Compliance and security

NIS2 compliance for SMEs in Italy: obligations, deadlines and how to comply

What Italian Legislative Decree 138/2024 requires, who is covered, the 2026-2027 deadlines and how ALAconnect helps companies adopt and document the security measures required by the Italian National Cybersecurity Agency (ACN).

NIS2

What is NIS2

NIS2 is EU Directive 2022/2555 on the security of network and information systems, transposed in Italy by Legislative Decree 138/2024, in force since 16 October 2024. It requires companies and public bodies in critical sectors, classified as essential or important entities, to register with the Italian National Cybersecurity Agency (ACN), adopt cyber risk management measures and notify significant incidents to CSIRT Italia.

October 2026: the deadline is now

  • For entities added to the NIS list in 2025, the basic security measures must be in place by October 2026, 18 months after the ACN notice, and must be demonstrable with documented evidence.
  • Notification of significant incidents has been mandatory since January 2026.
  • Entities added to the list in 2026 have until 31 July 2027 for the measures, with incident notification from 1 January 2027.

Who is covered

Who falls under NIS2

NIS2 applies by sector and size; many small companies are affected indirectly as suppliers.

01

Medium and large companies in NIS sectors

Companies with at least 50 employees or annual turnover or balance sheet above €10 million operating in the 18 sectors listed in the decree are covered, including energy, transport, health, water, digital infrastructure, managed ICT services, waste management and the manufacture of medical devices, machinery, electronics and food.

02

Entities covered regardless of size

Some entities are covered even if small, for example DNS service providers, domain name registries, trust service providers and public communication networks, as well as the public administrations identified by the decree.

03

Suppliers of NIS entities

Companies that are not NIS entities but supply goods or services to an essential or important entity are affected through supply chain security: clients ask for evidence of the measures adopted and may include them in contracts.

04

Essential and important entities

ACN classifies entities as essential or important by sector and size. Obligations are similar, but essential entities face broader measures and closer supervision.

Deadlines

NIS2 deadlines in Italy

Timeline for entities already listed and for those added from 2026.

WhenObligation
Every year, 1 January - 28 FebruaryRegistration of new entities on the ACN platform
Every year, by 31 MayAnnual update of information on the ACN platform, including relevant suppliers
From January 2026Notification of significant incidents to CSIRT Italia for entities listed in 2025
By October 2026Basic security measures adopted and documented for entities listed in 2025
From 1 January 2027Incident notification for entities added in 2026
By 31 July 2027Basic security measures for entities added in 2026

Obligations

What NIS2 requires from companies

The main obligations of Legislative Decree 138/2024 and ACN determinations.

01

Governance and accountability

Management bodies approve the risk management measures, oversee their implementation and are accountable for them; they must also take cybersecurity training.

02

Basic security measures

Risk analysis, asset inventory, vulnerability management, access control and multi-factor authentication, encryption, backup and business continuity, supply chain security and staff training, according to ACN specifications.

03

Incident notification

Significant incidents must be notified to CSIRT Italia with an early warning within 24 hours, a notification within 72 hours and a final report within one month. This requires system monitoring and an incident management procedure.

04

Penalties

For essential entities, fines reach up to €10 million or 2% of worldwide annual turnover; for important entities up to €7 million or 1.4%. Directors can be held liable for breaches.

How we help

The NIS2 compliance path with ALAconnect

ALAconnect handles the technical and organisational side of security; for legal aspects we work with your advisor or DPO.

  1. 01

    Check

    We establish whether the company is a NIS entity or a supplier of NIS entities, and which obligations apply.

  2. 02

    Gap analysis

    We compare systems and procedures with the ACN basic measures and define a prioritised compliance plan.

  3. 03

    Implementation

    We deliver the technical measures: firewalls, MFA, backup, monitoring, vulnerability management and incident procedure.

  4. 04

    Evidence

    We document controls and deadlines in the Privacy & Compliance Portal to demonstrate compliance.

Services

ALAconnect services for NIS2

The technical measures required by NIS2 match services ALAconnect already manages for its clients.

01

Monitoring and incident management

Security event monitoring with SIEM/XDR, to detect attacks in time and have the information needed to notify within 24 hours.

Cybersecurity

02

Network and access protection

Next-generation firewalls, network segmentation, VPNs, multi-factor authentication and endpoint protection.

Networking and perimeter security

03

Backup and business continuity

Encrypted and tested backups with regular restore tests and disaster recovery plans, as required by the basic measures.

Backup & Business Continuity

04

Documentation and controls

ACN basic measures checklists, deadline calendar, incident register with notification deadlines and dated technical evidence from monitoring.

Privacy & Compliance Portal

Many of these measures can be funded with the Cloud & Cybersecurity Voucher and hyper-depreciation 2026-2028: see Grants and funding.

FAQ

Frequently asked questions about NIS2

Short answers to the most common questions from SMEs.

How do I know if my company falls under NIS2?

Two elements must be checked: whether the activity falls within one of the sectors listed in the annexes of Legislative Decree 138/2024, and whether the company exceeds the medium-sized enterprise thresholds, that is at least 50 employees or more than €10 million in turnover or balance sheet. Some entities are covered regardless of size. If in doubt, a check with an advisor is recommended.

Does NIS2 affect me if I run a small company?

Often yes, indirectly. Small companies supplying goods or services to NIS entities fall within supply chain security: clients ask them to demonstrate the measures adopted, such as backup, multi-factor authentication and incident management, and may include them in contracts.

What is the deadline for NIS2 security measures?

For entities added to the NIS list in 2025, the basic security measures must be adopted by October 2026, 18 months after the ACN notice. For entities added in 2026, the deadline is 31 July 2027. Incident notification has been mandatory since January 2026 for the former and from 1 January 2027 for the latter.

How quickly must a cyber incident be notified?

A significant incident must be reported to CSIRT Italia with an early warning within 24 hours of becoming aware of it, a notification within 72 hours and a final report within one month. If the incident also involves personal data, notification to the Italian Data Protection Authority within 72 hours under the GDPR must be assessed in parallel.

Does ALAconnect certify NIS2 compliance?

No. There is no NIS2 compliance certification: responsibility lies with the company and its directors. ALAconnect helps implement the technical and organisational measures, keep them up to date and collect the evidence that demonstrates compliance in the event of an ACN inspection.

NIS2 compliance

Want to know where you stand on NIS2?

We start with a gap analysis against the ACN basic measures and tell you what is missing, in which order to act and at what cost.

Request a NIS2 gap analysis
Need support?