Digital Resource Rent Extraction Measurement Systems .
Digital Resilience Regulation (NIS2) and Competition Implications
1. Introduction
The NIS2 Directive — Directive (EU) 2022/2555 — establishes a higher common level of cybersecurity across the EU. It replaced NIS1 and substantially expanded the sectors and entities subject to cybersecurity obligations. NIS2 covers areas including energy, transport, healthcare, digital infrastructure, electronic communications, digital services, manufacturing, public administration and space. It requires covered entities to adopt risk-management measures, manage supply-chain risks, report significant incidents and comply with stronger supervisory and enforcement mechanisms.
Although NIS2 is principally a cybersecurity and resilience instrument, it has important competition-law consequences. Cybersecurity requirements can affect:
- entry barriers;
- supplier selection;
- interoperability;
- cloud and infrastructure markets;
- multi-vendor strategies;
- switching costs;
- access to technical standards;
- vertical integration;
- procurement;
- dominance of trusted suppliers;
- exclusion of high-risk suppliers;
- concentration of critical digital infrastructure.
The central competition-law question is therefore:
How can the EU increase cybersecurity and systemic resilience without allowing security regulation to become a mechanism for unnecessary market foreclosure or concentration?
Importantly, there is not yet a substantial body of CJEU judgments directly interpreting NIS2 itself. Therefore, the relevant case law comes principally from EU competition cases concerning essential facilities, infrastructure access, regulatory constraints, interoperability, exclusionary conduct and the relationship between public-interest regulation and competition.
2. Core Structure of NIS2
NIS2 creates several mechanisms that can influence competitive conditions.
A. Wider sectoral coverage
NIS2 substantially expands the number of entities covered compared with NIS1. It includes digital infrastructure and services such as:
- cloud computing;
- data centres;
- content delivery networks;
- DNS services;
- online marketplaces;
- search engines;
- social-networking platforms;
- managed service providers;
- managed security service providers.
The Commission's implementing rules specify technical and methodological cybersecurity requirements for several of these categories.
B. Supply-chain security
NIS2 expressly requires cybersecurity risks arising from supply chains and supplier relationships to be addressed.
This is particularly important for competition because cybersecurity decisions can influence which suppliers remain commercially viable.
C. Risk-based security requirements
Entities must assess and mitigate risks involving matters such as:
- network and information-system security;
- incident handling;
- business continuity;
- crisis management;
- supply-chain security;
- vulnerability management;
- cryptography;
- access controls;
- authentication.
D. Incident reporting
Covered entities face stronger incident-notification obligations than under NIS1.
E. Supervisory and enforcement powers
NIS2 strengthens national supervisory authorities and harmonises aspects of enforcement and sanctions.
3. How NIS2 Can Affect Competition
A. Cybersecurity compliance as an entry barrier
A small company may be technically capable of entering a market but unable to afford:
- cybersecurity certification;
- security monitoring;
- incident-response infrastructure;
- compliance personnel;
- audits;
- supply-chain assessments;
- continuous vulnerability management.
Consequently, NIS2 can produce a legitimate quality-based barrier to entry.
The competition-law concern arises where compliance requirements become disproportionately expensive relative to the actual cybersecurity risk.
Example
Suppose a cloud market contains:
- two very large cloud providers; and
- fifty smaller specialist providers.
If security compliance requires extensive fixed infrastructure that only the two largest providers can economically provide, regulation could unintentionally strengthen concentration.
This does not make NIS2 anticompetitive. It means regulators must consider proportionality and competitive neutrality.
4. Cybersecurity Regulation and Essential Facilities
Digital infrastructure can become indispensable to downstream competitors.
Examples include:
- cloud infrastructure;
- DNS;
- authentication systems;
- payment infrastructure;
- telecommunications networks;
- cybersecurity threat-intelligence systems;
- critical APIs;
- data centres;
- identity infrastructure.
Where a dominant company controls infrastructure necessary for competitive activity, refusal or discriminatory access can potentially raise Article 102 TFEU concerns.
