Solutions · Cloud and digital infrastructure
The Implementing Regulation was written for you.
Cloud providers, data centres, DNS and CDN providers, managed service and security providers. Commission Implementing Regulation 2024/2690 spells out the technical measures for exactly these entity types, and some are in scope regardless of size.
Typical profile
- Sector
- Digital infrastructure (cloud, data centres, DNS, CDN, telecoms)
- Employees
- 50 to 249
- AI
- Uses AI tools
- Flags
- None
- Digital infrastructure is Annex I; DNS providers and TLD registries are in scope at any size (Art 2(2)).
- The Implementing Regulation's 47 technical requirement sections apply here.
- Serving a financial entity can make you a DORA ICT third-party provider.
Obligations to prove
64
NIS2 important entity on this profile.
- Regulation (EU) 2016/679 — data protection3
Applies to every organisation established in the EU that processes personal data.
- Directive (EU) 2022/2555 — cybersecurity8
You declared yourself a NIS2 important entity.
- Commission Implementing Regulation (EU) 2024/2690 — NIS2 Art 21(2) technical requirements48
The Implementing Regulation's 47 technical requirement sections elaborate NIS2 Art 21(2).
- Regulation (EU) 2024/1689 — artificial intelligence5
You build or use AI systems — Art 4 AI literacy already applies; other tiers depend on classification.
First statutory clock if something goes wrong: NIS2 early warning, 24 hours (NIS2 Art 23(4)(a)).
Computed by the platform's scope finder. A starting point, not a legal determination.
The modules that matter here
Start with these 64 obligations.
Sign up, confirm the scope in onboarding, connect your first system.
Start free →