D-mærket

Denmark · d-maerket.dk · 11 vendors

D-mærket is Denmark's official labeling scheme for IT security and responsible data usage. It helps companies enhance their IT security, protect against cyberattacks, and demonstrate digital responsibility to consumers and partners. The scheme guides businesses in meeting recognized international standards for IT security, data protection, and data ethics.

Resilience scores

Technology vendors

Insights

Last updated 2026-05-05 · revision 16

11 direct vendors, 183 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 7/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

D-mærket demonstrates high migration readiness, primarily due to its modern core technology stack. The use of Next.js, Sanity CMS (a headless, API-first platform), and HubSpot (a SaaS solution) indicates a cloud-friendly and modular architecture that is conducive to migration, potentially to containerized or serverless environments. The 'Custom web portal' is the main unknown, and its architecture would need to be assessed for potential monolithic characteristics. Regulatory compliance, particularly GDPR, is well-managed, which provides a solid foundation, though the 'Assessment Required' status for NIS2, SOC2, ISO 27001, and ISAE 3000 means these compliance requirements would need to be actively integrated into any migration strategy, potentially adding complexity but also offering an opportunity for 'compliance by design.' Data residency requirements, stipulating primary processing within the EU/EEA, are a clear constraint that would guide cloud provider and region selection, but are manageable with appropriate safeguards like SCCs for necessary third-country transfers. While vendor lock-in risk is 'Unknown,' the reliance on a few key SaaS platforms (Sanity, HubSpot) could present some lock-in, but also simplifies the migration of those specific services as they are already cloud-managed. The financial capacity for a large-scale migration is unclear due to unknown revenue growth history, which could be a limiting factor. Overall, the modern tech stack and existing cloud-native components position D-mærket well for a migration, despite the regulatory and data residency considerations.

Compliance

5 in-scope frameworks identified; showing 3.

ISO 27001 (source) — Assessment Required

As a cybersecurity certification organization, ISO 27001 certification would be highly valuable for credibility and competitive positioning. Medium risk because while not legally mandated, clients expect cybersecurity service providers to demonstrate their own security management systems meet international standards. Lack of ISO 27001 could impact market credibility and client trust.

NIS2 (source) — Assessment Required

D-mærket operates in cybersecurity services sector in Denmark, which may qualify as 'digital providers' under NIS2 Important Entities. Medium risk because while NIS2 compliance would be beneficial for their credibility as a cybersecurity certification body, the specific sector classification and size thresholds need verification. Non-compliance could impact their ability to serve NIS2-covered clients effectively.

Evidence: https://www.d-maerket.dk/da/nis2

GDPR (source) — Assessment Required

As a Danish organization processing personal data of EU residents (customer data, employee data, certification applicant data), GDPR compliance is mandatory. High risk due to potential fines up to 4% of global turnover and reputational damage. The company processes sensitive business information through their certification platform, making data protection critical. Their privacy policy shows extensive personal data processing activities including customer onboarding, audit processes, and marketing communications.

Evidence: https://www.d-maerket.dk/da/privatlivspolitik

Financials

Three-year financials

Financial Resilience Score: 6/10

D-mærket's financial resilience is anchored by strong institutional backing rather than commercial scale. Industriens Fond reportedly earmarked approximately DKK 35M to develop and run the scheme during its build-up phase, and the organisation is co-sponsored by Denmark's largest business and consumer organisations (Dansk Erhverv, DI, SMVdanmark, Forbrugerrådet Tænk). This significantly de-risks the early-stage operating model and provides a stable funding base while the audit-fee revenue stream scales. The operating model is capital-light: an audit-and-certification scheme with a small core team of ~10 employees, no inventory, and minimal physical infrastructure. NIS2 implementation in Denmark provides a structural demand tailwind, and D-mærket is the only nationally endorsed combined IT-security and data-ethics label in Denmark, giving it brand exclusivity domestically. However, resilience is constrained by grant dependency, low certification volumes (dozens to low hundreds of certified companies), key-person risk in a small team, and substitution risk from international standards like ISO 27001. Verified revenue, EBIT, and equity figures could not be retrieved in this research session, limiting quantitative assessment.

Key strengths: Backed by Industriens Fond with ~DKK 35M earmarked grant funding, Sponsorship from Denmark's largest business and consumer organisations, NIS2 regulatory tailwind driving SME demand, Capital-light audit-and-certification operating model, Only nationally endorsed combined IT-security + data-ethics label in Denmark, Annual recertification provides recurring revenue potential

Risk factors: Grant dependency on Industriens Fond funding tranches, Low adoption volume (dozens to low hundreds of certified companies), Customer churn risk after first-year certification, Substitution by ISO 27001 and other international standards, Key-person dependency in a ~10-person organisation, Voluntary scheme—uptake risk constrains fee revenue

Revenue by geography

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report