Source: OJ L, 2024/2690, 18.10.2024

Current language: EN

Article 5 Significant incidents with regard to DNS service providers


Summary What does Article 5 of the Cybersecurity measures and significant incidents for relevant entities say?

This article sets out the specific criteria that determine when an incident affecting a DNS service provider must be classified as significant under Article 3(1)(g).

It focuses on three measurable thresholds covering service availability, performance degradation, and data integrity, giving DNS service providers clear benchmarks against which to assess their incidents.

Important points:

  • DNS service providers must report an incident as significant if a recursive or authoritative domain name resolution service is completely unavailable for more than 30 minutes.
  • DNS service providers must report an incident as significant if average DNS response times exceed 10 seconds for more than one hour.
  • A data integrity, confidentiality, or authenticity compromise triggers significance, unless fewer than 1,000 domain names are affected and this represents no more than 1% of managed domain names due to misconfiguration.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

With regard to DNS service providers, an incident shall be considered significant under Article 3(1)(g), where it fulfils one or more of the following criteria:

  1. a recursive or authoritative domain name resolution service is completely unavailable for more than 30 minutes;

  2. for a period of more than one hour, the average response time of a recursive or authoritative domain name resolution service to DNS requests is more than 10 seconds;

  3. the integrity, confidentiality or authenticity of stored, transmitted or processed data related to the provision of the authoritative domain name resolution service is compromised, except in cases where the data of fewer than 1 000 domain names managed by the DNS service provider, amounting to no more than 1 % of the domain names managed by the DNS service provider, are not correct because of misconfiguration.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod