Information Security Management › Frameworks

D-seal or ISO 27001? How to Choose the Right Certification

The D-seal is a Danish trust label, ISO 27001 is an international standard, and GDPR is a law you cannot be certified against. See what each one covers, what the two routes cost, and which your organisation should choose.

Comparison of the Danish D-seal and ISO 27001 showing two certification routes built on a shared foundation of risk assessment, policies and roles

Table of Contents

    Buyers, procurement teams and compliance leads in Denmark keep running into the same question: should we go for the D-seal or ISO 27001? The question usually arrives bundled with two others. How does the D-seal compare with GDPR? And should we choose a certification body instead?

    Those questions are reasonable, but they compare things that belong to different categories. This article sorts the categories out first, then compares the two that can actually be compared, and ends with a clear answer to the choice. Where we quote figures, they come from the scheme itself, from Dansk Standard, from Datatilsynet or from our own ISO 27001 articles, and we say which.

    The short answer: D-seal or ISO 27001?

    If you sell mainly in Denmark and want to show customers, citizens and partners that you handle data responsibly, the D-seal is the faster and cheaper route. If you face international tenders or supplier assessments, ISO 27001 is what you will be asked for. If you need both, take the D-seal first: the self-assessment is free, and the risk assessment, policies and roles you document count towards ISO 27001 later. One caveat applies throughout: if you are a covered entity under NIS2, neither label replaces your legal obligations.

    Three things that often get mixed up

    The comparison queries we see put the D-seal, ISO 27001 and GDPR side by side as if they were three competing certifications. They are not. Sorting them into the right categories is the most useful thing this article can do.

    What people compare What it actually is Can you be certified against it?
    The D-seal A Danish labelling scheme for IT security and responsible data use. A seal you can display. Yes. Awarded by the scheme's own auditors, one year at a time.
    ISO 27001 An international standard for an information security management system (ISMS). Yes. Certified by an accredited certification body, valid three years.
    GDPR A law. You comply with it, you are not approved against it. Not in Denmark. No GDPR Article 42 certification scheme has been approved by Datatilsynet.

    A fourth confusion appears in the same searches: people compare the D-seal with individual certification bodies. A certification body is the organisation that audits you against ISO 27001 and issues the certificate. It is not an alternative to the standard, and choosing one is a separate decision you make after deciding which standard to be certified against. We return to that below.

    That leaves one comparison that makes sense: the D-seal against ISO 27001.

    Diagram sorting the D-seal, ISO 27001, GDPR and certification bodies into the categories label, standard, law and auditor

    What is the D-seal?

    The D-seal (D-mærket in Danish) is Denmark's labelling scheme for IT security and responsible data use. It was launched in September 2021 by Industriens Fond together with Dansk Industri, Dansk Erhverv, SMVdanmark and the consumer council Forbrugerrådet Tænk, with support from the Danish Business Authority. The scheme describes itself as the first of its kind in the world to combine IT security and responsible data use in a single seal. Industriens Fond has committed DKK 20.7 million to the scheme for 2026 to 2029.

    Two features distinguish the D-seal from a pure security standard. It covers data ethics and the responsible use of algorithms and AI, not only information security. And it is scaled to the size and role of the company, so a nine-person consultancy and a 500-person software supplier are not assessed against the same list.

    The eight criteria

    The D-seal is built on eight criteria. Criteria 1 to 5 are mandatory for every company. Criteria 6 to 8 are conditional and apply depending on what the company does.

    Criterion Applies to
    1. Management anchoring All companies
    2. Awareness and safe behaviour All companies
    3. Technical IT security All companies
    4. Requirements for suppliers All companies
    5. Transparency and control of data All companies
    6. Privacy and security by design and by default Companies that develop software
    7. Reliable algorithms and AI Companies that use or develop algorithms or AI
    8. Data ethics Mainly company groups II to IV

    Company groups

    Placement depends on employees and turnover, and is adjusted upwards if the company is an IT or software supplier or processes sensitive personal data. Requirements are cumulative, so a higher group includes the controls of the groups below it.