5. Case Law 1 — Bronner v Mediaprint
Case
Oscar Bronner GmbH & Co. KG v Mediaprint Zeitungs und Zeitschriftenverlag GmbH & Co. KG, C-7/97
Principle
The CJEU established the stringent conditions under which refusal by a dominant undertaking to provide access to infrastructure can constitute an abuse.
Generally, the facility must be indispensable, refusal must be capable of eliminating effective competition, and there must be no objective justification.
NIS2 relevance
Cybersecurity regulation does not automatically convert every critical digital infrastructure into an access obligation.
For example, a dominant cloud provider cannot simply be required to open every proprietary cybersecurity system to competitors merely because the infrastructure is important.
The Bronner framework protects incentives to invest while preventing truly indispensable infrastructure from being used anticompetitively.
Competition implication
NIS2 compliance should therefore not automatically become a justification for:
- unrestricted access;
- mandatory technology sharing;
- forced interoperability;
- compulsory disclosure of proprietary security architecture.
There must be a careful balance between resilience and investment incentives.
6. Case Law 2 — Slovak Telekom v Commission
Case
Slovak Telekom a.s. v European Commission, C-165/19 P
Principle
The case concerned access to telecommunications infrastructure and exclusionary conduct by a dominant operator.
The Court emphasised the importance of competition in infrastructure and the circumstances in which regulatory obligations and Article 102 TFEU interact.
NIS2 relevance
Telecommunications networks are fundamental to digital resilience.
NIS2 requires secure electronic communications infrastructure. But a dominant telecommunications operator could potentially exploit cybersecurity requirements to:
- deny access to competitors;
- impose discriminatory security requirements;
- make interoperability unnecessarily difficult;
- favour its affiliated services.
Competition implication
A cybersecurity justification should be genuine, proportionate and objectively connected to security risk.
A dominant operator should not be permitted to disguise exclusionary conduct as cybersecurity compliance.
7. Case Law 3 — Deutsche Telekom v Commission
Case
Deutsche Telekom AG v European Commission, C-152/19 P
Principle
The case concerned exclusionary conduct in telecommunications markets and the relationship between wholesale access and downstream competition.
The Court recognised the importance of preserving incentives for infrastructure investment while ensuring effective competition.
NIS2 relevance
This principle is particularly relevant to critical digital infrastructure.
Suppose a dominant network operator invests heavily in cybersecurity infrastructure. It may legitimately argue that unrestricted access could:
- create security vulnerabilities;
- increase attack surfaces;
- undermine system integrity;
- increase operational risks.
However, the existence of cybersecurity concerns does not automatically immunise exclusionary behaviour from Article 102 scrutiny.
Competition implication
The appropriate regulatory model is:
security requirement → risk assessment → proportionate access conditions
rather than:
security requirement → unrestricted exclusion of competitors.
8. Case Law 4 — Google Shopping
Case
Google and Alphabet v Commission — Google Shopping, C-48/22 P
Principle
The CJEU confirmed that a dominant digital platform can infringe Article 102 TFEU where its conduct disadvantages competing services through the use of its dominant platform position.
The case is particularly important because competition can be harmed through self-preferencing and platform architecture, rather than merely through traditional pricing practices.
NIS2 relevance
Cybersecurity systems can become part of platform architecture.
A dominant platform could potentially claim that:
"Only our affiliated cybersecurity service satisfies our security requirements."
If independent security providers are technically capable of satisfying equivalent security standards, an exclusive preference for the dominant firm's own service could potentially raise competition concerns.
Competition implication
NIS2 should promote:
- security;
- resilience;
- authentication;
- trusted services;
but not unnecessarily require single-provider dependence.
9. Case Law 5 — Alphabet and Others
Case
Alphabet and Others, C-233/23
Principle
The CJEU addressed access to a digital platform and the application of the Bronner conditions.
The Court distinguished infrastructure created for the dominant firm's own use from infrastructure designed to accommodate third parties. Where infrastructure is developed for third-party use, particularly strict Bronner conditions may not apply in the same way.
NIS2 relevance
This distinction is extremely important for digital resilience.
Consider a cybersecurity platform deliberately designed to provide services to:
- banks;
- telecommunications operators;
- cloud providers;
- government agencies;
- competing digital businesses.
