NIS2 Country Guide

NIS2 Italy: D.lgs. 138/2024, Deadlines & the ACN Annual Cycle

Italy transposed the NIS2 Directive as Legislative Decree 138/2024, in force since 16 October 2024. Over 20,000 organisations are on the ACN list of NIS subjects. Unlike most member states, Italy runs compliance as a recurring annual cycle, and basic security measures fall due in October 2026.

In force: 16 Oct 2024 Law: D.lgs. 138/2024 Register: 1 Jan – 28 Feb, yearly Authority: ACN Last updated: 2 Aug 2026

Introduction: NIS2 Directive & the Italian context

Italy implemented the NIS2 Directive through Legislative Decree 138 of 4 September 2024, known in Italy as the decreto NIS. It was adopted under the mandate in the Legge di delegazione europea 2022-2023, and it has been in force since 16 October 2024 — one day before the EU transposition deadline, making Italy one of the earliest member states to complete transposition.

The Agenzia per la Cybersicurezza Nazionale (ACN) is the single national competent authority and the single point of contact, supported by nine ministries acting as sectoral authorities. What makes Italy unusual is not the law itself but how it is run: registration, information updates and categorisation all repeat on fixed annual windows, so compliance here is a cycle rather than a one-off.

Quick link: Read our overview “What is NIS2?” and “NIS vs NIS2” before exploring Italy’s implementation path.

What you must do in Italy

Italy phases obligations by the year you entered the list of NIS subjects. These are the duties that bind you, in order.

  1. Register on the ACN portal between 1 January and 28 February. Every year, not once. Registration is a self-assessment against the decree’s annexes — nobody designates you first. See Registration.
  2. Wait for ACN’s notice in April. ACN tells you whether you are in the list and whether you are an essential or an important entity. That notice starts your clock.
  3. Update your information between 15 April and 31 May. Contacts, senior officers, member states served, public IP ranges and domain names — and, since 2026, your list of relevant NIS suppliers.
  4. Declare your activities and services between 1 May and 30 June. The categorisation exercise that sets how much is proportionately expected of you.
  5. Notify significant incidents to CSIRT Italia. Live since January 2026 for entities listed in 2025. See Incident reporting.
  6. Have the basic security measures in place by October 2026 if you were listed in 2025, or by 31 July 2027 if you were first listed in 2026.
The binding date for most organisations is October 2026. It falls 18 months after the notice ACN sent you, so your exact date depends on when you were notified. This is also the point at which ACN has said it moves from supporting entities to verifying them.

NIS2 Directive implementation in Italy

Italy implemented the NIS2 Directive through Legislative Decree No. 138 of 4 September 2024, adopted pursuant to Law No. 15 of 21 February 2024 (Legge di delegazione europea 2022-2023). The decree runs to 44 articles and 4 annexes, replaces the previous national NIS framework and substantially widens Italy’s cybersecurity perimeter.

It repeals and updates, in particular:

  • Decreto Legislativo 65/2018, the NIS1 implementation, now repealed.
  • Sectoral cybersecurity obligations coordinated with the Perimetro di Sicurezza Nazionale Cibernetica, which continues to exist as a separate and stricter regime for a small set of strategically critical operators.

Status

In force since 16 October 2024. Published in Gazzetta Ufficiale n. 230 of 1 October 2024, one day before the EU deadline of 17 October 2024.

Legislative basis

Law No. 15/2024 (European Delegation Law 2022-2023) delegated the transposition; Legislative Decree No. 138/2024 carried it out. ACN then filled in the detail through a series of binding determinations.

Scale

Over 30,000 organisations filed declarations in the first cycle. ACN identified more than 20,000 NIS subjects, over 5,000 of them essential entities. The 2026 list is of comparable size.

