twoday
Denmark · www.twoday.com · 9 vendors
twoday is a Nordic technology and IT consulting company specializing in applied AI, advanced engineering, data, software, and cloud solutions. The company provides services in software engineering, data & AI, digital experiences, and business applications to private and public sector organizations. Established in 2022 from Visma's consulting business, twoday aims to drive digital transformation for its clients across the Nordics and Lithuania.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 8
- Financial Resilience: 7
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Demandware — Technology — United States
- and 6 more
Services catalogue
5 services in catalogue across 4 categories; runs on 9 sub-vendors.
- IT development and conversion
- digital transformation
- Application development
Insights
Last updated 2026-09-13 · revision 2
9 direct vendors, 194 subvendors
Direct vendors by controlling owner country (sample)
- United States: 6
- Denmark: 2
- Sweden: 1
Subvendors by controlling owner country (sample)
- United States: 129
- Portugal: 2
- Netherlands: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
twoday exhibits very high migration readiness, largely driven by its core business offerings and internal technological alignment. The company's product portfolio includes 'Cloud Platforms & Security' services focused on cloud migration and management for Microsoft Azure and AWS, demonstrating deep internal expertise and experience in this domain. Its internal tech stack is heavily cloud-native, utilizing Azure, AWS, Databricks, Snowflake, and various Microsoft Power Platform and AI tools, which are inherently conducive to flexible and efficient migration. The multi-cloud strategy (Azure and AWS) further indicates a lack of significant lock-in to a single cloud provider and a capability to operate in diverse cloud environments. The diverse set of major technology vendors used internally also minimizes vendor lock-in risks that could complicate migration efforts. While specific data on twoday's own data residency requirements or detailed regulatory environment is not provided, the company's expertise in GDPR compliance (as seen in products like Addo Sign) suggests an understanding of regulatory landscapes relevant to migration. The overall picture points to a highly agile and capable organization for digital migration.
Compliance
10 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 risk is Medium because: (1) Twoday is a large technology services company (3,000 employees) providing cloud, security, and data services — a profile where ISO 27001 is a near-universal market expectation, (2) Twoday holds Microsoft Security Solution Partner designation (including Cloud Security, Data Security, Threat Protection, Identity & Access Management specializations), which requires demonstrating security competency but does not itself constitute ISO 27001 certification, (3) clients in government, finance, health, and energy sectors typically mandate ISO 27001 from their technology suppliers, (4) no ISO 27001 certificate is publicly listed on the partnerships/certificates page or Trust Center. Risk is Medium because the absence of a publicly confirmed ISO 27001 certificate creates supplier risk for regulated-sector clients, though the company may hold certifications not publicly disclosed.
Evidence: https://www.twoday.com/about/partnerships-certificates, https://www.twoday.com/trustcenter/security, https://www.twoday.com/services/cloud-platforms-and-security, https://www.iso.org/standard/27001
DORA (source) — Assessment Required
DORA risk is Medium because: (1) Twoday serves financial sector clients (Finance & Insurance industry vertical) and provides ICT services to them, (2) under DORA (applicable from January 2025), ICT third-party service providers to EU financial entities may be designated as 'Critical ICT Third-Party Providers' (CTPPs) subject to direct EU oversight, (3) even without CTPP designation, Twoday's financial sector clients are required under DORA to include specific contractual provisions in ICT service agreements, conduct due diligence on ICT providers, and manage concentration risk, (4) Twoday's cloud and data services to financial institutions trigger DORA supply chain obligations. Risk is Medium rather than High because CTPP designation requires a formal ESA determination and applies to the largest/most systemic providers.
Evidence: https://www.twoday.com/finance-and-insurance, https://www.twoday.com/trustcenter, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554, https://www.eba.europa.eu/regulation-and-policy/digital-operational-resilience-act-dora
GDPR (source) — Partially Compliant
Twoday is headquartered in Denmark (EU), making GDPR universally applicable. As a large technology services company with ~3,000 employees processing personal data of employees, clients, and end-users across multiple Nordic countries, the scope of GDPR obligations is extensive. The company has a publicly accessible Trust Center with a dedicated Privacy section and a Whistleblowing Channel (required under EU Whistleblower Directive, complementary to GDPR accountability), indicating active compliance investment. However, no publicly available DPO appointment record, GDPR audit report, or Data Processing Agreement (DPA) template was found on the public-facing website, preventing a 'Compliant' determination. The risk level is Medium rather than High because the company demonstrates clear awareness of privacy obligations and has structured governance in place, but the absence of publicly verifiable audit evidence introduces residual risk. Danish DPA (Datatilsynet) enforcement is active, with fines issued to Danish companies in recent years.
Evidence: https://www.twoday.com/trustcenter/privacy, https://www.twoday.com/trustcenter, https://www.twoday.com/privacy-policy, https://www.datatilsynet.dk/english, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
Financials
Three-year financials
- 2025: revenue DKK 972M, EBIT DKK 82.8M, equity DKK 305M
- 2024: revenue DKK 963M, EBIT DKK 74.1M, equity DKK 238M
- 2002: revenue DKK 492M, EBIT DKK 69.0M, equity DKK 87.0M
Financial Resilience Score: 7/10
Twoday demonstrates solid financial resilience, supported by its scale in the fragmented Nordic IT services market (~€390m revenue, 2,300-3,000 experts) and significant margin expansion. Despite essentially flat revenue growth in 2025 (+0.9%), the company grew adjusted EBITDA margin from ~11.3% to 16.4%, well above the guided 13-15% range, indicating disciplined cost management and a favorable mix shift toward higher-value data/AI work. Core business revenue grew 8.2% to €340.1m, showing underlying business strength masked by the winding down of non-core activities. The company benefits from elite technology partnerships (Microsoft Inner Circle top 1% globally, Databricks Gold Partner, Snowflake Elite, top-tier AWS), a diversified customer base spanning public sector and private enterprises, and strong private equity backing from Axcel providing capital for consolidation and long-term investment. However, the 2025 revenue growth missed the 5-10% guided range, reflecting Nordic macro caution and consulting industry cyclicality. Limited public financial transparency (no EBIT, net income, equity, or leverage figures disclosed) and typical PE-backed capital structure risks temper the score, as does M&A integration risk from multiple acquisitions and brand consolidations.
Key strengths: Significant EBITDA margin expansion from 11.3% to 16.4% adjusted in 2025, Scale as one of the larger Nordic IT-consulting groups (~€390m revenue), Elite technology partnerships (Microsoft Inner Circle, Databricks Gold, Snowflake Elite, AWS), Diversified customer base across public and private sectors, Private equity backing from Axcel provides long-term capital, Core business grew 8.2% to €340.1m in 2025, ~700 data & AI specialists across the group
Risk factors: Revenue stagnation - only +0.9% growth in 2025, missing 5-10% guidance, Consulting industry cyclicality and exposure to discretionary IT spend, M&A integration risk from Kaito acquisition and Nordic brand consolidations, Talent competition and wage inflation in hot AI-talent market, Limited public financial transparency (no EBIT, net income, or equity disclosed), Currency risk - reports in EUR while costs/revenue in DKK, SEK, NOK, Growing gap between reported and adjusted EBITDA suggests ongoing one-off costs, Headcount variance (2,300 vs 3,000) may indicate 2025 rightsizing
Revenue by product/service
- Core business (Data, AI, Agentic Engineering, Digital Foundations): 87%
- Non-core / Other: 13%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.