Italy NIS2 Transposition (Legislative Decree 138/2024)
Italian transposition supervised by the National Cybersecurity Agency (ACN); phased registration and obligations for essential and important entities through 2026.
| Jurisdiction | Italy |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Italy has transposed NIS2 via Legislative Decree 4 September 2024, n. 138, which entered into force in October 2024 and establishes a phased regime of registration, cybersecurity obligations, supervision and sanctions for essential and important entities under the responsibility of the Agenzia per la Cybersicurezza Nazionale (ACN).Gazzetta Ufficiale D.Lgs. 138/2024 Normattiva D.Lgs. 138/2024 ACN – Portale NIS2 / ACN Authority info via NIS2 status Italy
Below is a structured, compliance‑oriented analysis.
Key Requirements
1. Scope, definitions and classification of entities
- NIS2 is transposed by Legislative Decree 138/2024, which implements Directive (EU) 2022/2555 in Italy and replaces the previous NIS framework.Gazzetta Ufficiale D.Lgs. 138/2024 Normattiva D.Lgs. 138/2024 Directive (EU) 2022/2555 – EUR‑Lex
- The decree defines “soggetti essenziali” (essential entities) and “soggetti importanti” (important entities) and sets sectoral and size criteria largely aligned with Annexes I and II of NIS2.Normattiva D.Lgs. 138/2024 NIS2 Directive Annex I–II – EUR‑Lex Italy – EU NIS2 overview
- ACN is designated as the single competent NIS authority, single point of contact and host of the national CSIRT Italia, with supervisory and enforcement powers over essential and important entities.D.Lgs. 138/2024 – Gazzetta Ufficiale NIS2 status Italy – ACN role ACN institutional site
2. Registration and notification to the national NIS list
- The decree introduces mandatory registration of in‑scope entities with ACN via the official portal, with annual windows for registration.Italy – EU NIS2 overview ACN Portal (login) D.Lgs. 138/2024 – Gazzetta Ufficiale
- According to public guidance, entities must complete registration in the ACN portal between 1 January and 28 February of each year following entry into force.Italy – EU NIS2 overview NIS2 status Italy – timelines Agenda Digitale – NIS2 scadenze
- Entities are included in a national NIS list maintained by ACN, and ACN notifications trigger subsequent deadlines for security measures implementation.Confindustria NIS2 explanatory page ACN “specifiche di base” article Determination ACN 164179/2025 summary
3. Cybersecurity risk‑management and “misure di base”
- D.Lgs. 138/2024 mandates risk‑based technical, operational and organizational measures, aligned with the ten security areas and minimum requirements under NIS2.Normattiva D.Lgs. 138/2024 NIS2 Directive Art. 21 – security requirements NIS2 status Italy – ten areas of security measures
- ACN’s Determination n. 164179 of 14 April 2025 defines the “misure minime di sicurezza” / “specifiche di base” for essential and important entities, operationalizing Articles 23–24 of the decree.ACN Determina 164179/2025 summary Cybersecurity360 – ACN specifiche di base NIS2 DirettivaNIS2.eu – misure di base
- Important entities must implement 37 measures, articulated into 87 requirements, while essential entities must implement 43 measures with 116 requirements, as detailed in Allegato 1 and Allegato 2 of Determination 164179/2025.DirettivaNIS2.eu – 37/43 controls Aegister – 37/43 controlli ACN Confindustria – reference to Allegato 1/2
4. Incident reporting and CSIRT engagement
- The decree provides a structured incident notification process, including timelines and severity criteria, with reports to CSIRT Italia and ACN.Normattiva D.Lgs. 138/2024 NIS2 status Italy – incident notification process NIS2 Directive Art. 23–24 – reporting
- CSIRT Italia’s functions are expanded under the decree to include enhanced incident handling, early warnings and sectoral cooperation.NIS2 status Italy – CSIRT functions ACN – CSIRT Italia information D.Lgs. 138/2024 – Gazzetta Ufficiale
5. Governance and management body accountability
- The decree attributes specific responsibilities to the “organo di gestione” (management body) of in‑scope entities for approving and overseeing cybersecurity risk‑management measures.Normattiva D.Lgs. 138/2024 NIS2 Directive Art. 20 – management accountability Italy – EU NIS2 overview
- Management must receive regular training and can be held personally accountable in case of gross negligence or non‑compliance with the obligations set out in NIS2 and D.Lgs. 138/2024.NIS2 Directive Art. 20 Normattiva D.Lgs. 138/2024 LCAlex – compliance commentary
6. Supervision, sanctions and enforcement
- ACN is empowered with supervisory powers, including audits, inspections, requests for information and the ability to order remedial measures.Normattiva D.Lgs. 138/2024 Italy – EU NIS2 overview NIS2 Directive Chapter VII – supervision
- The decree introduces administrative sanctions consistent with NIS2, with higher maximum fines for essential entities than for important entities.Normattiva D.Lgs. 138/2024 NIS2 Directive Art. 31 – penalties LCAlex – sanctions overview
Compliance Challenges
1. Entity identification and scoping
- Organizations often struggle to determine whether they are within the NIS2 scope as essential or important entities, especially in complex groups and cross‑sector activities.Agenda Digitale – NIS2 guida pratica LCAlex – profiles of compliance JusTech – NIS2 cosa cambia
- Italian commentary highlights uncertainty until ACN notifications confirm inclusion in the national NIS list, delaying internal planning.Agenda Digitale – obligations timeline Confindustria NIS2 note NIS2 status Italy – phased approach
