NIS2
What is NIS2
NIS2 is EU Directive 2022/2555 on the security of network and information systems, transposed in Italy by Legislative Decree 138/2024, in force since 16 October 2024. It requires companies and public bodies in critical sectors, classified as essential or important entities, to register with the Italian National Cybersecurity Agency (ACN), adopt cyber risk management measures and notify significant incidents to CSIRT Italia.
October 2026: the deadline is now
- For entities added to the NIS list in 2025, the basic security measures must be in place by October 2026, 18 months after the ACN notice, and must be demonstrable with documented evidence.
- Notification of significant incidents has been mandatory since January 2026.
- Entities added to the list in 2026 have until 31 July 2027 for the measures, with incident notification from 1 January 2027.