Instantané du 8 octobre 2026 · ICANN APS, champs publics

Candidatures / .icp / DS2698T-T60168 · publié par l'ICANN le 7 octobre 2026 · instantané du 2026-10-08

.icp

StandardActive

DFINITY Stiftung, CH Q1·Q25

Contrôle ultime déclaré : Dominic Williams Q108 · Fiche ICANN ↗

§ 1 — Sens de la chaîne Q118·Q120

Abbreviation for "Internet Computer Protocol," the name of the protocol underlying the Internet Computer network. The protocol has been developed by the DFINITY Foundation. ICP also serves as the name of the governance/utility token within the network.

/ˌaɪ.siːˈpiː/

§ 2 — Mission et objet Q133

The primary intended use of the TLD is for services that run on ICP (e.g., websites, applications, agents). We expect that most services associated with the ICP community will prefer a domain under the .icp TLD. Besides branding, one main reason is the reliance on less centralized trust assumptions, which is an important topic in the ecosystem.

§ 3 — Engagements et sauvegardes Q164–Q188

Confiance accrue, risque pour le consommateur, secteur réglementé, déclarations à l'État, préjudice, fonction régalienne Q164–Q169Non à chacune
PIC de sauvegarde volontaires Q170·Q171

• Registry Operators will include a provision in their Registry-Registrar Agreements that requires Registrars to include in their Registration Agreements a provision requiring registrants to comply with all applicable laws, including those that relate to privacy, data collection, consumer protection (including in relation to misleading and deceptive conduct), fair lending, debt collection, organic farming, disclosure of data, and financial disclosures. • Registry Operators will include a provision in their Registry-Registrar Agreements that requires registrars at the time of registration to notify registrants of the requirement to comply with all applicable laws. • Registry Operators will include a provision in their Registry-Registrar Agreements that requires Registrars to include in their Registration Agreements a provision requiring that registrants who collect and maintain sensitive health and financial data implement reasonable and appropriate security measures commensurate with the offering of those services, as defined by applicable law. • Registry Operators will proactively create a clear pathway for the creation of a working relationship with the relevant regulatory or industry self-regulatory bodies by publicizing a point of contact and inviting such bodies to establish a channel of communication, including for the purpose of facilitating the development of a strategy to mitigate the risks of fraudulent and other illegal activities.

Registry Voluntary Commitments Q172·Q173
Q173.1

The Registry Operator commits to including in its Registry-Registrar Agreements a provision requiring registrars to include in their Registration Agreements a provision requiring that the web frontend served at any domain name registered under the .icp TLD is hosted on the Internet Computer Protocol (ICP, including Cloud Engines) within 90 days of domain registration. Specifically, HTTP responses served at the registered domain must include a valid ICP certification header (ic-certificate), which constitutes a cryptographic proof that the content originates from a canister (smart contract) deployed on the Internet Computer. The ic-certificate is generated through the ICP's certified variables mechanism: at each consensus round, the subnet hosting the canister computes a Merkle tree of its replicated state, signs the root hash using a threshold BLS signature, and embeds the resulting certificate in HTTP response headers. Any party can verify this certificate against the subnet's public key, which chains to the NNS root key — a publicly known value (see https://internetcomputer.org/docs/references/http-gateway-protocol-spec and https://github.com/dfinity/response-verification). Verification does not depend on DFINITY-controlled infrastructure; the open-source response-verification library and the published root key enable fully independent auditing. This mechanism is resilient to CDN caching because the certificate is bound to the specific response body via Merkle inclusion proofs — a cached response retains its original valid certificate, and any tampering with the body invalidates the proof. Backend services, APIs, and data storage may be hosted on any infrastructure at the registrant's discretion. The compliance check is performed by the Registry Operator through automated periodic scans (not at the point of registration). Domains that remain parked or pointed to non-ICP infrastructure beyond the 90-day activation window are in violation and subject to the enforcement process described below.

