Stratu ApS

Denmark · www.stratu.com · 59 vendors

Stratu ApS is a Danish IT company that provides multi-cloud services, IT outsourcing, and cybersecurity solutions. The company offers services such as SOC as a Service, NIS2 consulting, Microsoft 365 backup and migration, and private cloud solutions. Stratu aims to deliver stable and secure IT infrastructure for businesses.

Resilience scores

Disruption prediction

Stratu ApS has an estimated 27% probability of disruption in the next 6 months.

26 of Stratu ApS's 59 vendors monitored for disruptions.

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 59 sub-vendors.

Insights

Last updated 2026-07-20 · revision 29

59 direct vendors, 473 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Stratu ApS exhibits high migration readiness (Score: 92). **Strengths:** The company possesses a highly modern and cloud-oriented internal tech stack, leveraging Microsoft Azure, Kubernetes, and Nutanix Cloud Platform (HCI), which are foundational for agile and scalable cloud environments. Their product offerings further underscore their expertise, including 'Cloud Migration,' 'Microsoft 365 Migration,' 'Azure Landing Zone,' and 'Kubernetes Platform,' indicating deep practical experience in facilitating complex transitions. Stratu demonstrates a sophisticated understanding of the regulatory landscape and data residency requirements, being compliant with GDPR (ISAE-3000) and ISO 27001, and offering NIS2 advisory services. Their emphasis on 'Dansk Cloud' and mechanisms for international data transfers (DPF, SCCs) highlight their capability to manage intricate compliance during migrations. While the 'Total Vendors' data point states 0, their reliance on a diverse set of technology vendors such as Nutanix, Microsoft, Veeam, Fortinet, and Arctic Wolf, whose HQs are spread across 12 unique countries, generally reduces vendor lock-in for specific components and offers flexibility in migration strategies. **Weaknesses:** The literal interpretation of 'Total Vendors: 0' is highly contradictory to their listed tech stack and would imply an unrealistic level of self-sufficiency, making a true vendor lock-in assessment difficult. Assuming they do have vendor relationships for their tech stack, their significant investment in specific ecosystems like Nutanix and Microsoft means their migration paths are likely to involve transitions within or deeper into these platforms, rather than a complete departure. However, their service offerings demonstrate their ability to manage such platform-specific migrations effectively. The absence of detailed growth history or product revenue concentration data prevents a comprehensive assessment of their financial capacity to fund large-scale internal migrations, though their business model as an IT service provider suggests inherent capabilities in this area.

Compliance

8 in-scope frameworks identified; showing 3.

EU Cybersecurity Act — Assessment Required

The EU Cybersecurity Act (Regulation EU 2019/881) establishes ENISA's permanent mandate and a European cybersecurity certification framework. For Stratu as an IT MSP and cloud provider, the EU CSA is relevant in that: (1) cloud services certification schemes (EUCS — EU Cloud Services Certification Scheme) are being developed and may apply to Stratu's cloud offerings; (2) ICT product/service certifications under the CSA may be required by regulated clients. Risk is Low currently as mandatory certification schemes are still being finalized, but this may increase as EUCS and other schemes become mandatory for certain service categories.

Evidence: https://www.stratu.com/cloud/, https://www.stratu.com/dansk-cloud/, https://www.stratu.com/ansvarlighed/

NIS2 (source) — Assessment Required

NIS2 applicability to Stratu requires careful analysis across two dimensions: (1) As a potential 'Important Entity' or 'Essential Entity' in its own right: Stratu provides managed IT services, cloud services, SOC-as-a-Service, and network services. Under NIS2 Annex I and II, 'ICT service management (B2B)' is listed as an Essential Entity sector, and 'digital providers' (including managed service providers) fall under Important Entities. Danish NIS2 implementation (Lov om sikkerhed i net- og informationssystemer, in force October 2024) covers managed service providers. The size threshold (50+ employees or €10M+ turnover) is uncertain from public sources — Stratu appears to be an SME but exact headcount/revenue is not publicly disclosed. (2) As a supplier to NIS2-regulated entities: Stratu serves clients such as Lyngby-Taarbæk Forsyning (a utility/water company, clearly NIS2 Essential Entity) and e-Boks (digital infrastructure), meaning Stratu faces indirect NIS2 supply chain requirements regardless of its own classification. Risk is Medium rather than High because: the size threshold uncertainty means direct applicability is not confirmed; however, the indirect supply chain pressure from regulated clients is real and significant. Stratu already offers NIS2 Advisory services, suggesting awareness of the regulatory landscape.

