DMA Maturity · Digital Markets Act
Your DMA obligations, measured theme by theme and turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
DMA Maturity · Digital Markets Act
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Regulation (EU) 2022/1925 on Digital Markets (DMA), applicable since March 2024 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism (a level, a level above, and the action linking the two) is what turns a finding into a trajectory.
Is data collected on a core platform service ring-fenced from the group’s other services?
- N1
No mapping of data flows between services. Combination is possible and no one can say whether it happens.
- N2
Main flows are identified in a document, but ring-fencing relies on internal rules that are not technically verified.
- N3
Ring-fencing is implemented in the systems, a separate consent mechanism exists, and exceptions are documented.
- N4
Technical controls are automated, access is logged, and any new flow goes through a compliance check before going into production.
- N5
The arrangement is audited periodically, gaps feed into a documented review, and product changes are tested against the obligations before deployment.
Action to move from L2 to L3
Translate the flow mapping into technical ring-fencing rules within the relevant data warehouses, roll out a separate consent mechanism per service, and add verification of exceptions to the monthly product committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon DMA.
What this framework covers
The Digital Markets Act, Regulation (EU) 2022/1925, has applied since March 2024. It targets platforms designated by the European Commission as gatekeepers of core platform services: search engines, online marketplaces, operating systems, interpersonal messaging services, social networks, online advertising services, browsers. Its Articles 5, 6 and 7 set out directly applicable obligations: a ban on forced combination of data between services, interoperability for messaging services, business users’ access to their advertising performance data, an end to self-preferencing in rankings, and freedom to uninstall applications and choose default settings.
In practice, the DMA is hard to govern because it cannot be reduced to a legal file. It reaches into product architecture, data models, ranking rules and installation journeys. Who in the organisation can say whether data collected on one service still feeds targeting on another without separate consent? Do product teams have a review procedure before launching a feature that might breach an interoperability obligation? Do business users genuinely have continuous access to the data the regulation grants them, or only a one-off export on request?
One confusion keeps coming back: that the DMA only concerns a handful of very large designated platforms. Designation covers a limited number of players, but the ripple effect is wide. Business users of these services must review their contracts, data flows and acquisition strategies. Platforms approaching the quantitative thresholds need to anticipate possible designation and document their position. The DMA also needs to be read alongside the DSA, which deals with content and moderation, whereas the DMA deals with contestability and fairness of markets.
A compliance audit ends with a gap or a pass on a given obligation. The maturity assessment asks a different question: at what level of control do your practices sit, and what specific action moves you up a level. For a regulation whose enforcement rests on internal arrangements, product teams and review procedures, this progressive reading is what turns a set of findings into a transformation programme rather than a list of observations.
In Datamensio, the framework is ready to use and remains yours. The AI adjusts themes, questions and levels to your scope, whether you are a designated gatekeeper or a business user, and can build a variant from your own internal documents, policies and legal notes.
Reference standard: Regulation (EU) 2022/1925 on Digital Markets (DMA), applicable since March 2024
The themes assessed
Qualification and scope
Analysis of quantitative and qualitative thresholds, identification of the core platform services concerned, tracking of designation decisions, monitoring of scope changes.
DMA compliance governance
Dedicated compliance function, reporting line, roles and responsibilities across legal, product and technical teams, information provided to the governing body.
Data use and combination
Mapping of flows between services, separate consent basis, ring-fencing of business users’ data, use of non-public data for competitive purposes.
Self-preferencing and ranking
Ranking and display rules, treatment of own services versus third-party services, transparency of criteria, control of algorithmic changes.
Interoperability and technical access
Interoperability of messaging services, access to hardware and software features, interfaces made available, documentation and associated service levels.
End user freedom of choice
Uninstalling pre-installed applications, choice screens, changing default settings, installing third-party apps and app stores.
Business users’ rights
Continuous access to data generated by their activity, fair and non-discriminatory commercial conditions, freedom to offer other conditions outside the platform, handling of complaints.
Portability and data transfer
Effective portability arrangements for end users and business users, formats, continuity and free access.
Merger notification and relations with the Commission
Procedure for prior notification of acquisitions in the digital sector, periodic reports, points of contact, handling of information requests and investigations.
Monitoring, audit and improvement
Internal and external audits of measures implemented, tracking indicators, handling of gaps, lessons learned and updates to the framework.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Can the DMA be certified?
No. It is a directly applicable EU regulation, enforced by the European Commission, with no certification body. The assessment measures the maturity of your internal arrangements and prepares your exchanges with the regulator, it does not issue any certificate.
What is the difference between this assessment and a DMA compliance audit?
An audit checks each obligation and ends with a gap or a pass. The assessment places your practices on a progressive scale and points to the action that moves you up a level. The two complement each other: the assessment builds the trajectory, the audit validates the outcome.
Our company is not designated as a gatekeeper. Is the framework still useful?
Yes. Business users of designated services see their data access rights, contractual terms and acquisition channels changed by the regulation. The framework adapts to this viewpoint, focusing on the rights to exercise and the contracts to review.
How long does the assessment take?
The short version takes around thirty minutes to complete. The full version, run collaboratively with legal, product and technical contributors, usually spans one to two weeks, with most of the time spent gathering input from the teams.
Can the framework be adapted to our scope?
Yes. Themes, questions and levels can be changed, and the AI builds a variant from your internal policies or legal notes. You can narrow the assessment to a single core platform service or extend it across several business units.
How do we align DMA and DSA without duplicating the work?
The two regulations cover distinct subjects, market contestability for one, content and moderation for the other, but involve the same teams and the same governance arrangements. A cross-cutting roadmap consolidates both assessments and groups the common actions together.
Can several entities be compared with each other?
Yes. The same framework rolled out to several business units produces an internal benchmark, and each entity is also compared against its own past assessments. The AI groups the gaps into a prioritised roadmap at group level.
Where is the data hosted?
In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





