EDIH, EEN, Interreg: the platform for European programmes.Find out more

DMA Maturity · Digital Markets Act

Your DMA obligations, measured theme by theme and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

DMA Maturity · Digital Markets Act

Qualification and scopeN1 → N5
DMA compliance governanceN1 → N5
Data use and combinationN1 → N5
Self-preferencing and rankingN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Qualification and scope6484
DMA compliance governance5379
Data use and combination6182
Self-preferencing and ranking3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • ANITI
  • Pôle SCS
  • Cetim
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2022/1925 on Digital Markets (DMA), applicable since March 2024 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (a level, a level above, and the action linking the two) is what turns a finding into a trajectory.

Is data collected on a core platform service ring-fenced from the group’s other services?

  1. N1

    No mapping of data flows between services. Combination is possible and no one can say whether it happens.

  2. N2

    Main flows are identified in a document, but ring-fencing relies on internal rules that are not technically verified.

  3. N3

    Ring-fencing is implemented in the systems, a separate consent mechanism exists, and exceptions are documented.

  4. N4

    Technical controls are automated, access is logged, and any new flow goes through a compliance check before going into production.

  5. N5

    The arrangement is audited periodically, gaps feed into a documented review, and product changes are tested against the obligations before deployment.

Action to move from L2 to L3

Translate the flow mapping into technical ring-fencing rules within the relevant data warehouses, roll out a separate consent mechanism per service, and add verification of exceptions to the monthly product committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon DMA.

What this framework covers

The Digital Markets Act, Regulation (EU) 2022/1925, has applied since March 2024. It targets platforms designated by the European Commission as gatekeepers of core platform services: search engines, online marketplaces, operating systems, interpersonal messaging services, social networks, online advertising services, browsers. Its Articles 5, 6 and 7 set out directly applicable obligations: a ban on forced combination of data between services, interoperability for messaging services, business users’ access to their advertising performance data, an end to self-preferencing in rankings, and freedom to uninstall applications and choose default settings.

In practice, the DMA is hard to govern because it cannot be reduced to a legal file. It reaches into product architecture, data models, ranking rules and installation journeys. Who in the organisation can say whether data collected on one service still feeds targeting on another without separate consent? Do product teams have a review procedure before launching a feature that might breach an interoperability obligation? Do business users genuinely have continuous access to the data the regulation grants them, or only a one-off export on request?

One confusion keeps coming back: that the DMA only concerns a handful of very large designated platforms. Designation covers a limited number of players, but the ripple effect is wide. Business users of these services must review their contracts, data flows and acquisition strategies. Platforms approaching the quantitative thresholds need to anticipate possible designation and document their position. The DMA also needs to be read alongside the DSA, which deals with content and moderation, whereas the DMA deals with contestability and fairness of markets.

A compliance audit ends with a gap or a pass on a given obligation. The maturity assessment asks a different question: at what level of control do your practices sit, and what specific action moves you up a level. For a regulation whose enforcement rests on internal arrangements, product teams and review procedures, this progressive reading is what turns a set of findings into a transformation programme rather than a list of observations.

In Datamensio, the framework is ready to use and remains yours. The AI adjusts themes, questions and levels to your scope, whether you are a designated gatekeeper or a business user, and can build a variant from your own internal documents, policies and legal notes.

Reference standard: Regulation (EU) 2022/1925 on Digital Markets (DMA), applicable since March 2024

The themes assessed

  • Qualification and scope

    Analysis of quantitative and qualitative thresholds, identification of the core platform services concerned, tracking of designation decisions, monitoring of scope changes.

  • DMA compliance governance

    Dedicated compliance function, reporting line, roles and responsibilities across legal, product and technical teams, information provided to the governing body.

  • Data use and combination

    Mapping of flows between services, separate consent basis, ring-fencing of business users’ data, use of non-public data for competitive purposes.

  • Self-preferencing and ranking

    Ranking and display rules, treatment of own services versus third-party services, transparency of criteria, control of algorithmic changes.

  • Interoperability and technical access

    Interoperability of messaging services, access to hardware and software features, interfaces made available, documentation and associated service levels.

  • End user freedom of choice

    Uninstalling pre-installed applications, choice screens, changing default settings, installing third-party apps and app stores.

  • Business users’ rights

    Continuous access to data generated by their activity, fair and non-discriminatory commercial conditions, freedom to offer other conditions outside the platform, handling of complaints.

  • Portability and data transfer

    Effective portability arrangements for end users and business users, formats, continuity and free access.

  • Merger notification and relations with the Commission

    Procedure for prior notification of acquisitions in the digital sector, periodic reports, points of contact, handling of information requests and investigations.

  • Monitoring, audit and improvement

    Internal and external audits of measures implemented, tracking indicators, handling of gaps, lessons learned and updates to the framework.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Can the DMA be certified?

No. It is a directly applicable EU regulation, enforced by the European Commission, with no certification body. The assessment measures the maturity of your internal arrangements and prepares your exchanges with the regulator, it does not issue any certificate.

What is the difference between this assessment and a DMA compliance audit?

An audit checks each obligation and ends with a gap or a pass. The assessment places your practices on a progressive scale and points to the action that moves you up a level. The two complement each other: the assessment builds the trajectory, the audit validates the outcome.

Our company is not designated as a gatekeeper. Is the framework still useful?

Yes. Business users of designated services see their data access rights, contractual terms and acquisition channels changed by the regulation. The framework adapts to this viewpoint, focusing on the rights to exercise and the contracts to review.

How long does the assessment take?

The short version takes around thirty minutes to complete. The full version, run collaboratively with legal, product and technical contributors, usually spans one to two weeks, with most of the time spent gathering input from the teams.

Can the framework be adapted to our scope?

Yes. Themes, questions and levels can be changed, and the AI builds a variant from your internal policies or legal notes. You can narrow the assessment to a single core platform service or extend it across several business units.

How do we align DMA and DSA without duplicating the work?

The two regulations cover distinct subjects, market contestability for one, content and moderation for the other, but involve the same teams and the same governance arrangements. A cross-cutting roadmap consolidates both assessments and groups the common actions together.

Can several entities be compared with each other?

Yes. The same framework rolled out to several business units produces an internal benchmark, and each entity is also compared against its own past assessments. The AI groups the gaps into a prioritised roadmap at group level.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon DMA.