AreaItalian note
Sectors covered 18 sectors — 11 of high criticality and 7 others — spanning more than 80 types of entity, each classified as essential or important.
Public sector A wide range of public administrations is in scope, listed in Annex III to the decree, coordinated with AgID and ACN guidance.
National Cybersecurity Perimeter Operators inside the Perimetro di Sicurezza Nazionale Cibernetica remain subject to that separate, stricter regime as well as to the NIS obligations, both supervised by ACN.

NIS2 Italy: what you need to know about compliance & certification

Italy follows NIS2’s structure of Essential Entities (EE) and Important Entities (IE), with additional obligations for operators within the National Cybersecurity Perimeter.

Scope criteria

  • Operate in one of the sectors in Annex I or II of NIS2 (energy, transport, health, finance, digital infrastructure, etc.).
  • Meet size thresholds (≥50 employees or ≥€10M turnover/balance sheet).
  • Established in Italy or providing NIS2-relevant services on Italian territory.
  • Possible inclusion regardless of size for high-criticality operators.

Obligations

  • Risk management and cybersecurity policy (IT/OT).
  • Incident reporting in strict timeframes.
  • Business continuity and crisis management.
  • Supply chain security and contractual controls.
  • Access control, encryption, vulnerability handling.
  • Board accountability and cybersecurity governance.

Standards & certification

Italy does not mandate compliance with a specific certification standard under NIS2, but recognised frameworks such as ISO/IEC 27001, NIST CSF and IEC 62443 (for industrial environments) are commonly used to structure and demonstrate compliance. Operators in the National Cybersecurity Perimeter are subject to enhanced technical and organisational requirements, including detailed assessments coordinated by ACN.

Competent authorities & CSIRT

Italy centralised NIS2 governance rather than splitting it by regulator. ACN is the single national competent authority and the single point of contact, and nine ministries act as sectoral authorities supporting it under Article 11 of the decree.

RoleAuthorityNotes
National NIS2 Authority ACN – Agenzia per la Cybersicurezza Nazionale Coordinates NIS2 implementation, issues guidelines, and supervises high-criticality sectors.
Sectoral authorities Nine ministries (Art. 11) They validate the list of NIS subjects for their sector, may propose further identifications and run the sectoral working tables. Among them: the Presidency of the Council for ICT services, space and public administration; the Ministry of Economy and Finance for banking and financial market infrastructure, with Banca d’Italia and Consob; MIMIT for digital infrastructure; and the Ministry of Health for health and medical devices.
National CSIRT CSIRT Italia (inside ACN) Receives every incident notification, coordinates response and alerts, and represents Italy in the EU CyCLONe network for cross-border crises.
Public administration Dipartimento per la Trasformazione Digitale & AgID (supporting) Coordinate digital security guidance for public sector bodies, which register through their IPA code.

Registration: who, where, by when

Italy is the only member state that makes registration an annual obligation rather than a one-time filing. The window is the same every year: 1 January to 28 February.

Where

The ACN Services Portal at portale.acn.gov.it. The point of contact signs in with SPID or CIE, the Italian digital identity and electronic ID card. No foreign eID equivalent is offered, so an Italian representative normally has to hold the account.

How

Register the point of contact, link them to the organisation using its IPA code for public bodies or its tax code otherwise, then complete the NIS declaration in four parts: context, characterisation, type of entity and self-assessment.

What happens next

ACN and the sectoral authorities review the declarations, and in April each registered organisation is told, at its digital address, whether it is on the list of NIS subjects and whether it counts as essential or important. That notice starts your compliance clock.

Registering is a self-assessment, and failing to do it is itself an offence. Nobody writes to tell you that you should have registered. Missing the window carries an administrative fine of up to 0.1% of worldwide annual turnover.

Two further windows follow in the same year, and both are easy to miss because they are separate filings:

  • 15 April – 31 May: information update. Administrative and contact data, board members and senior officers, the member states where you provide services, static public IP addresses and domain names. Since the 2026 cycle this also includes your list of relevant NIS suppliers — named, with tax code, country and CPV codes.
  • 1 May – 30 June: categorisation. An inventory of your activities and services, mapped across ten macro-areas, from which ACN assigns each one a relevance level of minimum, low, medium or high. This is how proportionality is applied in Italy. The first cycle ran in 2026.

