Sembra che tu preferisca leggere in italiano.

Passa all'italiano
NIS2

NIS2: what it is, who it applies to, deadlines and requirements

Updated 19 August 2026·9 min read·Alberto Scarpa

NIS2 does not regulate a product: it regulates the organisation. It requires a broad audience of companies and administrations to manage cyber risk, to make top management accountable for it, and to notify significant incidents within tight deadlines. Those who build products meet it on a different level from the CRA, as an entity and not as a manufacturer. This guide gathers what the official sources provide, at European level and in the Italian transposition, on scope, deadlines and requirements, with precise references to the articles.

This guide reports the binding text of Directive (EU) 2022/2555, of Legislative Decree No 138/2024 and of the implementing determinations of the Italian National Cybersecurity Agency (ACN), with precise references. Where the relationship with other rules calls for an applied reading, the pointer is to the linked articles.

For how NIS2 sits against the CRA and DORA, the overall picture is in the guide NIS2, DORA and the CRA compared.

What NIS2 is

NIS2 is Directive (EU) 2022/2555, which as of 18 October 2024 repealed and replaced the first NIS directive of 2016. It is a directive, not a regulation: it sets common objectives but requires a national transposition law in each Member State. In Italy the transposition is Legislative Decree No 138 of 4 September 2024, in force since 16 October 2024.

Compared with NIS1, NIS2 changes three things substantially. It widens the scope: from the few “operators of essential services” to a much broader list of sectors and entities. It shifts responsibility to the top: the management bodies approve the measures and are accountable for them (Art. 20). It raises the penalties and harmonises the incident-notification obligations around precise deadlines (Arts. 21 and 23).

Who it applies to: essential and important entities

The scope of application is determined by two combined criteria (Art. 2 and Art. 3): the sector and the size.

On the sector, the directive distinguishes two annexes. Annex I lists the “highly critical” sectors: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management between businesses, public administration, space. Annex II lists “other critical sectors”: postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacturing (including medical devices, computer, electronic and optical products, electrical equipment, machinery and equipment, vehicles), digital providers, research.

On size, as a general rule the medium-sized enterprise threshold applies (from 50 employees, or more than EUR 10 million in turnover or balance-sheet total, under Recommendation 2003/361/EC). Below this threshold the entity generally remains out of scope, save for exceptions provided by the directive for certain types regardless of size.

From the combination of the two criteria comes the distinction between the two categories of entity (Art. 3):

  • Essential entities: in short, the large enterprises of the Annex I sectors (above the medium-sized enterprise thresholds), plus some types included regardless of size.
  • Important entities: the other entities of Annexes I and II that do not fall among the essential ones. In practice, the entities of Annex II, including manufacturing companies, fall in as important entities.

The difference between the two categories does not change the security requirements, which are the same, but it changes the supervision regime (proactive for the essential ones, ex post for the important ones) and the ceiling of the penalties.

The deadlines

The deadlines are read on two levels: the European calendar of the directive and the Italian calendar set by the decree and the ACN determinations.

At European level, the directive set the transposition deadline for Member States at 17 October 2024 (Art. 41) and required each State to establish the list of essential and important entities by 17 April 2025 (Art. 3(3)).

At Italian level, Legislative Decree 138/2024 builds a gradual path, managed through the ACN digital platform. The main steps:

  • Registration on the ACN platform. The entities within scope register in the annual window provided for by Art. 7. The first window was 1 January - 28 February 2025; the cycle repeats each year for new entities, with the windows set by ACN each time.
  • Notification of inclusion in the list. ACN notifies each entity of its inclusion in the list of essential or important entities. This notification starts the subsequent deadlines running.
  • Gradual nature of the obligations. From the notification of inclusion the deadlines to comply start running: the incident-notification obligations become operational within nine months, the baseline security measures within eighteen months.

Translated into dates for the entities included in the first round (2025): the incident-notification obligations are operational from 15 January 2026; the baseline security measures must be adopted by 31 October 2026. For entities included for the first time in 2026 the deadlines shift forward accordingly (notification from 2027, baseline measures during 2027), under the ACN determinations that set the calendar.

Obligation Deadline (entities included in 2025) Reference
Transposition of the directive (EU) 17 October 2024 Art. 41 dir. 2022/2555
National list of entities by 17 April 2025 Art. 3(3) dir. 2022/2555
First registration on the ACN platform 1 January - 28 February 2025 Art. 7 Legislative Decree 138/2024
Incident-notification obligations operational 15 January 2026 ACN determination, implementing Art. 25
Adoption of the baseline security measures 31 October 2026 ACN determination No 379907/2025

31 October 2026 also marks the shift from the accompaniment phase to the verification phase: from that moment ACN may open checks and inspections.

