Syddansk Universitet
Denmark · www.sdu.dk · 10 vendors
Resilience scores
- Digital Sovereignty: 60
- Digital Resilience: 7
- Financial Resilience: 7
Technology vendors
- Comdia — Denmark
- Google LLC — Technology — United States
- Hellenic Academic and Research Institutions Certification Authority (HARICA) — Cybersecurity — Greece
- and 7 more
Services catalogue
1 service in catalogue across 1 category; runs on 10 sub-vendors.
- Research and development contribution to 'Det holistiske LAR-vejbed' project
Insights
Last updated 2026-08-15 · revision 2
10 direct vendors, 135 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 3
- Canada: 1
- United States: 3
Subvendors by controlling owner country (sample)
- Romania: 1
- Germany: 6
- United Kingdom: 3
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Syddansk Universitet exhibits a medium level of migration readiness. The tech stack includes a mix of modern cloud services (Microsoft Azure Active Directory, Microsoft 365) which indicates some familiarity with cloud adoption and could facilitate future migrations. However, a substantial portion of the internal tech stack consists of specialized commercial platforms (e.g., Sitecore CMS, itslearning, Pure, DigitalEksamen, Ex Libris Alma/Primo, Kaltura). Migrating these systems can be complex due to potential vendor-specific architectures, data formats, and integration points, which may not be inherently cloud-native, containerized, or microservices-based. The lack of information regarding the current architecture's modernity (e.g., containerization, microservices) for these specialized platforms suggests a traditional deployment model for many, increasing migration effort. Critical data gaps exist for assessing migration readiness, including 'Regulatory Environment' and 'Data Residency Requirements,' which can significantly impact migration strategies and costs. Financial stability data (revenue concentration, growth history) is also missing, making it impossible to assess the company's ability to fund a large-scale migration. While the provided data for 'Total Vendors: 0' is contradictory, assuming the 14 listed services imply multiple vendors, the vendor geographic diversity (6-7 unique countries) could mitigate some overall vendor lock-in risk. However, individual platform lock-in for each of the specialized systems remains a potential challenge. The 'Vendor Lock-in Risk' is explicitly unknown, which is a significant factor in migration planning.
Compliance
9 in-scope frameworks identified; showing 3.
Danish University Act — Compliant
SDU operates under the Danish University Act as a state-funded public university under the Ministry of Higher Education and Research. SDU has a strategic framework contract (rammekontrakt) with the Ministry, publishes annual reports, and operates under full regulatory oversight. As a long-established institution (founded 1966) with formal governance structures (Board, Rector, Administration), compliance with the University Act is well-established. Risk is Low as SDU is a mature, publicly accountable institution with transparent governance.
Evidence: https://www.sdu.dk/da/om-sdu/strategi-politikker/aarsrapporter, https://www.sdu.dk/da/om-sdu/strategi-politikker/rammekontrakt, https://www.sdu.dk/da/om-sdu/ledelse-administration/bestyrelsen, https://www.retsinformation.dk/eli/lta/2019/778
NIS2 (source) — Assessment Required
NIS2 (EU Directive 2022/2555, transposed into Danish law via 'Lov om sikkerhed i net- og informationssystemer') is potentially applicable to SDU on multiple grounds: (1) SDU is a large public institution (4,128 employees, DKK 3.6 billion revenue) that clearly exceeds the NIS2 size thresholds (50+ employees, €10M+ turnover); (2) NIS2 explicitly includes 'public administration' entities as Essential Entities under Annex I — Danish universities are state-funded public institutions under the Ministry of Higher Education and Research; (3) SDU's Faculty of Health Sciences and research collaborations with hospitals (OUH — Odense University Hospital) may bring it within the 'health' sector scope; (4) SDU operates critical digital infrastructure (IT systems, research networks, student portals) at scale. The risk is Medium rather than High because: the precise classification of universities under Danish NIS2 transposition is subject to regulatory interpretation; Denmark's Centre for Cyber Security (CFCS) and the Danish Business Authority are the competent authorities and their specific guidance on university classification is not publicly confirmed. A formal NIS2 scoping assessment is required.