Incident reporting in Italy

Significant incidents go to CSIRT Italia, and the clock has three stages. It is the most operationally demanding part of the regime, because the first deadline is measured in hours.

Within 24 hourspre-notifica. A short pre-notification giving CSIRT Italia enough to place the incident in context. The clock starts when you hold objective evidence that one of the defined incident types has occurred.
Within 72 hoursnotifica. The full notification, with the information gathered since, plus an initial assessment of severity and impact.
Within one monthrelazione finale. A detailed account: what happened, the threat type or root cause, mitigations applied and still running, and any cross-border impact. If the incident is still open, monthly progress reports are filed instead, and the final report is due a month after closure.

ACN groups reportable incidents into four types:

  • IS-1 and IS-2 — loss of confidentiality or integrity of data or systems.
  • IS-3 — loss of availability of a service or system.
  • IS-4 — unauthorised access or abuse of privileges.
The cause is irrelevant. A flood, a hardware failure and a ransomware crew all trigger the same duty if the effect meets the threshold. And in a supply relationship the duty can fall on both sides: if a provider’s systems are hit, the provider notifies, and the customer notifies too where its own regulated services are affected.

Incident notification became mandatory in January 2026 for organisations listed in 2025 — nine months after their notice of inclusion. Organisations first listed in 2026 must designate their CSIRT contact by 31 December 2026 and begin notifying from 1 January 2027.

National NIS2 timeline & key dates (Italy)

27 Dec 2022 — NIS2 Directive published in the Official Journal of the EU.
21 Feb 2024 — Law 15/2024, the European delegation law, empowers the government to transpose NIS2.
4 Sep 2024 — Decreto Legislativo 4 settembre 2024, n. 138 is adopted.
1 Oct 2024 — Published in Gazzetta Ufficiale n. 230.
16 Oct 2024The decree enters into force, repealing D.lgs. 65/2018.
17 Oct 2024 — EU transposition deadline for all member states. Italy met it with a day to spare.
17 Jan 2025 — Registration deadline for cloud, data centre, managed service and online platform providers under Art. 42(1)(a).
28 Feb 2025 — First registration window closes. Over 30,000 organisations have filed declarations.
Apr 2025 — ACN notifies inclusion in the list of NIS subjects: more than 20,000 organisations, over 5,000 of them essential entities.
14 Apr 2025 — Determination 164179/2025 sets out the basic security measures.
Dec 2025 — Determination 379907/2025 updates and consolidates the basic specifications and the notification arrangements.
Jan 2026 — Incident notification becomes mandatory for organisations listed in 2025.
13 Apr 2026 — Determinations 127434/2026 and 127437/2026 set the timetable for newly listed organisations and add the relevant-supplier list.
1 May – 30 Jun 2026 — First categorisation cycle, under Determination 155238/2026.
October 2026Basic security measures fall due for organisations listed in 2025, 18 months after their notice of inclusion.
31 Dec 2026 — Organisations first listed in 2026 must have designated their CSIRT contact.
1 Jan 2027 — Incident notification begins for organisations first listed in 2026.
31 Jul 2027 — Basic security measures fall due for organisations first listed in 2026.

Sector-specific requirements (Italy)

  • Energy: alignment with ARERA and MASE requirements for critical operators. MASE, the Ministry of Environment and Energy Security, replaced the former MITE in 2022.
  • Transport: aviation, rail, maritime and road operators under sectoral regulators.
  • Digital infrastructure: data centers, CDN, cloud, IXPs, and managed service providers under NIS2 scope.
  • Finance: the Ministry of Economy and Finance is the sectoral authority, working with Banca d’Italia and Consob. Where DORA applies, its rules take precedence as lex specialis.
  • Health: hospitals, labs and health service operators monitored by the Ministry of Health.

