The classic trap
Recital 32 explicitly extends NIS 2 to TLD registries and DNS providers (public recursive resolvers and authoritative servers for third parties). In practice, the ILR sanctions two confusions: assuming an internal corporate DNS resolver is out of scope (false as soon as it serves third parties or is exposed), and neglecting the DNS dependency chain when you are an essential entity delegating your zone to a provider not identified as a critical supplier. Root name servers are excluded, but every other layer is in scope.
The concrete test to know if you are in scope
- You operate a TLD (.lu, .eu, gTLD): in scope as an essential entity registry.
- You run a publicly available recursive resolver (ISP, hyperscaler, public 1.1.1.1-style service): in scope.
- You host authoritative DNS zones for third parties (registrar, managed DNS hosting): in scope.
- You only operate internal DNS (Active Directory, private split-horizon): out of DNS scope, but still covered if you are essential or important under another sectoral entry.
- You delegate your DNS to Cloudflare, AWS Route 53, Gandi, EBRC: these providers become a critical dependency to document in your supply chain (article 21).
The forgotten angle: resilience of your own domains
Even if you are not a DNS provider, NIS 2 requires you to treat the resilience of your domains as a security measure. An expired domain, a broken DNSSEC chain, a compromised registrar or a single DNS provider with no secondary all open availability incidents notifiable to the ILR within 24 hours.
How Luxgap automates this risk
Our Luxgap DNS Resilience Sentinel turns DNS monitoring from a yearly checklist into a real-time probe that knows, to the minute, whether your resolution chain would survive a notifiable incident. The tool continuously queries your zones from 12 European vantage points, cross-references answers with registrar databases (EURid, DNS-LU, ICANN RDAP), and detects DNSSEC drifts, imminent expirations, orphan NS records and unauthorized changes before they become an ILR incident.
- Scans DNSSEC consistency every 5 minutes (signatures, DS records, chain of trust) on each of your zones and alerts Teams or Slack the moment a break appears.
- Detects domains expiring within 90 days via registrar RDAP queries and prevents loss of critical zones.
- Maps your real DNS dependency chain (registrar, primary and secondary DNS hosting, anycast network) and classifies each link as a critical supplier under NIS 2 article 21.
- Simulates failure scenarios (loss of primary DNS, NS hijack, registrar account compromise) and computes a resilience score defensible before the ILR.
- Automatically builds the pre-filled DNS incident dossier for the 24h notification, with timeline, IOCs and impact.
- Produces a timestamped, cryptographically sealed PDF report, defensible during an ILR inspection, that demonstrates the continuous monitoring required by NIS 2.
Available alongside a Luxgap CISO mandate or as a standalone SaaS module depending on your perimeter. Request a tailored quote and our teams prepare a demonstration on your real zones, with a free 48h blank audit to measure your DNS exposure before any engagement.