§ NIS2 Directive BRIEFING

NIS2 Directive Obligations for Domain name system providers

9 obligations from NIS2 Directive mapped to domain name system providers. Articles, deadlines, and penalties — extracted verbatim from the Regulation.

Summary

NIS2 Directive sets 9 obligations that apply to domain name system providers. This page lists them with article references, obligated-entity language, and penalties — extracted verbatim from the Regulation, not paraphrased.

Use the obligation table and breakdown to scope a compliance programme. The cross-regulatory conflicts section surfaces places where this regulation pulls against neighbouring EU frameworks for the same sector.

Who this applies to
Companies operating in domain name system providers that fall within NIS2 Directive's scope.
Compliance deadline
Mixed timelines — see obligations below.
§ Detail

In depth

Obligations in scope

Article 28 — TLD name registries and entities providing domain name registration services

Collect and maintain accurate and complete domain name registration data in a dedicated database with due diligence in accordance with Union data protection law. Action required: collect and maintain.

Article 28 — TLD name registries and entities providing domain name registration services

Ensure the database contains necessary information to identify and contact domain name holders and administrators, including domain name, registration date, registrant details, and administrator contact details. Action required: contain.

Article 28 — TLD name registries and entities providing domain name registration services

Have policies and procedures, including verification procedures, in place to ensure the databases include accurate and complete information. Action required: have.

Article 28 — TLD name registries and entities providing domain name registration services

Make policies and procedures regarding data accuracy and verification publicly available. Action required: make publicly available.

Article 28 — TLD name registries and entities providing domain name registration services

Make publicly available, without undue delay after registration, the domain name registration data which are not personal data. Action required: make publicly available. Deadline: without undue delay after registration.

Article 28 — TLD name registries and entities providing domain name registration services

Provide access to specific domain name registration data upon lawful and duly substantiated requests by legitimate access seekers, in accordance with Union data protection law. Action required: provide access.

Article 28 — TLD name registries and entities providing domain name registration services

Reply to requests for access to specific domain name registration data without undue delay and in any event within 72 hours of receipt. Action required: reply. Deadline: within 72 hours of receipt.

Practical steps

What the obligations on this page actually require you to do, ordered by article. Use this as a starting checklist; verify each item against the underlying article text before treating it as legal advice.

Obligation reference table

ArticleObligated entityDeadlinePenalty
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration serviceswithout undue delay after registration
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration serviceswithin 72 hours of receipt
Art 28TLD name registries and entities providing domain name registration services
Art 28TLD name registries and entities providing domain name registration services

Penalty exposure

None of the 9 obligations on this page carry an explicit penalty figure in the NIS2 Directive text itself — the fine ceiling is set elsewhere in the regulation and applies by reference. Refer to NIS2 Directive's general penalties article (or the diagnostic below) to estimate exposure before signing off on a compliance programme.

Cross-regulatory conflicts

NIS2 Directive interacts with other EU regulations in ways that can pull compliance teams in opposite directions. The most concrete conflicts in the Fontvera corpus involving this regulation:

Related Fontvera pages

Check your full compliance exposure with the 5-minute Fontvera diagnostic →

§ What Fontvera found

Documents in our corpus

enisa EU Fetched 2026-04
enisa EU Fetched 2026-04
§ Cross-references

Related Fontvera intelligence

Need a cross-border briefing on this?
Search Fontvera ↵ Run the AI Act diagnostic
AI Act enforcement
63 days
until 2026-08-02, when most AI Act provisions begin to apply.