Digital Resilience Regulation (Nis2) And Competition Implications .
Digital Resilience Infrastructure And Systemic Dependency Risks
Introduction
Digital resilience infrastructure refers to the technological, organizational, and institutional systems designed to ensure that essential digital services continue operating during cyberattacks, technical failures, supply-chain disruptions, natural disasters, geopolitical events, or other systemic shocks. It includes cloud infrastructure, data centres, telecommunications networks, payment systems, digital identity infrastructure, cybersecurity systems, backup and disaster-recovery arrangements, critical software, APIs, and shared digital platforms.
The competition-law concern arises when resilience itself produces dependency and concentration. A market may become more resilient operationally by relying on a small number of cloud providers, cybersecurity vendors, payment processors, telecom operators, software platforms, or infrastructure intermediaries. This can create a paradox:
The infrastructure may become individually more reliable while the overall economic system becomes more dependent on a few providers.
A failure, exclusionary practice, discriminatory access condition, acquisition, interoperability restriction, or cyber incident affecting one dominant infrastructure provider can therefore propagate through many downstream markets.
1. Meaning of Digital Resilience Infrastructure
Digital resilience infrastructure has several components:
A. Redundancy
Systems maintain alternative servers, networks, data centres, suppliers, or communication channels.
B. Disaster recovery
Organisations maintain backups and recovery mechanisms so that services can resume following disruption.
C. Cybersecurity
Firewalls, identity management, encryption, monitoring, incident response and threat intelligence protect infrastructure against attacks.
D. Interoperability
Different systems can communicate and substitute for one another rather than becoming isolated technological ecosystems.
E. Portability
Users can transfer data, workloads, applications, or configurations from one infrastructure provider to another.
F. Multi-sourcing
Businesses avoid reliance upon a single supplier by maintaining relationships with several infrastructure providers.
G. Systemic monitoring
Authorities and infrastructure operators monitor risks that could spread across multiple markets.
2. What Is Systemic Dependency?
Systemic dependency exists when numerous businesses, public bodies, or markets depend upon the same infrastructure provider or technological layer and cannot realistically substitute it within a reasonable period.
For example:
Cloud provider → banks → payment applications → retailers → consumers
If the cloud provider experiences a major outage, the disruption can move through the entire chain.
Similarly:
Operating system → app store → authentication → payment → digital services
A restriction imposed at one technological layer can affect competition at several downstream levels.
Systemic dependency therefore differs from ordinary commercial dependence.
| Ordinary dependency | Systemic dependency |
|---|---|
| One firm depends on another | Many firms depend on the same provider |
| Usually bilateral | Network-wide |
| Limited consequences | Potential economy-wide consequences |
| Alternative suppliers may exist | Switching may be difficult |
| Failure affects individual firm | Failure can cascade across markets |
3. Competition-Law Significance
Digital resilience becomes a competition issue where infrastructure operators possess substantial market power.
Relevant theories include:
- abuse of dominance;
- refusal to supply;
- discriminatory access;
- tying and bundling;
- interoperability restrictions;
- data portability restrictions;
- self-preferencing;
- exclusive dealing;
- excessive switching costs;
- discriminatory technical standards;
- foreclosure of downstream competitors;
- strategic acquisitions of infrastructure competitors;
- leveraging infrastructure dominance into adjacent markets.
The central question is not merely:
"Is the infrastructure reliable?"
It is also:
"Who controls the infrastructure on which competitors must rely?"
4. Cloud Infrastructure and Concentration
Cloud computing illustrates the problem particularly well.
Large businesses increasingly rely upon infrastructure-as-a-service, databases, authentication, storage, machine-learning infrastructure and specialised computing resources.
A dominant cloud provider may therefore become a critical input for competitors.
Potential competition concerns include:
4.1 Switching costs
Migration may require:
- rewriting applications;
- transferring massive datasets;
- changing APIs;
- retraining employees;
- reconstructing security systems;
- renegotiating licences.
Consequently, nominally competitive cloud markets can develop substantial lock-in.
4.2 Data-egress barriers
If transferring data away from a provider is expensive or technically difficult, customers may remain with the incumbent even when better alternatives emerge.
4.3 Technical interoperability
Proprietary APIs and architectures may make migration more difficult.
4.4 Bundling
A provider could combine cloud infrastructure with:
- cybersecurity;
- productivity software;
- AI models;
- identity services;
- databases;
- analytics.
