NIS 2 โ Cybersecurity: the Italian Practical Guide ๐ฎ๐น๐
NIS turns information security from “an IT department thing” into a boardroom responsibility. If you thought GDPR was the hard part, welcome to the second half.
What it is and why it matters ๐
Directive (EU) 2022/2555 โ better known as NIS 2 (Network and Information Security) โ is the new European cybersecurity legislation. It updates the first NIS Directive (2016/1148), which covered only a handful of sectors, and introduces a much broader and stricter framework.
Italy transposed it with Legislative Decree 138/2024 (the so-called NIS Decree), published in the Official Gazette on 1 October 2024 and applicable since 18 October 2024 (art. 41, para. 1). The Decree replaces the old d.lgs. 65/2018, which implemented the previous NIS Directive.
Who is the competent authority? The National Cybersecurity Agency (ACN) is the national competent authority for NIS: it oversees implementation, adopts the list of NIS entities, defines the obligations and exercises supervisory and sanctioning powers. CSIRT Italia, the national incident response team, also operates under ACN and receives significant incident notifications.
The NIS Decree is not just another filing deadline. It is the first framework that puts cybersecurity on the boardroom table, with sanctions aligned with GDPR.
What changed versus the old NIS ๐
The previous directive covered a limited number of sectors and only the “networks and systems serving essential services”. Under the NIS Decree everything changes:
- Expanded scope: over 80 entity types in 18 sectors, 11 highly critical and 7 critical.
- Wider perimeter: obligations now cover the entire ICT infrastructure of the entity, not just systems providing the essential service.
- Automatic identification: entities are identified by objective criteria (sector + size). No more “are we in or out?” ambiguity.
- Essential/important categorisation: proportional obligations, differentiated inspection and sanctioning powers.
- Board accountability: management and executive bodies (the C-level) approve the measures, are liable for them, and must be trained.
- Significant sanctions: up to โฌ10M or 2% of worldwide turnover for essential entities and โฌ7M or 1.4% for important ones (art. 38).
- More structured incident notification: early warning within 24 hours, notification within 72 hours, final report within one month.
Who is in scope: the 18 sectors ๐
The sectors are grouped into annexes:
Annex I โ Highly critical sectors (10)
These include: energy, transport, banking sector, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), space.
Annex II โ Other critical sectors (7)
Postal and courier services, waste management, manufacture and processing of chemicals, production and processing of food, manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles), digital service providers (online marketplaces, search engines, social networks, registrars), research.
In the European count โ shared by ACN โ the headline figure is 18 sectors, 11 highly critical and 7 critical: the difference is public administration, which the Italian decree regulates separately in Annex III (central, regional, local and other administrations). The decree’s Annex I thus has 10 sectors.
For each sector, the Decree and the sectoral FAQs define the entity types in detail (e.g. “electricity supply undertaking”, “ICT service manager”, “food business operator”, “qualified trust service provider”). The list is not closed: ACN, on a proposal from sector authorities, can identify additional entities.
Essential or important? The criteria โ๏ธ
Depending on their criticality level, entities are classified as essential or important. The distinction derives from the sector and whether the entity is a medium or large enterprise, or from the specific cases set out in Article 3 of the Decree.
In a nutshell:
| Criterion | Essential entity | Important entity |
|---|---|---|
| Entity types | The most critical ones (e.g. energy, transport, banks, digital infrastructure, PA) | Other types under Annexes I and II |
| Size | Generally large enterprises or types designated by law | Medium enterprises and types not qualified as essential |
| Inspections | Ex ante and ex post supervision | Mostly ex post supervision |
| Sanctions (art. 38) | Up to โฌ10M or 2% of turnover | Up to โฌ7M or 1.4% of turnover |
The distinction is not a badge. Being “important” does not mean a softer bar: the substantive obligations โ measures, notifications, governance โ are identical. What changes is supervision and sanctions.
Am I a NIS entity? The self-assessment in 3 steps ๐
This is the chapter most companies get wrong: they either convince themselves they are out of scope (and then trouble arrives), or they register out of caution when it is not needed. The ACN self-assessment process has three steps (PDA1 โ PDA2 โ PDA3).
flowchart TD
A["Start self-assessment"] --> B{"PDA1<br/>Italian jurisdiction?"}
B -- "No (unless exceptions)" --> OUT1["OUT OF SCOPE<br/>stop"]
B -- "Yes" --> C{"PDA2<br/>Micro or small enterprise?"}
C -- "Yes (unless exceptions)" --> OUT2["OUT OF SCOPE<br/>stop"]
C -- "No" --> D{"PDA3<br/>Activities in Annex I or II?"}
D -- "Yes, even residual" --> IN["IN SCOPE<br/>register"]
D -- "Uncertain" --> IN2["REGISTER ANYWAY<br/>better safe"]
D -- "No" --> OUT3["OUT OF SCOPE<br/>stop"]
PDA 1 โ Does Italian jurisdiction apply to you? ๐ฎ๐น
Unless exceptions apply, the Decree applies if your organisation is established on Italian territory.
- PDA1.1 โ Established in Italy? Move to PDA2.
- PDA1.2 โ Do you provide public electronic communications networks/services accessible to the public in Italy? You are in scope, the process stops positively.
- PDA1.3 โ Do you provide inherently cross-border services (DNS, cloud, data centres, CDNs, online marketplaces, search engines, social networks, managed/managed-security services)? Italian jurisdiction applies if: you are established in Italy without establishments in other Member States, or your main EU establishment is in Italy, or โ if you have no EU establishment โ you have designated your EU representative in Italy.
- PDA1.4 โ Not established in Italy and not covered by PDA1.2/PDA1.3? Out of scope, stop.
PDA 2 โ Are you a micro or small enterprise? ๐
Micro and small enterprises โ fewer than 50 employees and turnover (or balance sheet) below โฌ10M โ are out of scope, with one important exception.
Watch out for the size calculation: if you have linked or partner undertakings, or are part of a group, you must aggregate the group data (Recommendation 2003/361/EC, art. 6 para. 2). Your own company does not count alone.
- PDA2.1 โ Medium or large enterprise? Move to PDA3.
- PDA2.2 โ Exception: qualified trust service providers (QTSPs), TLD registries and DNS service providers are in scope regardless of size. If you are in this list, you are in, stop.
- PDA2.3 โ Micro or small enterprise (without the exception above)? Out of scope, stop.
PDA 3 โ Do your activities fall under Annex I or II? ๐ฏ
Check whether the entity types defined in Annexes I and II apply to the activities you carry out or the services you provide.
- PDA3.1 โ Yes, even for a single type, even residually (except drinking water, wastewater and waste management)? You are in scope: register.
- PDA3.2 โ Uncertain about even one type? Register anyway. Better to be included out of caution than to discover the problems later.
- PDA3.3 โ No for all types? Out of scope, stop.
The “uncertainty = register” rule is not weakness: those who register enter the communication channel with ACN and gain clarity on their position. Those who do not register and are later found to be in scope have bigger problems.
Suppliers, public administrations and exclusions ๐งฉ
Even those who are not directly in the annexes can be called in:
- Supply chain (art. 3, para. 9, letter f): organisations providing systemic elements of the supply chain of NIS entities can be identified as essential or important, following ACN notification to their digital domicile (art. 3, para. 13). These are the NIS-relevant providers, communicated annually via CPV codes (Reg. EC 213/2008).
- Annex III โ Public administrations: central administrations (constitutional bodies, Presidency of the Council, Ministries, tax agencies, independent authorities), regional (Regions, autonomous Provinces), local (metropolitan cities, municipalities above 100,000 inhabitants, regional-capital municipalities, local health authorities) and other public bodies (research, zooprophylactic institutes, etc.).
- Annex IV โ Additional entity types: local public transport, research-active educational institutions, cultural interest activities, in-house/controlled/public-owned companies. For these, the registration obligation arises only after the identification notification by the Authority.
- Sub-suppliers: security responsibility along the chain remains with the NIS entity, which must identify which of its suppliers are “NIS-relevant” and ensure they promptly report security events affecting the service.
Exclusions (art. 4):
- Parliament, the judiciary, the Bank of Italy, the Financial Intelligence Unit (UIF).
- Public administrations operating in public security, national defence and law-enforcement, plus the national cybersecurity security services and ACN itself.
Special regimes (art. 3, paras. 14-15):
- Banking and financial-market-infrastructure entities (Annex I sectors 3 and 4) follow DORA (Reg. EU 2022/2554) for obligations and supervision: for them the NIS Decree is essentially reduced to registration.
