D-mærket as a predefined framework
Add D-mærket in the Frameworks module and the controls arrive with it, in D-Seal's own structure and naming. The evidence tasks beneath them are .legal's own catalogue, with descriptions and practical tips.
D-Seal's own criteria sit in the platform under a formal agreement with D-Seal, mapped 1:1 with the level 3 criteria. Work the controls, collect the documentation, and export it per task so it can be transferred into D-Seal's own supervisory tool at the audit.
Unlimited users • Free onboarding and support • No commitment
Maria Holm is group GRC lead at Meridian Nordic. Their ISO 27001 certificate answers the international question, and D-mærket is the Danish one, so before she committed to anything she wanted to know what it would actually cost her in work. The platform could tell her before she switched the framework on, because D-mærket and ISO 27001 draw on the same catalogue of evidence tasks. Then she added D-mærket in the Frameworks module, the controls arrived with it, and she worked through the ones that were left.
D-Seal's own criteria
A formal agreement with D-Seal lets .legal reproduce and apply their criteria in the platform, mapped 1:1 with the D-Seal level 3 criteria at control level.
Scope by company group
The framework carries classification by company groups I to IV, and the implementation groups are cumulative, so a higher group includes the controls beneath it.
Documentation that transfers
Documentation exports per task, specifically so it can be transferred into D-Seal's own supervisory tool at the audit.
The work overlaps ISO 27001
Both frameworks draw on the same catalogue of evidence tasks, so D-seal work shows up as progress towards ISO 27001 as well.
The D-seal is Denmark's certification scheme for IT security and responsible data use, and it is the first mark to combine those two. It was established by the Danish Industry Foundation together with the industry confederations and the Danish Consumer Council, and it is supported by the Danish Business Authority.
.legal and D-Seal have a formal reproduction agreement, which permits us to incorporate and apply D-Seal's criteria inside the platform. So what you read in .legal at control level is what D-Seal wrote.
Your scope is D-Seal's call, not ours, and it is not something we assess for you. What .legal does is carry the scheme's own classification and hold the controls that come with it.
Most of the work is not the controls, it is the evidence underneath them. Each control carries tasks with a description, a status and somewhere to put the proof, and a task either links to a policy document you already have or stands on its own.
Both frameworks sit on the same evidence base, so this is not two projects. A task you document under the D-seal also counts on an ISO 27001 basis, and you can see how far you already are before you activate anything.
That sentence is the honest version of what you get. The platform gives you the framework, the controls, the tasks and the place the evidence goes, and your colleagues do the work.
Add D-mærket in the Frameworks module and the controls arrive with it, in D-Seal's own structure and naming. The evidence tasks beneath them are .legal's own catalogue, with descriptions and practical tips.
The framework arrives with classification by company groups I to IV. The implementation groups are cumulative, so controls from lower categories are included automatically at the higher levels, and moving up a group adds controls instead of replacing work already done.
Privacy and Security by Design and Default, Reliable Algorithms and AI, and NIS2 sit as specialist modules on top of the group classification.
Each control carries tasks with descriptions, documentation and status. A task either links to a policy document you already have or stands on its own.
Documentation is exportable per task, specifically so it can be transferred into D-Seal's own supervisory tool when the audit comes.
Set a frequency on each task and it comes back when the frequency expires, with a reminder to the responsible person, so the documentation stays current after the mark is awarded.
The Danish mark, and the international standard it overlaps with.
D-mærket (the D-seal)
D-Seal's own criteria in the platform under a formal reproduction agreement, mapped 1:1 with the level 3 criteria and classified by company groups I to IV.
ISO 27001
The Annex A controls on the same shared evidence, so the D-seal work shows up as progress here too, whether ISO 27001 is your next step or not.
Run your information security management in one place: the D-mærket and ISO 27001 frameworks, the controls beneath them, and the tasks that document them.
Explore Information Security ManagementThe mark covers responsible data use as well as security, so your GDPR documentation and Article 30 records sit in the same platform as the security work.
