A core platform service is one of the platform categories covered by the DMA, such as search engines, social networks, app stores, operating systems, cloud services, browsers, virtual assistants, and advertising services. These services matter because the legislation treats them as strategic control points in the digital economy.
What Defines a Core Platform Service
A core platform service is not just any digital product, it is a category of platform service that the DMA treats as strategically important because it can shape market access, user reach, and distribution in the wider digital economy. The term is used for services that sit in a gatekeeping position, such as search, social networking, app distribution, operating systems, browsers, cloud, virtual assistants, and advertising.
That designation matters because the legal and governance focus is not the feature set alone, but the platform’s role as an intermediary between other businesses and end users. A service can become a strategic control point when it influences discovery, default choices, technical compatibility, ranking, account access, or commercial visibility.
Why the DMA Treats These Services Differently
The DMA does not use core platform service as a generic label for large technology products. It identifies service categories that can create durable leverage over business users and consumers, which is why the law pays attention to how these services structure access, rules, and dependencies. A search engine or app store, for example, can affect whether downstream services are seen, installed, paid for, or even permitted to operate effectively.
That governance role is the key distinction. The question is less “what does the service do?” and more “what power does the service have over the surrounding ecosystem?” In practice, that can include ranking control, default placement, terms of distribution, API constraints, interoperability decisions, and changes that ripple across a market.
Where Security and Operational Control Become Relevant
Because core platform services sit at a control point, failures or policy changes can have broad downstream effects. Availability issues, account compromise, platform rule changes, or abuse of administrative control can affect many dependent businesses at once. The service itself may be consumer-facing, but the operational risk often comes from concentration of dependence and the scale of downstream impact.
The most useful way to think about the security angle is through trust and dependency. If a platform service becomes a single point through which discovery, access, or distribution flows, then the resilience of that control point matters as much as its feature design. In governance terms, the service can become an upstream dependency whose outages, misconfigurations, or enforcement decisions have system-wide consequences.
How Practitioners Should Read the Term
Governance implication: When a service qualifies as a core platform service, it should be evaluated as a strategic intermediary, not only as a standalone product. That means looking at the service’s role in ranking, access, distribution, and switching friction, because those are the properties that make the category legally and operationally significant.
Practitioner note: A useful litmus test is whether the service can materially shape who reaches whom, under what conditions, and with what dependencies. If it can, the service is functioning as a control point, not just a feature set.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | Core platform services are governance-sensitive control points with broad ecosystem impact. |
| ID.AM — Asset Management | A core platform service is a strategic asset and dependency that must be inventoried and understood. | |
| Recommendation — Establish governance over platform dependencies, policy changes, and concentration risk. Inventory core platform services as critical assets and map their downstream dependencies. | ||
| CIS Controls v8 | CIS 12 — Network Infrastructure Management | Platform services depend on resilient, controlled infrastructure and reliable service operation. |
| Recommendation — Manage platform infrastructure changes and resilience to reduce service disruption. | ||
Related resources from NHI Mgmt Group
- Why do compromised service integrations create outsized risk even when the core platform is not breached?
- Who should be accountable for secure migrations when a managed service team becomes part of the core platform organisation?
- What breaks when approval reporting is limited in a service management platform?
- Who is accountable when a service principal bypasses a platform access policy?