EDIH, EEN, Interreg: the platform for European programmes.Find out more

DSA maturity · Digital Services Act

Your DSA obligations placed on a maturity scale and translated into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

DSA maturity · Digital Services Act

Service qualification and scopeN1 → N5
Points of contact and representationN1 → N5
Terms and conditions and interface fairnessN1 → N5
Notice and action on contentN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Service qualification and scope6484
Points of contact and representation5379
Terms and conditions and interface fairness6182
Notice and action on content3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • ANITI
  • Pôle SCS
  • Cetim
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2022/2065 on Digital Services (Digital Services Act) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism, a level, the level above, and the action linking the two, is what turns an observation into a trajectory.

Are moderation decisions accompanied by a statement of reasons sent to the affected recipient?

  1. N1

    No reason is communicated. The content or account is removed, the recipient sees the removal with no explanation.

  2. N2

    A standard message is sent in some cases. It specifies neither the grounds invoked nor the possible remedy, and whether it is sent depends on the handling channel.

  3. N3

    A statement of reasons is sent for all restriction decisions: the underlying fact, contractual or legal grounds, scope of the measure, available remedies.

  4. N4

    The statement of reasons is generated from the moderation tool, submitted to the transparency database, and complaints received are reconciled with the original decisions.

  5. N5

    Overturn rates from complaints and out of court settlement feed into the periodic review of rules and statement of reasons templates, with documented tracking of revisions.

Action to move from level 2 to level 3

Replace standard messages with a single statement of reasons template covering the elements required by Article 17, make it mandatory in every moderation flow, and check a sample of decisions at the monthly Trust and Safety committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon DSA.

What this framework covers

The Digital Services Act, Regulation (EU) 2022/2065, has applied to all intermediary services since 17 February 2024. It organises obligations in layers: a common baseline for intermediary services, reinforced obligations for hosting services, additional obligations for online platforms, then a specific regime for very large online platforms and very large online search engines designated by the Commission. Notice and action mechanism, statement of reasons for moderation decisions, internal complaint handling system, transparency of advertising and recommender systems, periodic reports: each layer adds enforceable requirements.

In practice, the difficulty is not knowing the text but knowing where the organisation stands. Is the notification mechanism accessible from every piece of content, or does it redirect to a generic support form? Are takedown decisions justified, logged and submitted to the transparency database, or handled in a ticketing tool with no audit trail? Are the main parameters of the recommender system described in the terms and conditions in genuinely understandable language? Does the single point of contact exist, and is it clear who responds when an authority writes in?

One confusion comes up often: the DSA is not GDPR, nor is it the DMA. GDPR covers personal data, the DMA covers gatekeeper practices, the DSA covers liability for content and fairness of the interface. Another commonly misunderstood point: the regime also applies to actors who do not see themselves as platforms, a marketplace embedded in a commerce site, a customer review space, a messaging service or a file hosting service. The designation of the Digital Services Coordinator in each member state has made these matters enforceable at national level.

The maturity assessment answers a different question from a compliance audit. An audit asks whether the requirement is met, yes or no. The assessment places the practice on a progressive scale: does the mechanism exist, is it documented, applied consistently, measured, reviewed. Above all it points to the concrete action that moves you up a level. Datamensio measures maturity and prepares for external review, it does not issue any certification.

The framework is ready to use in Datamensio and adapts to your scope. AI adjusts themes, questions and levels according to your status under the regulation, or builds a bespoke version from your terms and conditions, moderation procedures and transparency reports.

Reference standard: Regulation (EU) 2022/2065 on Digital Services (Digital Services Act)

The themes assessed

  • Service qualification and scope

    Determination of status under the regulation, intermediary services, hosting, online platform, exemptions for micro and small enterprises, mapping of affected services across the group.

  • Points of contact and representation

    Single point of contact for authorities and for recipients of the service, legal representative in the Union for actors established outside the EU, publication of contact details, response times.

  • Terms and conditions and interface fairness

    Clarity of terms of use, description of moderation policies, information for minors, absence of misleading dark patterns in interface design.

  • Notice and action on content

    Accessibility of the notification mechanism, handling of notices, trusted flaggers, measures against abuse of the mechanism.

  • Statement of reasons and remedies

    Statement of reasons sent to recipients, submission to the transparency database, internal complaint handling system, out of court dispute settlement.

  • Advertising and recommendation transparency

    Identification of adverts and the advertiser, advertising repository for relevant actors, description of the main parameters of recommender systems, option not based on profiling.

  • Trader traceability

    For platforms enabling distance contracts, verification of trader information, interface design for pre contractual information, informing consumers in the event of an illegal product.

  • Transparency reports and data

    Frequency and content of reports, moderation indicators, declared human and language resources, quality and auditability of underlying data, researcher access to data where applicable.

  • Systemic risk assessment

    For designated entities, analysis of risks relating to the dissemination of illegal content, fundamental rights, civic discourse and protection of minors, mitigation measures, independent audit, crisis response mechanism.

  • Governance and cooperation with authorities

    Internal roles and responsibilities, procedures for responding to orders to act against illegal content or to provide information, logging, relationship with the national coordinator and the Commission.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Can the DSA be certified?

No. It is a directly applicable EU regulation, overseen by the Digital Services Coordinator of the member state of establishment and, for designated entities, by the Commission. The assessment measures the maturity of your arrangements and prepares for these exchanges, it does not issue any certification.

What is the difference between this assessment and a DSA compliance audit?

An audit checks whether a requirement is present and concludes with a gap or a pass. The assessment places each practice on a progressive scale and points to the action that moves it up a level. The two complement each other: the assessment prepares, the audit validates.

Is my company affected if it is not a large platform?

The baseline of the regulation applies to any intermediary service, including a review space, an embedded marketplace or a hosting service. Obligations accumulate by layer according to the nature of the service, and some exemptions exist for micro and small enterprises. The first theme of the framework is precisely designed to qualify your situation.

How long does the assessment take?

The short version takes 20 to 30 minutes to complete. The full version, run collaboratively with legal, product and moderation teams, typically spans one to two weeks, with most of the time spent gathering evidence.

Can the framework be adapted to our scope?

Yes. Questions, levels and themes can be changed, and you can remove sections that do not apply to your status. AI also builds a bespoke version from your terms and conditions and internal procedures. The framework belongs to you.

How can several services or subsidiaries be compared?

Each online service is assessed separately, then scores are compared by theme across business units and over time. A cross cutting roadmap consolidates action plans to avoid funding the same work twice.

How does the DSA fit with the DMA and GDPR?

The three texts stack without overlapping: liability for content under the DSA, gatekeeper practices under the DMA, personal data processing under GDPR. Advertising transparency and governance arrangements are largely reusable from one assessment to another.

Where is data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.

Take your first measurementon DSA.