SEPO

Denmark · owned by AX VI itm8 Holding III ApS (Denmark) · sepo.dk · 15 vendors

SEPO is a Danish-developed secure email solution that encrypts and decrypts emails using OCES certificates to protect sensitive data. It offers top-class security and compliance, including ISAE 3000 type II, ISAE 3402 type II, and ISO 27001 certifications, with all data stored in Denmark. The solution is flexible, scalable, and compatible with various systems, serving both public and private companies in Denmark.

Resilience scores

Disruption prediction

SEPO has an estimated 13% probability of disruption in the next 6 months.

7 of SEPO's 15 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 3 categories; runs on 15 sub-vendors.

Insights

Last updated 2026-09-13 · revision 1

15 direct vendors, 232 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 3/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

SEPO's migration readiness is low, primarily driven by significant architectural and regulatory constraints. The internal tech stack includes legacy components such as 'Oracle Database' and extensive 'On-premise Hosting,' which are typically complex and costly to migrate to modern cloud environments. A major impediment is the strict 'Data Sovereignty (Denmark-only storage)' requirement for its 'SEPO Hosted Email Encryption (SaaS)' and general operations, severely limiting public cloud options and necessitating specialized, potentially more expensive, regional deployments to maintain compliance. The core 'OCES Certificate Infrastructure (PKI)' is a specialized technology that may require substantial re-engineering or specific vendor solutions during migration. While SEPO holds strong certifications (ISAE 3000 Type II, ISAE 3402 Type II, ISO 27001), maintaining these during a migration adds a layer of complexity and validation. The absence of information on containerization or microservices suggests a more monolithic architecture, which is harder to migrate. The presence of 'Hybrid Cloud Infrastructure' indicates some existing cloud adoption, offering a slight advantage. However, the lack of financial stability data and unknown vendor lock-in risk are significant gaps in assessing the company's ability to fund and execute a complex migration. The total number of vendors is not specified, so vendor lock-in risk cannot be fully assessed.

Compliance

5 in-scope frameworks identified; showing 3.

GDPR (source) — Assessment Required

GDPR applies to all EU-based companies processing personal data. As a Danish IT services company handling employee, customer, and supplier data, GDPR compliance is mandatory. Non-compliance can result in fines up to 4% of annual turnover or €20 million. Given the company's size and IT services nature, the likelihood of processing significant personal data is high, making this a critical compliance requirement.

Evidence: https://itm8.dk/om-itm8/politikker/privatlivspolitik

NIS2 (source) — Assessment Required

NIS2 applies to Important Entities including digital service providers. As an IT services company providing cybersecurity, cloud services, and managed IT services in Denmark, the company likely qualifies as a digital service provider under NIS2. The company appears to exceed the 50+ employee threshold based on their scale (1700+ employees mentioned). Non-compliance can result in significant fines and operational restrictions.

Evidence: https://itm8.dk/cyber-security/nis2

ISO 27001 (source) — Assessment Required

ISO 27001 is critical for cybersecurity service providers and IT companies handling sensitive client data. Given the company's cybersecurity services, managed solutions, and enterprise client base, ISO 27001 certification is important for credibility and client requirements. Many enterprise clients require their IT service providers to have ISO 27001 certification.

Evidence: https://itm8.dk/om-itm8/certificeringer

Financials

Three-year financials

Financial Resilience Score: 6/10

SEPO as a standalone entity has been fully absorbed into itm8, a large Danish IT services and cybersecurity group with 1,700+ employees and a multi-city presence across Denmark and Sweden. The combined entity benefits from strong market tailwinds driven by NIS2 directive compliance requirements, rising ransomware threats, and broad digital transformation demand across Nordic public and private sectors. The breadth of the itm8 service portfolio — spanning cybersecurity, ERP, cloud, AI, managed services, and hardware — reduces single-service revenue concentration risk and supports recurring revenue streams. The Top-5 Microsoft Solutions Partner status in Denmark, including a rare European-level Support Services Designation, signals deep vendor relationships and a structurally advantaged position in Microsoft licensing and managed services revenue. Geographic diversification across seven Danish offices and a Swedish presence in Malmö further reduces regional concentration risk. However, meaningful financial analysis is severely constrained by the private nature of the entity and the inaccessibility of CVR registry filings during this research session. No revenue, EBIT, or equity figures could be verified from official sources. The score reflects the qualitative strength of the underlying business model and market position, tempered by significant opacity risk and the inability to confirm financial health through audited data. Additional risks include integration execution challenges from rapid M&A-driven growth, competitive pressure from Atea, Bechtle, and KMD, potential revenue volatility once the initial NIS2 compliance wave subsides, and persistent talent retention challenges in the tight Nordic IT labor market.

Key strengths: 1,700+ employee scale providing delivery capacity advantages over smaller Danish IT firms, Top-5 Microsoft Solutions Partner status in Denmark with rare European-level Support Services Designation, Broad multi-service portfolio across cybersecurity, ERP, cloud, AI, managed services, and hardware, Strong NIS2 and Nordic digital transformation market tailwinds, Multi-city Danish presence (7 offices) plus Sweden reducing regional concentration risk, M&A-driven consolidation strategy consistent with Nordic IT managed services sector trends

Risk factors: Private company opacity — no public financial disclosures beyond statutory CVR filings, CVR registry and all major Danish financial databases were inaccessible during research — financials unverifiable, Integration execution risk from rapid acquisition-led growth absorbing entities such as SEPO, High competitive pressure from Atea, Bechtle, and KMD in Danish IT services and cybersecurity, NIS2 compliance-driven demand may create revenue volatility once initial compliance wave subsides, Tight Nordic IT labor market creates persistent key-person and talent retention risk

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report