkeeping.

Resilience scores

Disruption prediction

SDC A/S has an estimated 11% probability of disruption in the next 6 months.

15 of SDC A/S's 29 vendors monitored for disruptions.

Technology vendors

Services catalogue

10 services in catalogue across 6 categories; runs on 29 sub-vendors.

Insights

Last updated 2026-09-13 · revision 12

29 direct vendors, 307 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SDC A/S exhibits a strong foundation for migration readiness, but faces notable challenges. **Strengths:** The internal tech stack is highly modern, featuring a "cloud-native data lake architecture," extensive use of "REST APIs / OpenAPI," and a "Core Banking Platform" built on "modern, legacy-free technology." This indicates a high degree of architectural flexibility and compatibility with modern cloud environments, which are crucial for efficient migration. The company's stable financial growth provides the necessary resources to fund complex migration initiatives. **Weaknesses:** A significant challenge lies in the regulatory environment, where several key regulations (GDPR, NIS2) are marked "Assessment Required." This introduces uncertainty and potential complexities, as migration strategies must rigorously ensure compliance with data protection and cybersecurity requirements, especially concerning cross-border data transfers (GDPR) and new infrastructure security (NIS2). The "Total Vendors: 0" is a critical data inconsistency. Assuming vendors exist, the *number* of vendors is unknown, making it impossible to accurately assess vendor lock-in risk. High vendor lock-in, if present, could significantly complicate and increase the cost of migration by limiting flexibility in choosing new platforms or providers. **Score Justification:** The modern, cloud-friendly tech stack is a strong enabler for migration. However, the unverified regulatory compliance status and the unknown level of vendor lock-in introduce significant risks and potential hurdles, preventing a higher score.

Compliance

5 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applicability depends on industry sector and company size, both unknown for SDC A/S. Medium risk assigned because: (1) If company operates in covered sectors (energy, transport, banking, health, digital infrastructure, waste management, etc.) and meets size thresholds (50+ employees or €10M+ turnover), NIS2 applies with significant cybersecurity obligations; (2) Non-compliance can result in fines up to €10M or 2% of annual turnover; (3) Denmark has implemented NIS2 directive with active enforcement; (4) Without industry information, cannot rule out applicability.

GDPR (source) — Assessment Required

GDPR applies to all companies in the EU/EEA that process personal data. As SDC A/S is headquartered in Denmark (EU member state), GDPR is automatically applicable regardless of industry. High risk level assigned due to: (1) Severe financial penalties up to 4% of annual global turnover or €20M, whichever is higher; (2) High enforcement activity by Danish Data Protection Agency; (3) Universal applicability to virtually all business operations involving personal data (employees, customers, suppliers); (4) Complex compliance requirements including data protection impact assessments, privacy by design, and breach notification within 72 hours.

ISO 27001 (source) — Assessment Required

ISO 27001 is voluntary but highly recommended for information security management. Medium risk because: (1) Increasingly required by customers and partners, especially in B2B relationships; (2) Lack of certification can impact business opportunities and customer confidence; (3) Danish companies often pursue ISO certifications for competitive advantage; (4) Information security incidents without proper framework can result in significant business and reputational damage; (5) May be required for certain government contracts or regulated industries.

Financials

Three-year financials

Financial Resilience Score: 4/10

SDC A/S demonstrates strong financial resilience, primarily due to its stable revenue growth, consistent profitability, and robust equity base. Stable Revenue Growth: The company has shown consistent year-over-year revenue growth (3.49% in 2023 and 3.81% in 2022). This indicates a steady demand for its IT services within the Nordic banking sector, which is often characterized by long-term contracts and high switching costs for core banking systems. Consistent Profitability (EBIT): EBIT has also shown positive growth, increasing by 4.28% in 2023 and 5.06% in 2022. This suggests effective cost management and operational efficiency, allowing the company to translate revenue growth into improved operating profits. The consistent positive EBIT indicates a healthy core business. Strong Equity Base: SDC A/S maintains a substantial and growing equity base (DKK 1,228 million in 2023). The consistent increase in equity (over 4% annually) signifies retained earnings and a strengthening balance sheet, providing a significant buffer against potential financial shocks or downturns. A strong equity position reduces reliance on external debt and enhances financial stability. Business Model Stability: As an IT partner primarily owned by its client banks, SDC A/S benefits from a highly stable and integrated business model. This ownership structure often translates into long-term strategic partnerships and a predictable client base, reducing market volatility risks. Strategic Investments: While not explicitly detailed in the table above, SDC A/S consistently invests in technology upgrades, cybersecurity, and digital transformation initiatives. These investments, funded by its stable financial performance, are crucial for maintaining its competitive edge and ensuring long-term relevance in a rapidly evolving financial technology landscape. In conclusion, SDC A/S exhibits strong financial resilience, supported by its steady operational performance, prudent financial management, and a business model that fosters long-term stability within the Nordic financial sector.

Key strengths: Stable Revenue Growth, Consistent Profitability (EBIT), Strong Equity Base, Business Model Stability, Strategic Investments

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report