How Italy differs from the NIS2 Directive

Italy did not simply restate the Directive. It built an administrative machine around it, and that machine is what you actually comply with.

  • Compliance is annual, not once. Most member states ask you to register and then leave you alone. Italy reopens the declaration every 1 January, asks for an information update between 15 April and 31 May, and a categorisation of your activities between 1 May and 30 June. Three filings a year, every year.
  • The security measures are prescriptive and counted. Where the Directive lists ten broad areas, ACN publishes a specific control set: 37 measures across 87 requirements for important entities, and 43 measures across 116 requirements for essential ones. They are built on the Italian National Framework for Cybersecurity and Data Protection. You are measured against a list, not a principle.
  • Your deadline depends on the year you were listed. Obligations run 9 and 18 months from your own notice of inclusion, so organisations added in 2026 are on a different timetable from those added in 2025 — and organisations added in 2027 will be on another one again.
  • Proportionality is assigned, not assumed. The categorisation model rates each of your activities and services at minimum, low, medium or high relevance. Your obligations scale to that rating rather than to your headcount alone.
  • You must name your suppliers. Since 2026, entities report a list of relevant NIS suppliers to ACN, with tax code, country of establishment and CPV codes. Few member states collect supply-chain data at this granularity.
  • One authority, not many. ACN is the single competent authority and single point of contact. The nine ministries support it; they do not supervise you in parallel.
  • The Perimetro survives. Italy’s pre-existing national cybersecurity perimeter continues alongside NIS2, so a small number of strategically critical operators carry both sets of obligations.
The practical consequence: a compliance calendar matters more in Italy than almost anywhere else in the EU. Most of what goes wrong here is a missed window, not a failed control.

Operating in more than one EU country?

If you are a DNS service provider, TLD name registry, cloud computing provider, data centre provider, content delivery network provider, managed service provider or managed security service provider, you answer to the regulator of the country where your main establishment sits — under Article 26 of the Directive, usually where decisions on cybersecurity risk management are taken. Not to every country you serve. If you have no establishment in the EU, you must designate a representative.

For those same entity types, Implementing Regulation (EU) 2024/2690 applies directly and is not transposed into national law, so the technical requirements read identically in Italy and in every other member state. Where it applies, it is the common denominator across your EU footprint.

Everyone else registers in each member state where they are established. Also in scope elsewhere? See our guides for Germany, Spain and France, or the full country index.

Penalties for non-compliance

Italy applies the NIS2 ceilings, and adds a separate penalty for staying invisible:

  • Essential entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
  • Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
  • Failure to register: an administrative fine of up to 0.1% of worldwide annual turnover. This one is charged for the omission itself, regardless of how good your security is.

ACN may also impose corrective measures, binding instructions, mandatory remediation and temporary suspension of activities. Operators inside the Perimetro di Sicurezza Nazionale Cibernetica face supervision under that regime in addition.

No NIS fines have been published in Italy so far. ACN has described the period up to October 2026 as a phase of accompanying entities rather than inspecting them, with formal verification following once the security measures fall due. Absence of enforcement to date is not evidence that it will stay that way.

How to prepare for NIS2 in Italy

  1. Build the calendar first: put 1 January, 15 April, 1 May and your own October 2026 date in the compliance diary, with an owner against each.
  2. Gap-assess against the actual control set: not against the Directive, but against the 87 or 116 requirements in the ACN annex that applies to you.
  3. Strengthen governance: management bodies approve the risk measures and are accountable for them under Article 23.
  4. Map the supply chain: you will have to name your relevant suppliers to ACN, so identify them before the update window rather than during it.
  5. Rehearse the 24-hour clock: decide now who declares an incident significant, who files the pre-notification and who covers nights and weekends.
  6. Document and evidence: keep records of controls, assessments and remediation. From October 2026 ACN moves to verification, and verification means evidence.

