What NIS2 compliance software must do for an organisation subject to Legislative Decree 138/2024, and how Nispo does it.

Key facts
  • Nispo is an Italian NIS2 compliance management platform, built on Legislative Decree 138/2024 and the ACN basic security measures.
  • It organises requirements, evidence, accountability, suppliers and remediation, and checks technical controls automatically on Microsoft 365, Google Workspace, AWS and Google Cloud.
  • It does not replace the tools that enforce controls (MFA, endpoint protection, backup) or a multi-framework platform (ISO/IEC 27001, SOC 2, DORA).

What NIS2 requires of an Italian company

In Italy NIS2 is transposed by Legislative Decree 138/2024. For an important or essential entity there are four obligations:

  • Management bodies (Art. 23): approve the security measures and are accountable for them.
  • Risk-management measures (Art. 24): the ACN basic security measures, with administrative and technical requirements.
  • Incident notification to CSIRT Italia (Art. 25): within 24 hours, 72 hours and one month.
  • ACN portal obligations: registration, the annual update with relevant suppliers, categorisation of activities and services.

The hard part is not reading the requirements but keeping them linked to owners, proof and the real state of your systems, year after year. Details and deadlines: NIS2 in Italy and ACN measures.

What NIS2 software must do, and how Nispo does it

MustHow Nispo does it
Follow the ACN measures, not just the directiveControl register with National Framework codes, for the entity’s category
Check automatically what can be checkedIntegrations with Microsoft 365 / Entra ID (read-only), Google Workspace, AWS and Google Cloud
Link evidence to controlsEvery piece of evidence has a date, source and owner
Turn gaps into tasksActions with owner, due date and closure check
Manage suppliersRegister with criticality, questionnaires and deadlines
Inform managementDashboard and reports, PDF and CSV export
Prepare the ACN portalFiles for categorisation and for the list of relevant suppliers
Last over timeRepeated checks, reminders, review statuses

How you work in Nispo

An illustrative example: a 180-employee company, an important entity, using Microsoft 365.

  1. Set up category, scope and the people involved: IT and your consultant work on the same data.
  2. Connect Microsoft 365 read-only: Nispo checks, for example, admin MFA and imports users and devices.
  3. Complete the rest with documents, policy templates and evidence linked to controls.
  4. See the gaps: three admins without MFA, an unapproved business continuity plan, a critical supplier without a questionnaire.
  5. Assign each gap an owner and a due date; the next check records the closure.
  6. Report to management and stay current: repeated checks, reminders, CSIRT Italia bulletins.

Who it is for, and what it does not do

Nispo is designed for Italian organisations subject to NIS2 with at least 50 employees and 20 IT assets (a commercial threshold, not the applicability criterion), without a large compliance team.

It does not decide whether you fall under NIS2, does not certify compliance and does not enforce technical controls: what is automated and what is not is described on the Platform and features page. If you need a multi-framework platform or a protection tool (EDR, SIEM), see the NIS2 solutions comparison.

A 30-minute demo: we connect your systems (Microsoft 365, Google Workspace, AWS or Google Cloud) and show you your real controls, evidence and gaps.