Such bundling may increase ecosystem dependency.
5. Cybersecurity Infrastructure and Systemic Dependency
Cybersecurity products increasingly operate as infrastructure rather than merely optional software.
A dominant security provider may control:
- endpoint protection;
- authentication;
- threat detection;
- security monitoring;
- identity management;
- incident response.
Concentration can produce a resilience paradox.
Advantages of concentration:
- unified security standards;
- rapid threat intelligence;
- economies of scale;
- coordinated incident response.
Risks:
- common-mode failure;
- cyberattack amplification;
- discriminatory access;
- exclusion of smaller cybersecurity competitors;
- dependence upon one technical architecture.
A vulnerability in one widely deployed system could therefore affect thousands of independent organisations simultaneously.
6. Telecommunications and Digital Backbone Dependency
Telecommunications networks provide another example.
Digital businesses rely upon:
- internet backbone networks;
- mobile networks;
- submarine cables;
- DNS infrastructure;
- content-delivery networks;
- cloud connectivity;
- authentication systems.
If a small number of firms control critical network infrastructure, competitors may have difficulty reaching consumers without their cooperation.
Competition authorities may therefore examine:
- access conditions;
- interconnection;
- discriminatory traffic management;
- network neutrality;
- infrastructure sharing;
- exclusive arrangements;
- vertical integration.
7. Payment Infrastructure
Digital payment systems can generate particularly significant systemic dependency.
A dominant payment network may sit between:
merchant → payment processor → network → bank → consumer
Network effects make these systems difficult to replicate.
A payment infrastructure operator that controls access to merchants or consumers may possess considerable bargaining power.
Competition concerns can include:
- exclusionary access conditions;
- interchange arrangements;
- technical discrimination;
- tying;
- refusal to interoperate;
- restrictions on competing payment methods.
8. Digital Identity as Critical Infrastructure
Digital identity systems increasingly serve as gateways to:
- banking;
- government services;
- healthcare;
- telecommunications;
- employment;
- education;
- online commerce.
Where identity authentication is concentrated, exclusion from the system can effectively prevent a business from reaching customers.
This creates a potential gatekeeper infrastructure.
The competition-law concern is particularly serious where:
- the system has become unavoidable;
- alternatives are weak;
- switching is difficult;
- access is technically controlled by one provider; and
- the provider also competes downstream.
9. Interoperability as a Resilience Remedy
Interoperability can simultaneously promote competition and resilience.
If systems are interoperable:
Provider A failure → Provider B can take over
If systems are closed:
Provider A failure → downstream services may collapse
Thus interoperability can operate as a form of competition-enhancing resilience regulation.
Possible remedies include:
- open APIs;
- data portability;
- technical standards;
- interoperability obligations;
- access obligations;
- non-discriminatory interfaces;
- multi-cloud deployment;
- migration assistance.
10. Six Important Case Laws
1. United Brands v Commission (1978)
The European Court of Justice established important principles concerning dominance and the special responsibility of a dominant undertaking.
The case concerned the banana market rather than digital infrastructure, but its principle is highly relevant.
Relevance
A dominant infrastructure provider cannot use its market power in a manner that unfairly exploits customers or excludes competitors.
In digital infrastructure, this principle can apply where an unavoidable infrastructure provider controls access to an essential technological layer.
Principle: Dominance is not itself unlawful, but its abusive exploitation can violate competition law.
2. Commercial Solvents v Commission (1974)
The case involved a dominant supplier that attempted to restrict access to an important input for a downstream competitor.
Relevance to digital infrastructure
The analogy is strong where a vertically integrated digital infrastructure provider supplies an input that downstream competitors require.
Examples include:
- cloud computing;
- authentication;
- network access;
- critical APIs;
- data infrastructure.
If a dominant provider selectively restricts access to a critical input to favour its downstream business, competition concerns arise.
Principle: A dominant undertaking controlling an indispensable input cannot arbitrarily use that control to eliminate downstream competition.
3. Bronner v Mediaprint (1998)
The European Court of Justice considered when refusal to provide access to infrastructure could constitute an abuse of dominance.
The Court adopted a demanding test for compulsory access.
Relevance
Bronner is particularly important for digital resilience infrastructure because it demonstrates that not every important infrastructure system automatically becomes an essential facility.
The infrastructure generally must satisfy stringent conditions concerning indispensability and the elimination of effective competition.
