Applications / .lugano / CDL2651T-T31516 · published by ICANN 7 October 2026 · snapshot 2026-10-08
§ 1 — Meaning of the string Q118·Q120
Lugano is the name of the City of Lugano
/luˈɡaːno/
§ 2 — Mission and purpose Q133
The City of Lugano (Città di Lugano) is applying for .lugano as a standard gTLD to establish a reliable, secure and intuitive namespace for the institutional, civic, social, cultural and economic life of Lugano.
It will be treated not merely as a catalogue of web addresses, but as a durable digital public asset and stable anchor for naming, governance, trust, discovery and interoperability across the city's digital territory.
Its purpose is to facilitate secure digital communication, strengthen recognition of legitimate local actors and services, and provide a common foundation for digital development. The namespace will serve municipal departments, public services, businesses, associations, cultural, sporting and research organisations, residents and other entities with a substantive, verifiable and continuing nexus to Lugano.
The Registry Operator will develop means of allocation to combine eligibility, intended use and proportionality to the public meaning of each name.
Institutional and strategic terms will be reserved: generic names implying official or sector-wide representation may be operated as neutral shared resources or assigned through transparent, time-limited procedures.
The new namespace will make the broader ecosystem recognisable, verifiable and interoperable for people, organisations, services, devices and software agents.
The .lugano TLD will provide localised names for e-government, mobility, tourism, culture, events, urban planning, open data, academic collaboration, student services, technology transfer and initiatives developed through the Lugano Living Lab and other city programmes.
The city of Lugano plans to introduce the TLD progressively. Initial phases will establish the secure registry, core policies, reserved names, nic.lugano and institutional domains; later phases will add qualified registrations, Digital Commons, interoperable services and controlled agent-ready capabilities.
§ 3 — Commitments and safeguards Q164–Q188
| More trustworthy, consumer risk, regulated sector, government reporting, harm, government function Q164–Q169 | Yes to: more trustworthy (Q164) |
|---|---|
| Voluntary Safeguard PICs Q170·Q171 | None · 90 applications in the round offer some |
| Registry Voluntary Commitments Q172·Q173 | None · 5 do |
| Code of Conduct exemption requested Q185·Q188 | No |
§ 4 — All other published answers
Every other answer ICANN published for this application, in the order of the form. Contact details (Q17–Q24) are left to the ICANN record.
Q192Q1.1-1 - Provide the applying entity's self-certification document that commits government support on official letterhead from a proper authority that the application for the gTLD(s) and its operation by the applying entity is permitted and that represents and warrants: SC1.1-1.1 - That the applying entity is the recognized government of its jurisdiction and that the government has authorized the application(s) for applied-for gTLD string(s) or is a recognized intergovernmental organization with relevant authorization for its application(s) for applied-for gTLD string(s). SC1.1-1.2 - That the applying entity and/or an affiliate commits to the long-term funding required to operate all of the existing gTLDs (if applicable) and newly applied-for gTLD string(s) of the applying entity.
Q1.1-1 - Provide the applying entity's self-certification document that commits government support on official letterhead from a proper authority that the application for the gTLD(s) and its operation by the applying entity is permitted and that represents and warrants: SC1.1-1.1 - That the applying entity is the recognized government of its jurisdiction and that the government has authorized the application(s) for applied-for gTLD string(s) or is a recognized intergovernmental organization with relevant authorization for its application(s) for applied-for gTLD string(s). SC1.1-1.2 - That the applying entity and/or an affiliate commits to the long-term funding required to operate all of the existing gTLDs (if applicable) and newly applied-for gTLD string(s) of the applying entity.
Answered with a document. Attachments are not published by ICANN.
Q193Q1.2-1 - Provide a document with a list of the applying entity’s current gTLDs (if applicable) and a list of all gTLDs for entities affiliated with the applying entity (if applicable). If the applying entity and affiliates have no current gTLDs, submit a document that confirms this.
Q1.2-1 - Provide a document with a list of the applying entity’s current gTLDs (if applicable) and a list of all gTLDs for entities affiliated with the applying entity (if applicable). If the applying entity and affiliates have no current gTLDs, submit a document that confirms this.
Answered with a document. Attachments are not published by ICANN.
Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.
Answered with a document. Attachments are not published by ICANN.
Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.
Answered with a document. Attachments are not published by ICANN.
Q119Script of String
Script of String
Latin
Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.
true
Q159Is the applied-for string the name of a city and, if so, is the intention to use the TLD primarily for purposes associated with the city name?
Is the applied-for string the name of a city and, if so, is the intention to use the TLD primarily for purposes associated with the city name?
Yes
Q160If answered yes to previous question, how will the applying entity market and/or use the TLD primarily for purposes associated with the city name?
If answered yes to previous question, how will the applying entity market and/or use the TLD primarily for purposes associated with the city name?
The Registry will operate under the public stewardship of the City of Lugano, separating strategic governance, technical operations, allocation, compliance and review. Specialist Registry Service Providers and ICANN-accredited registrars will deliver registry, DNS, escrow and continuity functions under strict security, portability and anti-lock-in requirements. Abuse mitigation will meet ICANN obligations and be complemented by a local policy addressing impersonation, fraud, compromised services, obsolete attestations and misuse of digital agents, with proportionate remediation and rights of review.
The programme will be introduced progressively. Initial phases will establish the secure registry, core policies, reserved names, nic.lugano and institutional domains; later phases will add qualified registrations, Digital Commons, interoperable services and controlled agent-ready capabilities. Sustainability will combine registration and renewal fees, differentiated revenues from verified, premium and sector names, optional services, and incremental municipal investment approved at defined stage gates. Part of the value generated will be reinvested in shared infrastructure, security and public-interest services.
Q158Is the applied-for string a geographic name as defined by it being any one of the following: a) the capital city name of a country or territory listed in the ISO 3166-1 standard; b) a city name, where it is clear from statements in the application that the applying entity intends to use the gTLD for purposes associated with the city name; c) a sub-national place name listed in the ISO 3166-2 standard; or d) Strings listed as UNESCO regions or appearing on the Geographic Regions section of the “Standard country or area codes for statistical use (M49)”
Is the applied-for string a geographic name as defined by it being any one of the following: a) the capital city name of a country or territory listed in the ISO 3166-1 standard; b) a city name, where it is clear from statements in the application that the applying entity intends to use the gTLD for purposes associated with the city name; c) a sub-national place name listed in the ISO 3166-2 standard; or d) Strings listed as UNESCO regions or appearing on the Geographic Regions section of the “Standard country or area codes for statistical use (M49)”
Yes
Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true
Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.
true