Styrelsen for It og Læring

Denmark · www.stil.dk · 8 vendors

Resilience scores

Technology vendors

Services catalogue

3 services in catalogue across 3 categories; runs on 8 sub-vendors.

Insights

Last updated 2026-08-02 · revision 2

8 direct vendors, 134 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

The company exhibits medium-low migration readiness. A primary challenge is its reliance on a "Private Cloud (own on-premises cloud infrastructure)," which implies a significant effort for re-platforming or lift-and-shift to a public cloud environment. While the company employs modern development methodologies like Agile/Scrum and utilizes CI/CD pipelines, which are beneficial for modernization, the core infrastructure is not inherently cloud-native. The lack of specified data residency requirements and an empty regulatory environment section are critical unknowns; for a Danish government agency, strict data residency within Denmark is highly probable and could significantly complicate migration to global public cloud providers. Financial stability data is also missing, making it impossible to assess the company's capacity to fund a substantial migration. Regarding vendor relationships, assuming vendors exist for the 9 services, the moderate vendor geographic diversity (3 countries) suggests a moderate level of vendor lock-in risk, which could add complexity to migration efforts. The absence of explicit information on containerization or microservices further suggests that applications may require significant refactoring for optimal cloud adoption.

Compliance

9 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

STIL explicitly lists ISO 27001 as one of the external requirements it must comply with ('Efterlevelse af ISO 27001' — compliance with ISO 27001 — is listed as a specific koncern-facing activity). This means ISO 27001 is not merely aspirational but is a stated compliance obligation for STIL and the broader Ministry of Children, Education and Equality. The risk level is Medium rather than High because: (1) ISO 27001 is a voluntary standard (though mandated internally by the ministry); (2) non-compliance with ISO 27001 does not carry direct regulatory fines; (3) however, failure to maintain ISO 27001 compliance could indicate systemic information security weaknesses that would elevate risk under GDPR and NIS2. The Danish government's ISO 27001 requirements for public authorities are set out in the 'Statens IT-sikkerhedsstandard' (State IT Security Standard), which is based on ISO 27001.

Evidence: https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed/, https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed-og-databeskyttelse-i-undervisningssektoren/

NSIS — Assessment Required

STIL explicitly references NSIS (National Standard for Identiteters Sikringsniveauer) as one of the external requirements it must comply with. NSIS is the Danish national standard for identity assurance levels, aligned with the EU eIDAS Regulation (Regulation 910/2014). STIL operates Unilogin — the national identity and login system for the entire Danish education sector — which is directly subject to NSIS requirements. Unilogin must meet specific NSIS assurance levels (Low, Substantial, High) for different use cases. Risk is Medium because: (1) STIL self-identifies NSIS as applicable; (2) Unilogin is a critical national identity infrastructure; (3) failure to meet NSIS requirements could compromise the integrity of national digital exams and educational access systems.

Evidence: https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed/, https://stil.dk/administration-og-infrastruktur/unilogin/

Databeskyttelsesloven — Assessment Required

The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions, including stricter rules for processing personal identification numbers (CPR numbers), special rules for public authorities, and specific provisions for research and statistics. STIL processes CPR numbers extensively across its systems (Unilogin, exam databases, study administrative systems), which triggers the Act's specific CPR number processing rules. As a public authority, STIL is subject to the Act's public sector-specific provisions. The Danish Data Protection Authority (Datatilsynet) actively enforces both GDPR and the Databeskyttelsesloven against public authorities. Risk is High due to the volume of CPR number processing and the sensitivity of children's data.

Evidence: https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed/, https://stil.dk/om-styrelsen/om-styrelsens-hjemmeside/behandling-af-personoplysninger/

Financials

Three-year financials

Financial Resilience Score: 9/10

Styrelsen for It og Læring (STIL) is a Danish government agency under the Ministry of Children and Education, not a private company. Its funding is guaranteed via the Danish state budget (Finansloven § 20.28), which effectively eliminates going-concern risk in the corporate sense. The agency operates mission-critical IT infrastructure used by more than one million daily users across the Danish education sector, making it structurally protected from budget cuts. Historical operating appropriations have been in the order of magnitude of DKK 300–500 million per year, plus separate project and programme funds. Strong political tailwinds around digitalisation, cyber-security in schools, and educational data have driven repeated additional appropriations. The main risks are political/appropriation risk at each finanslov cycle, operational risk on critical national IT services (Unilogin, Optagelse.dk, Netprøver.dk), vendor concentration among a small number of Danish IT suppliers (KMD, Netcompany, Systematic), and a legacy modernisation burden inherited from the former UNI-C organisation.

Key strengths: State-guaranteed funding via Finansloven § 20.28, Mission-critical mandate serving over 1 million daily users, Strong political tailwinds in digitalisation and cyber-security, Broad and expanding scope since 2014 establishment, Denmark-only operations with no export/FX exposure

Risk factors: Political/appropriation risk at each finanslov cycle, Operational risk on critical national IT services (Unilogin, Optagelse.dk, Netprøver.dk), Vendor concentration among few Danish IT suppliers (KMD, Netcompany, Systematic), Legacy modernisation burden from former UNI-C systems, Political controversy around national tests reforms causing rework

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report