    Group Employees Turnover Audit fee (ex. VAT)
    I 0 to 9 Up to DKK 7.9m DKK 5,000
    II 10 to 49 DKK 8m to 155.9m DKK 15,000
    III 50 to 249 DKK 156m to 313m DKK 37,000 (DKK 56,250 with the NIS2 module)
    IV 250 to 999 Over DKK 313m DKK 69,750 (DKK 83,700 with the NIS2 module)
    IV+ 1,000 or more Any Priced individually

    Prices are the scheme's published audit fees as of 1 July 2025, the first increase since the launch. Older guides and competitor pages still quote the previous fees, so check the current price page before you budget.

    Process and validity

    The route runs in five steps. You complete the free self-assessment in the scheme's online tool, which requires a Danish CVR number. When every item is answered and documented, you request an audit, sign a solemn declaration and pay the invoice. The scheme's own auditors then hold a kick-off meeting, review your documentation and award the seal together with an audit report. Approved external advisers can help you prepare, but they do not perform the audit.

    The seal is awarded for one year at a time. Renewal means going through the self-assessment again, updating what has changed and requesting a new audit. There is no lighter surveillance model of the kind ISO 27001 uses.

    The scheme reported more than 100 companies awarded and more than 1,800 working towards the seal in its most recent published figures from spring 2025, with 69 awards made in 2024 alone. The seal is a national scheme. Its recognition value is strong in Denmark and limited outside it.

    Five-step D-seal process from free self-assessment through audit request and auditor review to seal awarded with annual renewal

    What is ISO 27001?

    ISO/IEC 27001 is the international standard for an information security management system. The current version is ISO/IEC 27001:2022, published in Denmark as DS/EN ISO/IEC 27001:2023. The transition from the 2013 edition closed on 31 October 2025, so any valid certificate today is against the 2022 revision.

    The standard has two parts. Clauses 4 to 10 set the management system requirements: context, leadership, planning, support, operation, performance evaluation and improvement. Annex A lists 93 reference controls in four themes: 37 organisational, 8 people, 14 physical and 34 technological. You select controls based on your own risk assessment and justify the selection in a Statement of Applicability. A 2024 amendment added climate change as a factor to consider in clauses 4.1 and 4.2 without changing Annex A.

    Certification is performed by a certification body accredited by DANAK in Denmark, in a two-stage audit. Stage 1 reviews your documentation, Stage 2 checks that the system works in practice. The certificate is valid for three years, with a surveillance audit each year and a full recertification audit in year three. Audit days scale with your headcount, which is why cost depends so heavily on size.

    Globally there were 96,709 valid ISO 27001 certificates in the latest ISO Survey (2024 edition). In Denmark the standard is what larger customers, public tenders and international partners ask for by name, and it is the natural backbone for organisations covered by NIS2. Read our guides to ISO 27001 compliance and the ISO compliance checklist for the full picture.

    D-seal vs ISO 27001: the comparison

    Aspect D-seal ISO 27001
    Type Danish labelling scheme International management system standard
    Geography Denmark (requires a CVR number) Recognised globally
    Mandatory? No, voluntary No, voluntary, but often a contractual requirement
    Covers IT security, data protection, data ethics, algorithms and AI Information security, risk-based
    Structure 8 criteria: 5 mandatory, 3 conditional Clauses 4 to 10 plus 93 Annex A controls
    Scaling 5 company groups by size, role and data Scope defined by the organisation
    Assessment Self-assessment reviewed by the scheme's own auditors Two-stage external audit by an accredited body
    Validity 1 year, full renewal each year 3 years, annual surveillance audit
    Typical time Weeks to a few months for an SME 6 to 18 months from scratch for a medium-sized organisation
    Typical cost Free self-assessment, audit fee DKK 5,000 to 83,700 ex. VAT DKK 150,000 to 400,000 all-inclusive
    Signal value Strong in Denmark, little known abroad Expected in international tenders
    NIS2 Optional NIS2 module adding requirements to 7 of the 10 minimum measures Covers roughly 70 to 80% of NIS2 requirements
    GDPR Supports and goes beyond GDPR on transparency and ethics. Not a GDPR certification Supports the security duties in Article 32. Not a GDPR certification
    AI and data ethics Explicit criteria (6, 7 and 8) Not covered. Needs ISO/IEC 42001 or 27701

    The practical difference is the assessment model. The D-seal builds on a self-assessment that is then audited, and the seal lasts one year. ISO 27001 requires a two-stage external audit by an accredited certification body, and the certificate lasts three years with an annual surveillance audit. That single difference drives most of the gap in both price and time.