Exemption du Code de conduite demandée Q185·Q188Non

§ 4 — Toutes les autres réponses publiées

Toutes les autres réponses que l'ICANN a publiées pour cette candidature, dans l'ordre du formulaire. Les coordonnées (Q17–Q24) sont laissées à la fiche ICANN.

Q212Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Q4.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. If financial statements are provided by a Qualified Parent Entity (QPE), the CEO, President, CFO, and/or equivalent officer of the QPE must co-sign the certification document. The self-certification document must represent and warrant: SC4.2-1.1 - The applying entity and/or a QPE will fund the startup and long-term operation of all applied-for gTLD strings and (if applicable) currently operated gTLDs of a QPE. SC4.2-1.2 - The applying entity or QPE has at a minimum of US$50,000 plus 25% of the application base fee for each applied-for gTLD string in Cash and Cash Equivalents on the balance sheet of the provided financial statements, up to a maximum of US$300,000, designated to support the startup and operation of all of the applying entity’s applied-for gTLD strings. SC4.2-1.3 - The applying entity and/or its officers are bound by law in its jurisdiction to represent financial statements accurately and the applying entity is in good standing in that jurisdiction.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q220Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Q5.1-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.1-1.1 - The applying entity will appropriately protect confidentiality of data and prevent unauthorized access to data and services. SC5.1-1.2 - The applying entity will maintain a mature, appropriately funded and staffed security program, following a recognized, modern security framework based on risk management (such as the ISO27000 series, COBIT, HITRUST CSF, legally required security frameworks, or equivalent). The security program must be in place prior to delegation, and exist through at least the period of the registry agreement. SC5.1-1.3 - The applying entity is aware of and has designed its systems and business to comply with the relevant privacy and security regulations for all countries in which it operates.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q221Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Q5.2-1 - Provide the applying entity’s self-certification document, signed by the CEO, President, CFO and/or equivalent officer of the applying entity. The self-certification document must represent and warrant: SC5.2-1.1 - The applying entity will, no later than delegation of the Top Level Domain (TLD), establish a dedicated abuse point of contact responsible for addressing matters requiring expedited attention and providing a timely response to abuse complaints concerning any name registered in the TLD. SC5.2-1.2 - The applying entity will, no later than delegation of the TLD, establish, publish, and provide to ICANN the location of a mechanism for members of the public to submit reports of abuse in accordance with the current obligations of the Base RA and any Consensus Policies. SC5.2-1.3 - The applying entity has developed proposed measures for removal of orphan glue records for names removed from the zone when provided with evidence in written form that the glue is present in connection with malicious conduct (see Specification 6). SC5.2-1.4 - The applying entity has or will have at time of delegation, established policies for handling complaints regarding abuse. Such policies are to be maintained and posted publicly so that anyone can review the policies via the Internet and any other means deemed appropriate by the applying entity. The applying entity’s policies at a minimum should contain appropriate confirmation of the receipt of the abuse report, the process of review of the report, and actions that will be taken if the applying entity confirms the report is legitimate. SC5.2-1.5 - The applying entity understands that DNS Abuse is Phishing, Malware, Botnets, Pharming and Spam (when used to deliver other forms of DNS Abuse). The applying entity understands and is prepared to contribute to the mitigation or disruption of DNS Abuse in domains in the TLD zone. SC5.2-1.6 - The applying entity’s abuse response capabilities are resourced appropriately to ensure a timely and adequate investigation and response to reports of DNS Abuse. This includes capabilities to receive and evaluate evidence of DNS Abuse in reports, and to take action to stop or disrupt the DNS Abuse. SC5.2-1.7 - The applying entity is prepared to conduct periodic scans of its zone to identify if domains are being used to perpetrate DNS Abuse, and to maintain statistical reports of the scans, the findings, and actions taken.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q119Script of String

Script of String

Latin

Q121As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

As per Section 3(d) of Specification 11 of the Base Registry Agreement, a registry operator of a “generic string” may not impose eligibility criteria for registering names in the TLD that limit registrations exclusively to a single person or entity and/or that person’s or entity’s “Affiliates” (as defined in Section 2.9(c) of the Registry Agreement). “Generic String” means a string consisting of a word or term that denominates or describes a general class of goods, services, groups, organizations or things, as opposed to distinguishing a specific brand of goods, services, groups, organizations or things from those of others. Confirm that the applied-for string is not a “generic string” in which the applying entity intends to limit registrations exclusively to a single person or entity.

true

Q174Explain the rationale for any limitations to the commitment proposed by the applying entity in Question 173.

