Skip to main content

SubTel Forum Issue #148 - Global Capacity

Page 84

NIS2’S EXTENDED SCOPE TAKES A DEEP DIVE: UNPACKING THE EU COMMISSION’S PROPOSED EXPANSION TO SUBMARINE DATA TRANSMISSION INFRASTRUCTURE By Mike Conradi, Nicholas De Lacy-Brown, Christian Keogh, Henry Kilding & Lola Stirling

NIS2, the EU’s second Network and Information Systems Directive, is not going anywhere. While the swathe of organisations newly in scope of the EU’s hallmark cybersecurity directive may have hoped that the EU’s recent announcements on regulatory simplification (including the Digital Omnibus) might have reduced their compliance burden, in some cases the EU is actually proposing to expand the scope of NIS2 further. In a set of proposed targeted amendments to the NIS2 Directive announced on 20 January 2026 (the “Proposal“), the European Commission has suggested a significant change to the organisations in scope of NIS2 that will be of particular note for entities that are operators of Submarine Data Transmission Infrastructure (SDTI). Under the Proposal, operators of SDTI would fall under the scope of NIS2 as a “sector of High Criticality” and as such, presuming they meet the relevant size criterion, will be “essential entities” triggering higher levels of regulatory supervision, proac84

tive audits, and accountability requirements (including personal liability considerations) all of which could require careful mapping, particularly in complex consortia models. Building on our recent analysis of the Proposal, this article takes a closer look at the specific changes suggested to bring SDTI squarely into scope, and why SDTI stakeholders should track this closely over the coming months. To note, whilst some organisations operating infrastructure in this space may have already been in scope of NIS2 as providers of public electronic communications networks and services or cloud computing service providers, the Commission is now proposing to specifically target the SDTI sector more broadly. This development reflects the Commission’s intention to harmonise cybersecurity obligations across critical infrastructure and address growing geopolitical and cyber-related risks which it sees as particularly pertinent to undersea communications systems.

WHAT IS THE CHANGE? As noted by the Commission in their proposals, SDTI has his-

SUBBTEL FORUM | Issue 148

torically been operated by entities already falling within NIS2’s scope (including public electronic communications networks / services or cloud service providers). However, not all SDTI operators fall neatly into these categories, and some entities may operate or lease SDTI without being captured by NIS2. For example: operators of non-public electronic communications networks; and entities leasing or co-operating portions of infrastructure to public network providers. The proposed inclusion of a specific new category of SDTI within the scope of NIS2 therefore seeks to capture all types of entities operating in submarine data transmission, recognising the increasing risks to submarine data transmission infrastructure and their resulting high criticality. It is not surprising then that under the proposed amendments to NIS2, SDTI is defined broadly. It includes not only the subsea cables themselves but any infrastructure essential to their operation, such as landing stations and the terrestrial portions of the network (i.e. the “fronthaul” between


Turn static files into dynamic content formats.

Create a flipbook
SubTel Forum Issue #148 - Global Capacity by Submarine Telelecoms Forum - Issuu