For the complete documentation index, see llms.txt. This page is also available as Markdown.

Commission DSA Q&A β€” Risk and audit reports

Commission Q&A on publication of DSA risk assessment, mitigation, audit and audit implementation reports.

Authority

Commission

Q&A ID

Commission DSA risk/audit FAQ

Topic

Risk assessment, mitigation, audit and audit implementation reports

Legal basis

Article 34, Article 35, Article 37 and Article 42(4) DSA

Status

Final Q&A

Published

18 February 2026

Source

Commission FAQ

Question

How does the Commission Q&A describe publication of DSA risk assessment, mitigation, audit and audit implementation reports?

Final answer

The Commission Q&A states that providers of VLOPs and VLOSEs must publish, on an annual basis, reports on their risk assessments, the mitigation measures put in place, audit reports and audit implementation reports. Those reports are transmitted to the Commission and the Digital Services Coordinator of establishment during the relevant risk-assessment cycle.

The Q&A explains that publication should take place no later than three months after the provider receives the yearly compliance audit report. It also addresses publication of ad hoc risk assessments, public versions of reports, confidentiality redactions, the need to explain removed information to the Commission and the Digital Services Coordinator of establishment, and the obligation to publish in a public, easily accessible and machine-readable format.

Last updated