Siscon A/S

Denmark · owned by BÆRENTZEN ApS (Denmark) · siscon.dk · 17 vendors

SISCON ApS develops and delivers the ControlManager™ platform, a scalable GRC (Governance, Risk, and Compliance) platform. This platform assists organizations in managing compliance with various standards and regulations, including NIS2, GDPR, and DORA. It provides structured compliance work, automates tasks, and offers insights into adherence levels.

Resilience scores

Disruption prediction

Siscon A/S has an estimated 11% probability of disruption in the next 6 months.

9 of Siscon A/S's 17 vendors monitored for disruptions.

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 17 sub-vendors.

Insights

Last updated 2026-09-13 · revision 24

17 direct vendors, 249 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Siscon A/S demonstrates medium migration readiness. A key strength is that its flagship ControlManager™ platform is a SaaS offering, indicating existing cloud adoption or experience with modern software delivery models. The internal tech stack, comprising common platforms like WordPress and HubSpot, generally offers established migration paths, reducing complexity compared to highly customized legacy systems. However, significant challenges exist. Strict GDPR data residency requirements, reinforced by their client base (Danish public sector, financial institutions), mandate data storage within the EU/EEA, severely limiting cloud provider and region choices and potentially increasing migration costs. Furthermore, Siscon operates under a high regulatory burden, with GDPR compliance and 'Assessment Required' statuses for NIS2, DORA, SOC2, and ISO 27001. Any migration must meticulously ensure continued compliance with these frameworks, adding substantial planning, auditing, and validation overhead. The absence of detailed financial data makes it impossible to assess Siscon's capacity to fund a significant migration project. Lastly, the 'Vendor Lock-in Risk: Unknown' status, coupled with the contradictory 'Total Vendors: 0' data, creates uncertainty regarding potential vendor dependencies that could complicate migration efforts.

Compliance

6 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 (Revised) is the international standard for assurance engagements other than audits or reviews of historical financial information, issued by the IAASB. ISAE 3402 specifically covers assurance reports on controls at a service organisation (the EU/international equivalent of SOC 2). As a Danish SaaS provider processing customer data and compliance information, Siscon may be expected by its customers (particularly financial institutions like DLR Kredit and Velliv, which are subject to financial regulatory oversight) to provide an ISAE 3402 Type II report demonstrating the effectiveness of its internal controls. Risk is Medium because: (1) financial sector customers (DLR Kredit, Velliv Foreningen) are subject to Danish FSA (Finanstilsynet) oversight and DORA requirements, which may cascade vendor assurance requirements to Siscon; (2) no ISAE 3000/3402 report is publicly available; (3) the absence of such a report may limit Siscon's ability to serve regulated financial sector customers.

Evidence: https://siscon.dk/controlmanager/, https://siscon.dk/vilkaar-og-betingelser/, https://siscon.dk/privatlivspolitik/

ISO 27001 (source) — Assessment Required

ISO 27001 is the international standard for Information Security Management Systems (ISMS). It is highly relevant to Siscon for two reasons: (1) Siscon provides a GRC platform (ControlManager™) that explicitly supports ISO 27001 compliance for its customers — the company's own reference case with Punktum.dk describes Siscon acting as 'internal auditor' for ISO 27001 compliance; (2) as a SaaS provider processing sensitive customer compliance and risk data, Siscon itself should ideally hold ISO 27001 certification to demonstrate its own security posture to customers. Risk is Medium because: the absence of ISO 27001 certification for a company that sells ISO 27001 compliance tools creates a credibility gap and potential commercial risk; however, ISO 27001 is voluntary and not legally mandated. The company's privacy policy references internal security procedures and policies, but no certification is publicly disclosed. Enterprise customers may require ISO 27001 certification as a vendor qualification criterion.

Evidence: https://siscon.dk/controlmanager/, https://siscon.dk, https://siscon.dk/privatlivspolitik/

GDPR (source) — Partially Compliant

Siscon A/S is headquartered in Denmark (EU), making GDPR universally applicable. The company processes personal data of customers, prospects, event attendees, newsletter subscribers, and employees. A published privacy policy (Privatlivspolitik) is in place and references GDPR legal bases (Art. 6(1)(b) and (f)), data subject rights, and the Danish supervisory authority (Datatilsynet). However, the privacy policy was last updated April 2024 and does not publicly disclose a named Data Protection Officer (DPO), a Record of Processing Activities (RoPA), or evidence of a formal DPIA process. As a data processor for customers (via ControlManager™), Siscon also bears processor obligations. Risk is Medium rather than High because the company is a GRC/compliance software vendor with demonstrated awareness of GDPR obligations, reducing the likelihood of systemic non-compliance, but the absence of publicly verifiable DPO appointment and processor-side documentation introduces residual risk.

Evidence: https://siscon.dk/privatlivspolitik/, https://siscon.dk/vilkaar-og-betingelser/, https://siscon.dk/controlmanager/, https://siscon.dk

Financials

Three-year financials

Financial Resilience Score: 6/10

Siscon A/S benefits from a strong regulatory tailwind driven by rising EU cybersecurity and compliance regulation (NIS2, DORA, GDPR, AI Act adjacencies), which creates structural demand for its ControlManager™ GRC platform among Danish and Nordic mid-market and public-sector customers. The company has approximately 20 years of operating history and recently converted from ApS to A/S, typically signaling growth in size and capital structure warranting stricter governance. Its hybrid revenue model combining recurring SaaS subscriptions with project-based advisory services provides both stability and upsell potential. However, the company is small and highly concentrated in Denmark, with a Danish-only website, exclusively Danish customer references, and a single office in Søborg. It competes against much larger international GRC players (ServiceNow GRC, Archer, OneTrust, LogicGate, Diligent, RSA) as well as Nordic peers (Neupart/Advisera, RISMA), requiring sustained R&D investment. Consulting revenue is people-dependent and scales linearly with headcount unless SaaS mix grows. Limited public disclosure as a small A/S means no analyst coverage or segment reporting is available. Actual financial figures (revenue, EBIT, equity) could not be retrieved in this session and should be verified via datacvr.virk.dk.

Key strengths: Regulatory tailwind from NIS2, DORA, GDPR, and AI Act driving structural demand, Diversified blue-chip Danish customer base including DLR Kredit, Velliv Foreningen, Argo, Nævnenes Hus, Stevns Kommune, Punktum.dk, JMA A/S, and Jobindex A/S, Hybrid revenue model combining recurring SaaS with project-based advisory, ~20 years of operating history, Recent conversion from ApS to A/S suggesting growth and governance maturity, High switching costs in financial-services, public-sector, and utility clients

Risk factors: Small, Denmark-concentrated company with ~100% domestic revenue exposure, Competitive GRC market with much larger international and Nordic peers requiring sustained R&D, Key-person and consulting dependency causing linear scaling with headcount, Limited public disclosure with no analyst coverage or segment reporting, Exposure to Danish public-sector procurement cycles and macro conditions

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report