Evidence: https://www.sdu.dk/da/om-sdu/noegletal, https://www.sdu.dk/da/om-sdu/fakulteterne/sundhedsvidenskab, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, https://www.cfcs.dk/, https://www.erhvervsstyrelsen.dk/
GDPR (source) — Partially Compliant
SDU is a large Danish public university (HQ in EU/Denmark) processing extensive personal data of 19,287 students, 4,128 employees, research subjects, patients, and clinical trial participants — GDPR is universally and unambiguously applicable. The risk level is High because: (1) SDU processes special categories of data (health/medical data via the Faculty of Health Sciences, research participant data, patient data referenced on the data protection page), which carry the highest GDPR risk under Article 9; (2) the scale of data subjects is very large (tens of thousands); (3) Denmark's Datatilsynet (Danish Data Protection Authority) is an active enforcement authority with a track record of investigating universities and public bodies; (4) SDU's international research collaborations and use of cloud services (Microsoft 365/Outlook, itslearning LMS) create cross-border data transfer risks; (5) research data under Article 89 exemptions requires careful governance. While SDU has appointed a DPO and published a data protection policy, the compliance status cannot be confirmed as fully compliant without audit evidence of complete GDPR implementation across all faculties and systems.
Evidence: https://www.sdu.dk/da/om-sdu/om-dette-websted/databeskyttelse, https://www.sdu.dk/da/, https://sdunet.dk/da/servicesider/it/databeskyttelse-og-informationssikkerhed, https://www.datatilsynet.dk/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Financials
Three-year financials
- 2024: revenue DKK 3.85B, EBIT DKK -121.7M, equity DKK 859.6M
- 2023: revenue DKK 3.55B, EBIT DKK -81.2M, equity DKK 957.3M
- 2022: revenue DKK 3.34B, EBIT DKK -52.7M, equity DKK 968.5M
Financial Resilience Score: 7/10
SDU is a large, well-established public Danish university with a highly stable revenue base of approximately DKK 3.85bn (2024), of which ~62% comes from Danish state block grants that are government-guaranteed and unlikely to fall abruptly. The balance sheet remains solid with equity of DKK 860m, total assets of DKK 2.64bn, and cash plus securities of DKK 643m at year-end 2024, plus DKK 592m in high-quality government debt instruments. External research grant income has grown strongly (+33% over two years to DKK 1.21bn in 2024), demonstrating competitive strength in attracting foundation, EU, and industry funding. However, SDU has run operating deficits for three consecutive years, with losses widening from DKK -53m in 2022 to DKK -122m in 2024. Cost inflation — particularly rent (+35% over two years) and staff expenses (+12.5% over two years) — has consistently outpaced income growth. Equity fell approximately 11% in 2024 alone, and continued erosion could attract political and regulatory scrutiny. Overall resilience is strong in the medium term thanks to government backing, healthy liquidity, and diversified grant income, but the widening loss trajectory represents a material risk that management will need to address.
Key strengths: Stable state block grant funding (~62% of revenue, DKK 2.39bn in 2024), Solid equity base of DKK 860m and total assets of DKK 2.64bn, Strong liquidity with DKK 643m in cash and securities, Growing external research grant income (+33% over two years), Audited by PwC and Denmark's National Audit Office, Diverse funding sources across state, EU, foundations, and industry
Risk factors: Persistent and widening operating losses three years running, Cost inflation in rent (+35% in 2 years) and staff (+12.5% in 2 years), Equity erosion of ~11% in 2024 alone, Political dependence on Danish government funding policy, Exposure to shifting policy on tuition, dimensioning, and international student caps, Geographic concentration entirely in Denmark
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Government fundings (state block grant): 62.2%
- Other fundings (external research grants): 31.4%
- Other revenues: 3.9%
- Sales of goods and services: 2.5%
Workforce by country
- Denmark: 4128
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.