Telia Company
Sweden · owned by Swedish Government (Sweden) · teliacompany.com · 34 vendors
Reinvent better connected living
Resilience scores
- Digital Sovereignty: 26
- Digital Resilience: 7
- Financial Resilience: 6
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Nokia — Telecommunications — Finland
- and 33 more
Services catalogue
7 services in catalogue across 2 categories; runs on 34 sub-vendors.
- Telia DNS
- Telia Email Service
- Email Hosting
Insights
Last updated 2026-07-19 · revision 29
34 direct vendors, 295 subvendors
Direct vendors by controlling owner country (sample)
- Denmark: 1
- Switzerland: 1
- Sweden: 4
Subvendors by controlling owner country (sample)
- India: 3
- Canada: 11
- Sweden: 10
Migration Readiness: 7/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Telia Company exhibits a strong technical posture for migration readiness, earning a score of 65 out of 100. The company's internal tech stack is highly aligned with modern migration strategies, featuring extensive use of containerization (Kubernetes, Docker), multi-cloud platforms (Azure, AWS, GCP), and private cloud solutions (OpenStack, VMware). The presence of automation tools like Terraform and Ansible, along with robust CI/CD pipelines (Jenkins, GitLab CI/CD), indicates a mature DevOps culture and the technical capability to efficiently migrate and manage cloud-native workloads. The adoption of 'Cloud-Native Network Architecture' and 'NFV/SDN' further underscores its readiness for agile infrastructure transformation. Financially, stable revenues suggest the capacity to fund significant migration initiatives. Despite these technical strengths, substantial challenges exist, primarily stemming from the regulatory and data residency landscape. Critical regulations such as GDPR, NIS2, EU Electronic Communications Code, and the Swedish Electronic Communications Act are all 'Assessment Required' with 'High' risk. These regulations impose stringent requirements on data protection, cybersecurity, and network security, which will significantly complicate any migration, particularly to public cloud environments. Furthermore, explicit data residency requirements mandate compliance with GDPR for EU/EEA data, potential national security/lawful intercept requirements in operating jurisdictions, and specific localization for telecommunications metadata. These constraints will limit the choice of cloud regions and providers, necessitating complex architectural designs and legal reviews to ensure compliance. The vendor relationship data also presents an area of uncertainty. While 'Total Vendors: 0' is stated, 'Total Services: 92' and details about vendor geographic diversity imply existing vendor relationships. The 'Vendor Lock-in Risk: Unknown' is a significant concern, as unassessed vendor dependencies and contract complexities could introduce delays and increased costs during a migration. While vendor geographic diversity is good for resilience, it does not directly mitigate lock-in risk. Overall, Telia possesses the technical prowess for migration, but the complex regulatory and data residency environment, coupled with unknown vendor lock-in, will require meticulous planning and execution.
Compliance
13 in-scope frameworks identified; showing 3.
Data Retention Legislation — Assessment Required
Data retention is a High-risk area for Telia because: (1) Telecom operators are subject to national data retention laws requiring retention of communications metadata for law enforcement purposes; (2) The CJEU has repeatedly ruled against blanket data retention (Tele2/Watson 2016, La Quadrature du Net 2020, Prokuratuur 2021), creating legal uncertainty; (3) National laws in Sweden, Finland, Estonia, Latvia, Lithuania, and Denmark impose retention obligations that may conflict with CJEU rulings; (4) Telia must navigate conflicting obligations between national retention laws and GDPR/ePrivacy; (5) Non-compliance with national retention laws risks criminal liability; non-compliance with CJEU rulings risks GDPR enforcement.
Evidence: https://curia.europa.eu/juris/document/document.jsf?docid=185382&doclang=EN, https://www.teliacompany.com/en/sustainability/ethics-and-compliance/transparency-report, https://www.pts.se/en/
EU AI Act (source) — Assessment Required
The EU AI Act risk is Medium because Telia uses AI/ML systems in network management, customer service (chatbots), fraud detection, and marketing personalization. The AI Act's risk classification (prohibited, high-risk, limited-risk, minimal-risk) needs to be applied to each AI system Telia deploys. Most telecom AI applications are likely 'limited-risk' or 'minimal-risk', but AI used in credit scoring, customer profiling, or employment decisions could be 'high-risk'. The AI Act has a phased implementation timeline (2024-2027).
Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689, https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence
SOC 2 (source) — Assessment Required
SOC 2 risk is Medium because Telia Company provides cloud and managed IT services to enterprise customers through Telia Cygate and other B2B divisions, which creates customer expectations for SOC 2 attestation. However, SOC 2 is a voluntary US framework (AICPA), and European telecom operators typically use ISO 27001 as the primary information security certification rather than SOC 2. The risk is Medium because failure to obtain SOC 2 reports could affect Telia's competitiveness in enterprise/cloud service markets where US-headquartered customers require SOC 2 attestation.
Evidence: https://www.teliacompany.com/en/business/services, https://www.aicpa-cima.com/resources/landing/soc-2-reporting-on-an-examination-of-controls-at-a-service-organization-relevant-to-security-availability-processing-integrity-confidentiality-or-privacy
Financials
Three-year financials
- 2024: revenue SEK 87.55B, EBIT SEK 10.90B, equity SEK 72.00B
- 2023: revenue SEK 89.41B, EBIT SEK 4.70B, equity SEK 72.90B
- 2022: revenue SEK 89.08B, EBIT SEK -15.30B, equity SEK 78.70B
Financial Resilience Score: 6/10
Telia Company demonstrates moderate financial resilience anchored by its position as the leading telecom incumbent across the Nordic and Baltic region, with strong market shares in Sweden, Finland, Norway, Denmark, Lithuania, and Estonia. The company maintains investment-grade credit ratings (S&P BBB / Moody's Baa1 area) and benefits from stable state-anchored ownership, with the Swedish State holding approximately 39% and Solidium (Finnish State) also holding a significant stake. Underlying EBITDA has remained stable in the SEK 27-29 billion range across all three years, demonstrating robust core cash generation despite reported EBIT volatility. However, resilience is tempered by significant challenges. FY2022 saw large non-cash impairments (~SEK 20-24 billion) on Finnish and Norwegian cash-generating units, resulting in a substantial reported EBIT loss. Revenue has been essentially flat-to-declining in SEK terms over the past decade, reflecting mature Nordic markets with limited subscriber growth. Leverage has hovered around 2.5-2.8x net debt/EBITDA, near the upper end of Telia's own 2.0-2.5x target band. High capex intensity for fiber and 5G rollout has kept free cash flow under pressure, sometimes below dividend commitments. Portfolio simplification through divestments (TV & Media in 2024, towers in Sweden 2021 and Finland 2022) is releasing capital and improving focus, but ongoing restructuring and workforce reductions signal continued operational transition.
Key strengths: Leading Nordic/Baltic telecom incumbent with strong market shares, Investment-grade credit rating (S&P BBB / Moody's Baa1), State-anchored ownership (Swedish State ~39%, Solidium), Stable underlying EBITDA of SEK 27-29 billion across all three years, 5G and fiber leadership in the Nordics, Portfolio simplification through divestments releasing capital, Subscription-based recurring cash flows
Risk factors: History of large impairments (FY2022 SEK 20-24 billion write-downs), Mature Nordic markets with limited subscriber growth, High capex intensity for fiber and 5G rollouts, FCF sometimes below dividend commitments, FX exposure to NOK, EUR, DKK, Regulatory risk from EU and national telecom regulators, Leverage near upper end of target band (2.5-2.8x net debt/EBITDA), Legacy compliance obligations from Uzbekistan bribery settlement
Revenue by geography
- Sweden: 40%
- Finland: 19%
- Other: 11%
- Norway: 11%
- Lithuania: 7%
- Denmark: 6%
- Estonia: 5%
- Latvia: 1%
Revenue by product/service
- Mobile services: 42%
- B2B/Enterprise solutions: 18%
- Fixed broadband/fiber: 15%
- TV & content: 10%
- Equipment sales: 10%
- Fixed voice/legacy telephony: 5%
Workforce by country
- Sweden: 5800
- Finland: 3000
- Lithuania: 3000
- Other: 2200
- Estonia: 1800
- Norway: 1400
- Denmark: 900
- Latvia: 600
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.