Digital Resilience Regulation (Nis2) And Competition Implications .

Digital Resilience Infrastructure And Systemic Dependency Risks

Introduction

Digital resilience infrastructure refers to the technological, organizational, and institutional systems designed to ensure that essential digital services continue operating during cyberattacks, technical failures, supply-chain disruptions, natural disasters, geopolitical events, or other systemic shocks. It includes cloud infrastructure, data centres, telecommunications networks, payment systems, digital identity infrastructure, cybersecurity systems, backup and disaster-recovery arrangements, critical software, APIs, and shared digital platforms.

The competition-law concern arises when resilience itself produces dependency and concentration. A market may become more resilient operationally by relying on a small number of cloud providers, cybersecurity vendors, payment processors, telecom operators, software platforms, or infrastructure intermediaries. This can create a paradox:

The infrastructure may become individually more reliable while the overall economic system becomes more dependent on a few providers.

A failure, exclusionary practice, discriminatory access condition, acquisition, interoperability restriction, or cyber incident affecting one dominant infrastructure provider can therefore propagate through many downstream markets.

1. Meaning of Digital Resilience Infrastructure

Digital resilience infrastructure has several components:

A. Redundancy

Systems maintain alternative servers, networks, data centres, suppliers, or communication channels.

B. Disaster recovery

Organisations maintain backups and recovery mechanisms so that services can resume following disruption.

C. Cybersecurity

Firewalls, identity management, encryption, monitoring, incident response and threat intelligence protect infrastructure against attacks.

D. Interoperability

Different systems can communicate and substitute for one another rather than becoming isolated technological ecosystems.

E. Portability

Users can transfer data, workloads, applications, or configurations from one infrastructure provider to another.

F. Multi-sourcing

Businesses avoid reliance upon a single supplier by maintaining relationships with several infrastructure providers.

G. Systemic monitoring

Authorities and infrastructure operators monitor risks that could spread across multiple markets.

2. What Is Systemic Dependency?

Systemic dependency exists when numerous businesses, public bodies, or markets depend upon the same infrastructure provider or technological layer and cannot realistically substitute it within a reasonable period.

For example:

Cloud provider → banks → payment applications → retailers → consumers

If the cloud provider experiences a major outage, the disruption can move through the entire chain.

Similarly:

Operating system → app store → authentication → payment → digital services

A restriction imposed at one technological layer can affect competition at several downstream levels.

Systemic dependency therefore differs from ordinary commercial dependence.

Ordinary dependencySystemic dependency
One firm depends on anotherMany firms depend on the same provider
Usually bilateralNetwork-wide
Limited consequencesPotential economy-wide consequences
Alternative suppliers may existSwitching may be difficult
Failure affects individual firmFailure can cascade across markets

3. Competition-Law Significance

Digital resilience becomes a competition issue where infrastructure operators possess substantial market power.

Relevant theories include:

  • abuse of dominance;
  • refusal to supply;
  • discriminatory access;
  • tying and bundling;
  • interoperability restrictions;
  • data portability restrictions;
  • self-preferencing;
  • exclusive dealing;
  • excessive switching costs;
  • discriminatory technical standards;
  • foreclosure of downstream competitors;
  • strategic acquisitions of infrastructure competitors;
  • leveraging infrastructure dominance into adjacent markets.

The central question is not merely:

"Is the infrastructure reliable?"

It is also:

"Who controls the infrastructure on which competitors must rely?"

4. Cloud Infrastructure and Concentration

Cloud computing illustrates the problem particularly well.

Large businesses increasingly rely upon infrastructure-as-a-service, databases, authentication, storage, machine-learning infrastructure and specialised computing resources.

A dominant cloud provider may therefore become a critical input for competitors.

Potential competition concerns include:

4.1 Switching costs

Migration may require:

  • rewriting applications;
  • transferring massive datasets;
  • changing APIs;
  • retraining employees;
  • reconstructing security systems;
  • renegotiating licences.

Consequently, nominally competitive cloud markets can develop substantial lock-in.

4.2 Data-egress barriers

If transferring data away from a provider is expensive or technically difficult, customers may remain with the incumbent even when better alternatives emerge.

4.3 Technical interoperability

Proprietary APIs and architectures may make migration more difficult.

4.4 Bundling

A provider could combine cloud infrastructure with:

  • cybersecurity;
  • productivity software;
  • AI models;
  • identity services;
  • databases;
  • analytics.

Such bundling may increase ecosystem dependency.

