Scandinavian Micro Biodevices

Denmark · owned by Technolution (Netherlands) · smpt.dk · 6 vendors

A contract development and manufacturing organization (CDMO) for microfluidic-based consumables, specializing in Lab-on-a-Chip (LOAC) products.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 29

6 direct vendors, 144 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company's migration readiness is low, primarily hindered by an undefined internal tech stack, a highly complex regulatory environment, and significant data gaps regarding financial capacity and vendor relationships. **Challenges:** * **Undefined Internal Tech Stack:** The complete absence of information regarding the company's internal tech stack (e.g., cloud-native, containerization, microservices, or legacy on-premise systems) makes it impossible to assess the technical feasibility and complexity of a migration. Without this data, a conservative assumption of a traditional, potentially monolithic architecture is prudent, which typically implies lower readiness and higher migration effort. * **Stringent Regulatory and Data Residency Requirements:** The company operates under a highly regulated environment, including GDPR, NIS2 (likely applicable given employee count), EU MDR, and ISO 13485. Crucially, strict EU data residency requirements mandate that personal data, and potentially medical device data, remain within the EU/EEA or countries with adequacy decisions. This significantly complicates any migration, particularly to global cloud providers, requiring careful selection of data centers, robust compliance strategies, and potentially re-architecting data flows to maintain regulatory adherence. * **Vendor Relationships (Contradictory Data):** Similar to resilience, the contradictory vendor data ('Total Vendors: 0' vs. 'Total Services: 20' from vendors in Malta and the US) creates uncertainty. If the company relies on a limited number of vendors for its 20 services, it suggests potential vendor lock-in, which would increase the complexity, cost, and risk associated with migrating these services or transitioning to new providers. * **Unknown Financial Capacity:** The lack of historical revenue and employee growth data prevents an assessment of the company's financial stability and its ability to fund a potentially significant and costly migration project. **Opportunities:** * If the 'Total Vendors: 0' is accurate and the company truly has no external service dependencies, this would represent a significant advantage for migration by eliminating vendor lock-in. However, this contradicts other provided vendor data and is unlikely given 'Total Services: 20'. Overall, the combination of an unknown technical landscape, stringent regulatory and data residency constraints, and financial uncertainty presents substantial hurdles for any significant migration initiative.

Compliance

6 in-scope frameworks identified; showing 3.

NIS2 (source) — Assessment Required

NIS2 applies to Important Entities in the manufacturing sector for companies with 50+ employees or €10M+ annual turnover. As a CDMO in the pharmaceutical/biodevices sector, this company likely falls under manufacturing Important Entities. However, without confirmed size information, the applicability requires assessment.

NIS2 applies to Important Entities in the manufacturing sector for companies with 50+ employees or €10M+ annual turnover. As a CDMO in the pharmaceutical/biodevices sector, this company likely falls under manufacturing Important Entities. However, without confirmed size information, the applicability requires assessment. Non-compliance can result in significant penalties and operational restrictions.

ISO 27001 (source) — Assessment Required

ISO 27001 is not legally mandatory but is industry best practice for information security management. For pharmaceutical CDMOs handling sensitive intellectual property and potentially regulated data, ISO 27001 certification is often expected by customers and may be required for certain contracts.

ISO 27001 is not legally mandatory but is industry best practice for information security management. For pharmaceutical CDMOs handling sensitive intellectual property and potentially regulated data, ISO 27001 certification is often expected by customers and may be required for certain contracts. Risk is moderate as it affects competitive positioning and customer requirements.

SOC 2 (source) — Assessment Required

SOC2 is not mandatory but increasingly expected for service providers, especially those handling sensitive data or providing services to US companies. As a CDMO, if they provide services to US pharmaceutical companies, SOC2 compliance may be contractually required.

SOC2 is not mandatory but increasingly expected for service providers, especially those handling sensitive data or providing services to US companies. As a CDMO, if they provide services to US pharmaceutical companies, SOC2 compliance may be contractually required. Risk is moderate as it affects business opportunities rather than regulatory compliance.

Financials

Three-year financials

Financial Resilience Score: 7/10

SMPT's moderately high resilience stems from its niche market position in microfluidics for diagnostics, protecting it from generalist competition. The CDMO model diversifies client risk, as success isn't tied to a single end-product. Sticky customer relationships, fostered by lengthy design and validation processes, create long-term, stable revenue streams. Operational longevity since 2003 indicates a sustainable business model, and ISO 13485 certification provides a competitive advantage in attracting healthcare clients. However, weaknesses exist. Customer concentration, common in CDMOs, means the loss of a major client could significantly impact financials. The business requires substantial and ongoing investment in cleanrooms and equipment, potentially straining cash flow. SMPT's ultimate success depends on its clients' products succeeding in the market and gaining regulatory approval.

Key strengths: Niche Market Position, Diversified Client Risk, Sticky Customer Relationships, Operational Longevity, Regulatory Compliance

Risk factors: Customer Concentration, Capital Intensity, Dependence on Client Success

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report