Explore GDPRcompanies
users
contracts
processing activities
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Bech-Bruun
Mikkel Friis Rossa (Partner)
Fenerum
Rasmus Boutrup (Financial Controller)
Lægeforeningen
Michael Berner (Lawyer)
Molecule Consultancy
Nanna Rodian Christensen (HR & Operational Manager)
Plum Safety
Ulrik Dueholm Beckmann (QC, CM og ESG Lead)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Novicell
Julie Oxenvad (Legal Consultant)
Min By Media
Tinna Schultz (HR Manager)
DMJX
Kaspar Rochholz (GDPR Coordinator)
Axel Kaufmann ApS
Julie Lundkvist Andreasen (Lawyer and Head of Costumer Service)
NRGi
Mette Mühlendorph (Compliance Specialist)
Every use case is a real piece of compliance work, told the way it actually runs in the platform. Filter by who you are, what you work with, and which frameworks you answer to.
6 use cases
No use cases match that combination yet. Try removing a filter.
Denmark's certification scheme for IT security and responsible data use, and the first mark to combine those two things. It was established by the Danish Industry Foundation together with the industry confederations and the Danish Consumer Council, and it is supported by the Danish Business Authority. More than 130 organisations have been awarded the mark, and over 2,200 are currently in the process.
Yes. .legal and D-Seal have a formal reproduction agreement that permits .legal to incorporate and apply D-Seal's criteria in the platform, so you work with the criteria directly in .legal and can use the platform as your primary tool for obtaining and maintaining the certification. The mapping is 1:1 with the D-Seal level 3 criteria at control level. The evidence tasks beneath the controls are .legal's own catalogue, written by us.
That decision is yours, and we do not make it for you. Some organisations use the D-seal as an alternative to ISO 27001, because their market is Danish and the mark is recognised here. Others use it as a step on the way towards ISO 27001, which is the international standard. Both routes exist, the two frameworks overlap heavily, and the work you do carries over either way. What we can do is show you the overlap in the platform before you commit to anything.
The estimate we work with is roughly 70%. Treat it as an illustration of how much of the work carries over rather than a measurement, because it is an estimate and not a measured result. The mechanism behind it is real enough: the frameworks share one catalogue of evidence tasks, so a task documented under the D-seal also counts on an ISO 27001 basis, and the platform shows you how far you already are.
What the Annex A controls areD-Seal does, not .legal. We are not the certifying body, we do not assess which requirements you fall under, and that part of the conversation belongs with D-Seal. What the platform does is carry the scheme's own structure: the framework arrives with classification by company groups I to IV, and the implementation groups are cumulative, so controls from lower categories are included at the higher levels. Moving up a group adds controls rather than replacing the work you have already done.
The D-seal has specialist modules for Privacy and Security by Design and Default, Reliable Algorithms and AI, and NIS2, and they sit on top of the group classification in the platform. Note that the D-seal's NIS2 specialist module is part of the D-seal scheme. It is not the same thing as the NIS2 framework, which exists in .legal in its own right.
D-Seal audits, not .legal. What the platform does is hold the documentation structured per control and per task while you build it, and then export it per task so it can be transferred into D-Seal's own supervisory tool at the audit. That export exists for exactly that hand-off, which is why it is worth knowing about early rather than the week before.
What an internal audit involvesNo. We build the plan, not the filling-in. The platform holds the framework, the controls, the tasks and the place the evidence goes, and you do the work and write the documentation. It is a documentation platform, not a monitoring tool: nothing is scanned, no status is derived from breaches found automatically, incidents are registered by hand, and there is no aggregated verdict anywhere that says you comply.
The task list under the controls can get long, which is the argument for spreading it. Users are unlimited, external users included, so the colleague who actually runs the backup or reviews the access rights can get the task, attach the documentation and close it. You keep the overview of what is still open and who it sits with.
How access control works in ISO 27001
Info
.legal A/S
hello@dotlegal.com
+45 7027 0127
VAT-no: DK40888888
Support
support@dotlegal.com
+45 7027 0127
Need help?
Let me help you get started
.legal is not a law firm and is therefore not under the supervision of the Bar Council.