NIS2 for internet and telecommunications providers

Published: 7. 2. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz

Internet service providers (ISPs) and telecommunications operators are among the entities subject to the strictest scrutiny under Act No. 264/2025 Coll. Digital infrastructure is classified in Annex I as a highly critical sector. - regardless of the provider's size. A smaller regional ISP with tens of thousands of connections may fall into the same regulatory category as a large operator.

Why? Because the internet functions as an interconnected network of dependencies. An outage or compromise of a single backbone node, DNS resolver, or BGP router can have a cascading effect on thousands of other entities, hospitals, industrial control systems, banking infrastructure. The regulator is well aware of this risk.

Which entities in the ISP/telecom sector are mandatorily covered by NIS2 OK?

In the digital infrastructure category, the law includes, among other things:

For the category of digital infrastructure and electronic communications The size exemption for small businesses does not apply.If you operate a public communications network or provide DNS services, the law applies to you regardless of whether you have 10 or 10,000 employees.

Specific technical requirements for digital infrastructure

The general requirements of NIS2 (risk management, incident response, continuity planning) apply to all sectors. For ISPs and telecoms, there are additional specific technical expectations arising from the nature of their services:

DNSSEC - signing of DNS zones

NÚKIB recommends and in many cases effectively requires the implementation of DNSSEC for DNS infrastructure. DNS cache poisoning and DNS hijacking are among the most common attacks on ISP infrastructure, DNSSEC is a fundamental defence. For providers managing authoritative DNS for customers, activating DNSSEC for managed zones is part of expected security measures.

BGP security: RPKI and Route Origin Validation

BGP routing security is critical for ISPs. Act No. 264/2025 Coll. Builds on recommendations from ENISA and NÚKIB, which include:

BGP hijacking (prefix hijacking) and route leaks remain a real threat, just recall the major BGP incidents of recent years. The regulator views this as a systemic risk that ISPs must address.

Reporting incidents to NÚKIB: deadlines for ISPs

For essential entities in digital infrastructure, the following applies: strict reporting deadlines:

Deadline Notification type Contents
24 hours Early warning Incident notification, initial severity assessment
72 hours Detailed report Impacts, affected systems, measures taken
1 month Final Report Root cause and corrective measures taken

The key issue is the definition of a "significant incident". The law uses criteria such as significant disruption to network availability or integrity, impact on a large number of users or critical customers (hospitals, energy sector), or economic damage exceeding a set threshold. ISPs must have an internal process in place to identify these situations promptly and trigger reporting.

DDoS protection and network monitoring

ISPs must implement appropriate measures for detecting and mitigating attacks. This includes:

Supply chain: specifics for ISPs

NIS2 places special emphasis on supply chain security. For ISPs, this means assessing security risks for:

Practical steps for ISPs: where to start?

A typical gap analysis for a medium-sized ISP reveals these most common gaps:

1

Absence of a formal risk analysis

ISPs typically implement security measures reactively. NIS2 requires proactive, documented and regularly updated risk management.

2

Missing incident response procedures

A process for identifying, classifying and reporting incidents with clear responsibilities and deadlines. It must operate 24/7.

3

Insufficient RPKI/ROV deployment

Many smaller ISPs still do not sign their prefixes in RPKI or implement ROV on upstreams.

4

Undocumented access management

Shared accounts for access to network components, lack of MFA, insufficient logging of configuration changes.

NIS2 compliance automation for ISPs

Manual management of compliance documentation, incident tracking and risk monitoring places a burden on the ISP operational team. Tools exist to automate this process: from continuous monitoring with alerting through automated report generation for NÚKIB to integration with ticketing systems for tracking remedial actions. If you are looking for such a solution, take a look at flylight.ai - a platform for automating security monitoring.

For managing the NIS2 agenda itself, documentation, management of the CISO, training and audit trail: the NIS2 OK platform is designated. nis2manager.cz, designed specifically for the Czech regulatory environment.

NIS2 readiness audit for ISPs

Find out where you have gaps in compliance with Act No. 264/2025 Coll. Our online audit is tailored for digital infrastructure providers. Free, no registration required.

Launch an audit for ISP