Go to Content

We are the flag of Portugal on the internet

Blog

Legal & Corporate Affairs
11-08-2026
ICANN86 in Seville: A new gTLD round, ccTLD resilience and a shifting regulatory framework
From 8 to 11 June 2026, Seville hosted the ICANN86 Policy Forum, one of the three annual public meetings of the Internet Corporation for Assigned Names and Numbers (ICANN). Unlike the Community Forum and the Annual General Meeting, the Policy Forum is predominantly dedicated to policy development, providing a privileged space for work among the different communities that make up ICANN's multistakeholder model.

The meeting took place at a particularly relevant moment for the Domain Name System (DNS) ecosystem: the launch of the new round of the New gTLD Program, the resilience of the Internet's critical infrastructure and the growing impact of the international regulatory framework dominated the work of the Governmental Advisory Committee (GAC) and of the Country Code Names Supporting Organization (ccNSO).

A new round of the New gTLD Program

One of the main topics at ICANN86 was the status update on the new round of the New gTLD Program, whose application phase runs from 30 April to 12 August 2026, subject to a fee of USD 227,000. The public disclosure of the applications received ("Reveal Day") will take place during October and November.

The session clarified the mechanisms intended to avoid conflicts between new strings and top-level domains already delegated or reserved: the evaluation will cover the analysis of visual, phonetic and conceptual similarity of the applied-for strings, and objections ("String Confusion Objection") may be filed whenever there is considered to be a risk of confusion for users. The community's concern was clear to ensure that the expansion of the domain name space remains compatible with the stability, predictability and security of the DNS. The "GAC Communiqué – Seville, Spain" is available here.

Registration data accuracy and abuse prevention

Within the GAC, the accuracy of registration data and its relationship with DNS abuse prevention was debated. The WHOIS Accuracy Program Specification of the 2013 Registrar Accreditation Agreement (RAA) requires registrars to validate registrant data after registration, but the INFERMAL study indicates that verification carried out only after the fact may be associated with a significant increase in malicious registrations, since it allows malicious actors to use the domain before validation is completed. A GAC working group is therefore discussing recommending that ICANN require registrant identity verification to be completed before the registration takes effect.

The role of ccTLDs in digital transformation

As usual, the ccNSO meetings focused on the sharing of experiences among operators. We highlight the presentation by .rw (Rwanda), which integrated domain name registration into the IremboGov government platform, through which citizens access a wide range of digital public services, with around 31% of the amount paid for registrations reverting to that platform. The .ke registry, in turn, reported approximately 30% growth in registrations and its intention to integrate the company incorporation process with the registration of the corresponding domain name.
These examples demonstrate how ccTLD operators often take on, regardless of their governance model, an active role in national digital transformation strategies.

ccTLD resilience: lessons from Ukraine

The presentation by .ua (Ukraine) was one of the most striking moments of the ccNSO. Drawing on experience accumulated since the beginning of the war, it was argued that the resilience of critical infrastructure does not result from the ability to respond to a crisis, but rather from the preparation carried out long before it occurs: geographic distribution of the DNS infrastructure, high security standards, robust internal procedures, team preparedness, and trusted relationships between the registry, registrars and the wider technical community. Resilience is today a structural element of ccTLD management, no longer seen merely as a technological component but also as an organizational and strategic dimension.

Business continuity and IANA records

Along the same lines, work continued on the study of IANA's possible role in disaster scenarios affecting ccTLD operators. The first results point to the need to distinguish the operator's primary responsibility for service continuity from a possible complementary role for IANA, while stressing that the diversity of governance models, legal frameworks and size of ccTLDs prevents a uniform solution. Also discussed was the accuracy of IANA's public records relating to ccTLDs, where cases of outdated information were identified — a relevant question given the role of these records in the official identification of ccTLD managers and in the application of RFC 1591.

Cybersecurity and the evolving regulatory framework

The European regulatory framework continues to exert a growing influence on the activity of registry operators. The NIS2 Directive, the Cybersecurity Act and the Cyber Resilience Act were addressed, as well as the ENISA Technical Implementation Guidance and the growing importance attached to DNSSEC, recommended in Implementing Regulation (EU) 2024/2690 as an essential mechanism for strengthening the authenticity and integrity of DNS responses.

A warning was also raised that deserves particular attention: while a single legislative initiative is unlikely to constitute a factor of Internet fragmentation, the accumulation of multiple national legal regimes could, in the future, compromise the global interoperability of the DNS. The trend was illustrated by the registry for the .RU and .РФ domains, which presented Federal Law No. 569-FZ, in force from 1 September 2026, requiring mandatory verification of registrant identity through the government USIA system.

Final considerations

ICANN86 confirmed several trends that have been consolidating. ccTLD operators are today recognized as critical infrastructure essential to the functioning of the digital economy, taking on growing responsibilities in cybersecurity, business continuity and user trust — and international legislative developments, particularly in the European context, require them to continuously adapt their technical, operational and legal processes.

For .PT, the topics debated in Seville are particularly relevant, given their alignment with the processes underway to implement the Cybersecurity Legal Framework and revise the Registration Rules, but also because of the preparation of ICANN88, which will take place in Lisbon in March 2027. .PT's active participation in the various ICANN forums continues to prove essential in order to follow the evolution of international policies, anticipate future challenges and strengthen its position as a reference operator in the European ccTLD landscape.




Please note: the articles on this blog may not convey the opinion of .PT, but of its author.
Back to Posts