- Entities exempted under DORA are also excluded from the NIS scope.
If you run a cloud-based SaaS and someone asks you “let’s certify this supply chain together” โ this is what is happening.
Registration: when and how ๐งพ
Registration takes place on the ACN NIS platform and consists of three phases: registering the point of contact, associating it with the entity, and completing the declaration.
When to register? Every year from 1 January to 28 February (by 17 January for digital service providers: DNS, TLD, cloud, data centres, CDNs, online marketplaces, search engines, social networks, managed and managed-security services). The first window was already open (deadline 28 February 2025) โ being late is not a defence.
Who is the point of contact? The legal representative, a general attorney, or a delegated employee. They do not “own” the compliance duties but “manage” their implementation: responsibility rests with the senior management (art. 23 of the Decree). Within a group, a NIS entity may designate an employee of another group company as point of contact.
What do you need for the declaration?
- ATECO codes of your activities (focusing on the NIS scope)
- Applicable sectoral EU regulations
- Number of employees, turnover and balance sheet (of the group, if not a standalone undertaking)
- Entity types (Annexes I, II, III, IV) you fall under
- Self-assessment as essential, important or out of scope
And then? By 31 March ACN adopts the list of essential and important entities; in April it notifies the outcome to the digital domicile. Remember: you are a NIS entity regardless of registration โ the list is a channel of certainty, not the source of the obligation.
Governance: security is a board matter ๐๏ธ
The NIS Decree puts cybersecurity into the boardroom. The wording of art. 23 is deliberately broad: obligations rest on management bodies and executive organs โ a concept that, besides the board, includes anyone performing directorial functions, i.e. the C-level (CEO, CFO, CTO, CIO, etc.):
- Management and executive bodies approve how the security measures are implemented, oversee their roll-out and are liable for violations (art. 23, para. 1);
- they must attend specific training and promote staff training (art. 23, para. 2);
- liability is personal: art. 38, para. 5, extends the burden to any natural person with authority to represent the entity, take decisions on its behalf or exercise control over it โ not “the technical office”.
The dividing line is not the job title but decision-making power: a CTO who signs off and decides on the measures is in scope; a department employee, even senior, is not. Formal approval still rests with the management body: the C-level prepares and proposes the measures.
Operationally, besides the point of contact (who manages implementation and liaises with ACN), a CSIRT referent must be designated โ the technical counterpart for incident notifications. It can be an external employee (e.g. an outsourced SOC/CERT), can coincide with the point of contact if internal, and has no nationality constraints. Substitutes for both figures are managed directly on the ACN portal.
For developers this means one simple thing: security is not a feature anymore, it is a governance requirement with someone’s name on it.
Security measures: the 10 areas ๐ก๏ธ
Art. 24 of the Decree imposes “adequate and proportionate” security measures in at least 10 areas, using a multi-risk (all-hazards) approach; art. 31 governs proportionality and graduality of obligations. ACN defined the baseline security measures with Determination 379907/2025, applicable during the initial implementation phase.
The required areas:
- Risk analysis and security policies for networks and information systems
- Incident management (detection, analysis, containment, recovery)
- Business continuity: backup, disaster recovery and crisis management
- Supply-chain security (including the relationship with cloud providers)
- Security in acquisitions (networking, development and maintenance of systems)
- Effectiveness assessment of measures (technical review, audits)
- Cyber hygiene and training: cryptography, identity and access management, asset management, MFA
- Policies and procedures to assess the effectiveness of risk management
- Use of cryptography and, where appropriate, pseudonymisation techniques
- Staff security, access control and human resources management
The baseline measures will be expanded by the end of 2026 with additional measures featuring advanced requirements, converging into “long-term security measures” with a defined timeframe. This is not a finish line: it is a direction.
Inventory and categorisation: the ACN model ๐๏ธ
After registration, NIS entities must produce the categorised inventory: the list of all the organisation’s activities and services (supported by information and network systems), each with its relevance category.
- 4 relevance categories: minimum, low, medium, high.
- The macro-areas and pre-assigned categories are defined in the categorisation model (Determination 155238/2026), completed on the platform from 1 May to 30 June each year.
