Updated augustus 8, 2026
Summary: The Digital Networks Act (COM(2026) 16) replaces the EECC with binding resilience, single-passport authorisation and high-risk vendor criteria that directly affect how regulated European organisations procure and govern sovereign connectivity. Integrating DNA obligations into existing NIS-2 and DORA frameworks is not optional: reporting gaps and conflicting competences create audit exposure.

The Digital Networks Act (DNA), proposed by the European Commission as COM(2026) 16, is the legislative successor to the European Electronic Communications Code (EECC) and the most significant rewrite of EU connectivity law in a decade. It places binding security and resilience obligations on electronic communications providers, introduces a single-passport authorisation model for cross-border connectivity, and establishes mandatory criteria for identifying and excluding high-risk vendors from 5G and future 6G networks. For compliance officers, CISOs and data-protection officers in regulated European sectors, the DNA is not a telecom-sector concern at arm’s length: it directly reshapes how sovereign data transit can be procured, governed and audited.

Security and resilience obligations under the DNA, and how they layer onto existing frameworks

The DNA’s security requirements for electronic communications providers build directly on the baseline established by NIS-2 Directive Article 21, but add communications-specific depth. Where NIS-2 Article 21 mandates generic risk management measures including access controls, incident handling, business continuity and supply-chain security, the DNA specifies those measures in terms of network integrity, routing security, traffic-localisation capabilities and mandatory incident notification timelines for telecom operators that are shorter than the general NIS-2 window.

The interaction with the Cybersecurity Act (Regulation (EU) 2019/881) is structural rather than duplicative: the DNA uses the Cybersecurity Act’s certification schemes as the technical reference for assessing network components and software used in communications infrastructure. A network component certified under a relevant European Cybersecurity Certification Scheme carries a rebuttable presumption of conformity with the DNA’s technical security requirements, which reduces audit friction for procuring organisations.

The CER Directive (Directive (EU) 2022/2557) covers resilience of critical entities at the physical and operational level: power, water, transport and digital infrastructure. The DNA and the CER Directive share scope where a communications operator is also designated a critical entity, but the DNA’s competent authority remains the national regulatory authority (NRA) for electronic communications, while CER competence sits with sector ministries or dedicated resilience authorities. The Commission’s explanatory memorandum to COM(2026) 16 explicitly addresses this overlap and requires member states to establish coordination mechanisms so that operators receive consistent guidance and are not subjected to duplicate audits.

Key point: An organisation designated as both an essential entity under NIS-2 and a critical entity under the CER Directive, that also operates electronic communications infrastructure, faces obligations from three overlapping regimes. The DNA introduces a single coordination point at national level, but only if member states implement the required interagency mechanism: organisations should verify that this mechanism is operational in every jurisdiction where they have infrastructure.

The EU Preparedness Plan for Digital Infrastructures and foreign-dependency reduction

The EU Preparedness Plan for Digital Infrastructures, introduced within the DNA framework, establishes a coordinated response architecture for large-scale connectivity failures, whether caused by cyberattack, physical disruption or deliberate interference by state actors. The Plan mandates that providers of public electronic communications networks publish and regularly test continuity scenarios covering loss of international connectivity, submarine cable failure and prolonged disruption to core routing infrastructure.

For regulated organisations that rely on third-party connectivity for sovereign data transit, the Preparedness Plan creates an indirect but enforceable obligation. Essential entities under NIS-2 and financial entities under DORA are expected to demonstrate that their own business-continuity plans are consistent with the scenarios the Plan defines. Where a connectivity provider’s tested resilience capabilities do not meet the Plan’s benchmarks, the procuring organisation faces audit exposure for having an inadequate ICT third-party risk assessment.

The DNA also mandates that member states report their degree of dependence on non-EU controlled network components and that this reporting feeds into a biennial EU-level dependency assessment coordinated by the Commission and BEREC (the Body of European Regulators for Electronic Communications). Organisations in finance, healthcare and government that route sensitive data over networks with significant non-EU component dependency should treat those assessments as red-flag indicators when reviewing connectivity procurement.

According to ENISA’s annual reports on telecom security incidents, around 30 percent of major outages in the EU between 2018 and 2022 were linked to third-party providers or hardware and software failures (ENISA, 2022). That figure underlines why the Preparedness Plan’s emphasis on reducing single points of foreign-controlled failure is commercially and operationally material, not merely a geopolitical policy preference.

See how Qsentinel solves this in practice.Start a 10-user pilot →

The Single Passport mechanism and supply-chain vetting in cross-border procurement

Under the EECC, a connectivity provider seeking to operate in multiple EU member states was required to obtain separate national authorisations in each jurisdiction, creating regulatory fragmentation and compliance cost. The DNA’s Single Passport replaces this with a single notification to one national regulatory authority, valid across the EU. The receiving NRA notifies BEREC, which maintains the EU-wide register of authorised providers.