    Side-by-side comparison of the D-seal and ISO 27001 on type, geography, assessment method, validity, time and cost

    What the D-seal's own ISO 27001 mapping shows

    The D-seal publishes a mapping of its criteria against other frameworks, including ISO 27001, GDPR and NIST. The ISO 27001 mapping covers the management system clauses 4 to 10, not Annex A, and scores each clause on a three-point scale. Read as a whole, it tells you exactly what you keep and what you still have to build when moving from one scheme to the other.

    ISO 27001 clause Covered by the D-seal?
    4.2 Interested parties ✓ Fully covered (3/3)
    5.2 Information security policy ✓ Fully covered (3/3)
    5.3 Roles, responsibilities and authorities ✓ Fully covered (3/3)
    6.1 Risk assessment and treatment (6.1.1 to 6.1.3) ✓ Fully covered (3/3)
    8.2 and 8.3 Operational risk assessment and treatment ✓ Fully covered (3/3)
    5.1 Leadership and commitment Partly covered (2/3)
    7.3 Awareness Partly covered (2/3)
    4.1 Context, 4.3 Scope, 4.4 The ISMS ✗ Not covered
    6.2 Objectives, 6.3 Planning of changes ✗ Not covered
    7.1 Resources, 7.2 Competence, 7.4 Communication, 7.5 Documented information ✗ Not covered
    8.1 Operational planning and control ✗ Not covered
    9.1 Monitoring and measurement, 9.2 Internal audit, 9.3 Management review ✗ Not covered
    10.1 Continual improvement, 10.2 Nonconformity and corrective action ✗ Not covered

    The pattern is clear. The D-seal covers the governance and risk core of a management system: who is responsible, what the policy says, what the risks are and how they are treated. It does not cover the operating cycle that makes ISO 27001 a management system rather than a control list: measurable objectives, internal audit, management review, corrective action and continual improvement. Nor does it require the formal scoping and document control an accredited auditor will look for.

    That has a direct consequence for sequencing. An organisation holding ISO 27001 already satisfies the management-side criteria of the D-seal and mainly needs to add the data ethics, AI and transparency layer. An organisation holding the D-seal has a real head start on ISO 27001, but still has to build the full ISMS lifecycle before an accredited audit.

    Coverage map of ISO 27001 clauses 4 to 10 showing which clauses the D-seal covers fully, partly or not at all

    What about GDPR?

    There is no GDPR certification in Denmark. GDPR is a law you have to comply with, not a scheme you can be approved against. Article 42 of the regulation allows for certification schemes, but they must be approved by the national supervisory authority to be valid in Denmark, and Datatilsynet's published position is that no such scheme has yet been approved at Danish or European level. At EU level, Europrivacy is the first scheme recognised as a European Data Protection Seal, but it is delivered through qualified certification bodies and is not a Danish approval.

    Both the D-seal and ISO 27001 support your GDPR compliance and document parts of it. ISO 27001 covers the security of processing that Article 32 requires. The D-seal goes further on transparency, control of data and data ethics than GDPR itself demands. Neither makes you GDPR compliant on its own.

    What about certification bodies?

    ISO 27001 certificates are issued by certification bodies accredited by DANAK, the Danish accreditation body. Several operate in Denmark. They audit you against the standard, but they are not the standard, and they are not an alternative to the D-seal. You choose a certification body after you have decided to pursue ISO 27001, based on sector experience, price and audit approach. For the D-seal, the choice does not arise, because the audit is carried out by the scheme's own auditors.

    What do the two routes cost?

    Cost is the comparison most articles avoid, so here are the figures we can stand behind. The D-seal fees are the scheme's published prices. The ISO 27001 figures are Danish market estimates from our own ISO 27001 material and Danish advisers, because certification has no fixed price list.

