Compliance Doesn't Start With a Checklist. It Starts With a Question
The wrong question
Most compliance conversations start the same way: "Are we DSA compliant?"
It's the wrong question, and not because it's too hard to answer. It's because it assumes every platform is answering the same exam. They're not. The DSA doesn't hand every online service one list of obligations. It hands different services different lists, and which list you get depends on what kind of service you are and how big you've grown.
The question that actually needs answering first is narrower: which obligations even apply to us? Everything downstream, policies, engineering work, evidence, reporting, depends on getting that answer right before you start ticking boxes.
How the DSA does it
The DSA builds its obligations on a ladder. Mere conduits (pure network access) sit at the bottom. Hosting services sit above them. Online platforms sit above that. Very Large Online Platforms and Search Engines, VLOPs and VLOSEs, sit at the top, triggered once a service crosses 45 million average monthly users in the EU.
Each rung adds obligations on top of the one below it. Nothing is replaced, it's additive. A handful of obligations apply regardless of tier, most notably the exemption for micro and small enterprises. That exemption drops away the moment a small platform is designated a VLOP. Size doesn't buy you out of the rules that scale with reach.
We pulled the real numbers from our live obligation set rather than quoting a fixed figure. The honest answer changes as the regulation gets interpreted and as new enforcement guidance lands. Right now, a basic intermediary service faces a fraction of the obligations a full online platform does. A designated VLOP with advertising, a recommender system, and a marketplace faces close to the full set. Add the recommender system alone and the obligation count jumps again. Article 27's transparency requirements only switch on for services that actually rank and recommend content. Same platform, one feature flag, a materially different compliance surface.
That's the part people miss when they picture the DSA as one checklist. It's four or five checklists, and which one lands on your desk depends on answers you may not have formally worked out yet.
How the OSA does it, differently
The UK's Online Safety Act draws its lines in a different place, with different thresholds, but the same underlying logic. Ofcom's categorisation register sorts services into three tiers. Category 1 covers large user-to-user services with a recommender system: over 34 million UK users on their own, or over 7 million UK users if the service also lets users share content onward. Category 2A covers search services with more than 7 million UK users. Category 2B covers other qualifying user-to-user services that fall below the Category 1 bar.
Ofcom's own working estimate, going in, was that somewhere between 12 and 16 services would land in Category 1. The register that actually published on 10 July 2026 named 11, alongside a separate "emerging services" list for platforms close enough to the line that Ofcom is watching them without formally categorising them yet.
Different statute, different regulator, different thresholds entirely, but the same shape: size and functionality decide which obligations apply, and the line isn't always where the first estimate said it would be.
The pattern
Strip away the article numbers and the acronyms, and the DSA and the OSA are doing structurally the same thing. Neither is a flat list you compare yourself against. Both are decision logic: is this platform hosting, or an online platform, or something bigger? Does it recommend content? Does it let users share what they see? How many people actually use it, and where?
Answer those questions and the applicable obligation set falls out the other end. Get one of those inputs wrong, an outdated user count, a feature you shipped last quarter that nobody flagged, and the list you're working from is wrong too. You end up either missing obligations you're now exposed on, or carrying obligations that never applied to you in the first place.
This is what we mean by categorisation-aware compliance: treating classification as a live input to the compliance process, not a one-time form filled in at onboarding and never revisited.
Categorisation isn't a life sentence
Worth remembering: crossing a threshold isn't permanent, and it isn't always final in the direction you'd expect. Wikipedia spent over a year in the UK courts arguing it shouldn't be swept into the most demanding tier. Its case rested on a simple point: Wikipedia looks nothing like the platforms the rule was written for. It lost that specific argument, and ended up off the list anyway, watched but not categorised.
That's worth remembering next time a threshold looks like a wall instead of a door. Categorisation gets contested, and it gets revisited. A platform that grows into VLOP territory this year isn't stuck there forever if its user numbers move. A platform that adds a recommender system doesn't need to wait for its next annual review to find out what that switched on.
Why this has to be a live system, not a form
This is the part of the product we spend significant engineering effort on, and it's the part that's easiest to underrate. We don't ask a platform to self-report its tier once and generate a static obligation list from that answer. Every obligation in our system carries its own applicability logic. It knows which service tiers it applies to, which features it requires, whether the SME exemption covers it, whether it only switches on above a VLOP threshold.
We built it this way because thresholds move, features ship, and regulators publish new registers on their own schedule, not yours. Compliance is not a rules and features exercise that happens once and is then filed away and forgotten. It's a continuously moving target (in the technical sense, not the cynical one). Treat categorisation as an input you check once, and you're not doing DSA or OSA compliance. You're doing compliance for the platform you used to be.
If you're working out where your own platform sits on either ladder, we're happy to walk through it.