The Digital Networks Act (DNA), proposed by the European Commission as COM(2026) 16, is the legislative successor to the European Electronic Communications Code (EECC) and the most significant rewrite of EU connectivity law in a decade. It places binding security and resilience obligations on electronic communications providers, introduces a single-passport authorisation model for cross-border connectivity, and establishes mandatory criteria for identifying and excluding high-risk vendors from 5G and future 6G networks. For compliance officers, CISOs and data-protection officers in regulated European sectors, the DNA is not a telecom-sector concern at arm’s length: it directly reshapes how sovereign data transit can be procured, governed and audited.
Security and resilience obligations under the DNA, and how they layer onto existing frameworks
The DNA’s security requirements for electronic communications providers build directly on the baseline established by NIS-2 Directive Article 21, but add communications-specific depth. Where NIS-2 Article 21 mandates generic risk management measures including access controls, incident handling, business continuity and supply-chain security, the DNA specifies those measures in terms of network integrity, routing security, traffic-localisation capabilities and mandatory incident notification timelines for telecom operators that are shorter than the general NIS-2 window.
The interaction with the Cybersecurity Act (Regulation (EU) 2019/881) is structural rather than duplicative: the DNA uses the Cybersecurity Act’s certification schemes as the technical reference for assessing network components and software used in communications infrastructure. A network component certified under a relevant European Cybersecurity Certification Scheme carries a rebuttable presumption of conformity with the DNA’s technical security requirements, which reduces audit friction for procuring organisations.
The CER Directive (Directive (EU) 2022/2557) covers resilience of critical entities at the physical and operational level: power, water, transport and digital infrastructure. The DNA and the CER Directive share scope where a communications operator is also designated a critical entity, but the DNA’s competent authority remains the national regulatory authority (NRA) for electronic communications, while CER competence sits with sector ministries or dedicated resilience authorities. The Commission’s explanatory memorandum to COM(2026) 16 explicitly addresses this overlap and requires member states to establish coordination mechanisms so that operators receive consistent guidance and are not subjected to duplicate audits.
The EU Preparedness Plan for Digital Infrastructures and foreign-dependency reduction
The EU Preparedness Plan for Digital Infrastructures, introduced within the DNA framework, establishes a coordinated response architecture for large-scale connectivity failures, whether caused by cyberattack, physical disruption or deliberate interference by state actors. The Plan mandates that providers of public electronic communications networks publish and regularly test continuity scenarios covering loss of international connectivity, submarine cable failure and prolonged disruption to core routing infrastructure.
For regulated organisations that rely on third-party connectivity for sovereign data transit, the Preparedness Plan creates an indirect but enforceable obligation. Essential entities under NIS-2 and financial entities under DORA are expected to demonstrate that their own business-continuity plans are consistent with the scenarios the Plan defines. Where a connectivity provider’s tested resilience capabilities do not meet the Plan’s benchmarks, the procuring organisation faces audit exposure for having an inadequate ICT third-party risk assessment.
The DNA also mandates that member states report their degree of dependence on non-EU controlled network components and that this reporting feeds into a biennial EU-level dependency assessment coordinated by the Commission and BEREC (the Body of European Regulators for Electronic Communications). Organisations in finance, healthcare and government that route sensitive data over networks with significant non-EU component dependency should treat those assessments as red-flag indicators when reviewing connectivity procurement.
According to ENISA’s annual reports on telecom security incidents, around 30 percent of major outages in the EU between 2018 and 2022 were linked to third-party providers or hardware and software failures (ENISA, 2022). That figure underlines why the Preparedness Plan’s emphasis on reducing single points of foreign-controlled failure is commercially and operationally material, not merely a geopolitical policy preference.
The Single Passport mechanism and supply-chain vetting in cross-border procurement
Under the EECC, a connectivity provider seeking to operate in multiple EU member states was required to obtain separate national authorisations in each jurisdiction, creating regulatory fragmentation and compliance cost. The DNA’s Single Passport replaces this with a single notification to one national regulatory authority, valid across the EU. The receiving NRA notifies BEREC, which maintains the EU-wide register of authorised providers.
For regulated organisations procuring cross-border connectivity, this simplification has a counterintuitive implication: a provider authorised under the Single Passport may be incorporated or ultimately controlled in a non-EU jurisdiction, and that fact will not appear in the authorisation itself. DORA Article 28 already requires financial entities to conduct documented risk assessments of ICT third-party providers, including their ownership structure, ultimate beneficial ownership and exposure to foreign-jurisdiction law. The DNA does not reduce that obligation; it adds a layer by requiring the procuring organisation to verify that the provider’s Single Passport registration is current and that no restrictions have been placed on it by BEREC or a national NRA.
Net neutrality, optimised services and traffic localisation for sovereign operators
The DNA retains the open internet principles established by Regulation (EU) 2015/2120 (the Open Internet Regulation) but introduces a clearer regulatory category for “optimised services”: traffic classes carrying contractual quality-of-service guarantees for latency-sensitive applications such as telemedicine, industrial automation and secure government communications. These services are permitted as long as they do not degrade general internet traffic below an acceptable minimum quality threshold.
Sovereign infrastructure operators who implement traffic-localisation policies, routing data exclusively through Swiss or EU-domiciled nodes to satisfy GDPR data-residency requirements or DORA geographic concentration rules, must structure those policies carefully. Traffic localisation is not inherently a net-neutrality violation, but it must be applied transparently and consistently. BEREC’s guidelines on the Open Internet Regulation, which will be updated to reflect the DNA’s optimised-services framework, provide the reference standard for demonstrating that localisation does not constitute discriminatory blocking or throttling.
ICT supply-chain dependencies and evaluating 5G and 6G providers against high-risk vendor criteria
The DNA formalises the high-risk vendor assessment process that was previously carried out through the EU 5G Toolbox (a non-binding coordinated approach agreed in 2020). Under the DNA, national NRAs and BEREC are required to evaluate network equipment suppliers against criteria including: the legal and regulatory environment of the supplier’s country of incorporation, the degree of state influence over the supplier, the supplier’s track record on security vulnerabilities and patch management, and the existence of any credible intelligence indicating the supplier as a vector for state-sponsored interference.
For sovereign infrastructure teams evaluating 5G or future 6G network providers, the DNA’s criteria provide a defensible, regulator-endorsed framework for vendor exclusion or conditional approval. The IBM Cost of a Data Breach Report 2024 recorded an average breach cost of USD 4.88 million globally, the highest figure in the report’s history (IBM, 2024). At that cost level, the risk calculus for allowing a high-risk vendor into core connectivity infrastructure is straightforward: the annual cost of vendor replacement is almost always lower than the expected value of a single significant incident traced to a compromised network component.
ENISA’s threat landscape for 2023 recorded 2,580 significant incidents against transport, energy, finance and digital infrastructure sectors in the EU (ENISA, 2023). Connectivity infrastructure is both a target in its own right and the medium through which attacks against other critical sectors are delivered.
Integrating DNA obligations into NIS-2 and DORA incident-management frameworks
The DNA introduces a third incident-reporting timeline alongside those already required by NIS-2 (24-hour early warning, 72-hour notification, one-month final report) and DORA (four-hour initial notification for major ICT incidents, 24-hour intermediate, one-month final). The DNA’s notification requirements for electronic communications providers follow a similar but not identical structure, and the competent authority receiving DNA notifications is the NRA for electronic communications, not the cybersecurity authority designated under NIS-2 or the financial supervisor competent under DORA.
This divergence in competent authorities is the most operationally significant integration challenge. An organisation that operates communications infrastructure and is also a financial entity subject to DORA (a realistic profile for large banks with private network operations) must route incident notifications to at least two separate authorities under potentially different timelines. The DNA requires member states to establish coordination protocols between the NRA and the NIS-2 national authority, but those protocols are still being developed in most jurisdictions.
The practical integration approach is to build a single incident classification matrix that identifies, at the moment of detection, which regulatory notification obligations are triggered: DNA (if the incident affects electronic communications services), NIS-2 (if the affected system is an essential or important entity system), and DORA (if the affected entity is a financial entity and the incident meets major incident criteria). Each pathway should have a named responsible owner, a documented notification template and a retention policy for evidence submitted to regulators. This matrix should be tested annually in a tabletop exercise that includes the communications provider as a participant, not only internal IT and legal teams.
| Regulatory framework | Competent authority | Initial notification deadline | Scope trigger |
|---|---|---|---|
| NIS-2 (Directive (EU) 2022/2555) | National cybersecurity authority (e.g. BSI, ANSSI, NCSC) | 24 hours (early warning) | Incident affecting essential or important entity |
| DORA (Regulation (EU) 2022/2554) | Sector financial supervisor (EBA, ECB, national authority) | 4 hours (major ICT incident) | Major ICT-related incident in a financial entity |
| Digital Networks Act (COM(2026) 16) | National regulatory authority for electronic communications | 24 hours (as proposed) | Incident affecting public electronic communications network or service |
| CER Directive (Directive (EU) 2022/2557) | Designated critical entity competent authority | As soon as practicable | Incident with significant disruptive effect on critical entity operations |
The European Commission’s explanatory memorandum to COM(2026) 16 is explicit that the DNA is a strategic instrument for reducing Europe’s dependency on non-EU controlled infrastructure, not merely a technical regulatory update. CISOs and compliance officers who treat it as a telecom-procurement matter rather than a sovereign-infrastructure governance matter will find themselves explaining gaps to regulators who have already aligned their inspection frameworks to that strategic intent.
FAQ
Does the Digital Networks Act replace the European Electronic Communications Code entirely?
Yes. COM(2026) 16 is designed to supersede the EECC (Directive 2018/1972) and consolidate electronic communications regulation into a single instrument. Transitional provisions will apply during the implementation period, so obligations under the EECC remain enforceable until national transposition of the DNA is complete.
If my organisation is already NIS-2 compliant, do the DNA’s security requirements add new obligations?
Partly. The DNA’s security obligations for electronic communications providers largely map onto NIS-2 Article 21 measures, but they also introduce connectivity-specific requirements around network integrity, traffic localisation and supply-chain vetting for 5G and 6G that go beyond the general NIS-2 baseline. Regulated entities that operate or procure communications infrastructure should conduct a gap analysis against both frameworks.
What is the EU Preparedness Plan for Digital Infrastructures and who does it bind?
The EU Preparedness Plan for Digital Infrastructures is an instrument introduced under the DNA framework that coordinates member state and operator responses to large-scale connectivity disruptions. It applies primarily to providers of public electronic communications networks, but organisations classified as critical entities under the CER Directive and essential entities under NIS-2 are expected to align their own business-continuity planning with the Plan’s scenarios and timelines.
How does the DNA Single Passport affect procurement of cross-border connectivity by a financial institution subject to DORA?
The Single Passport allows a connectivity provider authorised in one member state to offer services across the EU without obtaining separate national licences. For a DORA-regulated financial entity, this simplifies contracting but does not reduce supply-chain due-diligence obligations: DORA Article 28 and the DNA’s high-risk vendor criteria both require documented risk assessments of ICT third parties, including their ownership structure and exposure to non-EU jurisdiction.
Can traffic localisation under a sovereign connectivity model conflict with the DNA’s net-neutrality rules?
Traffic localisation for data-residency reasons is not inherently incompatible with net neutrality, provided the routing policy is applied consistently and does not degrade other internet traffic. Sovereign infrastructure operators should document their localisation logic to demonstrate compliance with both regimes to national regulators and BEREC.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
