- Meaning
- A provider of DNS services
- Examples
- Managed DNS providers, hosting providers
- Link to NIS2
- Part of digital infrastructure
- Related
- DNS, TLD name registry
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is a DNS service provider?
A DNS service provider is the company that runs the name servers answering DNS queries for the domains of its customers. Where the term DNS describes the technical system itself, the DNS service provider is the company behind it – a specialised managed DNS service, a hosting provider or a content delivery network. Organisations outsource name resolution to such providers because their globally distributed infrastructure keeps domains reachable reliably, quickly and protected against attack.
What they provide
- Managing and maintaining the DNS records (A, AAAA, MX, TXT and others)
- Protection against DNS-related attacks such as DDoS and cache poisoning
- High availability through geographically distributed, redundant servers (anycast)
- Protection through DNSSEC and monitoring of resolution times
Why they matter for NIS2
Because DNS decides whether almost any online service is reachable at all, Annex I to the NIS2 Directive names DNS service providers expressly under digital infrastructure. Article 2(2) goes one step further: they are in scope regardless of their size, so the usual thresholds of 50 employees or EUR 10 million turnover do not shield a small provider. Depending on their role they are themselves classified as an essential or an important Entity . That brings duties to register with the body designated in their Member State, to run risk management and to observe the reporting chain of 24 hours, 72 hours and one month. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
What this means for customers
Even if you only buy DNS in, you should treat the provider as a Third-party risk and fold its availability, safeguards and response times into your own Supply chain security arrangements.
A typical case: an energy company in NIS2 scope picks a new DNS service provider. Instead of looking at price alone, it has service level commitments on availability, DNSSEC support and a documented contingency plan written into the contract. That is how it makes sure an outage or attack at the provider does not turn into a reporting obligation of its own towards its competent authority – and the vetting itself is documented as evidence for supply chain security.
Further reading: European Commission – the NIS2 Directive
Frequently asked questions
What is a DNS service provider?
A DNS service provider is the company that runs the name servers answering DNS queries for the domains of its customers – a managed DNS service, a hosting provider or a content delivery network, for example. Organisations outsource name resolution to such providers because their globally distributed infrastructure keeps domains reachable reliably, quickly and protected against attacks such as DDoS or cache poisoning.
Are DNS service providers covered by NIS2?
Yes. Annex I to the NIS2 Directive names DNS service providers expressly under digital infrastructure, and Article 2(2) brings them into scope regardless of their size – the usual thresholds of 50 employees or EUR 10 million turnover do not shield a small provider. Depending on their role they count as essential or important entities, have to register with the body designated in their Member State and have to meet the risk management and reporting duties. Article 34 sets a minimum ceiling for fines of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
Do I have to vet my DNS provider?
Yes. Even if you only buy DNS in, you should assess the provider as a third-party risk and fold its availability, safeguards and response times into your own supply chain security under NIS2. In practice that means contractually agreed service levels for availability, DNSSEC support and a documented contingency plan. It is how you avoid an outage at your provider turning into a reporting obligation of your own towards your competent authority.