2. Complexity and breadth of ACN “misure di base”
- The 37/43 ACN controls and their 87/116 requirements represent a comprehensive security baseline, challenging especially for medium‑sized entities.DirettivaNIS2.eu – misure e requisiti Aegister – misure di base NIS2 Cybersecurity360 – specifiche di base NIS2
- Legal and industry analyses note significant alignment work needed with existing frameworks (ISO/IEC 27001, GDPR security, sectoral rules) to avoid duplication.LCAlex – profiles of compliance JusTech – overview and impacts OpenKritis – EU NIS2 Italy summary
3. Governance, accountability and board engagement
- NIS2’s management accountability requirements force boards and top management to take explicit responsibility for cybersecurity, which may require cultural change and new governance structures.NIS2 Directive Art. 20 Italy – EU NIS2 overview LCAlex – governance focus
- Industry guides indicate difficulty in establishing KPIs, reporting lines and risk appetite for NIS2‑level cyber risks.Agenda Digitale – guida per aziende Confindustria – NIS2 support DirettivaNIS2.eu – governance content
4. Incident management and reporting readiness
- Organizations face challenges in classifying incidents, meeting strict reporting timelines and integrating CSIRT notifications with internal processes.NIS2 Directive Art. 23–24 NIS2 status Italy – reporting scheme Agenda Digitale – incident obligations
- Case‑study style commentary from Italian legal and advisory firms emphasizes the need for playbooks and SOC integration to avoid non‑compliance during major incidents.LCAlex – incident obligations [JusTech – practical changes](https://justech.it/nis2-e-decreto-legislativo-138-2024
Recent developments
- — Whitepaper-style operational guide for NIS2 in Italy noting that **Legislative Decree 138/2024** extends rules to **18 sectors and over 80 types of public and private entities**, with practical guidance on risk management, governance, and incident-reporting processes; reflects industry concerns about the breadth of scope and the need for structured compliance programs.[6] (source)
- — Analysis of **Decree 138/2024 sanctions regime**, explaining ACN’s supervisory powers, the tiered penalty system (up to 10M EUR or 2% of worldwide turnover), and expanded scope across 11 highly critical and 7 other critical sectors, including public administration, waste management, medical devices, automotive, postal/courier, and ICT/B2B service providers; discusses expected enforcement focus and risk-based supervision.[4] (source)
- — Detailed 2026 country profile on “NIS2 Italy 2026: D.lgs. 138/2024, ACN Deadlines & Fines,” outlining implementation timelines, supervisory role of the National Cybersecurity Agency (ACN), fine ranges, and practical compliance milestones for essential and important entities; highlights phased introduction of obligations and sectoral coverage.[3] (source)
- — Overview update confirming that Italy has completed NIS2 transposition via **Legislative Decree 138/2024**, in force since 2024, summarizing scope, key obligations, and positioning Italy among the earliest EU states to finalize NIS2 implementation; includes recent clarifications on the decree’s application and deadlines.[1][3] (source)
- — Legal update summarizing how Decree 138/2024 replaces the previous NIS framework and introduces a broader, more stringent regime: clearer classification of **essential vs. important entities**, stronger management accountability, and structured incident reporting, with commentary on implications for boards and senior management in regulated sectors.[7] (source)
- — Consolidated official text of **D.Lgs. 138/2024 (Decreto NIS)** as currently in force, reflecting any technical or editorial updates since publication; used by practitioners to verify the latest binding provisions on cybersecurity measures, supervisory powers, and sanctioning rules for NIS2 entities in Italy.[5] (source)
- — Industry-focused article on the “Italian challenge” of NIS2 implementation, emphasizing strengthened cybersecurity obligations and **supply chain security**, the extended scope of the NIS2 Decree, and the practical impact on Italian companies’ vendor management and contractual practices.[8] (source)
- — Update on **key dates** for Italy’s NIS2 implementation, noting that Decree 138/2024 is in force since 16 October 2024 but that obligations are being **introduced gradually over 15 months**, with a timeline of when different categories of entities must meet risk-management, governance, and reporting requirements.[9] (source)
- — Cross-country NIS2 comparison page detailing Italy’s **NIS2 implementation law (D.Lgs. 138/2024)**, including dates of adoption, publication, and entry into force, and summarizing national specificities compared to other EU Member States; discusses how Italy’s approach to scope and supervision may influence regulatory expectations and industry compliance strategies.[12] (source)
- — Technical guide by a conformity assessment body describing the NIS2 Directive and its Italian transposition via Decree 138/2024, with focus on certification, audit, and assurance implications; highlights growing market demand for cybersecurity assessments and support services among newly in-scope entities.[13] (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Belgium NIS2 Transposition — Belgium, Active, effective 2024-10-18
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: NIS2 Compliance Policy (cyberpolicy.shop)
- Build it yourself: DORA + NIS2 EU Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates