D-mærket
Also known as: D-seal, D-label
A Danish label showing that a company takes care of IT security and data, starting with a free self-check.
Draft - this entry has not been reviewed yet.
Formal
A Danish label scheme, first presented in 2019, with eight criteria spanning management, staff behaviour, technical IT security, supplier demands, openness about data, security built in, reliable AI and data ethics; every firm must meet the first five, the rest depending on its activities.
In plain English
Like the hygiene smiley on a restaurant door, but for how carefully a company treats the information and computers in its care.
In practice
The owner of a heating installer with 30 staff runs the free self-check, learns that backups have never been tested and that suppliers were never asked about security, fixes both and applies for the label.
Why it matters
Small firms rarely have a security team or budget for a full standard; the label gives them a plain starting point and a visible way to show customers they take data seriously.
Technical deep dive
D-mærket was announced on 30 October 2019 as a labelling scheme for IT security and responsible data use, created by Industriens Fond together with Dansk Industri, Dansk Erhverv, SMVdanmark and Forbrugerrådet Tænk, with Industriens Fond funding the build-up. It is run as an independent private organisation with support from Erhvervsstyrelsen, and it is voluntary: unlike NIS2 or GDPR it creates no legal duties, and unlike ISO 27001 certification it is not delivered by accredited certification bodies under ISO/IEC 17021-1. Its distinctive design choice is to combine security controls with data-ethics and algorithm requirements in a single mark aimed at small and medium-sized companies.
The scheme has eight criteria: 1 governance and management anchoring (Styring og forankring i ledelsen), 2 awareness and secure behaviour, 3 technical IT security, 4 requirements for suppliers' IT security and responsible data use, 5 transparency and control over data, 6 privacy and security by design and default, 7 trustworthy algorithms and AI, and 8 data ethics. Criteria 1-5 apply to every company. Criterion 6 applies to companies that develop software, criterion 7 to those that use or develop algorithms or AI, and criterion 8 to companies in groups II-IV and only exceptionally to group I. The self-evaluation places each company in one of four groups based on size, business model and use of data and IT services, and the group determines the concrete sub-criteria, so two labelled companies may have met quite different requirement sets.
The process runs in five steps: a free online self-evaluation that doubles as a gap analysis, a request for control once every applicable requirement can be answered yes with documentation, a start-up meeting and document review with D-mærket's own auditors, award of the label, and annual renewal that repeats the self-evaluation and control. Payment is charged only when control is requested. Because the label is valid for one year rather than on a three-year cycle with surveillance audits, drift is caught through the yearly renewal rather than mid-cycle checks.
Its limits matter when it is used as supplier evidence. The control is document-based and scoped by the self-assessment, so it says less about operational effectiveness than an ISO 27001 stage 2 audit or an ISAE 3000/3402 assurance report covering a period. It does not by itself demonstrate NIS2 compliance or GDPR Art. 28 "sufficient guarantees", though criteria 3-5 overlap substantially with NIS2 Art. 21 measures and GDPR Art. 32. For a small firm it is a structured, affordable baseline; for a regulated customer it is one input to supplier due diligence, not a substitute for contractual security terms.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →D-mærket
Relationships
- Requires
- Compliance
- Don't confuse with
- ISO 27001
Sources & further reading
Official documentation
- D-mærket
- D-mærkets kriterier · D-mærket
Course material
- Cyber Security Fast Track - Ordliste
- Cyber Security Fast Track - Kursuskompendium, Modul 8
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…