The proposed revision of the EU Cybersecurity Act is now a direct concern for national domain registries. CENTR, the association representing European ccTLD registries, has welcomed the goal of improving digital resilience while warning that supply-chain rules must not create disproportionate obligations for operators of essential DNS infrastructure.
The issue is not whether national domains should be secure. The real question is how to turn ICT supply-chain security into workable obligations for registries that are often non-profit or small-scale operators and already subject to NIS 2, critical-entity rules, data protection duties and sector-specific security expectations.
Read also: Nominet prova a rilanciare .uk: incentivi ai registrar senza aprire la porta all’abuso
The trusted supply-chain question
The Commission proposal, introduced in January 2026, would create a framework for assessing high-risk ICT suppliers. CENTR argues that such assessments should be grounded in concrete security evidence, not broad or subjective non-technical criteria that could disrupt critical internet operators without improving actual resilience.
For a registry, replacing network components, registry platforms, software dependencies or operational providers is not a simple procurement exercise. It can involve long migrations, costs, contractual complexity and continuity risk. CENTR therefore asks for impact assessments, meaningful consultation and the ability for affected entities to challenge decisions that could interfere with operations.
Why ccTLDs are different
National domain registries operate public internet infrastructure. They maintain DNS zones, registration data, registrar relationships, abuse-handling procedures and local cooperation channels with authorities and technical communities. In many countries, the ccTLD is also part of the country’s digital identity.
That is why CENTR is pushing for a narrower supply-chain definition focused on direct contractual relationships, with broader systemic risks considered only where necessary and proportionate. The DNS is distributed and standards-based; treating open protocols or indirect dependencies as if they were all controllable suppliers could weaken the model the rules are meant to protect.
Read also: La registry .co cambia rotta sulle aste dei domini scaduti: cosa rischiano registrar e investitori
The Webinvest View
For the domain market, this debate is more than a policy detail. Cybersecurity regulation is becoming an industrial variable for registries and registrars. Better supplier governance is necessary, but overbroad rules could increase costs, slow investment and make national namespaces less competitive.
The strongest path is evidence-based regulation: clear risk criteria, operator consultation, realistic transition periods and respect for ccTLD governance autonomy. That would improve resilience without turning DNS operations into an excessive compliance burden.
Source: CircleID; CENTR document: CENTR Comment on Cybersecurity Act 2.
← All news