For regulated organisations procuring cross-border connectivity, this simplification has a counterintuitive implication: a provider authorised under the Single Passport may be incorporated or ultimately controlled in a non-EU jurisdiction, and that fact will not appear in the authorisation itself. DORA Article 28 already requires financial entities to conduct documented risk assessments of ICT third-party providers, including their ownership structure, ultimate beneficial ownership and exposure to foreign-jurisdiction law. The DNA does not reduce that obligation; it adds a layer by requiring the procuring organisation to verify that the provider’s Single Passport registration is current and that no restrictions have been placed on it by BEREC or a national NRA.

Compliance action: When onboarding a connectivity provider under the DNA’s Single Passport regime, compliance teams should request the provider’s BEREC registration reference, the jurisdiction of incorporation of the ultimate parent entity, and written confirmation of whether the provider or any subsidiary is subject to the US CLOUD Act, FISA 702, or equivalent non-EU data-access legislation. This documentation should be retained as evidence in the DORA ICT third-party register.

Net neutrality, optimised services and traffic localisation for sovereign operators

The DNA retains the open internet principles established by Regulation (EU) 2015/2120 (the Open Internet Regulation) but introduces a clearer regulatory category for “optimised services”: traffic classes carrying contractual quality-of-service guarantees for latency-sensitive applications such as telemedicine, industrial automation and secure government communications. These services are permitted as long as they do not degrade general internet traffic below an acceptable minimum quality threshold.

Sovereign infrastructure operators who implement traffic-localisation policies, routing data exclusively through Swiss or EU-domiciled nodes to satisfy GDPR data-residency requirements or DORA geographic concentration rules, must structure those policies carefully. Traffic localisation is not inherently a net-neutrality violation, but it must be applied transparently and consistently. BEREC’s guidelines on the Open Internet Regulation, which will be updated to reflect the DNA’s optimised-services framework, provide the reference standard for demonstrating that localisation does not constitute discriminatory blocking or throttling.

ICT supply-chain dependencies and evaluating 5G and 6G providers against high-risk vendor criteria

The DNA formalises the high-risk vendor assessment process that was previously carried out through the EU 5G Toolbox (a non-binding coordinated approach agreed in 2020). Under the DNA, national NRAs and BEREC are required to evaluate network equipment suppliers against criteria including: the legal and regulatory environment of the supplier’s country of incorporation, the degree of state influence over the supplier, the supplier’s track record on security vulnerabilities and patch management, and the existence of any credible intelligence indicating the supplier as a vector for state-sponsored interference.

For sovereign infrastructure teams evaluating 5G or future 6G network providers, the DNA’s criteria provide a defensible, regulator-endorsed framework for vendor exclusion or conditional approval. The IBM Cost of a Data Breach Report 2024 recorded an average breach cost of USD 4.88 million globally, the highest figure in the report’s history (IBM, 2024). At that cost level, the risk calculus for allowing a high-risk vendor into core connectivity infrastructure is straightforward: the annual cost of vendor replacement is almost always lower than the expected value of a single significant incident traced to a compromised network component.

ENISA’s threat landscape for 2023 recorded 2,580 significant incidents against transport, energy, finance and digital infrastructure sectors in the EU (ENISA, 2023). Connectivity infrastructure is both a target in its own right and the medium through which attacks against other critical sectors are delivered.

Integrating DNA obligations into NIS-2 and DORA incident-management frameworks

The DNA introduces a third incident-reporting timeline alongside those already required by NIS-2 (24-hour early warning, 72-hour notification, one-month final report) and DORA (four-hour initial notification for major ICT incidents, 24-hour intermediate, one-month final). The DNA’s notification requirements for electronic communications providers follow a similar but not identical structure, and the competent authority receiving DNA notifications is the NRA for electronic communications, not the cybersecurity authority designated under NIS-2 or the financial supervisor competent under DORA.

This divergence in competent authorities is the most operationally significant integration challenge. An organisation that operates communications infrastructure and is also a financial entity subject to DORA (a realistic profile for large banks with private network operations) must route incident notifications to at least two separate authorities under potentially different timelines. The DNA requires member states to establish coordination protocols between the NRA and the NIS-2 national authority, but those protocols are still being developed in most jurisdictions.

The practical integration approach is to build a single incident classification matrix that identifies, at the moment of detection, which regulatory notification obligations are triggered: DNA (if the incident affects electronic communications services), NIS-2 (if the affected system is an essential or important entity system), and DORA (if the affected entity is a financial entity and the incident meets major incident criteria). Each pathway should have a named responsible owner, a documented notification template and a retention policy for evidence submitted to regulators. This matrix should be tested annually in a tabletop exercise that includes the communications provider as a participant, not only internal IT and legal teams.

Regulatory framework Competent authority Initial notification deadline Scope trigger
NIS-2 (Directive (EU) 2022/2555) National cybersecurity authority (e.g. BSI, ANSSI, NCSC) 24 hours (early warning) Incident affecting essential or important entity
DORA (Regulation (EU) 2022/2554) Sector financial supervisor (EBA, ECB, national authority) 4 hours (major ICT incident) Major ICT-related incident in a financial entity
Digital Networks Act (COM(2026) 16) National regulatory authority for electronic communications 24 hours (as proposed) Incident affecting public electronic communications network or service
CER Directive (Directive (EU) 2022/2557) Designated critical entity competent authority As soon as practicable Incident with significant disruptive effect on critical entity operations

The European Commission’s explanatory memorandum to COM(2026) 16 is explicit that the DNA is a strategic instrument for reducing Europe’s dependency on non-EU controlled infrastructure, not merely a technical regulatory update. CISOs and compliance officers who treat it as a telecom-procurement matter rather than a sovereign-infrastructure governance matter will find themselves explaining gaps to regulators who have already aligned their inspection frameworks to that strategic intent.

FAQ

Does the Digital Networks Act replace the European Electronic Communications Code entirely?

Yes. COM(2026) 16 is designed to supersede the EECC (Directive 2018/1972) and consolidate electronic communications regulation into a single instrument. Transitional provisions will apply during the implementation period, so obligations under the EECC remain enforceable until national transposition of the DNA is complete.

If my organisation is already NIS-2 compliant, do the DNA’s security requirements add new obligations?

Partly. The DNA’s security obligations for electronic communications providers largely map onto NIS-2 Article 21 measures, but they also introduce connectivity-specific requirements around network integrity, traffic localisation and supply-chain vetting for 5G and 6G that go beyond the general NIS-2 baseline. Regulated entities that operate or procure communications infrastructure should conduct a gap analysis against both frameworks.

What is the EU Preparedness Plan for Digital Infrastructures and who does it bind?

The EU Preparedness Plan for Digital Infrastructures is an instrument introduced under the DNA framework that coordinates member state and operator responses to large-scale connectivity disruptions. It applies primarily to providers of public electronic communications networks, but organisations classified as critical entities under the CER Directive and essential entities under NIS-2 are expected to align their own business-continuity planning with the Plan’s scenarios and timelines.

How does the DNA Single Passport affect procurement of cross-border connectivity by a financial institution subject to DORA?

The Single Passport allows a connectivity provider authorised in one member state to offer services across the EU without obtaining separate national licences. For a DORA-regulated financial entity, this simplifies contracting but does not reduce supply-chain due-diligence obligations: DORA Article 28 and the DNA’s high-risk vendor criteria both require documented risk assessments of ICT third parties, including their ownership structure and exposure to non-EU jurisdiction.

Can traffic localisation under a sovereign connectivity model conflict with the DNA’s net-neutrality rules?

Traffic localisation for data-residency reasons is not inherently incompatible with net neutrality, provided the routing policy is applied consistently and does not degrade other internet traffic. Sovereign infrastructure operators should document their localisation logic to demonstrate compliance with both regimes to national regulators and BEREC.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Does the Digital Networks Act replace the European Electronic Communications Code entirely?
Yes. COM(2026) 16 is designed to supersede the EECC (Directive 2018/1972) and consolidate electronic communications regulation into a single instrument. Transitional provisions will apply during the implementation period, so obligations under the EECC remain enforceable until national transposition of the DNA is complete.
If my organisation is already NIS-2 compliant, do the DNA's security requirements add new obligations?
Partly. The DNA's security obligations for electronic communications providers largely map onto NIS-2 Article 21 measures, but they also introduce connectivity-specific requirements around network integrity, traffic localisation and supply-chain vetting for 5G and 6G that go beyond the general NIS-2 baseline. Regulated entities that operate or procure communications infrastructure should conduct a gap analysis against both frameworks.
What is the EU Preparedness Plan for Digital Infrastructures and who does it bind?
The EU Preparedness Plan for Digital Infrastructures is an instrument introduced under the DNA framework that coordinates member state and operator responses to large-scale connectivity disruptions. It applies primarily to providers of public electronic communications networks, but organisations classified as critical entities under the CER Directive and essential entities under NIS-2 are expected to align their own business-continuity planning with the Plan's scenarios and timelines.
How does the DNA Single Passport affect procurement of cross-border connectivity by a financial institution subject to DORA?
The Single Passport allows a connectivity provider authorised in one member state to offer services across the EU without obtaining separate national licences. For a DORA-regulated financial entity, this simplifies contracting but does not reduce supply-chain due-diligence obligations: DORA Article 28 and the DNA's high-risk vendor criteria both require documented risk assessments of ICT third parties, including their ownership structure and exposure to non-EU jurisdiction.
Can traffic localisation under a sovereign connectivity model conflict with the DNA's net-neutrality rules?
The DNA retains net-neutrality principles from the Open Internet Regulation but introduces a clearer framework for 'optimised services' that can carry quality-of-service guarantees without violating neutrality. Traffic localisation for data-residency reasons is not inherently incompatible with net neutrality, provided the routing policy is applied consistently and does not degrade other internet traffic. Sovereign infrastructure operators should document their localisation logic to demonstrate compliance with both regimes to national regulators and BEREC.