NIS2 in Italy
What binds you in Italy is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.
Reviewed . Verify against the national official journal before relying on this for a filing.
National transposition
Decreto Legislativo 4 settembre 2024, n. 138
Published in the Gazzetta Ufficiale on 1 October 2024. It replaced the earlier 2018 NIS framework and confirms ACN as competent authority and single point of contact.
This is not the article you read in the directive
The decree sets the regime; the operative security measures live in binding ACN determinations, which can be updated without amending the decree. Entities had eighteen months from entry into force — to 18 April 2026 — to put the measures in place.
ACN inspections
ACN may begin inspections from October 2026.
ACN security measures and implementation guidelines — Determinazioni ACN under D.Lgs. 138/2024
by Agenzia per la Cybersicurezza Nazionale (ACN). Built on Article 21 of the directive as transposed by D.Lgs. 138/2024, detailed by binding ACN determinations.
A label is not compliance
There is no ACN label to hold and no certification to obtain: compliance is demonstrated to the authority, not certified by a third party. Because the measures live in determinations rather than in the decree itself, they can be updated without a change in the law — check the current determination, not a summary.
ACN measures in full — levels, controls and what it does not cover →
Who supervises you
ACN is the competent authority designated by Italy. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.
Incident notifications under article 23 normally go to CSIRT Italia, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.
What differs from the directive
Because NIS2 is a directive, Italy legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:
- Registration. The portal, the information required and the deadline are national.
- Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
- Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
- Reporting format. Deadlines are fixed by the directive; the form and the language are national.
If you operate in several member states
You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.