Unit IT A/S
Denmark · owned by SelfGenerations T ApS (Denmark) · unit-it.dk · 12 vendors
Unit IT is a Danish full-service IT company that delivers IT solutions to ambitious businesses with complex IT needs or demanding business goals. Their services span infrastructure & cloud, managed services, cybersecurity, modern workplace, and data & AI. Originally founded as Outforce in 2003 in Middelfart, the company rebranded to Unit IT in 2019 following a series of acquisitions.
Resilience scores
- Digital Sovereignty: 42
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
Unit IT A/S has an estimated 27% probability of disruption in the next 6 months.
7 of Unit IT A/S's 12 vendors monitored for disruptions.
Technology vendors
- Cookiebot (Cybot A/S) — Technology — Denmark
- Cygrids A/S — Technology — Denmark
- HubSpot, Inc. — Technology — United States
- and 11 more
Services catalogue
7 services in catalogue across 4 categories; runs on 12 sub-vendors.
- UNIT-IT-SERVICES Hosting
- Affiliate marketing software
- Web Hosting
Insights
Last updated 2026-09-13 · revision 9
12 direct vendors, 186 subvendors
Direct vendors by controlling owner country (sample)
- Netherlands: 1
- Sweden: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Romania: 1
- Poland: 2
- China: 2
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Unit IT A/S exhibits high migration readiness, largely due to its core business offerings and existing technology stack. The company provides 'Azure Migration & Modernisation' and 'Cloud Consulting' services, indicating deep internal expertise and experience in planning and executing cloud migrations. Their current internal tech stack already incorporates Microsoft Azure and Kubernetes, demonstrating a significant existing adoption of modern, cloud-native technologies. This hybrid cloud environment (VMware and Azure) provides a solid foundation for further cloud adoption. Financial stability, indicated by 'Stable growth,' suggests the capacity to fund migration initiatives. However, the presence of VMware for private cloud, Citrix for virtual desktop infrastructure, and Active Directory suggests there may be legacy workloads or infrastructure components that would require careful planning and effort to migrate or modernize. Strict data residency requirements (Denmark/EU) and regulatory compliance (GDPR, NIS2) add complexity to migration, but as a service provider in this domain, Unit IT is likely well-versed in navigating these challenges. The 'Vendor Lock-in Risk: Unknown' and the contradictory 'Total Vendors: 0' data point make it difficult to fully assess potential vendor lock-in, which could impact migration flexibility. Despite these potential complexities, Unit IT's strong internal capabilities and strategic focus on cloud services position them with high migration readiness.
Compliance
11 in-scope frameworks identified; showing 3.
ISAE 3402 — Compliant
Risk is Low because Unit IT A/S holds a current ISAE 3402 Type II report (2025), which is the gold standard for IT service provider assurance. This directly addresses their role as a managed services and cloud infrastructure provider. Type II reports provide the highest level of assurance by covering both design and operating effectiveness of controls. The existence of this report significantly reduces risk for both Unit IT and their clients, as it provides independent verification of service delivery controls. Identified deviations have been formally responded to, demonstrating mature governance.
Evidence: https://unit-it.dk/om-os/certificering-compliance, https://unit-it.dk/hubfs/E-b%C3%B8ger%20og%20Downloads/Certifikater/ISAE%203402%202025%20type%20II.pdf, https://unit-it.dk/hubfs/E-b%C3%B8ger%20og%20Downloads/Certifikater/Svar%20p%C3%A5%20afvigelser%20i%20ISAE%203402%20%26%20ISAE%203000.pdf, https://unit-it.dk/hubfs/E-b%C3%B8ger%20og%20Downloads/Certifikater/Status%202%20on%20deviations%20from%203402%20audit%20-%20underskrevet.pdf
NIS2 (source) — Assessment Required
NIS2 risk is High for Unit IT A/S for several compounding reasons: (1) As a Danish ICT managed services provider with 250+ employees, they likely meet or exceed the 'medium enterprise' threshold (50+ employees or €10M+ turnover) required for NIS2 applicability; (2) They fall squarely within the NIS2 'Important Entities' category under Annex II — specifically 'ICT service management (B2B)' which explicitly covers managed service providers; (3) Their parent group USTC has 4,000+ employees and 150 billion DKK turnover, further supporting size threshold applicability; (4) They serve critical infrastructure clients (TV2 Denmark, transport companies like Sydtrafik) meaning a security incident at Unit IT could cascade to essential entities; (5) Denmark's NIS2 implementation (Lov om sikkerhed i net- og informationssystemer) entered into force in 2024, and the Danish Centre for Cyber Security (CFCS) is actively enforcing; (6) Non-compliance penalties can reach €10M or 2% of global annual turnover. Risk is 'Assessment Required' rather than confirmed because no public NIS2 registration or compliance declaration has been found.
