The regulatory context
Directive (EU) 2022/2555, known as NIS2, has significantly widened the number of businesses subject to cyber security obligations. In Italy it was transposed by Italian Legislative Decree 138/2024, in force since 16 October 2024, which designates the Agenzia per la Cybersicurezza Nazionale (ACN, the Italian national cyber security agency) as the competent national authority and single point of contact, and CSIRT Italia as the recipient of incident notifications.
The legislation distinguishes between essential entities and important entities according to sector and size: as a rule mid-sized and large companies in the Annex I and II sectors, with some exceptions that apply regardless of the threshold. The sectors covered include energy, transport, banking and financial market infrastructure, health, drinking water and waste water, digital infrastructure (including electronic communications networks and services, and therefore telecommunications operators), management of business-to-business ICT services, space, postal services, waste, chemicals, food, certain manufacturing activities (medical devices, electronics, machinery, motor vehicles), digital service providers and research. Financial entities are governed primarily by Regulation (EU) 2022/2554, known as DORA.
There are five main obligations: registration on the ACN platform within the annual window and the subsequent updating of the data (Article 7); the categorisation of activities and services according to the ACN model (Article 30); the adoption of the risk management measures required by Article 24; the notification of significant incidents (Article 25); and the direct involvement of management bodies (Article 23), which approve the measures, oversee their implementation and undergo dedicated training.
ACN set out the baseline specifications for security measures and incident notification in determinations issued in 2025, updated at the end of that year and supplemented in 2026. For entities included in the list in 2025 the notification obligation has applied since the beginning of 2026 and the baseline measures must be in place by October 2026; for those entering the list in later years the deadlines are set by ACN from the notice of inclusion. The baseline specifications will be followed by those covering long-term obligations.
Administrative fines reach up to €10 million or 2% of annual worldwide turnover, whichever is higher, for essential entities, and up to €7 million or 1.4% for important entities. Failure to comply with ACN formal notices may also lead to a temporary ban on holding managerial functions for directors and senior management (Article 38). The most tangible risk, however, remains an incident handled without procedures: operational downtime, notifications sent too late, clients and authorities to be informed without reliable data.
Our approach
We start from the question that matters: do the rules apply, and to what? We examine sector, thresholds, services and group relationships, and draw the line between what falls within scope and what stays outside it. This avoids two opposite mistakes: adjusting everything without need, or overlooking obligations that carry fines.
Next comes a gap analysis against the Article 24 measures and the ACN baseline measures, carried out through interviews, document review and, where needed, targeted technical testing such as vulnerability assessments and penetration tests. The result is a compliance plan ordered by priority, with owners and deadlines, which the management body approves on a properly informed basis.
During implementation we work alongside IT, operational functions, procurement and management: we write short policies and procedures, handle the requirements towards ACN, structure incident handling, bring security requirements into supplier contracts and train both those who decide and those who operate. Where an ISO/IEC 27001 system or a structured GDPR management system already exists, we integrate NIS2 into the existing controls instead of building a parallel system: the same risk analysis, the same incident procedure with its different notification channels, the same supplier register.
We close with exercises on the incident procedure and periodic effectiveness checks, because NIS2 compliance is a continuing obligation and not a project that ends with a delivery.
What sets our service apart
- Scope first: a reasoned applicability opinion, so that investment goes only where the rules require it.
- Practical governance: resolutions, reporting lines and training designed for directors who have to decide, not for technical specialists.
- Integration: risk analysis, incident procedure and supplier register shared across NIS2, GDPR and ISO/IEC 27001, without building parallel systems.
- Proof in the field: technical testing and exercises to establish that the measures work, not merely that they are written down.