This prevents competition law from automatically converting every commercial dependency into a compulsory-access obligation.
Principle: Compulsory access to infrastructure requires a sufficiently strong legal and economic justification.
4. IMS Health v Commission (2004)
IMS Health concerned access to a pharmaceutical data structure protected by intellectual property.
The Court examined circumstances in which refusal to license an intellectual-property-protected resource could constitute abuse.
Relevance
Digital infrastructure frequently combines:
- intellectual property;
- databases;
- proprietary APIs;
- technical standards;
- data architectures.
Where competitors cannot realistically operate without a particular proprietary technological structure, IMS Health provides an important framework for analysing access.
Principle: Exceptional circumstances may justify access to an otherwise protected resource where refusal threatens the elimination of effective competition.
5. Microsoft Corp. v Commission (2007)
The Microsoft case is one of the most important precedents for modern digital infrastructure competition law.
The European Commission found problems involving Microsoft's refusal to provide interoperability information and the tying of products.
The General Court largely upheld the Commission's approach.
Relevance to digital resilience
Microsoft demonstrates how interoperability can become a competition issue.
Where a dominant technological platform controls an important interface, withholding interoperability information may make competing products less viable.
The case is especially relevant to:
- cloud interoperability;
- operating systems;
- enterprise software;
- APIs;
- identity systems;
- AI infrastructure.
Principle: Control over interoperability information can become an important source of exclusionary power.
6. Google Android (Commission, 2018; General Court, 2022)
The European Commission found several practices involving Google's Android ecosystem to be abusive, including restrictions concerning application distribution and competing search services.
The General Court substantially upheld the Commission's findings, while adjusting certain aspects of the Commission's reasoning and penalty.
Relevance
Android demonstrates how control over one digital infrastructure layer can be leveraged into adjacent markets.
An infrastructure ecosystem can create:
operating system → app distribution → search → advertising → data
This illustrates the systemic nature of digital dependency.
Principle: Ecosystem control and contractual restrictions can reinforce dominance across interconnected digital markets.
11. Additional Relevant Case Laws
7. Slovak Telekom v Commission (2021)
The case concerned access to telecommunications infrastructure and the application of competition law to vertically integrated infrastructure operators.
Importance
It demonstrates that infrastructure access must be assessed carefully where a dominant operator also competes downstream.
The case is highly relevant to digital networks because modern infrastructure providers may simultaneously operate infrastructure and downstream digital services.
8. Deutsche Telekom v Commission (2010)
The case concerned pricing practices in telecommunications and the possibility of exclusionary effects on competitors.
Importance
It illustrates how control over an upstream telecommunications network can affect downstream competition.
The broader lesson is that infrastructure pricing can itself become a mechanism for foreclosure.
12. Systemic Risk From Common Infrastructure Providers
The greatest danger is common-mode dependency.
Consider:
10,000 businesses → same cloud provider
8,000 → same identity provider
7,000 → same cybersecurity system
6,000 → same payment infrastructure
Each business may have an individual resilience plan.
But collectively they may have almost no systemic redundancy.
This creates:
Common-mode failure
One failure affects many supposedly independent businesses simultaneously.
Cascading failure
Failure at one infrastructure layer disrupts other connected systems.
Concentration risk
A small number of infrastructure providers acquire disproportionate bargaining power.
Recovery asymmetry
Large infrastructure providers may recover quickly while smaller businesses remain unable to operate.
13. Digital Resilience and Merger Control
Mergers can increase systemic dependency.
A transaction involving:
- cloud computing;
- cybersecurity;
- payment systems;
- identity infrastructure;
- AI compute;
- telecom networks;
may produce competitive concerns even where conventional market shares appear moderate.
Authorities may therefore need to examine:
- infrastructure bottlenecks;
- switching costs;
- interoperability;
- multi-homing;
- network effects;
- data advantages;
- vertical integration;
- downstream foreclosure;
- resilience consequences.
A merger may therefore be problematic not simply because it increases prices, but because it reduces the number of independent infrastructure providers capable of absorbing systemic shocks.
14. Resilience as a Non-Price Competition Parameter
Traditional competition analysis frequently focuses on:
- price;
- output;
- quality;
- innovation.
Digital infrastructure adds another parameter:
Resilience.
Two providers may charge identical prices, but one may offer:
- multiple data centres;
- independent backup systems;
- interoperable architecture;
- geographically distributed infrastructure.
The other may depend upon a single technical architecture.