Official links & resources

Looking for the decree in English? There is no official English translation. The authoritative text is the Italian original, Decreto Legislativo 4 settembre 2024, n. 138. ACN publishes much of its NIS guidance in English, but the determinations and their annexes — the documents that contain the actual control requirements — are issued in Italian only. English summaries, including this page, are guidance. Where an obligation matters, work from the Italian text.

FAQ: NIS2 in Italy

Has Italy implemented the NIS2 Directive?
Yes. Legislative Decree No. 138 of 4 September 2024 was published in Gazzetta Ufficiale n. 230 on 1 October 2024 and entered into force on 16 October 2024, a day before the EU deadline. Italy was one of the first member states to transpose NIS2.
Who is the main authority for NIS2 in Italy?
ACN (Agenzia per la Cybersicurezza Nazionale) is the single national competent authority and the single point of contact. Nine ministries act as sectoral authorities supporting it, and CSIRT Italia, which sits inside ACN, receives incident notifications.
Are operators in the National Cybersecurity Perimeter covered by NIS2?
Yes, and the two regimes run in parallel. The Perimetro di Sicurezza Nazionale Cibernetica was not absorbed into the NIS decree, so operators inside it carry both sets of obligations, with ACN supervising each.
When exactly must we register, and where?
Between 1 January and 28 February, on the ACN Services Portal at portale.acn.gov.it, signing in with SPID or CIE. It repeats every year — this is not a one-off registration — and failing to register carries a fine of up to 0.1% of worldwide annual turnover.
What is the deadline for the security measures?
18 months from the date ACN notified you that you were on the list of NIS subjects. For the organisations notified in April 2025 that falls in October 2026. Organisations first listed in 2026 have until 31 July 2027. Check your own notice: your date is personal to you.
How quickly must we report an incident?
A pre-notification to CSIRT Italia within 24 hours, the full notification within 72 hours, and a final report within one month. If the incident is still open at that point, you file monthly progress reports and the final report a month after closure.
Will Italy follow NIS2 size thresholds?
Yes. Italy applies the NIS2 size-based model (generally medium-sized and above - ≥50 employees or ≥€10 million turnover or balance sheet total), with specific provisions allowing inclusion of entities regardless of size where they are considered critical.
Are we required to get ISO 27001 certified?
No. Italy mandates no certification. What it does mandate is a specific control set: the basic security measures in the ACN determination, which run to 87 requirements for important entities and 116 for essential ones. ISO/IEC 27001 is a useful way to organise the work, but it is your mapping to the ACN requirements that will be assessed.

Sources & verification

Every date and figure on this page was checked against the Italian primary sources below on 2 August 2026. Public NIS2 trackers contradict each other, so we do not use them.

  • Gazzetta Ufficiale n. 230, 1 October 2024 — the decree, its publication and its entry into force.
  • ACN — Registration — the annual window, the portal, SPID and CIE, the four-part declaration, the April notice and the 0.1% penalty.
  • ACN — Obligations — the 15 April to 31 May update window and the 9-month and 18-month clocks.
  • ACN — Basic measures and specifications — Determination 379907/2025, the annexes for essential and important entities, and the measure and requirement counts.
  • ACN — Categorisation — the 1 May to 30 June window, Determination 155238/2026, the ten macro-areas and four relevance levels.
  • ACN determinations 127434/2026 and 127437/2026 of 13 April 2026 — the timetable for newly listed entities and the relevant-supplier list.
Two things we deliberately do not state. Several Italian advisories give “31 October 2026” as the security-measures deadline. ACN defines it as 18 months from your own notice of inclusion, which lands in October 2026 but is not a single national date, so we describe the rule instead. And we give December 2025 for Determination 379907/2025 rather than a specific day, because sources disagree on it.
General guidance, not legal advice. Italian NIS obligations change with each ACN determination — check the primary sources listed above before acting on a deadline.