Skip to content
atlas

D-mærket

Also known as: D-seal, D-label

A Danish label showing that a company takes care of IT security and data, starting with a free self-check.

Draft - this entry has not been reviewed yet.

Formal

A Danish label scheme, first presented in 2019, with eight criteria spanning management, staff behaviour, technical IT security, supplier demands, openness about data, security built in, reliable AI and data ethics; every firm must meet the first five, the rest depending on its activities.

In plain English

Like the hygiene smiley on a restaurant door, but for how carefully a company treats the information and computers in its care.

In practice

The owner of a heating installer with 30 staff runs the free self-check, learns that backups have never been tested and that suppliers were never asked about security, fixes both and applies for the label.

Why it matters

Small firms rarely have a security team or budget for a full standard; the label gives them a plain starting point and a visible way to show customers they take data seriously.

Technical deep dive

D-mærket was announced on 30 October 2019 as a labelling scheme for IT security and responsible data use, created by Industriens Fond together with Dansk Industri, Dansk Erhverv, SMVdanmark and Forbrugerrådet Tænk, with Industriens Fond funding the build-up. It is run as an independent private organisation with support from Erhvervsstyrelsen, and it is voluntary: unlike NIS2 or GDPR it creates no legal duties, and unlike ISO 27001 certification it is not delivered by accredited certification bodies under ISO/IEC 17021-1. Its distinctive design choice is to combine security controls with data-ethics and algorithm requirements in a single mark aimed at small and medium-sized companies.

The scheme has eight criteria: 1 governance and management anchoring (Styring og forankring i ledelsen), 2 awareness and secure behaviour, 3 technical IT security, 4 requirements for suppliers' IT security and responsible data use, 5 transparency and control over data, 6 privacy and security by design and default, 7 trustworthy algorithms and AI, and 8 data ethics. Criteria 1-5 apply to every company. Criterion 6 applies to companies that develop software, criterion 7 to those that use or develop algorithms or AI, and criterion 8 to companies in groups II-IV and only exceptionally to group I. The self-evaluation places each company in one of four groups based on size, business model and use of data and IT services, and the group determines the concrete sub-criteria, so two labelled companies may have met quite different requirement sets.

The process runs in five steps: a free online self-evaluation that doubles as a gap analysis, a request for control once every applicable requirement can be answered yes with documentation, a start-up meeting and document review with D-mærket's own auditors, award of the label, and annual renewal that repeats the self-evaluation and control. Payment is charged only when control is requested. Because the label is valid for one year rather than on a three-year cycle with surveillance audits, drift is caught through the yearly renewal rather than mid-cycle checks.

Its limits matter when it is used as supplier evidence. The control is document-based and scoped by the self-assessment, so it says less about operational effectiveness than an ISO 27001 stage 2 audit or an ISAE 3000/3402 assurance report covering a period. It does not by itself demonstrate NIS2 compliance or GDPR Art. 28 "sufficient guarantees", though criteria 3-5 overlap substantially with NIS2 Art. 21 measures and GDPR Art. 32. For a small firm it is a structured, affordable baseline; for a regulated customer it is one input to supplier due diligence, not a substitute for contractual security terms.

What to learn first

Everything this builds on, foundations first.

  1. Compliance
  2. →D-mærket

Relationships

Requires
Compliance
Don't confuse with
ISO 27001

Sources & further reading

Official documentation

Course material

  • Cyber Security Fast Track - Ordliste
  • Cyber Security Fast Track - Kursuskompendium, Modul 8

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.