If the platform becomes a central infrastructure for an ecosystem, its operator may have greater responsibilities concerning access and competitive neutrality.
Competition implication
The more an infrastructure is designed to function as a shared ecosystem, the weaker the argument that access necessarily threatens the owner's legitimate investment incentives.
10. Case Law 6 — Lietuvos geležinkeliai v Commission
Case
European Commission v Lietuvos geležinkeliai AB, C-42/21
Principle
The case concerned the removal of infrastructure and the exclusionary consequences of a dominant undertaking's conduct.
The Court emphasised that the analysis of refusal/access cases must take account of the nature of the infrastructure and the circumstances surrounding the dominant undertaking's control.
The later case law confirms that where a dominant undertaking is subject to a regulatory obligation to grant access, the strict Bronner conditions do not necessarily apply in the same way.
NIS2 relevance
This is highly relevant where cybersecurity regulation itself establishes access, interoperability or security obligations.
A dominant undertaking cannot necessarily invoke property or investment rights to defeat an access obligation that has already been imposed through legitimate regulation.
Competition implication
There can therefore be a three-layer structure:
NIS2 obligation → regulated access/security conditions → Article 102 oversight.
11. Case Law 7 — Meca-Medina
Case
Meca-Medina and Majcen v Commission, C-519/04 P
Principle
The CJEU established that rules pursuing legitimate regulatory objectives may still fall within competition law if they restrict competition.
At the same time, restrictions inherent in pursuing legitimate objectives may be assessed in their proper regulatory context.
NIS2 relevance
Cybersecurity is unquestionably a legitimate public-interest objective.
But legitimate objectives do not create an unlimited competition-law exemption.
A cybersecurity measure should therefore be assessed according to:
- legitimate objective;
- necessity;
- proportionality;
- competitive impact;
- availability of less restrictive alternatives.
Competition implication
NIS2-based restrictions should therefore be designed to be security-effective but competition-neutral wherever possible.
12. Case Law 8 — Wouters
Case
Wouters and Others v Algemene Raad van de Nederlandsche Orde van Advocaten, C-309/99
Principle
The CJEU recognised that certain rules pursuing legitimate public-interest objectives may fall outside Article 101(1) where their restrictive effects are inherent in and proportionate to those objectives.
NIS2 relevance
Cybersecurity requirements may inherently restrict commercial freedom.
For example:
- restricting insecure suppliers;
- requiring security audits;
- imposing authentication requirements;
- requiring incident reporting;
- limiting insecure network architectures.
Such restrictions can be legitimate where they are necessary and proportionate to cybersecurity objectives.
Competition implication
The Wouters logic supports a regulatory balancing approach rather than treating every restriction resulting from cybersecurity rules as an infringement.
13. Cybersecurity Standards and Standardisation
One of the most important competition issues concerns technical standards.
Cybersecurity depends on standards for:
- encryption;
- identity;
- authentication;
- vulnerability management;
- cloud security;
- network security;
- incident reporting;
- interoperability.
Standards can promote competition because they reduce uncertainty and allow different products to interoperate.
But standards can also become gatekeeping mechanisms.
Potential problem
If a dominant supplier controls the relevant standard-setting process, it may attempt to design technical requirements that:
- favour its own products;
- exclude rivals;
- increase switching costs;
- prevent interoperability;
- raise competitors' costs.
The EU's emerging ICT supply-chain framework explicitly recognises the strategic importance of cybersecurity standards and supply-chain security.
14. Supplier Concentration and NIS2
NIS2 encourages organisations to assess cybersecurity risks in their supply chains.
This creates an important tension.
Resilience logic
An organisation may prefer:
"Use only the most trusted supplier."
Competition/resilience logic
But excessive dependence on one supplier can itself create systemic risk.
For example:
Supplier A → 70% of European cloud infrastructure
may provide economies of scale but create a catastrophic single point of failure.
Therefore:
Cybersecurity resilience ≠ maximum supplier concentration.
Indeed, the EU ICT Supply Chain Security Toolbox promotes measures including assessment of critical suppliers, multi-vendor strategies and reducing dependencies on high-risk suppliers.
