Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should organisations prepare for DMA compliance when…
Governance, Ownership & Risk

How should organisations prepare for DMA compliance when their platform may qualify as a gatekeeper?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Governance, Ownership & Risk

Organisations should map whether their core platform services meet the DMA thresholds for size, gateway power, and durable market position, then prepare evidence to rebut designation if appropriate. They should also identify profiling activities, document data processing logic, and plan for the independent audit and public overview required by Article 15. Governance, legal review, and technical traceability all matter.

What to assess before designating gatekeeper status

The first job is to test the platform against the DMA’s gatekeeper logic as an evidence problem, not a branding exercise. That means checking whether the core service sits at scale, whether users and business customers are locked into it as a gateway, and whether the market position looks durable enough to survive rebuttal scrutiny.

Organisations should treat this as a cross-functional review across legal, product, finance, and architecture. The practical question is whether the platform can produce a coherent record showing how it meets, or does not meet, the threshold conditions and the behavioural signs that regulators will expect to see in a designation inquiry.

  • Document the service boundary: which products count as core platform services, which do not, and why.
  • Collect usage, revenue, and dependency evidence that supports or challenges threshold tests.
  • Preserve internal decisions that show how the platform’s market role is measured over time.

Build the evidence trail for profiling, processing logic, and audit readiness

Once gatekeeper qualification becomes plausible, the compliance burden shifts from proving abstract capability to showing traceable, explainable operations. Organisations need to map profiling activities, understand what data is used to reach user-facing or market-facing decisions, and be able to describe the logic at a level that survives both internal challenge and external review.

This is where technical traceability matters. Logs, documentation, data lineage, and model or rule descriptions should be aligned so that the organisation can explain not only what it does, but how it does it. That same evidence base should also support the independent audit and public overview expected under Article 15.

  • Inventory every profiling path and link it to the product or service that performs it.
  • Keep decision logic, data sources, and change history in a reviewable form.
  • Make sure audit artefacts can be regenerated without relying on institutional memory.

Risk and Threat Considerations

DMA preparation fails most often when organisations treat designation as a legal formality and leave the operating evidence too thin to defend. The main exposure is not only being designated, but being unable to show the factual basis for rebuttal, profiling transparency, or audit readiness when regulators ask for it.

Failure mechanism: fragmented ownership, incomplete logging, and undocumented decision logic create gaps between the platform’s actual behaviour and the evidence available to prove it.

Impact: the organisation may lose rebuttal credibility, enter remediation under pressure, and face broader compliance exposure if profiling or data-processing claims cannot be substantiated.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV — OversightDMA readiness depends on governance oversight for designation, profiling, and audit evidence.
ID.GV — Risk Management StrategyThreshold testing and rebuttal preparation are risk-governance activities for a regulated platform.
Recommendation — Assign oversight for gatekeeper assessment and compliance evidence across legal, product, and technical owners. Document the platform-risk strategy for designation, rebuttal, and audit readiness.
CIS Controls v88 — Audit Log ManagementArticle 15 readiness relies on traceable records of profiling and processing decisions.
Recommendation — Centralise and retain logs needed to reconstruct profiling and data-processing decisions.
ISO/IEC 42001:2023AI Management SystemIf profiling uses AI, organisational governance must control transparency, accountability, and reviewability.
Recommendation — Govern profiling systems with documented accountability, traceability, and reviewable decision logic.

Practitioner Guidance

What to prioritise: Build one defensible compliance record for each core platform service, then reuse it across legal review, product governance, and audit preparation. The highest-value work is usually evidence consolidation, not policy drafting.

What to verify: Confirm that profiling descriptions, data-processing maps, and service boundary decisions all point to the same operating reality. If those three views diverge, treat the gap as a compliance issue before designation becomes formal.

Practitioner takeaway: Organisations should prepare for DMA scrutiny by proving how the platform works in practice, not by asserting what it intends to do; traceable evidence is what makes rebuttal and audit readiness credible.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org