Resilience in the DNA: Simplifying to Strengthen Security

The proposed Digital Networks Act (DNA) introduces new sector-specific cybersecurity and resilience obligations that overlap with NIS2 and CER requirements. Would this approach genuinely strengthen resilience, legal certainty, and investment in digital networks, or does it instead call for greater regulatory simplification and coherence?

Picture of Gonzalo García Arribas

Gonzalo García Arribas Follow

Reading time: 3 min

A Shared Objective, a Questionable Approach

With this post, we finalise a series focused on the Digital Networks Act, in which we present Telefónica’s perspective on how to ensure that the regulatory framework helps drive innovation and growth in the European Union telecommunications sector.

The resilience of digital infrastructure has become a strategic priority for Europe. Telecommunications networks are essential to the economy, public services, and crisis management, making the strengthening of their security an objective fully shared by the sector.

However, the resilience provisions included in the proposed DNA raise significant concerns. Rather than simplifying the regulatory framework, they introduce sector-specific rules that duplicate and potentially conflict with obligations already established under the NIS2 Directive and the Critical Entities Resilience (CER) Directive, creating complexity and legal uncertainty.

Overlaps with NIS2 and CER

Articles 4 to 8 of the DNA introduce specific requirements aimed at ensuring the availability and resilience of electronic communications networks. However, many of these issues are already covered by NIS2 and CER through risk management, business continuity, and critical infrastructure protection obligations.

In its opinion on the DNA, the Body of European Regulators for Electronic Communications (BEREC) warns that the proposal could lead to a complex regulatory framework with potential duplication and inconsistencies regarding compliance requirements, supervision, and reporting obligations for operators.

More Complex Governance Under the European Passport

The proposal for a single European authorization, or Single Passport, raises additional questions. Under this system, an operator could be authorized in one Member State and provide services across the European Union, while different national authorities oversee cybersecurity and resilience matters.

This arrangement may generate jurisdictional conflicts and situations in which one national authority requests measures that affect rights granted by an authority in another Member State. Rather than simplifying governance, the system could make it more complex.

Sector Regulators and Cybersecurity Authorities

The proposal also increases the number of actors involved in resilience oversight. National Regulatory Authorities (NRAs), BEREC, the future Office for Digital Networks (ODN), and national cybersecurity authorities could end up sharing responsibilities in overlapping areas.

Without a clear allocation of responsibilities, there is a risk of parallel supervision, additional administrative burdens, and coordination challenges in the practical implementation of obligations.

The Key Issue: Preserving Regulatory Certainty Instead of Increasing Complexity

One of the most concerning elements of the proposal is the possibility of linking compliance with resilience and cybersecurity obligations to the retention of general authorizations or spectrum usage rights.

If, through the DNA, non-compliance with obligations derived from NIS2 could ultimately affect authorizations or spectrum rights, the regulatory risk associated with providing services would increase significantly, and so would the risks for investment in digital infrastructure. In this regard, BEREC emphasizes that such measures should be used only as a last resort and that regulators must retain the ability to assess the proportionality of each individual case.

At a time when Europe needs to accelerate the deployment of next-generation networks, regulatory certainty must remain a fundamental principle, accompanied by simplification rather than greater complexity.

Conclusion

Strengthening the resilience of Europe’s digital infrastructure is an essential objective. However, this should not result in the creation of sector-specific obligations that duplicate or interfere with well-established horizontal frameworks such as NIS2 and CER.

The goal should be to enhance network resilience while avoiding duplication, legal uncertainty, and disincentives to investment

Share it on your social networks


Communication

Contact our communication department or requests additional material.