What NIS2 compliance software must do for an organisation subject to Legislative Decree 138/2024, and how Nispo does it.
- Nispo is an Italian NIS2 compliance management platform, built on Legislative Decree 138/2024 and the ACN basic security measures.
- It organises requirements, evidence, accountability, suppliers and remediation, and checks technical controls automatically on Microsoft 365, Google Workspace, AWS and Google Cloud.
- It does not replace the tools that enforce controls (MFA, endpoint protection, backup) or a multi-framework platform (ISO/IEC 27001, SOC 2, DORA).
What NIS2 requires of an Italian company
In Italy NIS2 is transposed by Legislative Decree 138/2024. For an important or essential entity there are four obligations:
- Management bodies (Art. 23): approve the security measures and are accountable for them.
- Risk-management measures (Art. 24): the ACN basic security measures, with administrative and technical requirements.
- Incident notification to CSIRT Italia (Art. 25): within 24 hours, 72 hours and one month.
- ACN portal obligations: registration, the annual update with relevant suppliers, categorisation of activities and services.
The hard part is not reading the requirements but keeping them linked to owners, proof and the real state of your systems, year after year. Details and deadlines: NIS2 in Italy and ACN measures.
What NIS2 software must do, and how Nispo does it
| Must | How Nispo does it |
|---|---|
| Follow the ACN measures, not just the directive | Control register with National Framework codes, for the entity’s category |
| Check automatically what can be checked | Integrations with Microsoft 365 / Entra ID (read-only), Google Workspace, AWS and Google Cloud |
| Link evidence to controls | Every piece of evidence has a date, source and owner |
| Turn gaps into tasks | Actions with owner, due date and closure check |
| Manage suppliers | Register with criticality, questionnaires and deadlines |
| Inform management | Dashboard and reports, PDF and CSV export |
| Prepare the ACN portal | Files for categorisation and for the list of relevant suppliers |
| Last over time | Repeated checks, reminders, review statuses |
How you work in Nispo
An illustrative example: a 180-employee company, an important entity, using Microsoft 365.
- Set up category, scope and the people involved: IT and your consultant work on the same data.
- Connect Microsoft 365 read-only: Nispo checks, for example, admin MFA and imports users and devices.
- Complete the rest with documents, policy templates and evidence linked to controls.
- See the gaps: three admins without MFA, an unapproved business continuity plan, a critical supplier without a questionnaire.
- Assign each gap an owner and a due date; the next check records the closure.
- Report to management and stay current: repeated checks, reminders, CSIRT Italia bulletins.
Who it is for, and what it does not do
Nispo is designed for Italian organisations subject to NIS2 with at least 50 employees and 20 IT assets (a commercial threshold, not the applicability criterion), without a large compliance team.
It does not decide whether you fall under NIS2, does not certify compliance and does not enforce technical controls: what is automated and what is not is described on the Platform and features page. If you need a multi-framework platform or a protection tool (EDR, SIEM), see the NIS2 solutions comparison.