Børne- og Undervisningsministeriet (Ministry of Children and Education)
Denmark · owned by Government of Denmark (Denmark) · uvm.dk · 37 vendors
The Danish Ministry of Children and Education is responsible for creating strong educational programs for all citizens. The ministry oversees early childhood education, primary and secondary education, vocational training, and adult education in Denmark.
Resilience scores
- Digital Sovereignty: 41
- Digital Resilience: 4
- Financial Resilience: 10
Technology vendors
- Adobe Inc. — Technology — United States
- Cookiebot (Cybot A/S) — Technology — Denmark
- Usercentrics GmbH — Technology — Germany
- and 34 more
Insights
Last updated 2026-09-18 · revision 26
37 direct vendors, 365 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- Finland: 1
- Japan: 4
Subvendors by controlling owner country (sample)
- United Kingdom: 12
- Poland: 3
- South Korea: 1
Migration Readiness: 4/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
The ministry exhibits a moderate level of migration readiness, scoring 40. Its internal tech stack and development practices are conducive to migration, featuring a primary philosophy of Open Source Software, Agile Development Methodologies, and an existing Private/Own Cloud Infrastructure. This experience with a self-hosted cloud environment provides a strong foundation for understanding cloud operations and potentially migrating to public cloud services. Stable financial growth also indicates the capacity to fund migration initiatives. However, several significant challenges impede higher readiness. Strict Danish and EU data residency requirements necessitate meticulous planning for any cloud migration, limiting options and increasing complexity to ensure data sovereignty and GDPR compliance. The 'Assessment Required' status and 'High Risk' for GDPR and NIS2, along with 'Medium Risk' for ISO 27001, mean that regulatory compliance will be a major hurdle, requiring extensive due diligence and potentially costly adjustments during migration. The ministry's reliance on 58 services, coupled with an 'Unknown' vendor lock-in risk, suggests a complex vendor landscape that could make disentangling dependencies and migrating systems challenging. While the internal tech stack is modern, the absence of explicit mention of cloud-native architectures like containerization or microservices implies that a direct 'lift and shift' to a public cloud might require significant refactoring, adding to migration effort and cost.
Compliance
7 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
Risk is Medium because: (1) ISO 27001 certification is not legally mandated for Danish public sector entities, but it is strongly recommended and increasingly expected, particularly for entities operating critical national IT infrastructure. (2) STIL operates society-critical IT infrastructure for over one million daily users — the absence of ISO 27001 certification would represent a significant security governance gap. (3) The Danish government's digitisation strategy and NIS2 requirements effectively push public sector entities toward ISO 27001 alignment. (4) Risk is not 'High' because ISO 27001 is voluntary and non-certification does not directly trigger regulatory penalties (unlike GDPR or NIS2 non-compliance). However, failure to implement equivalent controls could increase NIS2 and GDPR risk exposure.
Evidence: https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed/, https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed-og-databeskyttelse-i-undervisningssektoren/, https://stil.dk/media/hefdzqyr/250825-informationssikkerhed-anbefalinger-for-selvejende-institutioner.pdf, https://stil.dk/media/htcmy3no/den-paedagogiske-it-beredskabsplan.pdf
Danish Data Protection Act — Partially Compliant
Risk is High because: (1) The Danish Data Protection Act (Act No. 502 of 23 May 2018, as amended) supplements GDPR with Danish-specific provisions, including stricter rules for processing sensitive data about children and special categories of data. (2) The ministry processes large volumes of children's data, special education data, and integration programme data — all subject to heightened protection under Danish law. (3) Datatilsynet (the Danish DPA) has enforcement authority and has issued guidance specifically for the education sector. (4) Non-compliance can result in criminal prosecution under Danish law in addition to GDPR administrative fines. Status is 'Partially Compliant' for the same reasons as GDPR — key compliance measures are in place but full verification is not possible from public sources.
