The Italian NIS2 framework in brief: who decides, what is required and by when.
- In Italy NIS2 (Directive (EU) 2022/2555) is transposed by Legislative Decree 138/2024, in force since 16 October 2024. The competent authority is the National Cybersecurity Agency (ACN).
- The basic security measures are set by ACN Determination 379907/2025, applicable from 15 January 2026: Annex 1 for important entities, Annex 2 for essential entities.
- Every year: registration on the ACN portal (1 January – 28 February) and the update with relevant NIS suppliers (15 April – 31 May). Significant incidents are notified to CSIRT Italia within 24 hours, 72 hours and one month.
The legal framework
- Directive (EU) 2022/2555 (NIS2): European obligations on risk management, incident notification and supervision.
- Legislative Decree 138/2024: transposes it in Italy, in force since 16 October 2024.
- ACN: the NIS competent authority; CSIRT Italia, which receives incident notifications, operates within it.
- ACN determinations: the operational rules. For the basic measures, Determination 379907/2025 applies, replacing 164179/2025.
Who is in scope
NIS2 applies to entities in the listed sectors, generally from medium-sized enterprises upwards, with some exceptions regardless of size. Entities are essential or important: the baseline obligations are the same, supervision and fines differ. ACN notifies the category. To get your bearings: essential or important entity?
Obligations and deadlines
| Obligation | Reference | When |
|---|---|---|
| Approval and oversight of the measures by management bodies | Art. 23 Legislative Decree 138/2024 | Always |
| Basic security measures (Annex 1 or 2) | Art. 24; ACN Det. 379907/2025 | Added to the list in 2025: 18 months from the notice. Added in 2026: 31 July 2027 |
| Notification of significant incidents to CSIRT Italia | Art. 25 | Early warning within 24 hours, notification within 72 hours, final report within one month (for entities added in 2025, from 9 months after the notice) |
| Registration or update on the ACN portal | ACN portal | Every year, 1 January – 28 February |
| Annual update with the list of relevant NIS suppliers | ACN Det. 127437/2026 | Every year, 15 April – 31 May |
| Categorisation of activities and services | Art. 30; ACN Det. 155238/2026 | Already registered entities: 30 June 2026 |
The list of relevant suppliers includes name, tax code, country, CPV codes and relevance criterion; the categorisation assigns each activity a relevance level (high, medium, low, minimal) across 10 macro-areas. Deadlines depend on the notice received from ACN: always check the official FAQ.
The basic security measures
From ACN’s specifications and FAQ:
- each measure has a National Framework code (e.g. GV.SC-07) and administrative requirements (policies, plans, procedures, registers) or technical ones (encryption, updates, MFA);
- adopting them means implementing all applicable requirements, at least on the relevant systems;
- documentation must be updated whenever something changes and be easily accessible (which evidence you need);
- ACN does not mandate a risk analysis model: measures are scaled to context, risk and the criticality of services.
Suppliers
For supplies with a potential security impact ACN describes four phases: risk assessment (GV.SC-07), security requirements (GV.SC-01), requirements in new, renewed or extended contracts (GV.SC-05), periodic verification (GV.SC-07). Existing contracts do not have to be renegotiated. How Nispo handles it: suppliers and supply chain.
Supervision and fines
Essential entities are subject to ex ante and ex post supervision, important entities only to ex post supervision (for example after an incident). Maximum fines: €10 million or 2% of worldwide annual turnover for essential entities, €7 million or 1.4% for important entities, whichever is higher.
Where Nispo fits
Nispo structures the control register on the ACN measures, links evidence and owners, manages suppliers and remediation, prepares reports for management and generates the files for the ACN portal (categorisation and relevant suppliers) from the inventory and supplier register. Implementing the measures, decisions, incident notification and uploading to the portal remain with the organisation.
Official sources
- ACN – NIS, official page
- ACN – FAQ on security measures and incident notification
- Legislative Decree 138 of 4 September 2024 on Normattiva
- Directive (EU) 2022/2555 on EUR-Lex
- ACN Determination 127437/2026, relevant suppliers (Cyberness summary, Italian)
- ACN Determination 155238/2026, categorisation (PQA summary, Italian)
For information only, not legal advice, current as of the date shown: ACN determinations can change.
- Does Nispo support the ACN requirements?
- Which ACN determination on basic security measures is currently in force?
- By when must the basic security measures be adopted?
- Does Nispo generate the files for the ACN portal?
- Does Nispo certify NIS2 compliance?
- Does Nispo notify incidents to CSIRT Italia on my behalf?