- The process: identify activities/services โ map them to macro-areas โ assign the relevance category (keeping the analysis documentation if you deviate from the pre-assigned one).
- Obligations under the National Cyber-Security Perimeter (Law Decree 105/2019) must be declared as “high impact” and are not part of the categorised inventory.
Categorisation is the prerequisite for understanding which security measures you actually need: the higher the category, the stricter the requirements.
Incident notification ๐จ
The notification of significant incidents to CSIRT Italia (art. 25) happens in three steps:
Significant incident = an event compromising the availability, authenticity, integrity or confidentiality of data or services. Determination 379907/2025 defines 4 factual patterns (IS-1, IS-2, IS-3, IS-4) tied to confidentiality, integrity, availability and unauthorised access/privilege abuse. The cause does not matter: the obligation triggers even for natural events (floods), accidental failures and human errors, under the multi-risk approach. The 24-hour clock starts when you acquire objective elements of the incident โ not from a vague “awareness”.
sequenceDiagram
participant E as NIS entity
participant C as CSIRT Italia
E->>C: Early warning (within 24h)
Note over C: Since incident awareness
E->>C: Incident notification (within 72h)
Note over C: Initial severity/impact assessment, IOCs
E->>C: Final report (within 1 month)
Note over C: Root causes, measures, impacts
C-->>E: Possible follow-up requests
- Early warning โ without undue delay and in any case within 24 hours of becoming aware of the incident, indicating whether it may result from unlawful or malicious acts and whether it may have cross-border impact.
- Incident notification โ within 72 hours (24 for qualified trust service providers), with available updates, severity and impact assessment, and indicators of compromise (IOCs).
- Final report โ within one month, with root cause analysis, measures taken, impacts and lessons learned.
After incident handling, CSIRT may request a detailed final report instead of the simple closure report. The NIS entity must also inform the recipients of the service of the incident when appropriate and notify the competent authorities.
In the case of an incident on a cloud service: the notification obligation applies to both the NIS entity client and the NIS entity provider โ exception for IaaS/hosting services of the client’s infrastructure, where it rests only with the client. And your contract with the provider must include prompt reporting of security events.
Sanctions and supervision โ๏ธ
The administrative sanctions (art. 38) are structured in two tiers, depending on the violation. First tier โ most serious violations: failure to comply with governance obligations (art. 23), risk-management measures (art. 24) and incident reporting (art. 25):
| Entity | Maximum sanction (art. 38, para. 9) |
|---|---|
| Essential | up to โฌ10M or 2% of worldwide annual turnover (minimum: 1/20 of the maximum) |
| Important | up to โฌ7M or 1.4% of worldwide annual turnover (minimum: 1/30 of the maximum) |
| Essential PA | from โฌ25,000 to โฌ125,000 |
| Important PA | essential-PA amounts reduced by one third |
Second tier โ registration and procedural violations (failure to register or update under art. 7, failure to categorise under art. 30, certification schemes, domain database art. 29, failure to cooperate with ACN and CSIRT):
| Entity | Maximum sanction (art. 38, para. 11) |
|---|---|
| Essential | up to 0.1% of worldwide annual turnover |
| Important | up to 0.07% of worldwide annual turnover |
| Essential PA | from โฌ10,000 to โฌ50,000 |
| Important PA | essential-PA amounts reduced by one third |
Alongside financial penalties there are accessory sanctions: warnings, compliance orders, orders to implement specific measures, appointment of a supervision body and, for non-compliant executives, disqualification from management roles. The procedure can close with a compliance invitation, or via reduced payment (one third of the maximum) for minor violations (art. 38, para. 15).
Liability for violations rests with senior management (art. 23): those who sign off on security measures are personally responsible.
How is supervision exercised? ACN acts following the principles of effectiveness, proportionality and deterrence (art. 34). Inspections of essential entities can be ex ante (regular verification programmes); for important entities inspection powers are exercised ex post, when evidence of a violation emerges (art. 36). Inspections are complemented by executive measures (art. 37): injunctions and warnings with modalities and deadlines, which do not preclude sanctions.
What this means for developers and CTOs ๐จโ๐ป
For you, concretely, the NIS Decree means:
- Security by design is no longer optional: security measures enter the development lifecycle. Area 5 (“security in acquisitions and development”) concerns you directly.
