D-mærket
Also known as: D-seal, D-label
A Danish label showing that a company takes care of IT security and data, starting with a free self-check.
Draft - this entry has not been reviewed yet.
Formal
A Danish label scheme, first presented in 2019, with eight criteria spanning management, staff behaviour, technical IT security, supplier demands, openness about data, security built in, reliable AI and data ethics; every firm must meet the first five, the rest depending on its activities.
In plain English
Like the hygiene smiley on a restaurant door, but for how carefully a company treats the information and computers in its care.
In practice
The owner of a heating installer with 30 staff runs the free self-check, learns that backups have never been tested and that suppliers were never asked about security, fixes both and applies for the label.
Why it matters
Small firms rarely have a security team or budget for a full standard; the label gives them a plain starting point and a visible way to show customers they take data seriously.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Get management to decide to pursue the label and name an owner who can pull in IT, HR and the people who manage suppliers.
- Complete the free online self-evaluation, which places the company in one of four groups (I-IV) and shows which criteria and requirements apply.
- Use the answers as a gap analysis; criteria 1-5 (management, awareness, technical IT security, supplier requirements, transparency and control over data) apply to everyone, criteria 6-8 depending on your activities and group.
- Close the gaps and collect documentation for every requirement, such as policies, backup test records, supplier agreements and privacy information.
- When every question can be answered yes with documentation, request control in the tool, sign the declaration and pay the invoice.
- Take part in the start-up meeting with D-mærket's auditors, upload the documentation and answer their questions until it is approved and the label and report are issued.
- Act on the observations in the report and repeat the self-evaluation and control every year before the label expires.
Common pitfalls
- Presenting the label as proof of NIS2 compliance or of the sufficient guarantees GDPR Art. 28 demands, which it does not provide on its own.
- Producing documents for the control that do not match how the company actually works day to day.
- Letting the yearly renewal slip so the label expires.
Good guides
- D-mærkets kriterier(opens in a new tab) · D-mærket (in Danish)
- Processen for at blive D-mærket(opens in a new tab) · D-mærket (in Danish)
- Virksomhedsgrupper(opens in a new tab) · D-mærket (in Danish)
Technical deep dive
D-mærket was announced on 30 October 2019 as a labelling scheme for IT security and responsible data use, created by Industriens Fond together with Dansk Industri, Dansk Erhverv, SMVdanmark and Forbrugerrådet Tænk, with Industriens Fond funding the build-up. It is run as an independent private organisation with support from Erhvervsstyrelsen, and it is voluntary: unlike NIS2 or GDPR it creates no legal duties, and unlike ISO 27001 certification it is not delivered by accredited certification bodies under ISO/IEC 17021-1. Its distinctive design choice is to combine security controls with data-ethics and algorithm requirements in a single mark aimed at small and medium-sized companies.
The scheme has eight criteria: 1 governance and management anchoring (Styring og forankring i ledelsen), 2 awareness and secure behaviour, 3 technical IT security, 4 requirements for suppliers' IT security and responsible data use, 5 transparency and control over data, 6 privacy and security by design and default, 7 trustworthy algorithms and AI, and 8 data ethics. Criteria 1-5 apply to every company. Criterion 6 applies to companies that develop software, criterion 7 to those that use or develop algorithms or AI, and criterion 8 to companies in groups II-IV and only exceptionally to group I. The self-evaluation places each company in one of four groups based on size, business model and use of data and IT services, and the group determines the concrete sub-criteria, so two labelled companies may have met quite different requirement sets.
The process runs in five steps: a free online self-evaluation that doubles as a gap analysis, a request for control once every applicable requirement can be answered yes with documentation, a start-up meeting and document review with D-mærket's own auditors, award of the label, and annual renewal that repeats the self-evaluation and control. Payment is charged only when control is requested. Because the label is valid for one year rather than on a three-year cycle with surveillance audits, drift is caught through the yearly renewal rather than mid-cycle checks.
Its limits matter when it is used as supplier evidence. The control is document-based and scoped by the self-assessment, so it says less about operational effectiveness than an ISO 27001 stage 2 audit or an ISAE 3000/3402 assurance report covering a period. It does not by itself demonstrate NIS2 compliance or GDPR Art. 28 "sufficient guarantees", though criteria 3-5 overlap substantially with NIS2 Art. 21 measures and GDPR Art. 32. For a small firm it is a structured, affordable baseline; for a regulated customer it is one input to supplier due diligence, not a substitute for contractual security terms.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →D-mærket
Relationships
- Requires
- Compliance
- Don't confuse with
- ISO 27001
Sources & further reading
Official documentation
- D-mærket
- D-mærkets kriterier · D-mærket
Course material
- Cyber Security Fast Track - Ordliste
- Cyber Security Fast Track - Kursuskompendium, Modul 8
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…