NIS2 · Sector deep-dive
NIS2 for Digital Infrastructure
Digital infrastructure is the broadest Annex I sector and the one most often underestimated. It covers internet exchange point providers, DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, providers of public electronic communications networks and providers of publicly available electronic communications services. Several of these are in scope regardless of headcount or turnover.
Why this sector is regulated differently
Every other NIS2 sector depends on this one. A hospital, a bank and a water utility all run on somebody's cloud, resolve somebody's DNS and terminate on somebody's network. That dependency is why the directive both widens the entity list and, in specific cases, removes the size-cap rule — a small registry or trust service provider can still be a single point of failure for millions of users.
It also explains the strong emphasis on supply chain security running through the directive. Recital 85 and Article 21(3) direct entities to take into account the vulnerabilities of each direct supplier and the overall quality of their products and cybersecurity practices. If you sell infrastructure services, you are the supplier being assessed, and increasingly your customers will pass their NIS2 obligations to you through contract clauses long before your own supervisor comes calling.
There is a jurisdictional twist too. For several digital infrastructure entity types, NIS2 applies the main establishment rule rather than the ordinary territoriality rule, so a provider serving many member states answers primarily to one authority — the one where it takes its cybersecurity decisions — and must nominate a representative in the EU if it is established outside it.
Where providers typically have the biggest gaps
- Assuming certification equals compliance. An ISO 27001 certificate is strong evidence for several measures but does not by itself cover the reporting timeline, the registration duty or management accountability.
- No registration submitted. Cloud, DNS, CDN and data centre providers must submit entity details to the competent authority under Article 27, including the member states where they provide services. Many have not.
- Vulnerability disclosure with no route in. A published contact and a coordinated vulnerability disclosure policy is expected of infrastructure providers, yet security.txt and a monitored inbox are still missing at a surprising share of them.
- Customer notification duties ignored. Article 23 requires informing recipients of your services about significant incidents that may adversely affect them, and about measures they can take. That is a communications capability, not just a legal clause.
What this means for the Article 21 measures
- Security in acquisition, development and maintenance — Article 21(2)(e). Secure development lifecycle, dependency management and a documented patch cadence for the platform your customers depend on.
- Cryptography and access control — Article 21(2)(h) and (i). Documented key management, tenant isolation, and MFA on every administrative and support path into customer environments.
- Effectiveness assessment — Article 21(2)(f). Evidence that the measures work: penetration test reports, audit findings and their remediation, not just a policy library.
See the full Article 21 requirements and the 24-hour, 72-hour and one-month reporting sequence, which for this sector includes notifying affected customers alongside the authority.
Documentation
The NIS2 Starter Kit covers the governance, risk and supplier documentation your own customers will ask you for during their vendor assessments.
