Cyber Security & NIS2

NIS2 Compliance

Alignment with the NIS2 Directive and Italian Legislative Decree 138/2024 for essential and important entities and their suppliers: we establish whether and how the rules apply, measure the gap against the ACN security measures and support management and IT from the compliance plan to incident handling.

What we do

Our areas of work

Applicability and scope assessment

We analyse sector, size and services provided to establish whether the business falls among essential or important entities, which systems and sites are within scope, and which obligations arise from acting as a supplier to NIS2 entities.

ACN registration and formal requirements

We support registration on the ACN platform within the annual window, the appointment of a point of contact, a deputy and a CSIRT contact person, the annual data update, the categorisation of activities and services and the notification of relevant suppliers.

Gap analysis against the ACN measures

We compare the organisation with the risk management measures under Article 24 and with the baseline measures defined by ACN: policies, incident handling, continuity, supply chain, access control, cryptography, multi-factor authentication.

Governance and directors’ responsibilities

We define roles, delegations and reporting lines to senior management, prepare the resolutions approving the measures and deliver the mandatory training for management bodies.

Incident handling and notification

We build the procedure to detect, classify and notify significant incidents to CSIRT Italia within the statutory deadlines (24 hours, 72 hours, one month), with roles, communication templates and practical exercises.

Supply chain security

We assess critical suppliers, identify the relevant suppliers to be notified to ACN, embed security requirements in contracts and define controls proportionate to risk: questionnaires, documentary evidence, periodic checks and management of non-conformities.

The regulatory context

Directive (EU) 2022/2555, known as NIS2, has significantly widened the number of businesses subject to cyber security obligations. In Italy it was transposed by Italian Legislative Decree 138/2024, in force since 16 October 2024, which designates the Agenzia per la Cybersicurezza Nazionale (ACN, the Italian national cyber security agency) as the competent national authority and single point of contact, and CSIRT Italia as the recipient of incident notifications.

The legislation distinguishes between essential entities and important entities according to sector and size: as a rule mid-sized and large companies in the Annex I and II sectors, with some exceptions that apply regardless of the threshold. The sectors covered include energy, transport, banking and financial market infrastructure, health, drinking water and waste water, digital infrastructure (including electronic communications networks and services, and therefore telecommunications operators), management of business-to-business ICT services, space, postal services, waste, chemicals, food, certain manufacturing activities (medical devices, electronics, machinery, motor vehicles), digital service providers and research. Financial entities are governed primarily by Regulation (EU) 2022/2554, known as DORA.

There are five main obligations: registration on the ACN platform within the annual window and the subsequent updating of the data (Article 7); the categorisation of activities and services according to the ACN model (Article 30); the adoption of the risk management measures required by Article 24; the notification of significant incidents (Article 25); and the direct involvement of management bodies (Article 23), which approve the measures, oversee their implementation and undergo dedicated training.

ACN set out the baseline specifications for security measures and incident notification in determinations issued in 2025, updated at the end of that year and supplemented in 2026. For entities included in the list in 2025 the notification obligation has applied since the beginning of 2026 and the baseline measures must be in place by October 2026; for those entering the list in later years the deadlines are set by ACN from the notice of inclusion. The baseline specifications will be followed by those covering long-term obligations.

Administrative fines reach up to €10 million or 2% of annual worldwide turnover, whichever is higher, for essential entities, and up to €7 million or 1.4% for important entities. Failure to comply with ACN formal notices may also lead to a temporary ban on holding managerial functions for directors and senior management (Article 38). The most tangible risk, however, remains an incident handled without procedures: operational downtime, notifications sent too late, clients and authorities to be informed without reliable data.

Our approach

We start from the question that matters: do the rules apply, and to what? We examine sector, thresholds, services and group relationships, and draw the line between what falls within scope and what stays outside it. This avoids two opposite mistakes: adjusting everything without need, or overlooking obligations that carry fines.

Next comes a gap analysis against the Article 24 measures and the ACN baseline measures, carried out through interviews, document review and, where needed, targeted technical testing such as vulnerability assessments and penetration tests. The result is a compliance plan ordered by priority, with owners and deadlines, which the management body approves on a properly informed basis.

During implementation we work alongside IT, operational functions, procurement and management: we write short policies and procedures, handle the requirements towards ACN, structure incident handling, bring security requirements into supplier contracts and train both those who decide and those who operate. Where an ISO/IEC 27001 system or a structured GDPR management system already exists, we integrate NIS2 into the existing controls instead of building a parallel system: the same risk analysis, the same incident procedure with its different notification channels, the same supplier register.

We close with exercises on the incident procedure and periodic effectiveness checks, because NIS2 compliance is a continuing obligation and not a project that ends with a delivery.

