Teknologisk Institut

Denmark · www.teknologisk.dk · 16 vendors

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 2 categories; runs on 16 sub-vendors.

Insights

Last updated 2026-08-14 · revision 2

16 direct vendors, 180 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 5/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Teknologisk Institut exhibits a medium level of migration readiness. A key strength is the existing adoption of Microsoft Azure, indicating a foundational move towards cloud infrastructure and potentially cloud-native practices. This significantly reduces the technical hurdle for further cloud migration or modernization efforts. The use of APIs like Google Maps and Rejseplanen also suggests experience with integrating external services. However, several factors contribute to a moderate readiness score. The company utilizes a high number of 'Total Services' (22), which could imply a complex web of integrations and dependencies that would need careful planning and execution during a migration. While vendor geographic diversity is good for resilience, it could introduce complexity in managing contracts and support across different regions during a large-scale migration. Crucially, the assessment is hampered by missing data regarding specific regulatory environments, data residency requirements, and financial stability. These unknowns represent potential significant challenges or costs that could impact the feasibility and complexity of a migration. The 'Vendor Lock-in Risk' is also unknown, which is a critical factor for migration planning. Without this information, it's difficult to fully gauge the ease of transitioning away from existing solutions or vendors.

Compliance

11 in-scope frameworks identified; showing 3.

ISAE 3000 (source) — Assessment Required

ISAE 3000 is relevant for organizations that provide assurance services or that commission third-party assurance reports on their controls (e.g., for GDPR compliance, sustainability/ESG reporting, or service organization controls). Teknologisk Institut publishes an annual report with audited financial statements and has an ESG program, both of which may involve ISAE 3000 or ISAE 3402 assurance engagements. As a GTS institute receiving public research funding (Resultatkontrakter from the Ministry of Higher Education and Research), it may also be subject to assurance requirements from public funders. Risk is Low as ISAE 3000 is not a direct regulatory requirement but an auditing standard that may be applied in the context of other compliance activities.

Evidence: https://www.teknologisk.dk/hvem-er-vi/aarsrapport-2025/5374,6, https://www.teknologisk.dk/esg, https://www.teknologisk.dk/om

SOC 2 (source) — Assessment Required

SOC 2 is a voluntary US auditing framework (AICPA) applicable to service organizations that store, process, or transmit customer data in the cloud. Teknologisk Institut provides technology services, operates teknologisk.ai (an AI platform), and likely uses cloud infrastructure for service delivery. However, SOC 2 is primarily relevant for US-market cloud service providers or organizations with US enterprise customers requiring SOC 2 attestation. As a Danish RTO primarily serving Danish and European clients, SOC 2 demand is likely low. Risk is Low because SOC 2 is voluntary and EU-market clients typically require ISO 27001 rather than SOC 2. However, if the organization has US enterprise clients or provides SaaS/cloud services, SOC 2 may become a commercial requirement.

Evidence: https://www.teknologisk.dk/om, https://www.teknologisk.ai

Danish Data Protection Act — Partially Compliant

The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions including stricter rules for processing sensitive personal data, employee data, and criminal record data. As a large employer (1,100 employees) and research organization, Teknologisk Institut is subject to these national provisions. The published Persondatapolitik demonstrates GDPR compliance awareness, but Danish-specific provisions (e.g., CPR number processing rules, employee monitoring rules) require separate assessment. Risk is Medium for the same reasons as GDPR — the compliance infrastructure exists but cannot be fully verified from public sources.

Evidence: https://www.teknologisk.dk/privatliv, https://www.datatilsynet.dk/, https://www.retsinformation.dk/eli/lta/2018/502

Financials

Three-year financials

Financial Resilience Score: 8/10

Teknologisk Institut demonstrates strong financial resilience underpinned by an exceptionally robust balance sheet. At year-end 2025, the equity ratio stood at 73.4% (up from 69.0% in 2024) with a current ratio of 173.3%, cash of DKK 158M plus DKK 138M in other securities. Equity has grown steadily from DKK 815M in 2021 to DKK 933M in 2025. The institute benefits from a diversified income model combining commercial contracts (70.6%), R&D activities (21.0%), and Danish state performance-contract funding (8.4%), reducing dependence on any single revenue stream or customer. As a GTS (Approved Technological Service Institute) under the Danish Ministry of Higher Education and Research, the institute enjoys tax-exempt status on core activities and multi-year state funding contracts, providing structural stability. Management explicitly notes no material customer concentration, limited FX risk, and limited interest-rate sensitivity. PwC issued a clean audit opinion. Subsidiary Danfysik A/S contributed strong momentum with 18% revenue growth to DKK 184M and DKK 20.8M pre-tax profit. However, operating margins remain structurally thin (1.0–4.1% over 5 years), typical for an RTO but leaving limited buffer for shocks. Operating cash flow was negative DKK 42M in 2025 due to DKK 74M capex and grant timing. The 2026 guidance signals broadly flat revenue (DKK 1.3–1.4B) and net result DKK 10–15M lower than 2025, reflecting geopolitical and market uncertainty. Overall, the combination of very strong solvency, diversified funding, and long institutional history (since 1906) supports a high resilience score, tempered by inherent margin volatility.

Key strengths: Very strong equity ratio of 73.4% at end-2025, Current ratio of 173.3% with DKK 158M cash plus DKK 138M securities, Diversified revenue mix across commercial, R&D, and public performance-contract funding, GTS status provides tax exemption and multi-year state funding, Clean PwC audit opinion with no critical remarks, No material customer concentration; limited FX and interest-rate risk, Consistent revenue growth (CAGR ~6.3% 2021–2025), Subsidiary Danfysik delivered 18% revenue growth and DKK 20.8M pre-tax profit, Operating margin recovered to 2.9% in 2025 from 1.0% trough in 2024

Risk factors: Structurally thin operating margin (1.0–4.1% range over 5 years), Operating cash flow volatility (-DKK 42M in 2025, negative also in 2021), Dependence on public/foundation funding streams (~21% R&D segment), Geopolitical and market uncertainty flagged by management for 2026, Capital-intensive operations requiring DKK 74–85M annual tangible investment, Execution risk on long-duration R&D and commercial projects, 2026 guidance signals flat revenue and DKK 10–15M lower net result

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report