The Italian NIS2 framework in brief: who decides, what is required and by when.

Key facts
  • In Italy NIS2 (Directive (EU) 2022/2555) is transposed by Legislative Decree 138/2024, in force since 16 October 2024. The competent authority is the National Cybersecurity Agency (ACN).
  • The basic security measures are set by ACN Determination 379907/2025, applicable from 15 January 2026: Annex 1 for important entities, Annex 2 for essential entities.
  • Every year: registration on the ACN portal (1 January – 28 February) and the update with relevant NIS suppliers (15 April – 31 May). Significant incidents are notified to CSIRT Italia within 24 hours, 72 hours and one month.
  • Directive (EU) 2022/2555 (NIS2): European obligations on risk management, incident notification and supervision.
  • Legislative Decree 138/2024: transposes it in Italy, in force since 16 October 2024.
  • ACN: the NIS competent authority; CSIRT Italia, which receives incident notifications, operates within it.
  • ACN determinations: the operational rules. For the basic measures, Determination 379907/2025 applies, replacing 164179/2025.

Who is in scope

NIS2 applies to entities in the listed sectors, generally from medium-sized enterprises upwards, with some exceptions regardless of size. Entities are essential or important: the baseline obligations are the same, supervision and fines differ. ACN notifies the category. To get your bearings: essential or important entity?

Obligations and deadlines

ObligationReferenceWhen
Approval and oversight of the measures by management bodiesArt. 23 Legislative Decree 138/2024Always
Basic security measures (Annex 1 or 2)Art. 24; ACN Det. 379907/2025Added to the list in 2025: 18 months from the notice. Added in 2026: 31 July 2027
Notification of significant incidents to CSIRT ItaliaArt. 25Early warning within 24 hours, notification within 72 hours, final report within one month (for entities added in 2025, from 9 months after the notice)
Registration or update on the ACN portalACN portalEvery year, 1 January – 28 February
Annual update with the list of relevant NIS suppliersACN Det. 127437/2026Every year, 15 April – 31 May
Categorisation of activities and servicesArt. 30; ACN Det. 155238/2026Already registered entities: 30 June 2026

The list of relevant suppliers includes name, tax code, country, CPV codes and relevance criterion; the categorisation assigns each activity a relevance level (high, medium, low, minimal) across 10 macro-areas. Deadlines depend on the notice received from ACN: always check the official FAQ.

The basic security measures

From ACN’s specifications and FAQ:

  • each measure has a National Framework code (e.g. GV.SC-07) and administrative requirements (policies, plans, procedures, registers) or technical ones (encryption, updates, MFA);
  • adopting them means implementing all applicable requirements, at least on the relevant systems;
  • documentation must be updated whenever something changes and be easily accessible (which evidence you need);
  • ACN does not mandate a risk analysis model: measures are scaled to context, risk and the criticality of services.

Suppliers

For supplies with a potential security impact ACN describes four phases: risk assessment (GV.SC-07), security requirements (GV.SC-01), requirements in new, renewed or extended contracts (GV.SC-05), periodic verification (GV.SC-07). Existing contracts do not have to be renegotiated. How Nispo handles it: suppliers and supply chain.

Supervision and fines

Essential entities are subject to ex ante and ex post supervision, important entities only to ex post supervision (for example after an incident). Maximum fines: €10 million or 2% of worldwide annual turnover for essential entities, €7 million or 1.4% for important entities, whichever is higher.

Where Nispo fits

Nispo structures the control register on the ACN measures, links evidence and owners, manages suppliers and remediation, prepares reports for management and generates the files for the ACN portal (categorisation and relevant suppliers) from the inventory and supplier register. Implementing the measures, decisions, incident notification and uploading to the portal remain with the organisation.

Official sources

For information only, not legal advice, current as of the date shown: ACN determinations can change.

A 30-minute demo: we connect your systems (Microsoft 365, Google Workspace, AWS or Google Cloud) and show you your real controls, evidence and gaps.