×

Simplification or centralisation? The Digital Omnibus and the case against an EU SEP

Blog 15-07-2026

One of the key priorities of the current European Commission is the “simplification” agenda, which aims to reduce administrative burden and support the competitiveness of European businesses. In the digital area, the flagship simplification initiative is the Digital Omnibus proposal that includes a set of technical amendments to digital legislation, selected to bring immediate relief to businesses, public administrations and citizens, and to stimulate competitiveness.

The proposal takes a stab at some of the core principles in the data protection and governance space, such as revising the definition of personal data to exclude pseudonyms from protection. This aspect of the Digital Omnibus proposal, however, remains controversial, especially in the age of AI, where strong personal data standards are needed more than ever. EU policymakers insist on supporting the emergence of competitors to US and Chinese tech companies, but may invertedly only deepen the monopolies of non-EU giants if current high regulatory standards drop.

Other relevant reforms to reduce administrative burden, as suggested by the Digital Omnibus, such as the proposal for a single entry point (SEP) for incident reporting under EU cybersecurity legislation, might be more in line with the need to move fast, without dismantling core regulations rooted in fundamental rights. The need for a SEP for incident reporting has been supported by industry and is generally considered beneficial for a range of technical operators, including ccTLD registries.

However, from the perspective of critical infrastructure operators, such as ccTLD registries, the proposal to create one EU-level SEP may have unintended negative consequences for the relationship between authorities and technical operators, as well as the resilience of the reporting mechanism. It also favours reducing the administrative burden for a limited number of companies, normally established outside the EU.

Reporting to multiple Member States

The EU single-entry point for incident reporting aims to reduce administrative burden for companies operating in multiple Member States. However, the supervisory frameworks under the EU law, such as the NIS2 Directive, DORA or GDPR, are predominantly tied to the place of establishment. An EU company can position itself as international with a global reach, but for the purposes of incident reporting or data breach notifications, there is typically one Member State that oversees those activities. This is also the case for the majority of EU ccTLDs whose domain names are open for registration globally and across the EU. However, each EU ccTLD registry is supervised and is subject to the reporting obligations in the country of its establishment. The situation is different for non-EU companies, which may be obliged to report in multiple Member States, or providers of electronic communication services under the NIS2 Directive, who may also be subject to several Member States' jurisdictions.

Naturally, it seems that EU-level SEP is more favourable for non-EU companies (or certain providers of electronic communication services). For the rest of the EU business and critical digital infrastructure, such as EU ccTLDs, the cross-border incident reporting is not relevant. National SEPs, however, will ease the compliance burden for most EU digital businesses while keeping reporting closer to home and within established reporting lines. 

Relationships with authorities

Essential and critical infrastructure entities, such as EU ccTLDs, are subject to an extensive ex ante supervisory regime under the EU cybersecurity legislation. This means that the established close relationship between essential infrastructure entities, supervisory authorities and CSIRTs is a crucial aspect of Member States’ cyber posture. The EU-level SEP treats cybersecurity reporting obligation solely as a one-event compliance burden, and does not take into consideration the complexities of multiple-step reporting mechanisms, such as those required under the NIS2 Directive, which foresees more regular contact between the reporting entity and the authority (i.e., 24 hr early warning, 72 hr notification, full report in 1 month). 

Technically, a national SEP will not alleviate the issue of inconsistent reporting timelines across different EU law requirements (various incidents must be reported immediately, within 24h, 72h, 1 month, etc.), nor how to handle the multi-step reporting obligations. However, national SEPs are more easily adaptable to the national context and allow essential entities to maintain their established communication channels with the authorities without the need to move sensitive information cross-border. 

Single point of failure

As operators of essential digital infrastructure, EU ccTLDs understand the importance of decentralisation and distributed operational responsibilities within a system. The Domain Name System (DNS) is designed with the same principle in mind, where responsibilities and technical functions are divided among different actors and technical operators to ensure the resilience and stability of the internet.

Moving towards one EU-level SEP seems counterintuitive, especially in such a sensitive area as cybersecurity. An EU-level SEP may become a lucrative target for increased attacks by malicious actors, but also more vulnerable to simpler errors of misconfiguration and in overall maintenance activities. Multiple national SEPs will distribute that load, both politically and technically, especially in the current tense geopolitical climate, with the intensification of hybrid attacks on EU infrastructure. 

Political will from the Member States & the role of the EU

There is definitely more room for simplification across the EU cybersecurity legislation, and the Digital Omnibus is just the first step towards streamlining overlaps and inconsistencies in the EU cybersecurity acquis. However, when it comes to the SEP, EU policymakers in Brussels are not the only ones to blame. In fact, EU law already promotes the development of national SEPs in the NIS2 Directive (albeit in its non-binding recitals). A few Member States have duly followed up and established their own SEP mechanisms, but these remain rare. These experiences should be further studied and promoted across Member States, including through EU funding. 

For a moment, it seemed that EU Member States were taking note and responding to the Digital Omnibus proposal with a commitment to establish national SEPs, under the auspices of the Cypriot Presidency of the Council of the EU. Unfortunately, the latest developments show that some EU Member States are getting cold feet, and national SEP provisions are being watered down to commitments to establish national ‘information points’ rather than full-fledged one-stop platforms for receiving incident notifications. The European Parliament, on the other hand, seems to be inclined to keep the original proposal of the European Commission requiring the development of an EU-level SEP, as the latest text shows. The discussions are still in early stages, and it remains to be seen what both co-legislators will decide regarding their negotiating positions before coming together to decide on the final wording of the law.

The EU can also play a crucial role in supporting Member States in developing their national SEPs. If the EU takes the lead in developing one, it should be readily reusable and implementable by Member States at the national level. Free and Open Source (FOSS) solutions are key to maximum reuse, without vendor lock-in or difficult conversations about supply chain security. This will also be in line with the European Commission's recent commitment to increase the use and development of FOSS, as outlined in its Open Source Strategy.

Conclusion

Ultimately, it is the responsibility of the national authorities to handle incident notifications, while operators deal with the aftermath. The national authorities must decide whether to share incident details with their counterparts across borders. Any sensitive incident information must be shared securely and confidentially, and reporting entities need greater legal clarity regarding reporting timelines. Consequently, Member States should resolve the question of a functioning SEP and commit to follow-through at a national level to support EU operators. The EU can support this with FOSS tools and a commitment to interoperability, enabling more efficient cross-border notifications without compromising security needs. National information points are not enough to simplify compliance burden for EU operators, but SEP alone will not alleviate the administrative burden for all parties involved. This is just the first step to demonstrate that the 'fast-track' simplification agenda can produce meaningful results. 

Published By Polina Malaja
Polina Malaja is the Policy Director at CENTR, leading its policy work and liaising with governments, institutions and other organisations in the internet ecosystem.