Commission DSA Q&A β Risk and audit reports
Commission Q&A on publication of DSA risk assessment, mitigation, audit and audit implementation reports.
Last updated
Commission Q&A on publication of DSA risk assessment, mitigation, audit and audit implementation reports.
Authority
Commission
Q&A ID
Commission DSA risk/audit FAQ
Topic
Risk assessment, mitigation, audit and audit implementation reports
Legal basis
Article 34, Article 35, Article 37 and Article 42(4) DSA
Status
Final Q&A
Published
18 February 2026
Source
How does the Commission Q&A describe publication of DSA risk assessment, mitigation, audit and audit implementation reports?
The Commission Q&A states that providers of VLOPs and VLOSEs must publish, on an annual basis, reports on their risk assessments, the mitigation measures put in place, audit reports and audit implementation reports. Those reports are transmitted to the Commission and the Digital Services Coordinator of establishment during the relevant risk-assessment cycle.
The Q&A explains that publication should take place no later than three months after the provider receives the yearly compliance audit report. It also addresses publication of ad hoc risk assessments, public versions of reports, confidentiality redactions, the need to explain removed information to the Commission and the Digital Services Coordinator of establishment, and the obligation to publish in a public, easily accessible and machine-readable format.
DSA Article 34 β risk assessment.
DSA Article 35 β mitigation of risks.
DSA Article 37 β independent audit.
DSA Article 42 β transparency reporting obligations.
Last updated