Evidence: https://unit-it.dk/om-os, https://unit-it.dk/om-os/certificering-compliance, https://unit-it.dk/services/managed-services, https://unit-it.dk/services/cyber-security, https://unit-it.dk/services/infrastructure-cloud, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
DORA (source) — Assessment Required
Risk is Medium because DORA (applicable from January 2025) primarily targets financial entities (banks, insurance companies, investment firms) and their critical ICT third-party service providers. Unit IT serves enterprise clients and their client portfolio includes financial sector companies (Leasing Fyn is a financial services company). If Unit IT is classified as a 'critical ICT third-party service provider' to financial entities under DORA, they would face direct regulatory obligations including oversight by EU supervisory authorities. Risk is Medium rather than High because: (1) DORA's direct obligations fall primarily on financial entities, not their IT providers; (2) Unit IT's classification as 'critical' under DORA depends on their materiality to financial sector clients; (3) However, their financial sector clients will impose DORA-derived contractual requirements on Unit IT as their ICT provider.
Evidence: https://unit-it.dk/cases/leasing-fyn, https://unit-it.dk/services/managed-services/disaster-recovery-as-a-service, https://unit-it.dk/om-os/certificering-compliance
Financials
Three-year financials
- 2025: gross profit DKK 99.1M, EBIT DKK -19.4M, equity DKK 28.5M
- 2024: gross profit DKK 121M, EBIT DKK 4.17M, equity DKK 42.7M
- 2023: EBIT DKK 19.7M, equity DKK 39.9M
Financial Resilience Score: 7/10
Unit IT A/S benefits from strong parent-group backing as a subsidiary of USTC (United Shipping & Trading Company), a Danish conglomerate with approximately DKK 150 billion in revenue and over 4,000 employees across ~40 countries. This provides balance-sheet support, a stable anchor client base, and a long investment horizon without pressure to IPO or exit. The company's business model emphasizes recurring revenue through managed services, private cloud, IT operations, and cyber defence, implying multi-year contracts and predictable ARR-like revenue streams. High-end certifications (ISO 27001, ISO 22301, ISAE 3402, ISAE 3000) create switching costs and support pricing power in regulated Danish mid-market and public-sector customers. However, several risks temper this resilience. Related-party concentration is likely material, with an undisclosed but meaningful share of revenue coming from USTC group companies (Bunker Holding, Uni-Tankers, etc.). If USTC's fuel/shipping cycle turns, IT spend at the parent could compress. Management's public language about 'several years of transformation' often correlates with restructuring charges, goodwill write-downs, or weak operating margins. Wage inflation and talent competition in the Danish IT services market persistently pressure margins for a headcount-driven business. The purely domestic footprint (all seven locations in Denmark) and mid-sized scale (~250 FTEs) versus larger competitors like NNIT, Netcompany, KMD, Fujitsu Denmark, and Atea Denmark limits diversification and scale advantages. Specific financial figures (revenue, EBIT, equity) were not retrieved in the source research, so quantitative confirmation of resilience is unavailable.
Key strengths: Parent-group backing from USTC (~DKK 150B revenue, 4,000+ employees globally), Recurring revenue model based on managed services and multi-year contracts, High-end certifications (ISO 27001, ISO 22301, ISAE 3402, ISAE 3000) create switching costs, Diversified blue-chip customer base (Universal Robots, TV 2 Danmark, Sydtrafik, WOCA, etc.), Strong vendor partnerships with Microsoft, VMware, Citrix, Veeam, IBM, Fortinet, Cisco, ~30 years of operating history (CVR registered since mid-1990s), Completion of multi-year transformation program signaling stabilization
Risk factors: Related-party concentration with undisclosed intercompany revenue share from USTC, Exposure to USTC's fuel/shipping cycle for internal IT spend, Transformation-related restructuring costs and potential goodwill write-downs, Wage inflation and talent competition in Danish IT services market, Purely domestic footprint with no geographic diversification, Mid-sized scale versus larger competitors (NNIT, Netcompany, KMD, Fujitsu, Atea), Customer concentration not publicly disclosed
Revenue by geography
- Denmark: 100%
Workforce by country
- Denmark: 250
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.