A platform is a strong DMA candidate when it has very large EU turnover or market value, operates a core platform service in at least three Member States, and has more than 45 million monthly active end users or more than 10,000 yearly active business users in the EU. Persistence over three financial years strengthens the case further.
What the DMA is really measuring before gatekeeper duties attach
The DMA does not look for a generic “big platform” label. It is designed to identify an entrenched intermediary that can shape market access, user choice, and business dependence across the EU. The signposts in the direct answer matter because they combine scale, multi-country reach, and durable activity, which together suggest structural market power rather than a temporary spike.
That is why turnover or market value alone is not enough. Likewise, a large user base without business-user dependence is not the full test. The obligation threshold is built to capture platforms whose position is durable, broad, and hard for competitors or users to обход.
One useful comparison point is how the DMA treats entrenched dominance as a measurable operational condition, not a branding exercise. The European Commission’s EU AI Act takes a different route, but it similarly ties obligations to defined thresholds rather than informal size judgments, which is the same regulatory logic at work here.
How to read the threshold pattern in practice
The strongest sign is the combination, not any single number. Very large EU turnover or market value tells you the platform has economic weight. Core platform service presence in at least three Member States tells you the service is not just local or incidental. More than 45 million monthly active end users or more than 10,000 yearly active business users shows the platform is already serving a mass or commercially embedded audience.
Persistence over three financial years matters because gatekeeper obligations are aimed at durable ecosystem power. A one-year surge can reflect growth, a product launch, or a cyclical market shift. Three years of threshold-level performance suggests the platform is operating at a scale where dependencies, switching costs, and access leverage are likely to be persistent.
For a practitioner, the key question is whether the platform’s commercial footprint and usage pattern are stable enough that the EU will view its position as structurally significant. If the platform is crossing the thresholds only briefly, the case is weaker. If it is repeatedly above them and operating across multiple Member States, the obligation analysis becomes much more credible.
Risk and Threat Considerations
When a platform is close to DMA gatekeeper status, the risk is not just regulatory exposure. The same scale signals that make obligations likely also indicate that the platform can become a control point for distribution, discovery, billing, ranking, or business access. That creates heightened consequences if the platform misclassifies its footprint, delays self-assessment, or underestimates how quickly obligations can attach once the thresholds are met.
Failure mechanism: Organisations often look at one metric in isolation, such as revenue or users, and miss the cumulative threshold pattern, especially when the activity is spread across subsidiaries, services, or Member States. If the three-year persistence test is also overlooked, teams may assume they are below the line until a formal designation process is already underway.
Impact: The result can be late compliance planning, weak internal ownership, and rushed changes to business practices after obligations become credible. For a platform that functions as a market gateway, that delay can translate into operational disruption, legal exposure, and avoidable friction with commercial partners who depend on stable platform rules.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 set the technical controls, while NIS2 and EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC — Organizational Context | DMA gatekeeper analysis depends on understanding the platform's EU footprint and business context. |
| GV.RM — Risk Management Strategy | Threshold proximity creates regulatory and operational risk that should be formally tracked. | |
| GV.SC — Cyber Supply Chain Risk Management | Gatekeeper platforms often create ecosystem dependence and partner exposure across connected services. | |
| Recommendation — Define the platform's EU operating context and threshold exposure before assigning compliance ownership. Track DMA threshold risk in the organisation's risk register and escalate persistent near-threshold status. Assess partner and ecosystem dependencies that may amplify the compliance impact of gatekeeper designation. | ||
| NIS2 | Art. 21 — Cybersecurity Risk-Management Measures | Cross-border operational scale and compliance governance require formal risk-management measures. |
| Recommendation — Use formal risk-management controls to monitor threshold-adjacent regulatory obligations. | ||
| EU AI Act | Article 52 — Transparency Obligations | The answer uses the same regulatory pattern of threshold-based obligations for powerful digital systems. |
| Recommendation — Apply threshold-based obligation tracking where platform scale changes regulatory duties. | ||
Practitioner Guidance
What to verify: Validate the threshold picture across the exact service scope that the DMA would examine, not just the parent company headline. Separate turnover, market value, service presence, user counts, and business-user counts by core platform service so you can see whether the same entity is persistently in scope.
Decision rule: If a platform is near threshold on more than one measure, treat it as a live gatekeeper candidate and prepare compliance workstreams before formal designation. If it is only near one measure, keep monitoring but avoid overcommitting to a designation-only response.
Practitioner takeaway: The practical signal is not “large platform equals DMA,” but “large, cross-border, and persistently used platform across multiple threshold dimensions equals a meaningful likelihood of gatekeeper treatment.”
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org