5. Cybersecurity Infrastructure and Systemic Dependency

Cybersecurity products increasingly operate as infrastructure rather than merely optional software.

A dominant security provider may control:

  • endpoint protection;
  • authentication;
  • threat detection;
  • security monitoring;
  • identity management;
  • incident response.

Concentration can produce a resilience paradox.

Advantages of concentration:

  • unified security standards;
  • rapid threat intelligence;
  • economies of scale;
  • coordinated incident response.

Risks:

  • common-mode failure;
  • cyberattack amplification;
  • discriminatory access;
  • exclusion of smaller cybersecurity competitors;
  • dependence upon one technical architecture.

A vulnerability in one widely deployed system could therefore affect thousands of independent organisations simultaneously.

6. Telecommunications and Digital Backbone Dependency

Telecommunications networks provide another example.

Digital businesses rely upon:

  • internet backbone networks;
  • mobile networks;
  • submarine cables;
  • DNS infrastructure;
  • content-delivery networks;
  • cloud connectivity;
  • authentication systems.

If a small number of firms control critical network infrastructure, competitors may have difficulty reaching consumers without their cooperation.

Competition authorities may therefore examine:

  • access conditions;
  • interconnection;
  • discriminatory traffic management;
  • network neutrality;
  • infrastructure sharing;
  • exclusive arrangements;
  • vertical integration.

7. Payment Infrastructure

Digital payment systems can generate particularly significant systemic dependency.

A dominant payment network may sit between:

merchant → payment processor → network → bank → consumer

Network effects make these systems difficult to replicate.

A payment infrastructure operator that controls access to merchants or consumers may possess considerable bargaining power.

Competition concerns can include:

  • exclusionary access conditions;
  • interchange arrangements;
  • technical discrimination;
  • tying;
  • refusal to interoperate;
  • restrictions on competing payment methods.

8. Digital Identity as Critical Infrastructure

Digital identity systems increasingly serve as gateways to:

  • banking;
  • government services;
  • healthcare;
  • telecommunications;
  • employment;
  • education;
  • online commerce.

Where identity authentication is concentrated, exclusion from the system can effectively prevent a business from reaching customers.

This creates a potential gatekeeper infrastructure.

The competition-law concern is particularly serious where:

  1. the system has become unavoidable;
  2. alternatives are weak;
  3. switching is difficult;
  4. access is technically controlled by one provider; and
  5. the provider also competes downstream.

9. Interoperability as a Resilience Remedy

Interoperability can simultaneously promote competition and resilience.

If systems are interoperable:

Provider A failure → Provider B can take over

If systems are closed:

Provider A failure → downstream services may collapse

Thus interoperability can operate as a form of competition-enhancing resilience regulation.

Possible remedies include:

  • open APIs;
  • data portability;
  • technical standards;
  • interoperability obligations;
  • access obligations;
  • non-discriminatory interfaces;
  • multi-cloud deployment;
  • migration assistance.

10. Six Important Case Laws

1. United Brands v Commission (1978)

The European Court of Justice established important principles concerning dominance and the special responsibility of a dominant undertaking.

The case concerned the banana market rather than digital infrastructure, but its principle is highly relevant.

Relevance

A dominant infrastructure provider cannot use its market power in a manner that unfairly exploits customers or excludes competitors.

In digital infrastructure, this principle can apply where an unavoidable infrastructure provider controls access to an essential technological layer.

Principle: Dominance is not itself unlawful, but its abusive exploitation can violate competition law.

2. Commercial Solvents v Commission (1974)

The case involved a dominant supplier that attempted to restrict access to an important input for a downstream competitor.

Relevance to digital infrastructure

The analogy is strong where a vertically integrated digital infrastructure provider supplies an input that downstream competitors require.

Examples include:

  • cloud computing;
  • authentication;
  • network access;
  • critical APIs;
  • data infrastructure.

If a dominant provider selectively restricts access to a critical input to favour its downstream business, competition concerns arise.

Principle: A dominant undertaking controlling an indispensable input cannot arbitrarily use that control to eliminate downstream competition.

3. Bronner v Mediaprint (1998)

The European Court of Justice considered when refusal to provide access to infrastructure could constitute an abuse of dominance.

The Court adopted a demanding test for compulsory access.

Relevance

Bronner is particularly important for digital resilience infrastructure because it demonstrates that not every important infrastructure system automatically becomes an essential facility.

The infrastructure generally must satisfy stringent conditions concerning indispensability and the elimination of effective competition.

