Valg
Denmark · valg.dk · 6 vendors
KOMBIT A/S is a municipally owned IT community in Denmark. It is responsible for procuring, managing, operating, and further developing IT solutions and infrastructure for the benefit of Danish citizens and businesses, including the official election portal valg.dk. KOMBIT's work encompasses over 30 nationwide IT solutions for municipalities.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 5
Technology vendors
- F5 — Technology — United States
- Google LLC — Technology — United States
- Microsoft Corporation — Technology — United States
- and 3 more
Insights
Last updated 2026-03-28 · revision 2
6 direct vendors, 122 subvendors
Direct vendors by controlling owner country (sample)
- United States: 4
- Japan: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- India: 1
- Denmark: 2
- China: 1
Migration Readiness: 3/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Valg's migration readiness is assessed as low (1-30), primarily due to the critical lack of information across several key dimensions. The internal tech stack, including details on cloud-nativity, containerization, or microservices adoption, is completely unknown. This is a fundamental gap, as the existing architecture significantly dictates the complexity and feasibility of migration. Similarly, specific regulatory environment details and data residency requirements are either not specified or unknown, which could introduce unforeseen challenges or costs during a migration. Financial stability, crucial for funding a potentially large-scale migration, is also unassessed due to missing revenue and growth data. Regarding vendor relationships, a contradiction exists with 'Total Vendors: 0' versus 'Total Services: 21' and 'Vendor Geographic Diversity: 3 unique countries'. Assuming vendors exist, Valg utilizes 21 services from vendors with headquarters in Denmark, Japan, and the United States. While there is some geographic diversity, the 'Vendor Lock-in Risk' is explicitly stated as 'Unknown'. The number of vendors is not clear (assuming >0), making it difficult to assess the degree of vendor lock-in. If a significant number of these 21 services are provided by a few key vendors, this could present a high vendor lock-in risk, complicating migration efforts. The geographic diversity of vendors could also add complexity if different contractual or compliance frameworks need to be navigated during a migration. Without data on the tech stack, specific regulatory requirements, financial capacity, or a clear understanding of vendor lock-in, Valg faces significant unknowns and potential challenges in any migration initiative. Therefore, migration readiness is considered low.
Compliance
4 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is voluntary but increasingly expected for companies handling sensitive data or providing technology services. Medium risk due to competitive disadvantage and customer requirements rather than regulatory penalties. Risk level varies by industry and customer base.
NIS2 (source) — Assessment Required
NIS2 applicability depends on company size (50+ employees OR €10M+ turnover) and sector classification. Without knowing Valg's specific industry and size, assessment is required. If applicable, medium risk due to significant cybersecurity requirements and potential business disruption from non-compliance, though penalties are less severe than GDPR.
GDPR (source) — Assessment Required
GDPR applies to all companies in EU/EEA (including Denmark) that process personal data. Given Denmark's EU membership, GDPR compliance is mandatory regardless of company size or industry. High risk due to significant penalties (up to 4% of annual turnover or €20M) and strict enforcement in Denmark. The Danish Data Protection Agency actively enforces GDPR with regular audits and investigations.
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: null/10
No financial data was retrievable for Valg (valg.dk) from any public source, including the company's own website, the Danish Central Business Register (CVR/virk.dk), Proff.dk, LinkedIn, or archival sources. As a result, a quantitative resilience score cannot be assigned. The entity's nature — whether a private commercial company, a micro-entity, or a government-affiliated portal — remains unconfirmed, making any financial resilience assessment speculative. If the entity is a government-affiliated election portal, it would likely benefit from stable public funding and carry no commercial revenue risk. If it is a small private Danish company (ApS or similar), it may operate under limited public disclosure obligations under Danish accounting law (Årsregnskabsloven), which would explain the absence of accessible financial data. The opacity of the website and the inability to render any content suggest the site may be inactive, under construction, or access-restricted, which itself represents an operational risk signal.
Key strengths: Possible government affiliation would imply stable public funding, Denmark's strong rule of law and business environment generally supports stable SME operations, Danish companies are required to file annual reports with CVR, providing a potential data source if access is obtained
Risk factors: Complete opacity — no financial, operational, or structural data retrievable from any source, Website returned no renderable content, suggesting possible inactivity or restricted access, If a micro-entity, likely has limited capital buffers and minimal public disclosure, Generic domain name does not signal a defensible commercial niche, Industry and business model entirely unconfirmed
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.