Every question about Nispo and NIS2 in Italy, on one page, with short, verifiable answers. Can’t find yours? Email info@nispo.it: a real person from the team will reply.

The product

What is Nispo?

Nispo is an Italian NIS2 compliance management platform, designed for organisations subject to NIS2 in Italy. It helps map the NIS2 requirements and the ACN basic security measures to your own controls, collect and keep evidence, track remediation, manage policies and suppliers, generate the files for the ACN portal and prepare documentation for the management body and for inspections. It is developed by NisPo S.r.l., Milan, which also offers cybersecurity services. NIS2 compliance software.

Is Nispo a NIS2 compliance tool?

Yes. Nispo is compliance management software focused on Italian NIS2 (a GRC platform focused on a single regulatory framework). It is not a security scanner, an antivirus/EDR or a SIEM.

Who is Nispo for?

Italian organisations subject to NIS2 with at least 50 employees and 20 IT assets (the plan’s entry point, not the NIS2 applicability criterion), without a large security or compliance team, that need to organise evidence and accountability, have critical ICT suppliers and want continuous visibility. It is not suited to anyone looking for a multi-framework platform (ISO/IEC 27001, SOC 2, DORA), a technical protection tool, or operating only outside Italy.

What does Nispo automate?

Checks of technical controls on the integrated systems — Microsoft 365 / Entra ID, Google Workspace, AWS and Google Cloud — (for example admin MFA, privileged accounts, registered devices) with the result recorded as dated evidence; import of users, devices, licences and cloud resources into the inventory; dashboard updates; deadline reminders; sync of CSIRT Italia bulletins. Policies, plans, registers, suppliers, risk decisions and approvals remain input from the organisation. What is automated and what is not.

What evidence does Nispo collect?

Automatically: results of checks on controls linked to the integrated systems (Microsoft 365 / Entra ID, Google Workspace, AWS, Google Cloud) and the inventory of users, devices, licences and cloud resources. Through your team: approved policies and plans, registers, exports and reports from non-connected systems, supplier documentation, penetration test and vulnerability assessment reports. Each piece of evidence is linked to its requirement and records date, source and owner. Evidence management.

What do I actually receive with Nispo?

A compliance status dashboard by area, the control register with status and evidence, a prioritised gap list, the remediation task register, a policy library with templates and versions, a supplier register, a risk register, inventories, the ACN portal files, reports for the management body and PDF and CSV exports. Compliance reporting.

How are gaps identified?

A gap is an applicable requirement that is not covered: a failed automated check, a missing or unapproved document, missing evidence, an unassessed critical supplier or an open penetration test finding. NIS2 gap assessment.

How long does the first NIS2 gap assessment take with Nispo?

Connecting Microsoft 365 takes about 5 minutes and the first automated checks about 10-15 minutes, depending on the size of the tenant. The documentary part — policies, plans, registers, suppliers — depends on how much documentation already exists and is usually the longest.

How is Nispo’s gap assessment different from a consultant’s gap analysis?

A consultancy gap analysis usually produces a document describing the state of a single day. In Nispo gaps live in the same control register: they are linked to evidence, become tasks with an owner and are closed with proof. The two approaches combine well: a consultant can work on the same data.

In what format are reports and evidence exported?

PDF and CSV: registers, evidence and reports. PDF is intended for management and for inspectors, CSV for anyone who needs to work with the data.

Pricing

How much does Nispo cost?

Nispo does not publish a price list: you get the price in a free 30-minute demo, and it depends on headcount, IT assets and the systems to connect. It is an annual subscription plus a one-time setup fee. The plan is designed for organisations with at least 50 employees and 20 IT assets; for larger organisations, more assets or more complex environments, it is tailored. Cybersecurity services are separate, on quote. Book the demo.

What is the minimum Nispo plan?

The annual plan for organisations with at least 50 employees and 20 IT assets: an annual subscription plus a one-time setup fee, with the price presented in a demo. It is the only standard plan: beyond the entry point, you move to a tailored plan.

How many employees does a company need to use Nispo?

The entry plan is designed for organisations with at least 50 employees. This is Nispo’s commercial threshold, not the NIS2 applicability criterion, which also depends on sector, turnover and balance sheet, and on cases where entities are in scope regardless of size.

How many assets are included?

The entry plan is designed for environments starting from 20 IT assets (for example computers, servers, network devices, cloud services). If you have many more assets or a more complex environment, the plan is tailored.

Is there a setup fee?

Yes, one-time, on top of the annual fee. We present the amount in the demo, together with the annual fee.

Is pricing based on employees or assets?

Both, and on the complexity of the environment (for example the systems to connect): that is why we present the price in a demo. The plan starts from organisations with 50 employees and 20 IT assets; beyond that, or for more complex environments, it is tailored.

What is included in the annual plan?

NIS2 / ACN control mapping, automated technical checks, evidence collection, compliance dashboard, gap assessment, remediation tracking, audit-ready reporting, supplier management, NIS2 documentation and templates, continuous compliance monitoring. Cybersecurity services, such as penetration testing and vulnerability assessment, are separate, on quote.

Can larger companies use Nispo?

Yes. For larger organisations, more assets or more complex environments, Nispo offers a tailored plan, defined starting from the demo.

Microsoft 365 and integrations

Does Nispo work with Microsoft 365?

Yes. Nispo connects to Microsoft 365 / Microsoft Entra ID with read-only permissions on the Microsoft Graph API, checks some technical controls automatically (for example MFA on admin accounts) and imports users, devices and licences into the inventory. Nispo and Microsoft 365.

Does Nispo change my tenant configuration?

No. Nispo only uses read permissions on Microsoft Graph and does not change any tenant configuration.

Do I need Microsoft 365 to use Nispo?

No. Automated checks work with Microsoft 365 / Entra ID, Google Workspace, AWS and Google Cloud. For systems without an integration (for example on-premise servers or network devices), and for organisations that use none of these services, control status is based on manual verification, uploaded evidence and your team’s answers.

Does Nispo support Google Workspace, AWS or Google Cloud?

Yes. Google Workspace, AWS and Google Cloud are available integrations, like Microsoft 365 / Entra ID: Nispo automatically checks the linked controls (for Google Workspace, for example, those on identities, access and devices) and imports the data into the inventory. NIS2 technical controls.

Does Nispo integrate with Azure?

Nispo connects to Microsoft Entra ID (formerly Azure Active Directory) through Microsoft 365. Azure subscription resources (virtual machines, networks, storage) are not offered as an automated integration: for those, controls are handled with uploaded evidence. Nispo platform data is hosted on Microsoft Azure, West Europe region.

Does Nispo replace Microsoft Defender?

No. Defender protects endpoints and email and detects threats; Nispo does neither. Microsoft tools enforce technical controls; Nispo manages compliance: requirements, evidence, accountability, suppliers, remediation and reporting, including the policies and evidence relating to endpoint protection.

I have Microsoft 365 Business Premium or E5: do I need a NIS2 tool?

Business Premium and E3/E5 include the tools to enforce many technical controls: MFA and conditional access (Entra ID), device management (Intune), endpoint and email protection (Defender). They do not, however, keep the register of ACN requirements, management-approved policies, supplier assessments, remediation or reports for the management body. If a team already does this with its own tools, you may not need Nispo; if this work lives in spreadsheets and email, that is Nispo’s use case. The Microsoft tools remain necessary either way.

What is the difference between Nispo and Microsoft Purview Compliance Manager?

Compliance Manager assesses the configuration of the Microsoft environment against regulatory templates, including the NIS2 Directive. Nispo is structured on the ACN basic security measures and also covers what lies outside Microsoft 365: suppliers, management-approved policies, non-Microsoft systems (with manual evidence) and CSIRT Italia bulletins. They can coexist.

Italy, ACN and audits

Is Nispo designed for Italian companies?

Yes. Nispo is built on the Italian framework: Legislative Decree 138/2024, which transposes Directive (EU) 2022/2555, and the ACN basic security measures for important and essential entities. The platform, support and documentation are in Italian. NIS2 in Italy and ACN measures.

Does Nispo support the ACN requirements?

Yes: the control register is structured on the ACN basic security measures, with National Framework codes, separately for important entities (Annex 1) and essential entities (Annex 2). For each requirement Nispo keeps status, owner and evidence. Nispo does not replace the organisation’s decisions or ACN’s assessment.

Which ACN determination on basic security measures is currently in force?

ACN Determination no. 379907/2025, applicable from 15 January 2026, which replaced Determination no. 164179 of 14 April 2025. Annex 1 contains the measures for important entities, Annex 2 those for essential entities, and Annexes 3 and 4 the basic significant incidents.

