Source: OJ L, 2024/2690, 18.10.2024

Current language: SV

Artikel 6 Betydande incidenter när det gäller registreringsenheter för toppdomäner


Summary What does Article 6 of the Cybersecurity measures and significant incidents for relevant entities say?

This article is one in a series of sector-specific articles that build on the general significance criteria established in Article 3, applying tailored thresholds to specific types of entities.

Here, it sets out the conditions under which an incident affecting a TLD (Top-Level Domain) name registry must be classified as significant.

Notably, the thresholds for TLD name registries are stricter than those for comparable entities, reflecting the critical nature of their role in internet infrastructure — for example, any complete unavailability of the authoritative domain name resolution service, regardless of duration, triggers a significant incident classification.

Important points:

  • TLD name registries must treat an incident as significant if any one of three criteria is met: complete unavailability of the authoritative DNS service, average response times exceeding 10 seconds for more than one hour, or a compromise of the integrity, confidentiality, or authenticity of data related to the TLD's technical operation.
  • Unlike other entity types in this regulation, there is no minimum duration threshold for complete unavailability — any outage qualifies as significant.
  • This article operates as a specific application of Article 3(1)(g), meaning these criteria supplement, rather than replace, the broader significance criteria set out in Article 3.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

När det gäller registreringsenheter för toppdomäner ska en incident anses som betydande enligt artikel 3.1 g om den uppfyller ett eller flera av följande kriterier:

  1. En auktoritativ tjänst för att lösa domännamnsfrågor är helt otillgänglig.

  2. Under en tidsperiod som överstiger en timme är den genomsnittliga svarstiden hos en auktoritativ tjänst för att lösa domännamnsfrågor över tio sekunder när det gäller en DNS-begäran.

  3. integriteten, konfidentialiteten eller autenticiteten hos lagrade, överförda eller behandlade uppgifter i samband med den tekniska driften av registreringsenheten för toppdomäner har komprometterats.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod