Organisations should map whether their core platform services meet the DMA thresholds for size, gateway power, and durable market position, then prepare evidence to rebut designation if appropriate. They should also identify profiling activities, document data processing logic, and plan for the independent audit and public overview required by Article 15. Governance, legal review, and technical traceability all matter.
What to assess before designating gatekeeper status
The first job is to test the platform against the DMA’s gatekeeper logic as an evidence problem, not a branding exercise. That means checking whether the core service sits at scale, whether users and business customers are locked into it as a gateway, and whether the market position looks durable enough to survive rebuttal scrutiny.
Organisations should treat this as a cross-functional review across legal, product, finance, and architecture. The practical question is whether the platform can produce a coherent record showing how it meets, or does not meet, the threshold conditions and the behavioural signs that regulators will expect to see in a designation inquiry.
- Document the service boundary: which products count as core platform services, which do not, and why.
- Collect usage, revenue, and dependency evidence that supports or challenges threshold tests.
- Preserve internal decisions that show how the platform’s market role is measured over time.
Build the evidence trail for profiling, processing logic, and audit readiness
Once gatekeeper qualification becomes plausible, the compliance burden shifts from proving abstract capability to showing traceable, explainable operations. Organisations need to map profiling activities, understand what data is used to reach user-facing or market-facing decisions, and be able to describe the logic at a level that survives both internal challenge and external review.
This is where technical traceability matters. Logs, documentation, data lineage, and model or rule descriptions should be aligned so that the organisation can explain not only what it does, but how it does it. That same evidence base should also support the independent audit and public overview expected under Article 15.
- Inventory every profiling path and link it to the product or service that performs it.
- Keep decision logic, data sources, and change history in a reviewable form.
- Make sure audit artefacts can be regenerated without relying on institutional memory.
Risk and Threat Considerations
DMA preparation fails most often when organisations treat designation as a legal formality and leave the operating evidence too thin to defend. The main exposure is not only being designated, but being unable to show the factual basis for rebuttal, profiling transparency, or audit readiness when regulators ask for it.
Failure mechanism: fragmented ownership, incomplete logging, and undocumented decision logic create gaps between the platform’s actual behaviour and the evidence available to prove it.
Impact: the organisation may lose rebuttal credibility, enter remediation under pressure, and face broader compliance exposure if profiling or data-processing claims cannot be substantiated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV — Oversight | DMA readiness depends on governance oversight for designation, profiling, and audit evidence. |
| ID.GV — Risk Management Strategy | Threshold testing and rebuttal preparation are risk-governance activities for a regulated platform. | |
| Recommendation — Assign oversight for gatekeeper assessment and compliance evidence across legal, product, and technical owners. Document the platform-risk strategy for designation, rebuttal, and audit readiness. | ||
| CIS Controls v8 | 8 — Audit Log Management | Article 15 readiness relies on traceable records of profiling and processing decisions. |
| Recommendation — Centralise and retain logs needed to reconstruct profiling and data-processing decisions. | ||
| ISO/IEC 42001:2023 | AI Management System | If profiling uses AI, organisational governance must control transparency, accountability, and reviewability. |
| Recommendation — Govern profiling systems with documented accountability, traceability, and reviewable decision logic. | ||
Practitioner Guidance
What to prioritise: Build one defensible compliance record for each core platform service, then reuse it across legal review, product governance, and audit preparation. The highest-value work is usually evidence consolidation, not policy drafting.
What to verify: Confirm that profiling descriptions, data-processing maps, and service boundary decisions all point to the same operating reality. If those three views diverge, treat the gap as a compliance issue before designation becomes formal.
Practitioner takeaway: Organisations should prepare for DMA scrutiny by proving how the platform works in practice, not by asserting what it intends to do; traceable evidence is what makes rebuttal and audit readiness credible.
Related resources from NHI Mgmt Group
- How should organisations prioritise IAM controls to improve compliance with limited resources?
- How should organisations decide which information security policies to create first when they need to support multiple compliance frameworks?
- How should organisations build a policy governance framework that keeps policies consistent across HR, legal, IT, and compliance teams?
- Why does a fragmented policy process increase compliance risk in large organisations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org