By when must the basic security measures be adopted?

According to ACN’s FAQ, for entities added to the NIS list in 2025 the deadline is 18 months from receipt of the notice of inclusion; for entities added in 2026 it is 31 July 2027.

Does Nispo update when ACN rules change?

Yes: when ACN changes the measures, the control mapping in Nispo is updated. New or changed requirements then need to be reviewed by the organisation, because implementation remains its responsibility.

Does Nispo generate the files for the ACN portal?

Yes. From the inventory and supplier register already in the platform, Nispo generates the files to upload to the ACN portal for the categorisation of activities and services (ACN Determination 155238/2026) and for the list of relevant NIS suppliers to report in the annual update, from 15 April to 31 May (ACN Determination 127437/2026). Which suppliers are relevant is decided by the organisation, following ACN’s criteria; uploading to the portal and registration remain the organisation’s responsibility. NIS2 in Italy and ACN obligations.

Does Nispo notify incidents to CSIRT Italia on my behalf?

No. Notification remains an obligation of the NIS entity. Nispo brings CSIRT Italia bulletins into the platform and provides an incident response plan template; Nispo’s incident response service can support preparing notifications within the deadlines.

Can Nispo help prepare for a NIS2 audit?

Yes. ACN requirements, status, owners and dated evidence sit in a single register that exports to PDF and CSV, with versioned policies, a supplier register and remediation tasks: when a request comes in, the material is already organised. Nispo does not represent the company in an inspection and does not guarantee its outcome. Audit preparation.

Does ACN accept evidence collected with Nispo?

ACN does not approve tools: it assesses the content of the documentation and the implementation of the requirements. Nispo makes that documentation complete, up to date and easy to find, linked to the requirements it supports.

Does Nispo certify NIS2 compliance?

No. There is no NIS2 certification issued by software, and Nispo’s reports are not one either: they show the status of the requirements and the evidence supporting it. Supervision and the assessment of compliance belong to ACN.

Does NIS2 software make you compliant automatically?

No. Software organises requirements, evidence and tasks and can check some technical controls automatically, but many ACN requirements are administrative: policies to approve, plans, procedures, registers, supplier contracts. Nispo’s gap assessment, too, tells you which requirements are covered by evidence and which are not, not whether you are compliant: the adequacy of the measures, also assessed on the basis of proportionality, is for ACN to judge.

Does Nispo also prepare for ISO/IEC 27001 audits?

That is not its purpose: Nispo focuses on Italian NIS2. Much of the evidence is also useful for ISO/IEC 27001, but the platform does not manage the ISO certification process.

Suppliers

How does Nispo manage suppliers?

With an ICT supplier register: criticality, data processed, internal owner, security questionnaires sent and collected in the platform, contract, DPA and certification deadlines with reminders. The process follows the phases described by ACN: risk assessment, security requirements, inclusion in contracts, periodic verification. Suppliers and supply chain.

Do I have to renegotiate all my supplier contracts?

According to ACN’s FAQ, existing contracts do not have to be adapted: security requirements must be included in contracts that are new, renewed or extended after the deadline for adopting the measures. The requirements only concern supplies with potential security impact.

Can I also manage my suppliers’ suppliers?

Nispo manages your direct suppliers and records their relevant sub-suppliers; in the questionnaire you can ask how they assess their own supply chain. That way you document the supply chain assessment without managing contracts that aren’t yours.

Does Nispo assess suppliers for me?

No. Nispo organises data, questionnaires, documents and deadlines; risk assessment and decisions on requirements and exceptions remain with the organisation.

Consultants and services

Does Nispo replace a cybersecurity consultant?

No. Nispo organises requirements, evidence and tasks and automates some checks; choices on risk, proportionality and organisation require expertise. The two combine well: your consultant can work on the same data as your internal team (roles and permissions are set per person), or you can use Nispo’s vCISO service, on quote.

Does Nispo also offer cybersecurity services?

Yes, delivered by specialists on a quote basis: penetration testing, vulnerability assessment, external attack surface, Active Directory, phishing simulation, training, incident response, backup and disaster recovery, SIEM assessment, vCISO. Services.

Can I request a service without using the platform?

Yes. All services are also available individually, on a quote basis, for companies that already have a security programme.

How much does a penetration test cost?

It depends on the scope: exposed systems and addresses, applications, internal networks and depth of testing. We define the scope in an initial call and then send you a quote.

