The Digital Markets Act is an EU competition law for large online platforms that act as gatekeepers between businesses and consumers. It sets thresholds for designation and imposes conduct rules meant to reduce bottlenecks, improve fairness, and increase transparency in how core platform services operate.
How the Digital Markets Act changes platform competition
The Digital Markets Act is not a general consumer protection law or a technical security standard. It is a competition regime aimed at a narrow set of large online platforms, with the main objective of reducing bottlenecks created when one company controls key gateways between businesses and users.
That matters because gatekeeper power can shape who gets discovered, which services can interoperate, how easily users can switch, and whether business users face fair terms. In practice, the Act is designed to curb self-preferencing and other conduct that can lock ecosystems into a dominant platform’s rules.
What obligations typically matter for gatekeepers
The Digital Markets Act combines designation thresholds with conduct obligations, so the first practical question is whether a platform meets the gatekeeper criteria and then which services fall within scope. Once designated, the platform must treat certain business users more fairly, open up specific access paths, and be more transparent about how core platform services operate.
For readers, the most important idea is that the Act regulates market structure and behavior, not just disclosure. It can require changes to default settings, ranking behavior, access to data, app distribution, and interoperability. Those obligations can alter product design, commercial terms, and platform governance at the same time.
Why transparency and interoperability are central
Transparency reduces the information asymmetry that often exists when a gatekeeper controls search, app stores, ad tech, operating systems, messaging, or marketplace access. Without clearer rules, business users may not know why they were ranked lower, why an account action was taken, or how platform rules are applied unevenly.
Interoperability is equally important because it limits lock-in. If users and business users can move data, connect competing services, or communicate across platform boundaries more easily, the platform’s control over distribution and switching costs becomes less absolute. For practitioners, this is a policy question about market access, but it also affects product architecture and operational change management.
How it is enforced and where the pressure points are
Enforcement can create significant operational pressure because compliance is measured against specific conduct rules rather than broad intentions. That means documentation, product behavior, ranking logic, interface design, and access controls may all need to be demonstrably aligned with the regime’s requirements.
Large platforms that are designated as gatekeepers often need to coordinate legal, engineering, product, and policy functions so the same service does not drift out of compliance in different countries or business lines. The practical challenge is not only following the rule, but proving that the platform’s implementation actually matches the rule’s intent.
Risk and Threat Considerations
When a platform is designated, the main risk is regulatory exposure from conduct that preserves bottlenecks, weakens transparency, or frustrates interoperability. Because the law targets structural power, even subtle product choices can create compliance problems if they are seen as preserving unfair advantage or restricting business user access.
Failure mechanism: A gatekeeper can introduce risk through self-preferencing, opaque ranking, restricted access paths, or design choices that keep users and business partners dependent on one ecosystem.
Impact: The likely consequences are enforcement action, forced product changes, reputational damage, and higher switching friction for businesses and consumers who rely on the platform.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | DMA compliance requires governance over platform conduct, accountability, and regulatory obligations. |
| PR.AC — Identity Management, Authentication, and Access Control | DMA obligations around access and fair treatment intersect with how platform access is governed and enforced. | |
| GV.SC — Cybersecurity Supply Chain Risk Management | DMA impacts third-party platform dependencies, distribution channels, and ecosystem concentration risk. | |
| Recommendation — Assign governance ownership for DMA-scoped platform conduct and track compliance decisions as part of enterprise risk management. Align access-control behavior with documented policy so platform rules are applied consistently and transparently. Map critical platform dependencies and third-party relationships that could amplify concentration or access risk. | ||
| CIS Controls v8 | 6 — Access Control Management | DMA interoperability and business-user access issues are directly affected by access control decisions and permissions. |
| Recommendation — Review and restrict platform access paths so business-user entitlements and interoperability choices match policy requirements. | ||
Practitioner Guidance
Governance implication: Teams should treat Digital Markets Act obligations as a cross-functional operating constraint, not a legal afterthought. Product decisions that affect ranking, access, defaults, data use, or interoperability need to be reviewable against the designation scope and the specific conduct rules that apply.
Practitioner takeaway: The safest approach is to design for demonstrable fairness and explainability early, because retrofitting compliance into a mature platform is usually slower, costlier, and more disruptive than building it in from the start.
Related resources from NHI Mgmt Group
- Why do open prediction markets and digital collectible platforms attract both legitimate users and illicit activity?
- Why do one-time identity checks fail when people, businesses, and AI agents all act across the same digital journey?
- Why do products with digital elements need continuous vulnerability management under the EU Cyber Resilience Act?
- Why does the Cyber Resilience Act make product cybersecurity a market entry issue for digital products?