Explain the rationale for any limitations to the commitment proposed by the applying entity in Question 173.

The RVC is limited to the web frontend rather than the full technology stack because defining and verifying a comprehensive hosting requirement for all application components is technically impractical. While ICP supports full-stack hosting including data storage and backend logic, many applications legitimately interact with APIs of external services, making it infeasible to draw a clear compliance boundary for backend infrastructure. The frontend requirement is meaningful because it is the component that is publicly served at the domain name and can be cryptographically verified. Verification mechanism: The Registry Operator will operate an automated compliance scanner that periodically issues HTTP requests to registered .icp domains and validates the ic-certificate response header. This scanner checks (1) that the header is present, (2) that the certificate's Merkle proof is valid against the subnet's public key, and (3) that the response body matches the certified hash. Scans are performed at minimum monthly after the 90-day activation window and again at each annual renewal. Lifecycle integration: A newly registered domain enters a 90-day activation grace period during which no compliance check is enforced. After activation, non-compliant domains trigger a notification to the registrar of record, who must notify the registrant and allow a 30-day cure period. If the domain remains non-compliant after the cure period, the registrar must place the domain on serverHold. Domains in redemption or pending-delete states are exempt from active compliance checks. On transfer to a new registrant, a new 90-day activation window begins, provided the domain has not already exhausted its cumulative non-compliance allowance. A domain may not remain non-compliant for more than 90 days in any rolling 12-month period, regardless of how many transfers occur; if a domain is still non-compliant at the time of its annual renewal, renewal is blocked until compliance is restored. The Registry Operator publishes a compliance dashboard and provides registrars with an API to query the compliance status of domains in their portfolio.

Q175Why are the commitment(s) being proposed?

Why are the commitment(s) being proposed?

This commitment ensures that the .icp TLD serves its intended purpose: providing a namespace for applications hosted on the Internet Computer Protocol. Without such a commitment, .icp domains could be used for conventional web hosting unrelated to ICP, diluting the TLD's identity. What makes this commitment uniquely feasible is the ic-certificate verification mechanism, which provides a cryptographic, machine-verifiable proof of ICP hosting — unlike most registry voluntary commitments, compliance can be checked automatically and objectively without human judgment. The verification mechanism is fully transparent: the IC interface specification and HTTP Gateway Protocol Specification are publicly documented (https://docs.internetcomputer.org/references/http-gateway-protocol-spec), the response-verification library is open source (https://github.com/dfinity/response-verification), and the NNS root public key is a published, immutable value. Any independent party — including ICANN compliance staff, registrars, or third-party auditors — can verify ic-certificate headers without reliance on DFINITY infrastructure. This commitment aligns with DFINITY's mission to build open internet infrastructure and ensures the .icp TLD remains a trusted, purpose-driven namespace.

Q222If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.

If the applying entity wishes to provide any additional information or supporting materials that the applying entity believes may be of interest to the public or relevant to the application, please include them here.

Réponse fournie sous forme de document. L'ICANN ne publie pas les pièces jointes.

Q223By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it is submitting this Application with a good faith (“bona fide”) intent to operate the gTLD for which it has applied, and that the applying entity has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true

Q224By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

By submitting this Application, the applying entity confirms that it has read and understands the provisions of Section 5.2.3.1 Prohibited Communications and Activities of the Applicant Guidebook regarding the New gTLD Program rules prohibiting certain communications and activities to prevent parties from privately resolving string contention among themselves.

true