Skip to content
atlas

D-mærket

Also known as: D-seal, D-label

A Danish label showing that a company takes care of IT security and data, starting with a free self-check.

Draft - this entry has not been reviewed yet.

Formal

A Danish label scheme, first presented in 2019, with eight criteria spanning management, staff behaviour, technical IT security, supplier demands, openness about data, security built in, reliable AI and data ethics; every firm must meet the first five, the rest depending on its activities.

In plain English

Like the hygiene smiley on a restaurant door, but for how carefully a company treats the information and computers in its care.

In practice

The owner of a heating installer with 30 staff runs the free self-check, learns that backups have never been tested and that suppliers were never asked about security, fixes both and applies for the label.

Why it matters

Small firms rarely have a security team or budget for a full standard; the label gives them a plain starting point and a visible way to show customers they take data seriously.

How to put it into practice

The usual steps, in order. Adapt them to your organisation.

  1. Get management to decide to pursue the label and name an owner who can pull in IT, HR and the people who manage suppliers.
  2. Complete the free online self-evaluation, which places the company in one of four groups (I-IV) and shows which criteria and requirements apply.
  3. Use the answers as a gap analysis; criteria 1-5 (management, awareness, technical IT security, supplier requirements, transparency and control over data) apply to everyone, criteria 6-8 depending on your activities and group.
  4. Close the gaps and collect documentation for every requirement, such as policies, backup test records, supplier agreements and privacy information.
  5. When every question can be answered yes with documentation, request control in the tool, sign the declaration and pay the invoice.
  6. Take part in the start-up meeting with D-mærket's auditors, upload the documentation and answer their questions until it is approved and the label and report are issued.
  7. Act on the observations in the report and repeat the self-evaluation and control every year before the label expires.

Common pitfalls

  • Presenting the label as proof of NIS2 compliance or of the sufficient guarantees GDPR Art. 28 demands, which it does not provide on its own.
  • Producing documents for the control that do not match how the company actually works day to day.
  • Letting the yearly renewal slip so the label expires.

Good guides

Technical deep dive

D-mærket was announced on 30 October 2019 as a labelling scheme for IT security and responsible data use, created by Industriens Fond together with Dansk Industri, Dansk Erhverv, SMVdanmark and Forbrugerrådet Tænk, with Industriens Fond funding the build-up. It is run as an independent private organisation with support from Erhvervsstyrelsen, and it is voluntary: unlike NIS2 or GDPR it creates no legal duties, and unlike ISO 27001 certification it is not delivered by accredited certification bodies under ISO/IEC 17021-1. Its distinctive design choice is to combine security controls with data-ethics and algorithm requirements in a single mark aimed at small and medium-sized companies.

The scheme has eight criteria: 1 governance and management anchoring (Styring og forankring i ledelsen), 2 awareness and secure behaviour, 3 technical IT security, 4 requirements for suppliers' IT security and responsible data use, 5 transparency and control over data, 6 privacy and security by design and default, 7 trustworthy algorithms and AI, and 8 data ethics. Criteria 1-5 apply to every company. Criterion 6 applies to companies that develop software, criterion 7 to those that use or develop algorithms or AI, and criterion 8 to companies in groups II-IV and only exceptionally to group I. The self-evaluation places each company in one of four groups based on size, business model and use of data and IT services, and the group determines the concrete sub-criteria, so two labelled companies may have met quite different requirement sets.

The process runs in five steps: a free online self-evaluation that doubles as a gap analysis, a request for control once every applicable requirement can be answered yes with documentation, a start-up meeting and document review with D-mærket's own auditors, award of the label, and annual renewal that repeats the self-evaluation and control. Payment is charged only when control is requested. Because the label is valid for one year rather than on a three-year cycle with surveillance audits, drift is caught through the yearly renewal rather than mid-cycle checks.

Its limits matter when it is used as supplier evidence. The control is document-based and scoped by the self-assessment, so it says less about operational effectiveness than an ISO 27001 stage 2 audit or an ISAE 3000/3402 assurance report covering a period. It does not by itself demonstrate NIS2 compliance or GDPR Art. 28 "sufficient guarantees", though criteria 3-5 overlap substantially with NIS2 Art. 21 measures and GDPR Art. 32. For a small firm it is a structured, affordable baseline; for a regulated customer it is one input to supplier due diligence, not a substitute for contractual security terms.

What to learn first

Everything this builds on, foundations first.

  1. Compliance
  2. →D-mærket

Relationships

Requires
Compliance
Don't confuse with
ISO 27001

Sources & further reading

Official documentation

Course material

  • Cyber Security Fast Track - Ordliste
  • Cyber Security Fast Track - Kursuskompendium, Modul 8

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.