15. Multi-Vendor Strategies
A competition-friendly NIS2 approach should encourage:
- multi-cloud deployment;
- alternative cybersecurity providers;
- interoperable security tools;
- portable security configurations;
- open technical standards;
- supplier diversification.
This produces a useful convergence:
Competition → supplier diversity → reduced concentration → greater resilience.
Thus, competition law can itself contribute to cybersecurity resilience.
16. High-Risk Suppliers
Cybersecurity regulation may require organisations or governments to restrict certain suppliers considered high risk.
This creates difficult competition questions.
Potential benefit
Restrictions can:
- protect critical infrastructure;
- prevent strategic dependency;
- reduce espionage risks;
- prevent systemic cyber vulnerabilities.
Potential competition cost
They may simultaneously:
- eliminate competitors;
- increase prices;
- reduce technological diversity;
- strengthen incumbent suppliers;
- create national champions;
- fragment the EU internal market.
The EU's 2026 cybersecurity proposals demonstrate how supply-chain security is increasingly treated as a strategic economic issue, including potential restrictions involving high-risk suppliers and key ICT assets.
17. Cybersecurity and Cloud Market Concentration
Cloud computing is particularly sensitive.
Large cloud providers benefit from:
- economies of scale;
- large security teams;
- extensive data centres;
- sophisticated monitoring;
- threat intelligence;
- proprietary security technologies.
NIS2 compliance can consequently strengthen their competitive position.
Possible cycle
Large provider
↓
greater security resources
↓
easier compliance
↓
more trusted by customers
↓
more customers
↓
greater resources
↓
even greater security advantage
This can create security-induced network effects.
18. Security as a Non-Price Competitive Parameter
Traditional competition law often focuses on:
- price;
- output;
- quality.
Cybersecurity introduces another major parameter:
security quality.
A company may legitimately compete by offering superior cybersecurity.
Therefore, competition authorities should not interpret every cybersecurity advantage as anticompetitive.
The problem arises when a dominant firm manipulates security standards to exclude equally secure rivals.
19. Cybersecurity Certification and Competition
Certification can have two opposite effects.
Pro-competitive effect
Certification:
- increases consumer confidence;
- reduces information asymmetry;
- makes quality measurable;
- facilitates cross-border trade.
Anti-competitive possibility
Certification can also:
- raise entry costs;
- favour incumbents;
- exclude innovative SMEs;
- create certification bottlenecks;
- encourage collusion around standards.
Therefore certification requirements should be:
objective + transparent + proportionate + non-discriminatory.
20. NIS2 and Interoperability
Interoperability is a particularly important competition issue.
Security systems should ideally permit:
- migration;
- data portability;
- API compatibility;
- multiple security vendors;
- substitution of suppliers.
Otherwise, cybersecurity compliance can unintentionally create security lock-in.
For example:
"Your entire security architecture must use our proprietary authentication system."
could turn a security requirement into a commercial switching barrier.
21. NIS2 and Self-Preferencing
A dominant platform may provide:
- marketplace;
- cloud;
- cybersecurity;
- identity;
- monitoring;
- authentication.
It may then establish technical security requirements that favour its own downstream products.
This creates a potential:
security self-preferencing problem.
The appropriate regulatory question is not:
"Is the security requirement legitimate?"
but:
"Is the particular technical requirement objectively necessary for cybersecurity, or does it unnecessarily favour the dominant firm's own services?"
22. NIS2 and Vertical Foreclosure
A vertically integrated firm could control:
hardware → operating system → cloud → cybersecurity → identity → marketplace.
If NIS2 compliance requires compatibility across these layers, the vertically integrated firm may have incentives to make competing components harder to use.
Potential forms include:
- proprietary APIs;
- restrictive authentication;
- security certification barriers;
- discriminatory threat-intelligence access;
- incompatible security protocols;
- contractual restrictions.
These can potentially produce vertical foreclosure.
23. NIS2 and Mergers
Cybersecurity regulation also has implications for merger control.
Suppose:
Company A = dominant cloud provider
Company B = major cybersecurity provider
Their merger could produce:
- stronger cybersecurity capabilities;
- lower cyber risk;
- better integrated protection.
But it could also eliminate an independent cybersecurity competitor.
The Commission or national competition authorities may therefore need to examine whether cybersecurity benefits are genuine and merger-specific or whether the transaction merely strengthens an existing ecosystem bottleneck.
24. NIS2 and Killer Acquisitions
A large digital infrastructure company could acquire:
- security startups;
- vulnerability-management companies;
- identity providers;
- encryption companies;
- threat-intelligence firms.
Even if the target has low turnover, it could possess strategically important technology.
This creates an intersection between:
NIS2 → digital resilience → strategic technology → merger control.
Competition authorities may therefore increasingly need to consider resilience-related competitive capabilities, not simply current revenues.
25. NIS2 and Procurement
Public authorities implementing cybersecurity requirements can unintentionally design procurement procedures around incumbent technologies.
For example:
"The supplier must have experience operating our existing proprietary security architecture."
Such criteria may make it almost impossible for new suppliers to compete.
Competition-sensitive procurement should instead use:
- technology-neutral specifications;
- performance-based requirements;
- objective security criteria;
- interoperability requirements;
- supplier-diversification criteria.
26. NIS2 and SMEs
NIS2 can produce asymmetric effects.
Large undertakings can spread compliance costs across enormous revenues.
SMEs cannot.
Consequently:
Compliance cost / revenue
may be substantially higher for smaller firms.
This can cause:
- SME exit;
- consolidation;
- fewer entrants;
- acquisition by incumbents;
- reduced innovation.
The Commission's 2026 proposals specifically seek to simplify EU cybersecurity compliance, with the Commission stating that the changes could ease compliance for approximately 28,700 companies, including about 6,200 micro and small enterprises.
27. Competition and Systemic Resilience
An important conceptual distinction is:
Individual resilience
Protecting one company.
versus
Systemic resilience
Protecting the entire digital ecosystem.
A competition policy focused only on individual firm security might encourage consolidation.
A systemic approach recognises that diversity itself can be a resilience asset.
For example:
10 interoperable cybersecurity providers may be more resilient than one extremely sophisticated provider.
This is one of the strongest competition-policy arguments supporting interoperability and multi-vendor architectures.
28. The "Security Necessity" Defence
A dominant undertaking accused of exclusionary conduct may argue:
"The restriction is necessary for cybersecurity."
Competition authorities should examine:
- Is there a genuine cybersecurity risk?
- Is the restriction technically capable of addressing that risk?
- Is it necessary?
- Is there a less restrictive alternative?
- Does the restriction apply equally to comparable competitors?
- Does the dominant firm benefit commercially?
- Does it create supplier lock-in?
- Does it prevent interoperability?
This produces a proportionality test for security-based competition restrictions.
29. Relationship with Article 101 TFEU
NIS2-related cooperation can also create Article 101 issues.
Cybersecurity companies may legitimately cooperate on:
- threat intelligence;
- incident information;
- vulnerability disclosure;
- security standards.
But competitors exchanging commercially sensitive information could potentially facilitate:
- price coordination;
- market allocation;
- customer allocation;
- production coordination.
Therefore:
Cybersecurity information sharing ≠ unlimited competitor information exchange.
The information should be:
- necessary;
- proportionate;
- security-related;
- appropriately protected;
- limited to the legitimate objective.
30. Relationship with Article 102 TFEU
Article 102 becomes particularly important where NIS2-regulated infrastructure is controlled by dominant firms.
Potential theories include:
1. Refusal to supply
A dominant infrastructure provider denies access to a genuinely indispensable security infrastructure.
2. Discriminatory access
Different competitors receive different security interfaces or technical access.
3. Self-preferencing
The dominant firm gives its own cybersecurity product privileged technical treatment.
4. Tying
Access to essential infrastructure is conditioned upon purchasing the dominant firm's security service.
5. Margin squeeze
Security-related wholesale charges make downstream competition commercially impossible.
6. Interoperability foreclosure
Technical security requirements make rival products incompatible.
31. Regulatory Conflict
NIS2 and competition law normally pursue complementary objectives, but conflicts can arise.
NIS2 priority
Security → resilience → risk reduction
Competition-law priority
Competition → contestability → innovation → consumer welfare
A cybersecurity rule may reduce the number of suppliers while increasing system security.
Therefore regulators must ask:
Is the loss of competition necessary to achieve the security objective?
If the answer is no, less restrictive mechanisms should be preferred.
32. NIS2 and the 2026 Cybersecurity Developments
The policy direction is increasingly toward treating ICT supply chains as strategic infrastructure.
The Commission's January 2026 cybersecurity package proposed further amendments to NIS2, including measures concerning jurisdiction, ransomware reporting and stronger coordination involving ENISA. It also proposed a revised cybersecurity framework addressing ICT supply-chain risks.
This development makes competition concerns even more important because cybersecurity policy is moving beyond individual network security toward strategic control of digital supply chains.
33. Key Competition Risks Under NIS2
| Risk | Competition consequence |
|---|---|
| High compliance costs | Entry barriers |
| Certification requirements | Incumbent advantage |
| Supplier restrictions | Market foreclosure |
| Single-vendor security | Lock-in |
| Proprietary standards | Interoperability barriers |
| Security self-preferencing | Downstream foreclosure |
| Mandatory infrastructure sharing | Investment concerns |
| Excessive information sharing | Article 101 risks |
| Vertical integration | Foreclosure |
| Security-based procurement | Incumbent protection |
| High-risk supplier exclusion | Market concentration |
| Cloud security dependence | Infrastructure bottlenecks |
| Regulatory fragmentation | Cross-border barriers |
34. Competition-Friendly NIS2 Implementation
A competition-sensitive implementation should follow several principles.
Principle 1 — Technology neutrality
Security requirements should specify security outcomes, rather than unnecessarily prescribing one supplier's technology.
Principle 2 — Interoperability
Where technically feasible, security architecture should permit alternative providers.
Principle 3 — Supplier diversity
Multi-vendor strategies should be encouraged where they improve systemic resilience.
Principle 4 — Proportionality
Compliance requirements should correspond to actual cyber risk.
Principle 5 — Non-discrimination
Comparable suppliers should be subject to equivalent security standards.
Principle 6 — Transparency
Security certification and technical requirements should be transparent.
Principle 7 — Competition scrutiny
Where dominant firms control critical infrastructure, cybersecurity-based restrictions should remain subject to Article 102 analysis.
35. Important Legal Synthesis
The case law produces a coherent framework.
Bronner
→ exceptional access obligations and protection of investment incentives.
Deutsche Telekom
→ regulated infrastructure and downstream competition.
Slovak Telekom
→ telecommunications access and exclusionary conduct.
Lietuvos geležinkeliai
→ infrastructure control and regulatory access.
Google Shopping
→ digital-platform leveraging and competitive foreclosure.
Alphabet
→ digital infrastructure designed for third-party use receives particularly important competition-law scrutiny.
Meca-Medina
→ legitimate regulatory objectives do not automatically eliminate competition-law analysis.
Wouters
→ proportionate restrictions inherent in legitimate public-interest regulation may be justified.
36. Overall Legal Position
NIS2 should not be understood as competition law, but its implementation can substantially reshape competitive structures in digital markets.
Its greatest competition implications arise when cybersecurity requirements affect:
who may enter the market + who may supply infrastructure + who may access infrastructure + which technologies may interoperate + which suppliers are considered trustworthy.
The central legal principle should therefore be:
Cybersecurity necessity can justify restrictions on competition only to the extent that those restrictions are objectively necessary, proportionate and genuinely connected with resilience objectives.
NIS2 should not become a mechanism through which dominant digital infrastructure providers transform legitimate security requirements into commercial exclusion, interoperability foreclosure or permanent supplier lock-in.
Conversely, competition law should not be used to prevent genuinely necessary cybersecurity measures merely because they reduce the number of suppliers.
The strongest approach is therefore competitive resilience:
Cybersecurity + interoperability + supplier diversity + proportionality + contestability.
That approach treats competition not as an obstacle to digital resilience, but as one of its structural safeguards.

comments