What sets our service apart

  • Scope first: a reasoned applicability opinion, so that investment goes only where the rules require it.
  • Practical governance: resolutions, reporting lines and training designed for directors who have to decide, not for technical specialists.
  • Integration: risk analysis, incident procedure and supplier register shared across NIS2, GDPR and ISO/IEC 27001, without building parallel systems.
  • Proof in the field: technical testing and exercises to establish that the measures work, not merely that they are written down.

Our method

How we work

  1. Applicability analysis

    We check sector, size thresholds, services provided and relationships with NIS2 entities; we set out the outcome in a reasoned opinion and identify the systems, processes and sites that fall within scope.

  2. Gap analysis

    Interviews, document review and targeted technical testing to measure the distance from the Article 24 measures and the ACN baseline measures, with a risk level attached to each shortfall.

  3. Compliance plan

    A document agreed with management: organisational and technical actions, owners, indicative budget and deadlines aligned with the terms set by the decree and the ACN determinations, approved by the management body.

  4. Supported implementation

    We draft policies and procedures, support IT and suppliers in putting the measures in place, prepare the registration and the reporting flows towards ACN, and train the board and the staff.

  5. Testing and exercises

    We test the incident procedure through simulations, verify the effectiveness of the measures through audits and technical testing, and update the system as legislation, the organisation and technologies change.

Benefits

What the business gains

  • Clarity on scope: knowing whether and how the rules apply, avoiding both needless requirements and omissions that carry fines
  • A compliance plan with priorities and deadlines consistent with the terms set by the decree and by the ACN determinations
  • A management body that is properly informed and trained, able to approve the measures on an informed basis and to account for the choices made
  • A genuine capability to handle an incident: who does what, within which deadlines, with which communications to CSIRT Italia and clients
  • Fewer procedures and lower costs: risk analysis, incident procedure and supplier register shared with GDPR and ISO/IEC 27001

Deliverables

What we deliver

  • Applicability opinion and definition of the NIS2 scope
  • Gap analysis report against Article 24 and the ACN baseline measures
  • Compliance plan with priorities, owners and deadlines
  • Security policy and risk analysis approved by the management body
  • Incident handling and notification procedure with templates for CSIRT Italia
  • Business continuity, backup and crisis management plan
  • Supply chain security procedure and contractual clauses for suppliers
  • Training for management bodies and staff, with certificates and registers

Frequently asked questions

Answers to the questions we hear most often

How do we know whether our company falls within NIS2?

It depends on three factors: the sector of activity (Annexes I and II to Italian Legislative Decree 138/2024), size (as a rule mid-sized and large companies, with some exceptions that apply regardless of the threshold) and the services actually provided. Some cases are obvious, others call for a specific analysis, not least because the qualification may depend on associated and linked enterprises, under the criteria of Recommendation 2003/361/EC. It is worth clarifying this early: entities within scope must register on the ACN platform during the annual window, and the other obligations run from the notice of inclusion in the list.

We are not a NIS2 entity, but our clients are: does it affect us?

Yes, indirectly but tangibly. NIS2 entities must oversee the security of their supply chain, and they do so by imposing contractual requirements, questionnaires and audits on suppliers; from 2026 they also notify ACN each year of their relevant suppliers, that is, ICT services and supplies that cannot be replaced. A company able to demonstrate an adequate level of security strengthens the relationship; a company that cannot demonstrate it risks dropping off supplier lists. We support the business in building a credible response, proportionate to its size.

What must directors do personally?

The legislation assigns to management bodies the approval of the risk management measures, oversight of their implementation and an obligation to undergo specific training; where there are breaches they may be held to account and, if the entity fails to comply with ACN formal notices, they face a temporary ban from holding managerial functions. We prepare resolutions, reporting lines and a training programme suited to people without a technical background.

Which incidents must be notified, and within what deadlines?

Significant incidents must be notified to CSIRT Italia: those that cause or may cause serious operational disruption, financial loss or material harm to third parties, according to the criteria set by ACN in the baseline specifications or, for the digital service providers listed in Implementing Regulation (EU) 2024/2690, directly by that Regulation. The deadlines are tight: an early warning within 24 hours of becoming aware of the incident, notification within 72 hours and a final report within one month of the notification. Meeting them calls for a procedure, roles and templates ready before the incident happens.

We are already certified to ISO/IEC 27001: are we covered?

The business has an advantage, not an exemption. Certification covers most of the measures under Article 24, but NIS2 adds obligations of its own: ACN registration, incident notification within the deadlines, the responsibility and training of management bodies, and specific measures defined by ACN. We map the correspondences and integrate what is missing into the existing management system, without duplication.

Let’s talk

Together, let’s build your tomorrow.

Tell us your business priorities: in a first meeting with no obligation we look at your context and propose a concrete way forward, with clear timescales and measurable results.