Systematic A/S

Denmark · owned by Michael Holm Holding ApS (Denmark) · systematic.com · 24 vendors

Systematic A/S is a Danish software company headquartered in Aarhus, Denmark, that develops critical software solutions for defence, healthcare, national security, critical infrastructure, and libraries. Its world-leading command-and-control system, SitaWare, forms the digital backbone of NATO land operations. With over 1,200 employees across 18 global offices, the company serves customers in more than 50 countries and is CMMI Maturity Level 5 certified.

Resilience scores

Technology vendors

Services catalogue

8 services in catalogue across 3 categories; runs on 24 sub-vendors.

Insights

Last updated 2026-09-13 · revision 23

24 direct vendors, 330 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Systematic A/S exhibits a medium level of migration readiness, scoring 45. The company possesses a modern technology stack, including existing 'Cloud Computing platforms,' 'AI,' 'Machine Learning,' and 'Open Architecture software design,' which are conducive to migration. Financial stability, evidenced by consistent employee growth, also supports the ability to fund migration efforts. However, the most significant challenge lies in its highly complex regulatory and data residency environment. Operating in defense and healthcare sectors across multiple EU/EEA countries, the US, and other regions necessitates stringent compliance with GDPR, potential NIS2 and HIPAA requirements, and specific data residency mandates for defense and healthcare data. Migrating such sensitive information while maintaining compliance across diverse jurisdictions will be exceptionally complex, costly, and time-consuming. Additionally, the 'Unknown' vendor lock-in risk and the ambiguity regarding the actual number of unique vendors for its 62 services present potential dependencies that could complicate migration. The numerous pending regulatory assessments also imply a high compliance overhead during any migration project.

Compliance

13 in-scope frameworks identified; showing 3.

CMMC — Assessment Required

Risk is rated High because: (1) Systematic Inc. (US subsidiary) explicitly serves the US Department of Defense as 'a leading provider of simple and reliable C4I integration software solutions for the Department of Defense'; (2) CMMC 2.0 is mandatory for all DoD contractors and subcontractors handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI); (3) CMMC 2.0 Level 2 (based on NIST SP 800-171) or Level 3 (based on NIST SP 800-172) is likely required for C4ISR software providers handling classified or sensitive defence information; (4) non-compliance with CMMC requirements can result in loss of DoD contracts; (5) CMMC 2.0 final rule became effective December 16, 2024, making compliance mandatory for new contracts. Risk is High because DoD contract eligibility depends on CMMC certification, and no public evidence of CMMC certification status was found.

Evidence: https://systematic.com/us/our-company/, https://systematic.com/us/industries/defense/

MDR — Assessment Required

Risk is rated Medium because: (1) Systematic's healthcare products (Columna Cura for care records, Columna Flow for hospital workflows, SitaWare Battlefield Health for military medical C2) may qualify as medical device software (SaMD - Software as a Medical Device) under EU MDR 2017/745; (2) if any software product is intended to be used for diagnosis, prevention, monitoring, treatment, or alleviation of disease, it falls under MDR; (3) SitaWare Battlefield Health explicitly processes medical/health data in a command-and-control context; (4) Columna Cura as a care records system for municipalities may or may not qualify as a medical device depending on its intended purpose; (5) MDR non-compliance can result in market withdrawal and significant penalties. Risk is Medium because the applicability depends on the specific intended purpose of each product, which requires detailed product-level assessment.

Evidence: https://systematic.com/int/industries/healthcare/, https://systematic.com/int/industries/defence/news-knowledge/news/sitaware-battlefield-health-at-medic-quadriga-2026/

CSRD (source) — Assessment Required

Risk is rated Medium because: (1) CSRD applies to large EU companies meeting two of three criteria: 250+ employees, €40M+ net turnover, €20M+ balance sheet total; (2) Systematic A/S, with 1,000+ employees worldwide and multiple subsidiaries, likely meets the size thresholds; (3) CSRD requires detailed sustainability reporting under European Sustainability Reporting Standards (ESRS) with mandatory ISAE 3000 limited assurance; (4) Systematic has a Sustainability page and Carbon Reduction Plan (linked from footer), suggesting awareness of sustainability reporting obligations; (5) the phased implementation means large EU companies must report from financial year 2024 (reports due 2025). Risk is Medium because non-compliance with CSRD reporting requirements can result in regulatory sanctions and reputational damage.

Evidence: https://systematic.com/int/our-company/sustainability/, https://systematic.com/int/contact/carbon-reduction-plan/

Financials

Three-year financials

Financial Resilience Score: 9/10

Systematic A/S demonstrates exceptional financial resilience for a private technology company. The Group is entirely debt-free with no bank loans or long-term interest-bearing debt, and holds EUR 95.5M in cash — roughly 5 months of revenue and about 2x total short-term liabilities. The solvency ratio of 62.4% reflects an extremely conservative capital structure, and return on equity of 33.6% is exceptional for a large enterprise software business. Profitability has expanded meaningfully over the past three years, with EBIT margin rising from 13.0% in FY21/22 to 20.5% in FY23/24, and net margin climbing from 10.9% to 15.7%. Cash generation is strong (EUR 57.3M from operations in FY23/24), and the company maintains a sizeable recurring revenue tail via EUR 23.0M of deferred service-contract income. Structural tailwinds from increased European defence spending, NATO wins, and CMMI Level 5 certification support the outlook. Key risks include heavy exposure to public/defence procurement cycles (which can be lumpy), deliberate non-disclosure of segment and geographic revenue splits (limiting external transparency), an aggressive dividend policy (EUR 38.5M paid in FY23/24 causing equity to decline despite record profits), cost-base inflation flagged by management, FX exposure across multiple currencies, and residual founder/key-person dependency following the 2023 CEO succession. Nonetheless, PwC issued a clean unqualified audit opinion, and management guides for continued 5–15% revenue and EBIT growth in FY24/25.

Key strengths: Debt-free balance sheet with no bank loans, EUR 95.5M cash reserves (5 months of revenue), Solvency ratio of 62.4%, Return on equity of 33.6%, EBIT margin expansion from 13.0% to 20.5% over 3 years, Strong operating cash flow of EUR 57.3M, 5-year revenue CAGR of ~10.1%, CMMI Level 5 certification since 2005, Clean unqualified PwC audit opinion, Structural tailwind from increased European defence spending

Risk factors: Heavy dependence on public/defence procurement cycles with lumpy large contracts, Deliberate non-disclosure of segment and geographic revenue breakdown, Aggressive dividend policy (EUR 38.5M paid in FY23/24) reducing retained equity, Cost-base inflation flagged by management, FX exposure across CHF, USD, GBP, AUD, DKK, SEK, NOK, RON, Founder/key-person dependency following 2023 CEO succession, Loss-making 50% associate CUBEDIN A/S (immaterial), Narrower FY24/25 guidance (5-15%) than FY23/24 actual performance

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report