NIS2 for internet and telecommunications providers
Published: 7. 2. 2026 | Author: Ing. Vít Vomáčko | NIS2OK.cz
Internet service providers (ISPs) and telecommunications operators are among the entities subject to the strictest scrutiny under Act No. 264/2025 Coll. Digital infrastructure is classified in Annex I as a highly critical sector. - regardless of the provider's size. A smaller regional ISP with tens of thousands of connections may fall into the same regulatory category as a large operator.
Why? Because the internet functions as an interconnected network of dependencies. An outage or compromise of a single backbone node, DNS resolver, or BGP router can have a cascading effect on thousands of other entities, hospitals, industrial control systems, banking infrastructure. The regulator is well aware of this risk.
Which entities in the ISP/telecom sector are mandatorily covered by NIS2 OK?
In the digital infrastructure category, the law includes, among other things:
- ✓Internet access providers - fixed and mobile operators, ISPs providing connectivity to end customers, and transit operators
- ✓DNS service providers - operators of authoritative and recursive DNS resolvers available to third parties
- ✓TLD Registries and Domain Registrars
- ✓Operators of Internet Exchange Points (IXPs)
- ✓Data centre operators providing colocation or cloud infrastructure
- ✓Providers of cloud computing services (IaaS, PaaS)
- ✓Public electronic communications networks and services in accordance with Act No. 127/2005 Coll. (the Electronic Communications Act)
For the category of digital infrastructure and electronic communications The size exemption for small businesses does not apply.If you operate a public communications network or provide DNS services, the law applies to you regardless of whether you have 10 or 10,000 employees.
Specific technical requirements for digital infrastructure
The general requirements of NIS2 (risk management, incident response, continuity planning) apply to all sectors. For ISPs and telecoms, there are additional specific technical expectations arising from the nature of their services:
DNSSEC - signing of DNS zones
NÚKIB recommends and in many cases effectively requires the implementation of DNSSEC for DNS infrastructure. DNS cache poisoning and DNS hijacking are among the most common attacks on ISP infrastructure, DNSSEC is a fundamental defence. For providers managing authoritative DNS for customers, activating DNSSEC for managed zones is part of expected security measures.
BGP security: RPKI and Route Origin Validation
BGP routing security is critical for ISPs. Act No. 264/2025 Coll. Builds on recommendations from ENISA and NÚKIB, which include:
- •RPKI (Resource Public Key Infrastructure) - cryptographic verification of the authorization of a BGP prefix-origin pair
- •ROV (Route Origin Validation) - active rejection of invalid BGP routes based on RPKI
- •MANRS (Mutually Agreed Norms for Routing Security) - implementation of recommended security standards for routing
BGP hijacking (prefix hijacking) and route leaks remain a real threat, just recall the major BGP incidents of recent years. The regulator views this as a systemic risk that ISPs must address.
Reporting incidents to NÚKIB: deadlines for ISPs
For essential entities in digital infrastructure, the following applies: strict reporting deadlines:
| Deadline | Notification type | Contents |
|---|---|---|
| 24 hours | Early warning | Incident notification, initial severity assessment |
| 72 hours | Detailed report | Impacts, affected systems, measures taken |
| 1 month | Final Report | Root cause and corrective measures taken |
The key issue is the definition of a "significant incident". The law uses criteria such as significant disruption to network availability or integrity, impact on a large number of users or critical customers (hospitals, energy sector), or economic damage exceeding a set threshold. ISPs must have an internal process in place to identify these situations promptly and trigger reporting.
DDoS protection and network monitoring
ISPs must implement appropriate measures for detecting and mitigating attacks. This includes:
- •Monitoring of network traffic with anomaly detection (NetFlow/sFlow analysis)
- •Capacities for DDoS mitigation: own or via a specialised provider of scrubbing centres
- •Segmentation and isolation of critical infrastructure from the operational network
- •Access control for network elements: multi-factor authentication, privileged access via jump hosts
- •Logging and audit records of network changes with sufficient retention period
Supply chain: specifics for ISPs
NIS2 places special emphasis on supply chain security. For ISPs, this means assessing security risks for:
- ✓Suppliers of network components, routers, switches, optical systems (security requirements in tenders, regular patch management)
- ✓OSS/BSS systems, operational and customer-facing systems where compromise could lead to customer data leaks or takeover of network elements.
- ✓Service and installation subcontractors: physical access to infrastructure constitutes a security risk.
- ✓Transit partners and peering relationships: security requirements must be included in peering agreements.
Practical steps for ISPs: where to start?
A typical gap analysis for a medium-sized ISP reveals these most common gaps:
Absence of a formal risk analysis
ISPs typically implement security measures reactively. NIS2 requires proactive, documented and regularly updated risk management.
Missing incident response procedures
A process for identifying, classifying and reporting incidents with clear responsibilities and deadlines. It must operate 24/7.
Insufficient RPKI/ROV deployment
Many smaller ISPs still do not sign their prefixes in RPKI or implement ROV on upstreams.
Undocumented access management
Shared accounts for access to network components, lack of MFA, insufficient logging of configuration changes.
NIS2 compliance automation for ISPs
Manual management of compliance documentation, incident tracking and risk monitoring places a burden on the ISP operational team. Tools exist to automate this process: from continuous monitoring with alerting through automated report generation for NÚKIB to integration with ticketing systems for tracking remedial actions. If you are looking for such a solution, take a look at flylight.ai - a platform for automating security monitoring.
For managing the NIS2 agenda itself, documentation, management of the CISO, training and audit trail: the NIS2 OK platform is designated. nis2manager.cz, designed specifically for the Czech regulatory environment.
NIS2 readiness audit for ISPs
Find out where you have gaps in compliance with Act No. 264/2025 Coll. Our online audit is tailored for digital infrastructure providers. Free, no registration required.
Launch an audit for ISP