Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
Domains 6 min read

NIS-2 at DENIC: What will change for your .de domain from 14 April 2026

Domain on dominoes

Since 14 April 2026, new, binding rules have been in force at DENIC eG for all .de domains. This follows on from the European NIS 2 Directive, which is intended to ensure greater security, transparency and data quality in domain registrations across the EU. For you as a domain holder, this means that your registered contact details will be checked on an ongoing basis in future, and incorrect or unconfirmed information could, in the worst-case scenario, lead to the deactivation or deletion of your domain.

In this article, we summarise exactly what the new requirements mean, what deadlines apply, what we at SpeedIT are already handling on your behalf - and where you should take action yourself.

In a nutshell: Why all this?

The NIS 2 Directive (Network and Information Security Directive 2) is the successor to the first NIS Directive and was adopted at European level at the end of 2022. Its aim: uniformly higher cyber security standards across the EU - from critical infrastructure right through to domain registrations.

As domains are considered a central building block of the internet, NIS-2 also obliges registry organisations such as DENIC eG to ensure the accuracy and accessibility of the registered owner data. In practical terms, this means that fake addresses, placeholder telephone numbers or unreachable email accounts are no longer acceptable.

An overview of the key changes

1. Mandatory email verification for all .de domains

Arguably the most noticeable change: every domain holder’s email address on file with DENIC must be actively confirmed. This applies to new registrations and transfers as well as to existing domains that have not yet been successfully verified.

In this case, you will receive an email containing a confirmation link. A single click is all it takes - provided the registered email address is up to date and accessible to you. This is precisely where the crux of the matter lies: if the address is out of date (e.g. a former service provider, a mailbox that is no longer in use, or the private email address of someone who has left the organisation), the verification process will fail - with far-reaching consequences.

2. Rigorous checking of address details

Since 14 April 2026, DENIC has been automatically checking all domain contact requests (new registrations and amendments) for plausibility and consistency. Typical pitfalls:

  • The postcode does not match the town
  • Street does not exist in this form
  • Incomplete or contradictory details
  • Unclear link between the company and the contact person

If any discrepancies are detected, the system will initially reject the request. Whilst it is still possible to submit the request via an explicit confirmation, DENIC may subsequently require proof of the details in such cases.

3. Risk assessment and identity checks by DENIC

In future, DENIC will systematically assess incoming applications and existing data using a risk-scoring system. If a data record is classified as suspicious - or is simply selected at random - the identity of the domain holder may be verified.

Industry estimates suggest that around 7 per cent of all applications will require additional verification in future. This applies in particular to:

  • New registrations with atypical details
  • Changes of ownership (transfers, owner changes)
  • Bulk transfers of larger domain portfolios
  • Older records that have never been verified

DENIC accepts, amongst other things, identity cards, passports, driving licences, recent utility bills (electricity/water/gas) or DHL registered post receipts as proof of identity. At SpeedIT, we can collect the necessary documents directly from you if required and forward the relevant data in a single bundle.

4. The trustee model no longer applies to .de domains

Until now, it was standard practice to appoint a trustee for registrants without a German address. This model is no longer required for .de domains - neither the registrant nor the Admin-C need to be based in Germany. On the contrary: trustee arrangements now pose a new risk, as if email verification fails for a trustee contact, this may, under certain circumstances, jeopardise all domains registered through that contact.

Our recommendation: Register new .de domains directly in the name of the actual owner and gradually migrate existing nominee-held domains. Please feel free to contact us - we’ll guide you through the owner change process.

Deadlines at a glance

The following deadlines are crucial - if you miss them, you risk, in the worst-case scenario, the permanent loss of the domain, as the standard 30-day recovery period (RGP) does not apply to NIS-2 deletions.

Scenario Deadline for email confirmation Consequences of inaction
Legacy domains (prior to 14 April 2026) with failed verification 7 days Deactivation, 90 days’ quarantine, then deletion without RGP
New registration or transfer from 14 April 2026 15 days (+ 7 days following a further reminder) Deactivation, 90 days’ quarantine, then deletion without RGP
Event-based verification request from DENIC 7 days Server hold, 90-day quarantine, then deletion without RGP
Identity verification of the holder 7 days Server hold, 90 days’ quarantine, then deletion without RGP

Particularly important: the 30-day Redemption Grace Period, during which a domain can normally be recovered following standard deletion, does not apply at all in the case of NIS-2-related deletions. Once the 90-day quarantine period has expired, the domain is irrevocably lost and can only be re-registered after that time - potentially even by third parties.

What does this mean for you in practical terms?

First, the good news: anyone who keeps their contact details up to date and confirms verification emails promptly is on the safe side. The most common pitfalls we observe amongst our customers are:

  • Outdated email addresses in the registrant’s contact details - for example, belonging to former employees, agencies or freelancers who created the entry years ago.
  • Collective mailboxes without clear responsibility - verification emails end up in the inbox but are not dealt with by anyone because responsibility is unclear.
  • Address details containing typos or outdated company names (name changes, relocations, changes in legal form).
  • Domains registered to former trustees or managing directors who have long since left the company.

What we at SpeedIT already do for you

As your hosting and domain service provider, we handle the majority of the operational work behind the scenes:

  • We monitor incoming verification and validation requests from DENIC and forward them directly to you - not a cryptic system email, but clear instructions on what to do.
  • For identity checks, we collect the relevant documents from you in an organised manner and submit the data to the registry in good time.
  • Our portal structure at kcp.speedit.org offers an encrypted upload function, ensuring that copies of ID documents and similar files never have to be sent via unencrypted email.
  • For existing customers, we are currently proactively reviewing the registered holder data and will contact you as soon as action is required.

Your checklist - what you should check now

  1. Check holder details in the customer portal: Log in at kcp.speedit.org and verify that your name, company name, address, telephone number and email address match your current details.
  2. Choose your email address carefully: Use an email account that will remain active in the long term and is actively maintained - ideally a role-based address such as domains@your-company.de rather than a personal address.
  3. Register a telephone number: From January 2026, placeholder numbers will no longer be permitted. A landline or mobile number that can be reached is mandatory.
  4. Dissolve any trust arrangements: If you still hold domains via an external trustee, have them re-registered in the name of the actual owner.
  5. Take verification emails seriously: An email sent via our systems is not spam - failing to click a link or provide the required details could cost you your domain.

Conclusion

NIS-2 may sound like red tape, but it has a perfectly sensible core purpose: fewer fake shops, fewer phishing domains, and clean data records. For legitimate domain owners, little will change in their day-to-day work - provided the registered details are correct and a reliable email address is on file.

If you’re unsure whether your domain details are up to date, or if you’ve received a verification email from DENIC that you don’t recognise, please get in touch. We’ll check the status with you and ensure your domain complies with the new requirements.

Questions about your .de domains? Our team can assist you with data reconciliation, owner changes, trust account transfers and identity checks. Simply log in to the customer portal at kcp.speedit.org or contact us directly.

More posts

All posts
Domains 5 min read

The Importance of a Tidy DNS Zone: A Security Guide

In the digital world, the management and maintenance of the Domain Name System (DNS) zone is one of the critical aspects that is often overlooked. A well-organised and tidy DNS zone is crucial for security, efficiency…

Domains 2 min read

Partial deactivation of domain management - .RU domains

Due to Russia’s military attacks on Ukraine, a wide range of restrictions may be imposed on the .RU top-level domain. As a precaution, we would like to draw your attention today to the possible restrictions. The…

Offers 2 min read

.de Domain Special Offer & UG Company Name

The year 2022 brings with it a number of changes. In November 2009, I, Tobias Goth, set up my sole trader business and have run it with great passion ever since under the name “SpeedIT Solutions”. There have been good times and difficult, even very difficult, times…