Source: OJ L, 2024/2690, 18.10.2024

Current language: FR

Article 6 Incidents importants concernant les registres de noms de domaine de premier niveau


Summary What does Article 6 of the Cybersecurity measures and significant incidents for relevant entities say?

This article is one in a series of sector-specific articles that build on the general significance criteria established in Article 3, applying tailored thresholds to specific types of entities.

Here, it sets out the conditions under which an incident affecting a TLD (Top-Level Domain) name registry must be classified as significant.

Notably, the thresholds for TLD name registries are stricter than those for comparable entities, reflecting the critical nature of their role in internet infrastructure — for example, any complete unavailability of the authoritative domain name resolution service, regardless of duration, triggers a significant incident classification.

Important points:

  • TLD name registries must treat an incident as significant if any one of three criteria is met: complete unavailability of the authoritative DNS service, average response times exceeding 10 seconds for more than one hour, or a compromise of the integrity, confidentiality, or authenticity of data related to the TLD's technical operation.
  • Unlike other entity types in this regulation, there is no minimum duration threshold for complete unavailability — any outage qualifies as significant.
  • This article operates as a specific application of Article 3(1)(g), meaning these criteria supplement, rather than replace, the broader significance criteria set out in Article 3.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

En ce qui concerne les registres de noms de domaine de premier niveau, un incident est considéré comme important au sens de l’article 3, paragraphe 1, point g), lorsqu’il remplit un ou plusieurs des critères suivants:

  1. un service de résolution de noms de domaine faisant autorité est totalement indisponible;

  2. pendant une période de plus d’une heure, un service de résolution de noms de domaine faisant autorité a un temps de réponse moyen aux demandes DNS supérieur à 10 secondes;

  3. l’intégrité, la confidentialité ou l’authenticité des données stockées, transmises ou traitées liées au fonctionnement technique du domaine de premier niveau est compromise.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod