Domain Name Wire Podcast cover image

Domain Name Wire Podcast

NIS2 is here – DNW Podcast #464

Dec 4, 2023
34:30
Snipd AI
Polina Malaja, Policy Director of CENTR, discusses the impact of the NIS2 EU Directive on domain name registrations. She explains the directive's purpose, its effects on domain registrars and registries, and its implications for the domain name ecosystem. They also cover various domain name news, including Donald Trump losing over a pet duck and Aftermarket Indicator.
Read more

Podcast summary created with Snipd AI

Quick takeaways

  • NIS2 Directive imposes minimum cybersecurity risk management measures and data accuracy obligations on TLD registries and DNS service providers.
  • Flexibility and proportionality are crucial in implementing verification procedures to balance cybersecurity objectives and accessibility for end users.

Deep dives

The NIS2 Directive and Its Impact on Domain Name Ecosystem

The NIS2 Directive is a new European Union law on cybersecurity that aims to harmonize cybersecurity preparedness levels in critical sectors, including the digital infrastructure. This directive applies to TLD registries and DNS service providers, making them essential entities that must adopt minimum cybersecurity risk management measures and report security incidents to authorities. Non-compliance with these measures could result in penalties of up to 2% of the total worldwide annual turnover. Additionally, the directive introduces a data accuracy obligation, requiring TLD registries and entities providing registration services to collect and maintain accurate registration data, respond to legitimate access seekers within 72 hours, and cooperate to prevent duplication of data collection. The penalties for non-compliance with data accuracy obligations are left to member states to decide. Registrants should be aware that additional verification steps for identity information may be introduced in the future, potentially leading to more costly and delayed domain registrations. Member states implementing the directive should carefully consider existing instruments, such as GDPR, and exercise caution when introducing verification procedures at the national level to avoid unnecessary obstacles for end users and allow flexibility for operators to conduct checks based on identified risks.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode