NIS2 is the European directive on the security of network and information systems (Directive (EU) 2022/2555), which each member state transposes into its own law, with its own deadlines. In Italy that law is Legislative Decree 138/2024, in force since 16 October 2024: it covers medium and large companies in the sectors listed in its annexes, and some entities regardless of size. Companies outside its scope often meet it anyway, as suppliers to an entity in scope.
For organisations in Italy listed as NIS entities in 2025, the national cybersecurity agency (ACN, determination 379907 of 19 December 2025) sets two deadlines:
- Notification of significant incidents to CSIRT Italia, from the ninth month after the notice of inclusion: a pre-notification no later than 24 hours after discovery, a full notification no later than 72 hours.
- Basic security measures, applied no later than eighteen months after the same notice.
The Italian decree also requires management bodies to follow cyber security training and to promote it among staff. Tested backup and restore, patch and vulnerability management, incident detection and training relate to these measures: our services help you meet them and document them, while compliance remains the responsibility of your organisation.