Evidence: https://uvm.dk/ministeriet/om-ministeriet/behandling-af-personoplysninger/generel-information/, https://uvm.dk/ministeriet/om-ministeriet/behandling-af-personoplysninger/, https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed-og-databeskyttelse-i-undervisningssektoren/
NIS2 (source) — Assessment Required
Risk is High because: (1) NIS2 Directive (EU 2022/2555), transposed into Danish law via the Lov om sikkerhed i net- og informationssystemer (NIS2-loven), explicitly lists 'public administration' as an Essential Entity sector. The ministry is a central government public administration body. (2) STIL operates what it describes as 'samfundskritisk it-infrastruktur' (society-critical IT infrastructure) reaching over one million daily users — this language directly aligns with NIS2's critical infrastructure scope. (3) Non-compliance with NIS2 for Essential Entities can result in fines up to €10M or 2% of global annual turnover, plus personal liability for management. (4) The Danish NIS2 implementation (effective October 2024) requires Essential Entities in public administration to register with the national authority, implement risk management measures, and report significant incidents. (5) The ministry clearly exceeds the size thresholds (50+ employees, €10M+ budget). Formal assessment is required to confirm exact scope classification and verify implementation status.
Evidence: https://stil.dk/om-styrelsen/styrelsens-maal-og-opgaver/sammenhaengende-digitalisering-og-samfundskritisk-it-infrastruktur/, https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed-og-databeskyttelse-i-undervisningssektoren/, https://stil.dk/media/htcmy3no/den-paedagogiske-it-beredskabsplan.pdf, https://stil.dk/informationssikkerhed-og-it-drift/informationssikkerhed/
Financials
Three-year financials
- 2024: revenue DKK 51.5B
- 2023: revenue DKK 49.5B
- 2022: revenue DKK 47.5B
Financial Resilience Score: 10/10
As a Danish government ministry, Børne- og Undervisningsministeriet operates with sovereign backing from the Danish state, which holds AAA credit ratings from both S&P and Moody's. Its funding is set annually by the Folketing through the Finanslov (§20), providing exceptionally stable and predictable financial support. There is no going-concern risk in the commercial sense, as the ministry does not generate revenue or profit but rather receives appropriations to fund Denmark's education system. A significant portion of the budget consists of rule-based statutory obligations, such as taxameter grants to gymnasier, erhvervsuddannelser, frie grundskoler, and efterskoler, making funding highly predictable for both the ministry and downstream institutions. Long-term political consensus on universal education funding in Denmark further reinforces financial stability. However, the ministry faces demographic pressures from shrinking youth cohorts in provincial regions, requiring reorganization of the institutional landscape. Reform and reorganization risks exist due to repeated renaming and portfolio shifts across governments. Political spending cycles periodically introduce new agreements (e.g., folkeskolens kvalitetsprogram, EPX gymnasium reform) that may be partially unfunded, and emerging challenges like AI-related exam integrity require rapid policy responses.
Key strengths: Sovereign funding backed by AAA-rated Danish state, Annual appropriations set by Folketing via Finanslov §20, Large rule-based statutory obligations (taxameter grants), Long-term political consensus on universal education funding, No going-concern risk in commercial sense
Risk factors: Demographic pressure from shrinking youth cohorts in provincial regions, Reform and reorganization risk with frequent ministry renaming and portfolio shifts, Political spending cycles introducing partially unfunded initiatives, AI and digitalization pressures on exams and assessment
Revenue by geography
- Denmark: 100%
Revenue by product/service
- Erhvervsuddannelser (EUD) incl. AUB/praktik: 27%
- Gymnasiale uddannelser (STX, HHX, HTX, HF, EPX): 22%
- Frie grundskoler, efterskoler, frie fagskoler: 17%
- Voksen- og efteruddannelse (AMU, AVU, FVU): 12%
- Øvrige puljer, tilskud, internationalt samarbejde: 10%
- Forberedende grunduddannelse (FGU): 6%
- Dagtilbudsområdet: 4%
- Departement + styrelser (drift): 2%
Workforce by country
- Denmark: 1150
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.