    Cost item D-seal ISO 27001
    Assessment tool / gap analysis Free self-assessment Gap analysis, 1 to 2 months, usually with external help
    External advisers Optional approved advisers Typically DKK 100,000 to 300,000
    Audit / certification fee DKK 5,000 to 69,750 ex. VAT by group, DKK 83,700 for group IV with NIS2 Certification body contract roughly DKK 60,000 to 90,000 over three years for a small organisation, more with headcount
    Ongoing Full renewal and audit fee every year Annual surveillance audit, recertification in year three
    Indicative total, first time Audit fee plus internal hours DKK 150,000 to 400,000 all-inclusive

    Two notes on reading the table. The D-seal fee looks small because the scheme relies on your own preparation, so the real cost sits in internal hours. And the yearly renewal means the D-seal fee recurs annually, whereas ISO 27001's surveillance audits are lighter than the initial certification.

    A worked example: choosing between the two

    Fjordbyg Software ApS and Sara Lind are fictional. We created them for this article, and they are not customers or a case study.

    Fjordbyg Software is a Danish SaaS supplier with 35 employees and a turnover of DKK 40 million. Its customers are Danish municipalities and housing associations, and it has just started answering tenders in Sweden and Germany. Sara Lind is Head of Operations and owns compliance alongside her other work.

    On employees and turnover, Fjordbyg would sit in company group II. Because it is a software supplier, the scheme places it in group III, where criterion 6 on privacy and security by design applies. The scheme offers a 40% discount to companies moved from group II to III for that reason, so the audit fee would be DKK 22,200 ex. VAT rather than DKK 37,000. The self-assessment itself costs nothing.

    Sara's decision runs like this. Her current customers are Danish public bodies who know the D-seal and increasingly ask about it. Her prospective customers abroad ask for ISO 27001 and have never heard of the D-seal. She has no formal ISMS today. She chooses the D-seal first, because the free self-assessment forces the company to document its risk assessment, policies, roles, supplier requirements and awareness programme within a few months, and because the seal supports the Danish sales she depends on now. She then plans ISO 27001 within 18 months, knowing from the mapping above that her risk assessment, policy and role documentation carry over, and that the work still ahead is the ISMS cycle: objectives, internal audit, management review and continual improvement.

    Had Fjordbyg's revenue been mostly foreign, or had a customer written ISO 27001 into a contract, the order would flip. The point of the example is that the answer depends on who is asking for proof and where.

    Decision flow for choosing between the D-seal and ISO 27001 based on market, who asks for proof and whether an ISMS exists

    Can you have both the D-seal and ISO 27001?

    Yes, and for a Danish company with international customers it is often the cheapest combined outcome, because the work overlaps. Both require management anchoring, risk assessment, access control, awareness training and supplier management. If you already hold ISO 27001, the D-seal's self-assessment becomes largely a matter of pointing to existing documentation and adding the data ethics and AI criteria. If you start with the D-seal, you have a structured first step towards ISO 27001 rather than a detour.

    The order that usually works is D-seal first, then ISO 27001. The self-assessment is free, the seal arrives in months rather than a year or more, and everything you document counts later. The exception is when a contract or tender already names ISO 27001, or when you are covered by NIS2, in which case build the ISMS first and treat the seal as documentation of it.

    One related point deserves its own sentence. The D-seal's NIS2 module adds requirements to seven of the ten minimum measures in the directive. That is useful structure. It is not the same as being NIS2 compliant, and the scheme does not claim it is. Denmark's NIS2 act entered into force on 1 July 2025, and covered entities carry their own legal duties regardless of which label they hold. Our NIS2 vs ISO 27001 comparison covers that side in detail.

    How .legal supports both routes

    Working towards two schemes creates one practical problem: documenting the same control twice. Our Frameworks module is built to avoid that. You map a single task or control, for example your annual risk assessment or your supplier review, to the D-seal criterion and the ISO 27001 clause it satisfies, and both frameworks update when the task is completed. Awareness training, policy sign-offs and the annual wheel live in the same place, so the internal audit and management review that ISO 27001 requires are fed by work you are already doing for the D-seal.

    See how organisations use the platform to get ready for the D-seal, or book a demo to see the cross-framework mapping in action.