This prevents competition law from automatically converting every commercial dependency into a compulsory-access obligation.

Principle: Compulsory access to infrastructure requires a sufficiently strong legal and economic justification.

4. IMS Health v Commission (2004)

IMS Health concerned access to a pharmaceutical data structure protected by intellectual property.

The Court examined circumstances in which refusal to license an intellectual-property-protected resource could constitute abuse.

Relevance

Digital infrastructure frequently combines:

  • intellectual property;
  • databases;
  • proprietary APIs;
  • technical standards;
  • data architectures.

Where competitors cannot realistically operate without a particular proprietary technological structure, IMS Health provides an important framework for analysing access.

Principle: Exceptional circumstances may justify access to an otherwise protected resource where refusal threatens the elimination of effective competition.

5. Microsoft Corp. v Commission (2007)

The Microsoft case is one of the most important precedents for modern digital infrastructure competition law.

The European Commission found problems involving Microsoft's refusal to provide interoperability information and the tying of products.

The General Court largely upheld the Commission's approach.

Relevance to digital resilience

Microsoft demonstrates how interoperability can become a competition issue.

Where a dominant technological platform controls an important interface, withholding interoperability information may make competing products less viable.

The case is especially relevant to:

  • cloud interoperability;
  • operating systems;
  • enterprise software;
  • APIs;
  • identity systems;
  • AI infrastructure.

Principle: Control over interoperability information can become an important source of exclusionary power.

6. Google Android (Commission, 2018; General Court, 2022)

The European Commission found several practices involving Google's Android ecosystem to be abusive, including restrictions concerning application distribution and competing search services.

The General Court substantially upheld the Commission's findings, while adjusting certain aspects of the Commission's reasoning and penalty.

Relevance

Android demonstrates how control over one digital infrastructure layer can be leveraged into adjacent markets.

An infrastructure ecosystem can create:

operating system → app distribution → search → advertising → data

This illustrates the systemic nature of digital dependency.

Principle: Ecosystem control and contractual restrictions can reinforce dominance across interconnected digital markets.

11. Additional Relevant Case Laws

7. Slovak Telekom v Commission (2021)

The case concerned access to telecommunications infrastructure and the application of competition law to vertically integrated infrastructure operators.

Importance

It demonstrates that infrastructure access must be assessed carefully where a dominant operator also competes downstream.

The case is highly relevant to digital networks because modern infrastructure providers may simultaneously operate infrastructure and downstream digital services.

8. Deutsche Telekom v Commission (2010)

The case concerned pricing practices in telecommunications and the possibility of exclusionary effects on competitors.

Importance

It illustrates how control over an upstream telecommunications network can affect downstream competition.

The broader lesson is that infrastructure pricing can itself become a mechanism for foreclosure.

12. Systemic Risk From Common Infrastructure Providers

The greatest danger is common-mode dependency.

Consider:

10,000 businesses → same cloud provider
8,000 → same identity provider
7,000 → same cybersecurity system
6,000 → same payment infrastructure

Each business may have an individual resilience plan.

But collectively they may have almost no systemic redundancy.

This creates:

Common-mode failure

One failure affects many supposedly independent businesses simultaneously.

Cascading failure

Failure at one infrastructure layer disrupts other connected systems.

Concentration risk

A small number of infrastructure providers acquire disproportionate bargaining power.

Recovery asymmetry

Large infrastructure providers may recover quickly while smaller businesses remain unable to operate.

13. Digital Resilience and Merger Control

Mergers can increase systemic dependency.

A transaction involving:

  • cloud computing;
  • cybersecurity;
  • payment systems;
  • identity infrastructure;
  • AI compute;
  • telecom networks;

may produce competitive concerns even where conventional market shares appear moderate.

Authorities may therefore need to examine:

  1. infrastructure bottlenecks;
  2. switching costs;
  3. interoperability;
  4. multi-homing;
  5. network effects;
  6. data advantages;
  7. vertical integration;
  8. downstream foreclosure;
  9. resilience consequences.

A merger may therefore be problematic not simply because it increases prices, but because it reduces the number of independent infrastructure providers capable of absorbing systemic shocks.

14. Resilience as a Non-Price Competition Parameter

Traditional competition analysis frequently focuses on:

  • price;
  • output;
  • quality;
  • innovation.

Digital infrastructure adds another parameter:

Resilience.