Evidence: https://www.stratu.com/nis2-raadgivning/, https://www.stratu.com/en/nis2-raadgivning/, https://www.stratu.com/ansvarlighed/, https://www.stratu.com/

ISAE 3402 — Compliant

Stratu explicitly confirms ISAE-3402 audit completion across multiple locations. ISAE 3402 provides assurance on the controls at a service organization relevant to user entities' financial reporting and operational controls — it is the international equivalent of SOC 1/SOC 2 and is the standard most commonly required by Danish and European enterprises when evaluating IT service providers and cloud operators. Risk is Low because: (1) the audit is conducted by external independent auditing firms across multiple data center locations; (2) ISAE-3402 requires rigorous testing of control design and operating effectiveness; (3) the certificate is available to customers free of charge; (4) as an IT MSP managing critical infrastructure for clients, ISAE-3402 is the most commercially critical assurance standard Stratu holds.

Evidence: https://www.stratu.com/ansvarlighed/, https://www.stratu.com/en/ansvarlighed/, https://www.stratu.com/

Financials

Financial Resilience Score: 6/10

Stratu ApS demonstrates moderate financial resilience based on qualitative indicators, though no verified financial figures were available to confirm the assessment quantitatively. The company benefits from ownership by Zibra Partner Equity, a family-office/holding structure of the Zibrandtsen family, which typically provides access to patient capital and reduces dependence on external debt financing. Its business model is centered on recurring-revenue managed services including SOC-as-a-Service, DRaaS, M365 backup, IT outsourcing, and cloud hosting, which improves cash-flow predictability. The company has established credibility with enterprise-grade reference customers such as e-Boks (Denmark's national secure digital-mail platform), Djøf, Copydan, Dansk Boligforsikring, Phase One, Nine United, Airlog Group, Group Online, and Lyngby-Taarbæk Forsyning. Certifications including ISO 27001, ISAE 3000 (GDPR), and ISAE 3402 reduce sales friction with regulated industries. Strong vendor partnerships with Nutanix, Veeam, Fortinet, Arctic Wolf, and Microsoft provide technology depth, and the NIS2 regulatory tailwind supports the cybersecurity segment. However, the company faces meaningful risks: small-company scale with a single-country focus limits revenue diversification, heavy vendor dependency creates margin exposure, and the Danish managed-IT/MSP market is highly competitive (itm8, Fujitsu DK, Atea, Globeteam, Cibicom). Talent scarcity in cybersecurity and cloud engineering pressures wage costs, and as a small/medium ApS, financial disclosure is limited to abbreviated Class B accounts.

Key strengths: Backed by Zibra Partner Equity family-office/holding structure providing patient capital, Recurring-revenue managed services model improves cash-flow predictability, Enterprise-grade reference customers including e-Boks, Djøf, Copydan, Phase One, ISO 27001, ISAE 3000 (GDPR), and ISAE 3402 certifications, Strong vendor partnerships with Nutanix, Veeam, Fortinet, Arctic Wolf, Microsoft, NIS2/cybersecurity regulatory tailwind in Danish market

Risk factors: Small-company scale with limited revenue base compared to pan-Nordic competitors, Geographic concentration - operations exclusively in Denmark, Vendor dependency on Nutanix, Microsoft, Veeam, Fortinet, Arctic Wolf, Competitive intensity in crowded Danish MSP market (itm8, Fujitsu DK, Atea, Globeteam, Cibicom), Cybersecurity and cloud engineering talent scarcity pressuring wage costs, Limited financial transparency due to abbreviated Class B accounting disclosure

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report