Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Digital Markets Act
Cyber Security

Digital Markets Act

← Back to Glossary
By NHI Mgmt Group Updated September 20, 2026 Domain: Cyber Security

The Digital Markets Act is an EU competition law for large online platforms that act as gatekeepers between businesses and consumers. It sets thresholds for designation and imposes conduct rules meant to reduce bottlenecks, improve fairness, and increase transparency in how core platform services operate.

How the Digital Markets Act changes platform competition

The Digital Markets Act is not a general consumer protection law or a technical security standard. It is a competition regime aimed at a narrow set of large online platforms, with the main objective of reducing bottlenecks created when one company controls key gateways between businesses and users.

That matters because gatekeeper power can shape who gets discovered, which services can interoperate, how easily users can switch, and whether business users face fair terms. In practice, the Act is designed to curb self-preferencing and other conduct that can lock ecosystems into a dominant platform’s rules.

What obligations typically matter for gatekeepers

The Digital Markets Act combines designation thresholds with conduct obligations, so the first practical question is whether a platform meets the gatekeeper criteria and then which services fall within scope. Once designated, the platform must treat certain business users more fairly, open up specific access paths, and be more transparent about how core platform services operate.

For readers, the most important idea is that the Act regulates market structure and behavior, not just disclosure. It can require changes to default settings, ranking behavior, access to data, app distribution, and interoperability. Those obligations can alter product design, commercial terms, and platform governance at the same time.

Why transparency and interoperability are central

Transparency reduces the information asymmetry that often exists when a gatekeeper controls search, app stores, ad tech, operating systems, messaging, or marketplace access. Without clearer rules, business users may not know why they were ranked lower, why an account action was taken, or how platform rules are applied unevenly.

Interoperability is equally important because it limits lock-in. If users and business users can move data, connect competing services, or communicate across platform boundaries more easily, the platform’s control over distribution and switching costs becomes less absolute. For practitioners, this is a policy question about market access, but it also affects product architecture and operational change management.

How it is enforced and where the pressure points are

Enforcement can create significant operational pressure because compliance is measured against specific conduct rules rather than broad intentions. That means documentation, product behavior, ranking logic, interface design, and access controls may all need to be demonstrably aligned with the regime’s requirements.

Large platforms that are designated as gatekeepers often need to coordinate legal, engineering, product, and policy functions so the same service does not drift out of compliance in different countries or business lines. The practical challenge is not only following the rule, but proving that the platform’s implementation actually matches the rule’s intent.

Risk and Threat Considerations

When a platform is designated, the main risk is regulatory exposure from conduct that preserves bottlenecks, weakens transparency, or frustrates interoperability. Because the law targets structural power, even subtle product choices can create compliance problems if they are seen as preserving unfair advantage or restricting business user access.

Failure mechanism: A gatekeeper can introduce risk through self-preferencing, opaque ranking, restricted access paths, or design choices that keep users and business partners dependent on one ecosystem.

Impact: The likely consequences are enforcement action, forced product changes, reputational damage, and higher switching friction for businesses and consumers who rely on the platform.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernDMA compliance requires governance over platform conduct, accountability, and regulatory obligations.
PR.AC — Identity Management, Authentication, and Access ControlDMA obligations around access and fair treatment intersect with how platform access is governed and enforced.
GV.SC — Cybersecurity Supply Chain Risk ManagementDMA impacts third-party platform dependencies, distribution channels, and ecosystem concentration risk.
Recommendation — Assign governance ownership for DMA-scoped platform conduct and track compliance decisions as part of enterprise risk management. Align access-control behavior with documented policy so platform rules are applied consistently and transparently. Map critical platform dependencies and third-party relationships that could amplify concentration or access risk.
CIS Controls v86 — Access Control ManagementDMA interoperability and business-user access issues are directly affected by access control decisions and permissions.
Recommendation — Review and restrict platform access paths so business-user entitlements and interoperability choices match policy requirements.

Practitioner Guidance

Governance implication: Teams should treat Digital Markets Act obligations as a cross-functional operating constraint, not a legal afterthought. Product decisions that affect ranking, access, defaults, data use, or interoperability need to be reviewable against the designation scope and the specific conduct rules that apply.

Practitioner takeaway: The safest approach is to design for demonstrable fairness and explainability early, because retrofitting compliance into a mature platform is usually slower, costlier, and more disruptive than building it in from the start.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org