NIS2 Recital 104
Providers of public electronic communications networks or of publicly available electronic communications services should implement security by design and by default, and inform their service recipients of significant cyber threats and of measures they can take to protect the security of their devices and communications, for example by using specific types of software or encryption technologies.
NIS2 is a Directive: the binding obligations live in each Member State's transposing national law, and this is the EU Directive text those laws implement.
Source text: EUR-Lex, Official Journal HTML (CELEX 32022L2555). The parser was validated against the anchor articles verified in REP-08.