Statens It (Agency for Governmental IT Services)
Denmark · owned by Finansministeriet (Danish Ministry of Finance) (Denmark) · statens-it.dk · 31 vendors
Statens It (the Agency for Governmental IT Services) is the Danish state's internal IT operations agency, providing IT infrastructure, workplace solutions, security, and support services to approximately 25 ministries and 60,000 users across the Danish government. It was established on 1 January 2010 through the merger of eight ministerial IT operations organizations, with the goal of achieving higher quality and lower costs through harmonization and economies of scale. The agency is ISO 27001 certified and focuses on accessibility, stability, efficiency, and information security.
Resilience scores
- Digital Sovereignty: 29
- Digital Resilience: 6
- Financial Resilience: 9
Technology vendors
- Adobe Inc. — Technology — United States
- Broadcom Inc. — Technology — United States
- Kyndryl — Technology — United States
- and 30 more
Services catalogue
16 services in catalogue across 4 categories; runs on 31 sub-vendors.
- Servicedesk
- DNS Hosting
- Infrastruktur
Insights
Last updated 2026-08-10 · revision 24
31 direct vendors, 306 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 6
- Sweden: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- France: 8
- New Zealand: 6
- Poland: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Statens It exhibits medium migration readiness, leaning towards low, primarily due to significant regulatory and data residency complexities. As a Danish government agency, it must comply with GDPR and likely NIS2 (both assessed as 'High risk' with identified compliance gaps), and adhere to stringent Danish and EU data sovereignty mandates. These requirements necessitate that sensitive government data remains within EU/EEA boundaries, and likely within Denmark for classified information, severely limiting the choice of cloud providers and architectures and adding considerable complexity and cost to any migration. The internal tech stack, characterized by Microsoft Active Directory, Exchange, Windows, centralized file storage, and virtualization, suggests a traditional enterprise IT environment rather than a cloud-native, containerized, or microservices-based architecture. This implies that a 'lift and shift' migration would be challenging, and a re-architecture would be extensive. There is also a degree of platform lock-in to the Microsoft ecosystem. The 'Total Vendors: 0' data point is contradictory to other information suggesting vendor engagement (e.g., 'Outsourced Drift og Miniudbud' service). This makes a precise assessment of vendor lock-in based on the *number* of vendors challenging. However, existing outsourcing contracts would need careful management during migration. On the positive side, Statens It's strong and consistent financial growth provides a solid foundation to fund a complex migration initiative. While the tech stack is not cloud-native, the existing reliance on Microsoft technologies could potentially streamline migration to Microsoft Azure, provided all stringent data residency and regulatory requirements can be met within that specific cloud environment.
Compliance
9 in-scope frameworks identified; showing 3.
SOC 2 (source) — Assessment Required
SOC 2 is a US-origin voluntary framework (AICPA) for service organisations that store, process, or transmit customer data. While not legally mandated in Denmark or the EU, Statens It is a large managed IT services provider handling sensitive government data for multiple public-sector customers. Some of its customers or international partners may contractually require SOC 2 reports as evidence of controls over security, availability, processing integrity, confidentiality, and privacy. Risk is Medium because: (1) the absence of a SOC 2 report could be a commercial or contractual gap if international or cloud-related engagements require it; (2) Statens It's ISO 27001 certification substantially overlaps with SOC 2 Trust Service Criteria and may serve as an equivalent; (3) Danish public-sector procurement typically relies on ISO 27001 and ISAE 3402/3000 rather than SOC 2, reducing the likelihood of a hard requirement. No evidence of a SOC 2 report was found.
Evidence: https://statens-it.dk/services/sikkerhed/, https://statens-it.dk/om-os/om-statens-it/
ISAE 3000 (source) — Assessment Required
ISAE 3000 (and its related standard ISAE 3402 for service organisations' controls over financial reporting) is highly relevant for Statens It given its role as a shared IT services provider for Danish government ministries and agencies. Danish public-sector entities are subject to audit by Rigsrevisionen, and IT service providers supporting financial and administrative systems are commonly required to provide ISAE 3402 or ISAE 3000 Type II assurance reports to their customers' auditors. Statens It explicitly provides standardised administrative systems (including financial systems) to government customers, making ISAE 3402 particularly relevant. Risk is Medium because: (1) the absence of an ISAE 3402/3000 report could create audit gaps for customer organisations' financial statement audits; (2) Rigsrevisionen reviews are referenced in Statens It's audit cycle, which may partially address this need; (3) no public ISAE report was found, but this does not mean one does not exist — such reports are often confidential and shared only with customers.