The requirements

The obligations group into four blocks: governance, risk management, incident notification, registration.

Governance (Art. 20)

The management bodies of essential and important entities approve the risk-management measures, oversee their implementation and are accountable for breaches (Art. 20(1)). The members of the management bodies must also follow periodic training, adequate to recognise the risks and to assess the management practices (Art. 20(2)). Responsibility for cybersecurity cannot be delegated in full to the IT function: it is an obligation that goes up to the top.

Risk-management measures (Art. 21)

The entities adopt technical, operational and organisational measures that are appropriate and proportionate to the risk, under an “all-hazards” approach. Art. 21(2) lists ten minimum categories of measures:

  • policies on risk analysis and information system security (point a);
  • incident handling (point b);
  • business continuity, backup management and disaster recovery, crisis management (point c);
  • supply-chain security, including the relationships with direct suppliers (point d);
  • security in the acquisition, development and maintenance of systems, including vulnerability handling and disclosure (point e);
  • policies and procedures to assess the effectiveness of the measures (point f);
  • basic cyber-hygiene practices and training (point g);
  • policies and procedures on the use of cryptography and, where appropriate, encryption (point h);
  • human-resources security, access control and asset management (point i);
  • multi-factor or continuous authentication, secure communications and secure emergency communication systems (point j).

In Italy, the concrete content of the baseline security measures is defined by ACN through its own determinations (most recently determination No 379907/2025), which break these categories down into specific requirements, differentiated for essential and important entities.

Incident notification (Art. 23)

The entities notify the national CSIRT, without undue delay, of any significant incident, that is, an incident that has caused or is capable of causing a serious operational disruption or financial loss, or that has repercussions on others. The notification is structured in three steps (Art. 23(4)):

  • Early warning, within 24 hours of becoming aware of the incident.
  • Incident notification, within 72 hours, with an initial assessment of severity, impact and, where available, the indicators of compromise.
  • Final report, within one month of the notification, with the detailed description, the cause and the mitigation measures applied.

In Italy, the competent CSIRT is CSIRT Italia at ACN, and the notification obligations are operational from 15 January 2026 for the entities of the first round.

Registration (Art. 27 dir.; Art. 7 Legislative Decree 138/2024)

The entities are required to register and to keep their data up to date on the platform of the competent authority. In Italy registration takes place on the ACN platform and also includes the designation of contact points and, in the subsequent windows, the communication of further information (for example the list of relevant suppliers).

Supervision and penalties

In Italy the competent national authority is ACN, which exercises differentiated supervisory powers: proactive on the essential entities (inspections, audits, requests for documents), predominantly ex post on the important entities (interventions following indications or reports). The verification and inspection phase opens from 31 October 2026.

The administrative penalties are set by Art. 38 of Legislative Decree 138/2024, in line with Art. 34 of the directive: for essential entities up to EUR 10 million or 2% of annual worldwide turnover, whichever is higher; for important entities up to EUR 7 million or 1.4% of annual worldwide turnover, whichever is higher. The directive also provides for measures that bear on the personal liability of top management.

Going deeper

For the specific case of those who manufacture devices and are subject both to the CRA (as a manufacturer) and to NIS2 (as a company), and to understand how much of the work done for the CRA also counts for the purposes of Art. 21, the blog article is You are a manufacturer subject to the CRA. Does NIS2 concern you as a company too?.


References: Directive (EU) 2022/2555 (NIS2), Articles 2, 3, 20, 21, 23, 27, 34 and 41 and Annexes I and II; Legislative Decree No 138 of 4 September 2024, Articles 7, 25 and 38; implementing determinations of the Italian National Cybersecurity Agency, including No 379907/2025 on the baseline security measures; Recommendation 2003/361/EC (definition of medium-sized enterprise). The article numbers of the directive and the decree are verified against the official texts; the dates and numbers of the ACN determinations are reconstructed from the acts and the Agency’s communications and should be confirmed against the specific act before any formal use.

Alberto Scarpa

AI · Cybersecurity · Regulation — I help industrial manufacturers integrate regulatory requirements into product decisions.

Not sure where to start?

45 free minutes to map your regulatory exposure — applied to your specific product.

Book the Regulatory Spark