Signaturgruppen

Denmark · owned by Independent (Denmark) · www.signaturgruppen.dk · 6 vendors

Signaturgruppen is a Danish company specializing in advanced digital identity and security solutions, including MitID and digital signatures. They provide tailored IT solutions to optimize workflows, simplify administration, and enhance security for both private and public organizations. The company was founded in 2006 and is now part of the French company IN Groupe.

Resilience scores

Disruption prediction

Signaturgruppen has a 93% probability of disruption in the next 6 months.

1 of Signaturgruppen's 6 vendors monitored for disruptions.

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 6 sub-vendors.

Insights

Last updated 2026-09-13 · revision 2

6 direct vendors, 85 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Signaturgruppen's migration readiness is assessed as moderate, with a score of 45. The primary challenges stem from its strong focus on specific national standards and data residency requirements. The internal tech stack's reliance on "Danish Hosted Data Centers" and the offering of a "Hosted IdP" "hosted in Denmark" strongly imply strict data residency requirements within Denmark or the EU. This significantly limits the choice of cloud providers and regions for potential migration. Compliance with NSIS and OCES3, while a strength for resilience, introduces complex regulatory hurdles that would require careful planning and potentially specialized solutions during a migration to a more generalized cloud environment. The presence of "Lokal IdP" (an "on-premise-style" solution) and "Active Directory (AD) Integration" in their tech stack suggests components that may not be inherently cloud-native, potentially requiring significant refactoring or re-platforming during a migration. Opportunities for migration exist, as the company already offers "Hosted IdP" solutions, demonstrating experience in managing external infrastructure. Their deep expertise in Identity and Access Management (IAM) and integrations with systems like Unilogin Broker and FK Organisation could be leveraged to streamline the migration of identity-related services. The geographic diversity of vendor HQs (Denmark, United States) and owner countries (Italy, Denmark, United States, Belgium) could reduce vendor-specific migration complexities compared to a highly concentrated vendor base. However, the lack of data on financial stability (e.g., revenue concentration, growth history) makes it difficult to assess the company's capacity to fund a potentially complex and costly migration initiative. The ambiguity of "Total Vendors: 0" for "Total Services: 7" also leaves some uncertainty regarding potential vendor lock-in, which could complicate migration efforts.

Compliance

8 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Partially Compliant

Signaturgruppen explicitly references four independent annual audit declarations ('revisionserklæringer') for its broker and IdP platform — a strong indicator of ISAE 3000 or ISAE 3402 assurance engagements. ISAE 3402 (Assurance Reports on Controls at a Service Organisation) is the European/international equivalent of SOC 2 and is the standard framework used by Danish IT service providers to demonstrate control effectiveness to clients. The company's quarterly audit cadence (three reports in summer, one in December) exceeds the typical annual cycle, suggesting a robust assurance programme. Medium risk because while the declarations are referenced, their full scope, independence, and public availability have not been confirmed.

Evidence: https://www.signaturgruppen.dk/signaturgruppen-idp, https://www.signaturgruppen.dk/en/terms

ISO 27001 (source) — Assessment Required

ISO 27001 certification is critically important for Signaturgruppen given its role as a certified MitID broker and identity provider for Danish public authorities and private organisations. The Danish government's NemLog-in infrastructure and MitID ecosystem impose stringent security requirements on certified brokers. ISO 27001 is the internationally recognised standard for information security management and is frequently required by government procurement frameworks. The company references NSIS compliance (Danish National Standard for Identity Solutions) and quarterly audit declarations, which overlap with ISO 27001 controls, but no ISO 27001 certificate has been publicly confirmed. High risk because absence of ISO 27001 certification could affect government contract eligibility and client trust in a security-critical sector.

Evidence: https://www.signaturgruppen.dk/signaturgruppen-idp, https://www.signaturgruppen.dk/en/about/about-us

eIDAS — Partially Compliant

Signaturgruppen provides digital signature services including OCES (Public Certificates for Electronic Services) and qualified electronic signatures, which fall directly under eIDAS Regulation (EU) No 910/2014. As a provider of qualified trust services (digital signatures), Signaturgruppen must comply with eIDAS requirements for qualified trust service providers (QTSPs) or operate under a QTSP. The updated eIDAS 2.0 (EU Digital Identity Wallet framework) introduces new requirements relevant to MitID broker services. Medium risk because the company's MitID broker role is tied to Denmark's eIDAS-notified eID scheme, but full QTSP status and eIDAS 2.0 readiness have not been publicly confirmed.

Evidence: https://www.signaturgruppen.dk/signeringsportal, https://www.signaturgruppen.dk/forside, https://www.signaturgruppen.dk/signaturgruppen-idp

Financials

Three-year financials

Financial Resilience Score: 7/10

Signaturgruppen is a strategically well-positioned niche Danish cybersecurity and digital identity firm that benefits significantly from being a subsidiary of IN Groupe, a French state-linked identity and security group with approximately €300m+ in revenue. This parent backing materially reduces standalone financial risk and provides access to capital and cross-border credibility. The company's certified MitID broker status creates a strong regulatory moat in Denmark's national eID scheme, and its recurring revenue model with sticky integrations into customer stacks provides revenue stability. The business benefits from favorable regulatory tailwinds including NIS2, eIDAS 2.0, NSIS compliance, and the OCES to qualified signing transition, all of which drive demand through 2027. Its public sector customer base (municipalities, VUCs, state agencies) implies low counterparty credit risk. However, the company faces meaningful concentration risk with essentially 100% of revenue in Denmark and heavy dependence on the MitID ecosystem, meaning regulatory or scheme changes from Digitaliseringsstyrelsen could materially impact the business. Competitive pressure from other certified brokers (Nets/Nexi, Criipto, Signicat) and the small absolute size of the Danish A/S entity mean its shock-absorption capacity depends on parent support. Post-acquisition integration and rebranding also introduce talent retention and roadmap alignment risks. Actual financial figures could not be verified from CVR filings in this session.

Key strengths: Backed by IN Groupe (France), a state-linked identity/security group with ~€300m+ revenue, Certified MitID broker status provides strong regulatory moat, Sticky recurring revenue model with high switching costs, Regulatory tailwinds from NIS2, eIDAS 2.0, NSIS compliance, and OCES-to-qualified signing transition, Public sector customer base implies low counterparty credit risk, Founded 2006 with long track record in Danish digital identity

Risk factors: High geographic concentration - essentially 100% Denmark, Heavy dependence on MitID ecosystem and Danish regulatory schemes, Competitive pressure from Nets/Nexi, Criipto, and Signicat, Small absolute size - shock absorption depends on parent, Post-acquisition integration and rebranding risks (talent retention, roadmap alignment)

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report