- You must document: vulnerability management, patching, identity management, authentication (MFA), cryptography. Doing it is not enough โ you need to prove it.
- Organised incident response: you can no longer “silently patch the hole”. The notification chain (24h/72h/1 month) requires ready playbooks, not Friday-night improvisation.
- Tested backup and recovery: business continuity becomes a compliance requirement, with drills and written procedures.
- Supply chain: if you provide ICT services to NIS entities, expect security questionnaires, incident-reporting SLAs and audits. This is your new commercial passport.
Deadlines at a glance ๐
| Deadline | What happens |
|---|---|
| 18 October 2024 | NIS Decree (d.lgs. 138/2024) applies (art. 41) |
| 17 January 2025 | Registration: digital service providers (cloud, DNS, TLD, data centres, CDN, online marketplaces, managed services) |
| 28 February 2025 | Registration: all other NIS entities |
| 1 Jan โ 28 Feb (yearly) | Registration/data update window |
| 31 March (yearly) | ACN adopts the list of essential/important entities |
| 15 Apr โ 31 May (yearly) | Data update: IPs, domains, contacts and substitutes (art. 7, para. 4) |
| 31 May (yearly) | Annual information update (board list, EU services, agreements) |
| Within 14 days | Continuous information update when data changes |
| 1 January 2026 | Inventory and categorisation obligation (art. 30) begins |
| 1 May โ 30 Jun (yearly) | Inventory and categorisation of activities and services |
| 31 December 2025 | End of first implementation phase: notification within 9 months and measures within 18 months of communication (art. 42) |
| 1 Jan 2027 / 31 Jul 2027 | Notification / measures for entities first listed in 2026 |
| End of 2026 | Definition of long-term security measures |
| Always | Significant incident notification (24h/72h/1 month) |
Compliance checklist โ
Scope and registration
- PDA1-PDA2-PDA3 self-assessment completed with documented outcome
- Size verification (group included) under Recommendation 2003/361/EC
- Annex I/II entity types checklist with outcome for each
- Registration completed on the ACN NIS platform (or documented out-of-scope reasoning)
- Point of contact designated and delegation deed loaded (if an employee)
- Substitutes for point of contact and operators configured on the portal
- CSIRT referent designated (external allowed, e.g. SOC/CERT) with substitutes
Governance
- Management bodies informed and trained on the NIS Decree
- Formal approval of security measures by senior management
- Security responsibilities assigned (CISO, reference persons, roles)
Security measures
- Multi-risk analysis covering the entire ICT infrastructure
- Incident management plan with 24h/72h/1-month playbooks
- Backup and disaster recovery tested with documented procedure
- Active vulnerability and patch management
- MFA and identity/access management with least privilege
- Encryption of data and channels
- Supplier contracts include prompt security event reporting
- NIS-relevant providers verified (with CPV codes) for the annual update
- Annual (31 May) and continuous (14 days) information update process
- Continuous staff training (and board training)
Categorisation
- Inventory of activities/services supported by ICT systems
- Mapping into the categorisation model macro-areas
- Relevance category assigned (minimum/low/medium/high) with documentation
- Categorised inventory uploaded on the platform (1 May โ 30 Jun)
Useful links ๐
- NIS regulation โ ACN portal โ Decree, directive and official sources
- Scope of application โ ACN portal โ Sectors, sub-sectors and entity types table
- Text of Legislative Decree 138/2024 โ Gazzetta Ufficiale
- Directive (EU) 2022/2555 (NIS2) โ EUR-Lex
- National Cybersecurity Agency (ACN) โ National competent authority for NIS
- CSIRT Italia โ National incident response team
- ACN NIS FAQ โ Official Q&A on scope and registration
- Determination 379907/2025 โ Baseline security measures (with annexes 1-4: important, essential, significant incidents)
- Determination 379887/2025 โ NIS platform: point of contact, CSIRT referent, data updates
- DPCM 221/2024 โ Safeguard clause for group aggregations
- Categorisation model โ ACN reading guide
- ENISA โ EU Agency for Cybersecurity
See also ๐
- GDPR โ The data protection regulation that shares the accountability paradigm with NIS
- Cyber Resilience Act โ Security requirements for digital products, complementary to NIS
- AI Act โ AI regulation, intersecting with NIS on security and governance