Consequently, competition on resilience can itself be economically significant.
15. Regulatory Remedies
Competition authorities and sector regulators could employ several remedies.
A. Interoperability mandates
Require dominant infrastructure providers to provide functional interoperability.
B. Data portability
Allow customers to transfer data efficiently.
C. Switching-cost restrictions
Prevent contractual or technical practices that unnecessarily inhibit migration.
D. Multi-provider requirements
Systemically important organisations could be encouraged or required to maintain alternative suppliers.
E. Non-discrimination
Infrastructure access should be provided on transparent and non-discriminatory terms.
F. Structural remedies
In extreme cases, separation of infrastructure and downstream operations may be considered.
G. Merger scrutiny
Infrastructure acquisitions should be assessed for their effect on systemic dependency.
H. Resilience audits
Authorities could examine whether infrastructure markets possess sufficient redundancy.
16. Competition Law Versus Resilience Regulation
There is an important distinction.
Competition law asks:
Does the undertaking's conduct harm competitive conditions?
Resilience regulation asks:
Can the system continue functioning when infrastructure fails?
The two objectives overlap but are not identical.
A monopoly might technically provide highly resilient infrastructure.
Conversely, a competitive market might still have poor resilience.
Therefore, policymakers may need a combined framework:
Competition + interoperability + cybersecurity + redundancy + operational resilience
17. The "Resilience Paradox"
Digital infrastructure produces a particularly important paradox:
Economies of scale can increase operational resilience while concentration can increase systemic vulnerability.
For example, centralising cybersecurity in a sophisticated provider may improve protection for each individual customer.
But if almost every customer uses that provider, a single compromise can produce enormous systemic damage.
Thus:
Micro-level resilience ↑
while
Macro-level resilience ↓
This is one of the central policy problems of digital infrastructure governance.
18. Analytical Framework
A competition authority assessing systemic dependency could ask:
Step 1 — Identify the infrastructure
What technological layer is indispensable?
Step 2 — Identify dependency
How many downstream firms rely upon it?
Step 3 — Examine alternatives
Can customers realistically switch?
Step 4 — Examine interoperability
Can competing systems communicate?
Step 5 — Examine concentration
How many independent providers exist?
Step 6 — Examine vertical integration
Does the infrastructure provider compete downstream?
Step 7 — Examine conduct
Is access being restricted, degraded, bundled or discriminated against?
Step 8 — Assess systemic consequences
Could failure or exclusion affect multiple markets simultaneously?
Step 9 — Consider remedies
Would portability, interoperability, access or structural separation restore competition and resilience?
19. Key Legal Principles From the Cases
| Case | Core principle | Digital-resilience relevance |
|---|---|---|
| United Brands | Special responsibility of dominant firms | Infrastructure gatekeeper conduct |
| Commercial Solvents | Control of important inputs | Critical digital infrastructure access |
| Bronner | Strict conditions for compulsory access | Essential-facility analysis |
| IMS Health | Exceptional access to indispensable protected resources | Proprietary APIs/data architectures |
| Microsoft | Interoperability can be competitively essential | Cloud/software interoperability |
| Google Android | Ecosystem leverage can reinforce dominance | Digital infrastructure ecosystems |
| Slovak Telekom | Infrastructure access and downstream competition | Telecom/cloud infrastructure |
| Deutsche Telekom | Infrastructure pricing can foreclose rivals | Network-access pricing |
Conclusion
Digital resilience infrastructure is becoming a competition-law issue because the same infrastructure that makes the digital economy more reliable can also make it more dependent on a small number of powerful providers.
Cloud computing, telecommunications, cybersecurity, payment networks, digital identity, APIs and AI-compute infrastructure increasingly function as foundational economic infrastructure. Their concentration can create systemic dependency, particularly where customers face high switching costs, proprietary architectures, data lock-in or limited interoperability.
The major lesson from Bronner, Commercial Solvents, IMS Health, Microsoft, United Brands, Google Android, Slovak Telekom and Deutsche Telekom is that competition law must look beyond the immediate transaction or price effect and examine control over indispensable inputs, interoperability, vertical leverage and exclusionary access conditions.
Ultimately, the objective should not necessarily be to eliminate scale. Large infrastructure providers can generate substantial efficiencies and improve security. The objective should instead be to ensure that scale does not become an unavoidable bottleneck through which competitors, consumers and essential services must operate.

comments