Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a platform is…
Cyber Security

What are the signs that a platform is likely to fall under DMA gatekeeper obligations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Cyber Security

A platform is a strong DMA candidate when it has very large EU turnover or market value, operates a core platform service in at least three Member States, and has more than 45 million monthly active end users or more than 10,000 yearly active business users in the EU. Persistence over three financial years strengthens the case further.

What the DMA is really measuring before gatekeeper duties attach

The DMA does not look for a generic “big platform” label. It is designed to identify an entrenched intermediary that can shape market access, user choice, and business dependence across the EU. The signposts in the direct answer matter because they combine scale, multi-country reach, and durable activity, which together suggest structural market power rather than a temporary spike.

That is why turnover or market value alone is not enough. Likewise, a large user base without business-user dependence is not the full test. The obligation threshold is built to capture platforms whose position is durable, broad, and hard for competitors or users to обход.

One useful comparison point is how the DMA treats entrenched dominance as a measurable operational condition, not a branding exercise. The European Commission’s EU AI Act takes a different route, but it similarly ties obligations to defined thresholds rather than informal size judgments, which is the same regulatory logic at work here.

How to read the threshold pattern in practice

The strongest sign is the combination, not any single number. Very large EU turnover or market value tells you the platform has economic weight. Core platform service presence in at least three Member States tells you the service is not just local or incidental. More than 45 million monthly active end users or more than 10,000 yearly active business users shows the platform is already serving a mass or commercially embedded audience.

Persistence over three financial years matters because gatekeeper obligations are aimed at durable ecosystem power. A one-year surge can reflect growth, a product launch, or a cyclical market shift. Three years of threshold-level performance suggests the platform is operating at a scale where dependencies, switching costs, and access leverage are likely to be persistent.

For a practitioner, the key question is whether the platform’s commercial footprint and usage pattern are stable enough that the EU will view its position as structurally significant. If the platform is crossing the thresholds only briefly, the case is weaker. If it is repeatedly above them and operating across multiple Member States, the obligation analysis becomes much more credible.

Risk and Threat Considerations

When a platform is close to DMA gatekeeper status, the risk is not just regulatory exposure. The same scale signals that make obligations likely also indicate that the platform can become a control point for distribution, discovery, billing, ranking, or business access. That creates heightened consequences if the platform misclassifies its footprint, delays self-assessment, or underestimates how quickly obligations can attach once the thresholds are met.

Failure mechanism: Organisations often look at one metric in isolation, such as revenue or users, and miss the cumulative threshold pattern, especially when the activity is spread across subsidiaries, services, or Member States. If the three-year persistence test is also overlooked, teams may assume they are below the line until a formal designation process is already underway.

Impact: The result can be late compliance planning, weak internal ownership, and rushed changes to business practices after obligations become credible. For a platform that functions as a market gateway, that delay can translate into operational disruption, legal exposure, and avoidable friction with commercial partners who depend on stable platform rules.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 set the technical controls, while NIS2 and EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC — Organizational ContextDMA gatekeeper analysis depends on understanding the platform's EU footprint and business context.
GV.RM — Risk Management StrategyThreshold proximity creates regulatory and operational risk that should be formally tracked.
GV.SC — Cyber Supply Chain Risk ManagementGatekeeper platforms often create ecosystem dependence and partner exposure across connected services.
Recommendation — Define the platform's EU operating context and threshold exposure before assigning compliance ownership. Track DMA threshold risk in the organisation's risk register and escalate persistent near-threshold status. Assess partner and ecosystem dependencies that may amplify the compliance impact of gatekeeper designation.
NIS2Art. 21 — Cybersecurity Risk-Management MeasuresCross-border operational scale and compliance governance require formal risk-management measures.
Recommendation — Use formal risk-management controls to monitor threshold-adjacent regulatory obligations.
EU AI ActArticle 52 — Transparency ObligationsThe answer uses the same regulatory pattern of threshold-based obligations for powerful digital systems.
Recommendation — Apply threshold-based obligation tracking where platform scale changes regulatory duties.

Practitioner Guidance

What to verify: Validate the threshold picture across the exact service scope that the DMA would examine, not just the parent company headline. Separate turnover, market value, service presence, user counts, and business-user counts by core platform service so you can see whether the same entity is persistently in scope.

Decision rule: If a platform is near threshold on more than one measure, treat it as a live gatekeeper candidate and prepare compliance workstreams before formal designation. If it is only near one measure, keep monitoring but avoid overcommitting to a designation-only response.

Practitioner takeaway: The practical signal is not “large platform equals DMA,” but “large, cross-border, and persistently used platform across multiple threshold dimensions equals a meaningful likelihood of gatekeeper treatment.”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org