Two providers may charge identical prices, but one may offer:

  • multiple data centres;
  • independent backup systems;
  • interoperable architecture;
  • geographically distributed infrastructure.

The other may depend upon a single technical architecture.

Consequently, competition on resilience can itself be economically significant.

15. Regulatory Remedies

Competition authorities and sector regulators could employ several remedies.

A. Interoperability mandates

Require dominant infrastructure providers to provide functional interoperability.

B. Data portability

Allow customers to transfer data efficiently.

C. Switching-cost restrictions

Prevent contractual or technical practices that unnecessarily inhibit migration.

D. Multi-provider requirements

Systemically important organisations could be encouraged or required to maintain alternative suppliers.

E. Non-discrimination

Infrastructure access should be provided on transparent and non-discriminatory terms.

F. Structural remedies

In extreme cases, separation of infrastructure and downstream operations may be considered.

G. Merger scrutiny

Infrastructure acquisitions should be assessed for their effect on systemic dependency.

H. Resilience audits

Authorities could examine whether infrastructure markets possess sufficient redundancy.

16. Competition Law Versus Resilience Regulation

There is an important distinction.

Competition law asks:

Does the undertaking's conduct harm competitive conditions?

Resilience regulation asks:

Can the system continue functioning when infrastructure fails?

The two objectives overlap but are not identical.

A monopoly might technically provide highly resilient infrastructure.

Conversely, a competitive market might still have poor resilience.

Therefore, policymakers may need a combined framework:

Competition + interoperability + cybersecurity + redundancy + operational resilience

17. The "Resilience Paradox"

Digital infrastructure produces a particularly important paradox:

Economies of scale can increase operational resilience while concentration can increase systemic vulnerability.

For example, centralising cybersecurity in a sophisticated provider may improve protection for each individual customer.

But if almost every customer uses that provider, a single compromise can produce enormous systemic damage.

Thus:

Micro-level resilience ↑

while

Macro-level resilience ↓

This is one of the central policy problems of digital infrastructure governance.

18. Analytical Framework

A competition authority assessing systemic dependency could ask:

Step 1 — Identify the infrastructure

What technological layer is indispensable?

Step 2 — Identify dependency

How many downstream firms rely upon it?

Step 3 — Examine alternatives

Can customers realistically switch?

Step 4 — Examine interoperability

Can competing systems communicate?

Step 5 — Examine concentration

How many independent providers exist?

Step 6 — Examine vertical integration

Does the infrastructure provider compete downstream?

Step 7 — Examine conduct

Is access being restricted, degraded, bundled or discriminated against?

Step 8 — Assess systemic consequences

Could failure or exclusion affect multiple markets simultaneously?

Step 9 — Consider remedies

Would portability, interoperability, access or structural separation restore competition and resilience?

19. Key Legal Principles From the Cases

CaseCore principleDigital-resilience relevance
United BrandsSpecial responsibility of dominant firmsInfrastructure gatekeeper conduct
Commercial SolventsControl of important inputsCritical digital infrastructure access
BronnerStrict conditions for compulsory accessEssential-facility analysis
IMS HealthExceptional access to indispensable protected resourcesProprietary APIs/data architectures
MicrosoftInteroperability can be competitively essentialCloud/software interoperability
Google AndroidEcosystem leverage can reinforce dominanceDigital infrastructure ecosystems
Slovak TelekomInfrastructure access and downstream competitionTelecom/cloud infrastructure
Deutsche TelekomInfrastructure pricing can foreclose rivalsNetwork-access pricing

Conclusion

Digital resilience infrastructure is becoming a competition-law issue because the same infrastructure that makes the digital economy more reliable can also make it more dependent on a small number of powerful providers.

Cloud computing, telecommunications, cybersecurity, payment networks, digital identity, APIs and AI-compute infrastructure increasingly function as foundational economic infrastructure. Their concentration can create systemic dependency, particularly where customers face high switching costs, proprietary architectures, data lock-in or limited interoperability.

The major lesson from Bronner, Commercial Solvents, IMS Health, Microsoft, United Brands, Google Android, Slovak Telekom and Deutsche Telekom is that competition law must look beyond the immediate transaction or price effect and examine control over indispensable inputs, interoperability, vertical leverage and exclusionary access conditions.

Ultimately, the objective should not necessarily be to eliminate scale. Large infrastructure providers can generate substantial efficiencies and improve security. The objective should instead be to ensure that scale does not become an unavoidable bottleneck through which competitors, consumers and essential services must operate.

LEAVE A COMMENT