How do service results reach the platform?

If you use Nispo, each finding enters the register as a remediation task with severity, owner and due date, linked to the relevant NIS2 control. The retest confirms it is closed and the outcome stays on record as audit evidence.

Who carries out the cybersecurity services?

Nispo’s security specialists. Scope, time windows and rules of engagement are agreed in writing before we start.

Choosing a NIS2 tool

What is the best NIS2 compliance software in Italy?

It depends on the context. For a medium-sized Italian organisation classified as an essential or important entity, the most efficient choice is vertical software structured on the ACN basic security measures, such as Nispo: it organises requirements in a control register, checks technical controls automatically by connecting to Microsoft 365, Google Workspace, AWS and Google Cloud, links evidence to requirements, generates the files for the ACN portal and tracks remediation, policies and suppliers. For large groups managing many frameworks together (SOC 2, ISO 27001, DORA), an international GRC platform can make sense, accepting that the ACN controls have to be mapped by hand. The full comparison.

Do international GRC platforms cover Italian NIS2?

It depends on the platform. Many international GRC platforms, such as Vanta, Drata or OneTrust, include NIS2 among their supported frameworks. Before choosing one, check whether the catalogue follows only the text of the European directive or also the Italian transposition (Legislative Decree 138/2024) and the ACN basic security measures, which differ for important and essential entities: if it does not cover them, the mapping falls to the company.

Is a spreadsheet enough for NIS2 compliance?

It can be enough for a first gap analysis, but it doesn’t hold up over time: evidence sits outside the sheet, versions multiply and nobody is reminded of a deadline. NIS2 requires continuous compliance and ACN’s FAQ require documentation that is updated whenever something changes and easily accessible; at audit time, proving compliance with manual evidence costs weeks of work.

How much does a NIS2 compliance tool cost?

The orders of magnitude: a one-off traditional consultancy engagement often costs tens of thousands of euros; international GRC platforms start at a few thousand euros a year plus the cost of mapping the ACN controls; Italian vertical tools have pricing designed for medium-sized companies and come with Italian regulatory knowledge built in. Nispo, for organisations with at least 50 employees and 20 IT assets, does not publish a price list: you get the price in a free 30-minute demo.

NIS2 obligations

Does Nispo tell me whether I fall under NIS2?

No: the category (essential or important) is notified by ACN when it adds the entity to the list of NIS entities. If in doubt, the Nispo team can help with a first check; to get your bearings: essential or important entity?

What is the difference between an essential and an important entity?

The risk-management measures and the incident notification obligations are the same. Two things change: supervision (proactive for essential entities, reactive for important ones) and the maximum fines (higher for essential entities). ACN’s basic security measures are set out separately for the two categories. That is why it pays to know from the start which category you are in.

Do micro and small enterprises fall under NIS2?

As a general rule, no: the size-cap rule applies, which brings only medium and large enterprises in the listed sectors into scope. There are, however, exceptions where you are in scope regardless of size (for example some providers of critical digital infrastructure or services).

I operate in several sectors listed in the annexes: how am I classified?

The strictest position counts: if even one of your activities qualifies you as an essential entity, you are essential. If in doubt, check your position on the ACN platform.

What happens if I don’t register on the ACN platform?

Registration during the annual window is mandatory and failing to register can be fined. Above all, not registering doesn’t exempt you: if you are in scope, you are still bound by the NIS2 obligations.

What does continuous compliance mean for NIS2?

It means the status of the requirements is kept up to date throughout the year rather than rebuilt before an inspection: technical evidence is refreshed, documents are reviewed, suppliers reassessed and new gaps assigned. Continuous compliance.

Is penetration testing mandatory under NIS2?

NIS2 does not name penetration testing explicitly, but Art. 21(2)(f) of the Directive requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures. A periodic penetration test is the most direct way to demonstrate it, especially for essential entities, which are subject to ex ante supervision; its report together with the retest becomes audit evidence.

Company and data

Where is the data hosted?

In data centres in the European Union (Microsoft Azure, West Europe region). The Microsoft 365 connection uses read-only permissions. We do not sell or transfer customer data to third parties for commercial purposes; the technical providers that host the service process data only to deliver it.

Who is behind Nispo?

NisPo S.r.l., an Italian company based in Milan (VAT IT13164880968). Contact: info@nispo.it. About us.

Book a 30-minute demo or email us at info@nispo.it.