    Frequently asked questions about the D-seal and ISO 27001

    What is the difference between the D-seal and ISO 27001?

    The D-seal is a Danish labelling scheme covering IT security, data protection, data ethics and AI, assessed through a self-assessment reviewed by the scheme's own auditors and valid for one year. ISO 27001 is an international management system standard for information security, certified through a two-stage audit by an accredited certification body and valid for three years with annual surveillance audits. The D-seal is broader on ethics and faster to obtain. ISO 27001 is deeper on management system rigour and recognised globally.

    Which certification should we choose, the D-seal or ISO 27001?

    Choose the D-seal if you sell mainly in Denmark and want to show customers and partners that you handle data responsibly. Choose ISO 27001 if you face international tenders, supplier assessments or contracts that name the standard. If you need both, take the D-seal first, since the self-assessment is free and the risk assessment, policies and roles you document count towards ISO 27001 later. If you are covered by NIS2, build the ISMS first.

    Can you have both the D-seal and ISO 27001?

    Yes. The two overlap on management anchoring, risk assessment, access control, awareness and supplier management. An ISO 27001 certified organisation mostly needs to add the D-seal's data ethics, AI and transparency criteria. A D-seal holder pursuing ISO 27001 keeps its risk and policy work but still has to build the ISMS cycle of objectives, internal audit, management review and continual improvement.

    Is a certification body an alternative to the D-seal or ISO 27001?

    No. A certification body is the accredited organisation that audits you against ISO 27001 and issues the certificate. It is not a standard and not an alternative to either scheme. You choose a certification body after deciding to pursue ISO 27001. The D-seal is audited by the scheme's own auditors, so no such choice arises.

    Can you become GDPR certified?

    Not in Denmark. GDPR is a law you comply with, not a scheme you are approved against. Article 42 allows certification schemes, but they must be approved by Datatilsynet to be valid in Denmark, and none has been approved at Danish or European level according to Datatilsynet. Both the D-seal and ISO 27001 support GDPR compliance, but neither is a GDPR certification.

    How much does the D-seal cost compared with ISO 27001?

    The D-seal self-assessment is free. The audit fee, payable when you request an audit, ranges from DKK 5,000 for company group I to DKK 69,750 for group IV excluding VAT, or DKK 83,700 for group IV with the NIS2 module, at prices valid from 1 July 2025. ISO 27001 typically costs DKK 150,000 to 400,000 all-inclusive for a medium-sized organisation starting from scratch, with external advisers accounting for DKK 100,000 to 300,000 of that.

    How long does it take to get the D-seal?

    Typically weeks to a few months for an SME, depending on how much documentation already exists. You can request the audit as soon as every item in the self-assessment is answered and documented. ISO 27001 typically takes 6 to 18 months from scratch for a medium-sized organisation.

    Who can get the D-seal?

    Any company or organisation with a Danish CVR number, from sole traders in company group I to organisations with 1,000 or more employees in group IV+. Placement depends on employees and turnover, and is adjusted upwards for IT and software suppliers and for companies processing sensitive personal data.

    Does the D-seal cover NIS2?

    Partly. The D-seal offers an optional NIS2 module that adds requirements to seven of the ten minimum measures in the directive, and choosing it places the company in group III or IV. The module is useful structure, but it does not make you NIS2 compliant, and the scheme does not claim it does. Covered entities carry their own legal duties under Denmark's NIS2 act, in force since 1 July 2025.

    Is the D-seal recognised outside Denmark?

    The D-seal is a Danish national scheme and requires a Danish CVR number. Its recognition is strong in Denmark and limited abroad. If your customers or tenders are international, ISO 27001 is the recognised option, and many Danish companies hold both.

    Still unsure?

    Ask Johannes directly, he runs most demos personally

    Book him here
    Processing activities

    .legal compliance platform One mapping, both schemes

    Map a single task — your annual risk assessment, your supplier review — to the D-seal criterion and the ISO 27001 clause it satisfies, and let both frameworks update when the work is done.

    • One control mapped to the D-seal and ISO 27001 at once
    • Risk assessment, policies and roles documented once
    • Awareness training, policy sign-offs and the annual wheel in one place
    • EU-hosted and ISAE-certified for security
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell