NIS2 for Digital infrastructure
The most size-independent sector in the directive. Several categories here are in scope whatever their headcount or turnover, which catches small specialist providers off guard.
Which entities are covered
IXP operators, DNS service providers excluding root name server operators, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, providers of public electronic communications networks and publicly available electronic communications services.
Sub-sectors named in the annex
- Internet exchange points
- DNS service providers
- TLD name registries
- Cloud computing service providers
- Data centre service providers
- Content delivery networks
- Trust service providers
- Public electronic communications networks and services
Scope traps specific to this sector
Trap 1
DNS service providers, TLD name registries, trust service providers and providers of public electronic communications networks or services are in scope REGARDLESS OF SIZE.
Trap 2
Cloud and data centre providers established outside the EU that serve EU customers must designate a representative in a member state.
Trap 3
Your customers own article 21(2)(d) supply chain obligations that will reach you contractually even where you are not directly in scope.
What else applies to you
eIDAS (Regulation (EU) No 910/2014) for trust service providers; the EECC (Directive (EU) 2018/1972) for telecoms.
NIS2 rarely arrives alone. Where another EU act covers the same ground and is at least equivalent in effect, article 4 disapplies the corresponding NIS2 provisions — but only those, and only where that test is met.