The difference is proportionality. Very large online platforms and very large online search engines face stricter obligations because of their scale and societal impact, including heightened scrutiny from the European Commission. Smaller and medium-sized enterprises are exempt from certain areas to preserve innovation, but they are still expected to assess scope and meet relevant duties that apply to their service type.
How DSA obligations scale with platform size
The Digital Services Act uses proportionality as its core design principle. The legal logic is that the more reach, systemic impact, and amplification power a service has, the more extensive the governance, transparency, and risk-management duties should be. That is why very large online platform and very large online search engine are treated differently from smaller services, even when they provide similar core functionality.
For a very large service, the difference is not just administrative volume. It changes the operating model: the platform must be prepared for more formal oversight, deeper documentation, and more scrutiny of how its systems shape exposure at scale. For smaller and medium-sized services, the regime still matters, but the intent is to avoid imposing the same burden where the systemic risk is materially lower.
The distinction also reflects the way platform effects compound. A larger service can influence more users, more content flows, and more downstream harm if controls fail, so the law expects stronger accountability. A smaller service may still need to assess its own scope carefully and meet the obligations that apply to its service type, but it is not automatically placed into the most intensive supervisory category.
What changes for very large online platforms and search engines
Very large online platforms and very large online search engines face stricter obligations because the European Commission treats their scale as a risk multiplier. In practical terms, that means more rigorous compliance expectations around transparency, systemic-risk assessment, and the ability to show that the service understands the effects of its own design and distribution mechanisms. See the NIS2 Directive, official EU legal text for the broader EU pattern of proportional controls, and the EU Cyber Resilience Act for the same policy logic applied to digital products.
That stricter tier is about governance depth, not only legal status. Larger services are expected to demonstrate that their risk controls are not ad hoc, that their internal ownership is clear, and that they can respond to Commission scrutiny with evidence rather than general assurances. The practical outcome is that a platform’s compliance posture has to be more operationalised, because size makes weak controls more consequential.
Smaller services are still within scope where the DSA applies to their service type, but the framework tries to avoid crushing early-stage or mid-market businesses with the same compliance load reserved for systemic actors. That is a policy choice to preserve innovation while still requiring relevant duties to be met. The important practitioner point is that smaller status reduces burden, it does not remove the need to assess classification, scope, and service-specific obligations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 set the technical controls, while NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIS2 | Art. 21 — Cybersecurity risk-management measures | The question concerns proportionate obligations and risk-management duties for regulated digital services. |
| Art. 23 — Incident reporting | Very large services face stronger oversight and response duties, including formal reporting expectations. | |
| Recommendation — Apply proportionate risk-management controls based on the service's regulatory classification and impact. Establish incident-reporting processes that match the service's scope and supervisory expectations. | ||
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | The answer turns on proportional governance and aligning controls to the service's scale and impact. |
| Recommendation — Align governance and controls to the service's measured risk and business impact. | ||
Practitioner Guidance
What to verify: Do not rely on a marketing description of the business size. Verify the formal designation, the actual service category, and whether any part of the service crosses into the very-large threshold through reach, user base, or search significance. The compliance profile follows the regulated service, not the organisation’s self-description.
Decision rule: If the service may be close to the very-large threshold, treat classification as a governance decision with legal and operational owners, not a one-time policy label. That avoids under-scoping obligations that later become expensive to unwind.
Practitioner takeaway: The key issue is proportionality, but proportionality only helps if the organisation can prove where it sits in the regime and can evidence the controls that match that position.
Related resources from NHI Mgmt Group
- How should very large online platforms prepare for independent audits under the DSA?
- What is the difference between direct access and effective access in Active Directory?
- What is the difference between managing human identities and non-human identities?
- Why does the Digital Services Act create operational risk for large online platforms?