Evidence: https://statens-it.dk/services/sikkerhed/, https://statens-it.dk/om-os/aarsrapport/, https://www.rigsrevisionen.dk/
Danish Whistleblower Protection Act — Compliant
Statens It has established a formal whistleblower scheme (Whistleblowerordning) as required by the Danish Whistleblower Protection Act, which transposed EU Directive 2019/1937 into Danish law. The scheme is publicly disclosed on the agency's website. Risk is Low as the agency has demonstrably implemented the required mechanism.
Evidence: https://statens-it.dk/om-os/statens-its-whistleblowerordning/
Financials
Three-year financials
- 2024: revenue DKK 932.4M, EBIT DKK -34.2M, equity DKK 55.4M
- 2023: revenue DKK 847.0M, EBIT DKK -45.1M, equity DKK 54.2M
- 2022: revenue DKK 717.0M, EBIT DKK -11.5M, equity DKK 41.8M
Financial Resilience Score: 9/10
Statens It is a Danish government agency ('styrelse') under the Ministry of Finance, operating on a full cost-recovery basis since 2016. As a sovereign-backed state entity, it carries the full credit of the Kingdom of Denmark, effectively eliminating default risk. Its captive customer base consists of all 24 Danish ministerial areas and self-governing educational institutions, providing highly stable and mandated demand growth driven by the government's IT consolidation policy. Revenue has grown approximately 30% cumulatively from 2022 to 2024 (DKK 717M to DKK 932M), with 2025 projected to exceed DKK 1 billion for the first time. The full cost-recovery pricing model structurally prevents sustained losses over multi-year cycles - in fact, the agency delivered 2% price reductions to customers in both 2024 and 2025 while maintaining balanced budgets, indicating realized scale economies. Fixed assets are almost entirely financed via the state's own long-term FF4 loan facility, with cash management through central state financing accounts. While equity is thin (DKK 55.4M against DKK 875M balance sheet), this is by design as a government agency rather than a commercial firm. The agency maintains ISO 27001, ISO 27701, and ISO 20000 certifications. Key risks are operational rather than financial: a 2023 Rigsrevisionen critical report on server-side technical debt, elevated cybersecurity threat exposure as central IT provider for the entire Danish state, execution risks on major transformation projects (SDDC rollout, network modernization, NIS2 compliance, EU presidency IT support), and rapid personnel cost inflation (33% growth in two years).
Key strengths: Sovereign backing from Kingdom of Denmark (Ministry of Finance), Full cost-recovery pricing model since 2016 eliminates structural loss risk, Captive customer base of all 24 Danish ministerial areas, Steady revenue growth ~10-18% annually, on track to exceed DKK 1B in 2025, ISO 27001, ISO 27701, and ISO 20000 certifications maintained, Fixed assets financed through state FF4 long-term loan facility, Realized scale economies enabling 2% customer price reductions in 2024 and 2025
Risk factors: Technical debt on server-side IT infrastructure flagged by Rigsrevisionen in 2023, Elevated cybersecurity threat as central IT provider for entire Danish state, Execution risk on major transformation projects (SDDC, NIS2, data center migration), Rapid personnel cost inflation - 33% growth 2022-2024, Slight decline in user satisfaction (3.8 in 2024 vs 3.9 in 2023), DKK 9.5M one-off correction of prior-year depreciation indicates asset-register control weaknesses, High loan facility utilization (95.5% of DKK 720M frame in 2024), High sickness absence (~12 days per employee) for Danish public sector, Thin equity buffer (DKK 55.4M) relative to balance sheet (DKK 875M)
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Secure operations (basic IT operations): 94%
- Reliable projects (customer projects): 6%
Workforce by country
- Denmark: 591
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.