NIS2 Italy: D.lgs. 138/2024, Deadlines & the ACN Annual Cycle
Italy transposed the NIS2 Directive as Legislative Decree 138/2024, in force since 16 October 2024. Over 20,000 organisations are on the ACN list of NIS subjects. Unlike most member states, Italy runs compliance as a recurring annual cycle, and basic security measures fall due in October 2026.
Introduction: NIS2 Directive & the Italian context
Italy implemented the NIS2 Directive through Legislative Decree 138 of 4 September 2024, known in Italy as the decreto NIS. It was adopted under the mandate in the Legge di delegazione europea 2022-2023, and it has been in force since 16 October 2024 — one day before the EU transposition deadline, making Italy one of the earliest member states to complete transposition.
The Agenzia per la Cybersicurezza Nazionale (ACN) is the single national competent authority and the single point of contact, supported by nine ministries acting as sectoral authorities. What makes Italy unusual is not the law itself but how it is run: registration, information updates and categorisation all repeat on fixed annual windows, so compliance here is a cycle rather than a one-off.
What you must do in Italy
Italy phases obligations by the year you entered the list of NIS subjects. These are the duties that bind you, in order.
- Register on the ACN portal between 1 January and 28 February. Every year, not once. Registration is a self-assessment against the decree’s annexes — nobody designates you first. See Registration.
- Wait for ACN’s notice in April. ACN tells you whether you are in the list and whether you are an essential or an important entity. That notice starts your clock.
- Update your information between 15 April and 31 May. Contacts, senior officers, member states served, public IP ranges and domain names — and, since 2026, your list of relevant NIS suppliers.
- Declare your activities and services between 1 May and 30 June. The categorisation exercise that sets how much is proportionately expected of you.
- Notify significant incidents to CSIRT Italia. Live since January 2026 for entities listed in 2025. See Incident reporting.
- Have the basic security measures in place by October 2026 if you were listed in 2025, or by 31 July 2027 if you were first listed in 2026.
NIS2 Directive implementation in Italy
Italy implemented the NIS2 Directive through Legislative Decree No. 138 of 4 September 2024, adopted pursuant to Law No. 15 of 21 February 2024 (Legge di delegazione europea 2022-2023). The decree runs to 44 articles and 4 annexes, replaces the previous national NIS framework and substantially widens Italy’s cybersecurity perimeter.
It repeals and updates, in particular:
- Decreto Legislativo 65/2018, the NIS1 implementation, now repealed.
- Sectoral cybersecurity obligations coordinated with the Perimetro di Sicurezza Nazionale Cibernetica, which continues to exist as a separate and stricter regime for a small set of strategically critical operators.
Status
In force since 16 October 2024. Published in Gazzetta Ufficiale n. 230 of 1 October 2024, one day before the EU deadline of 17 October 2024.
Legislative basis
Law No. 15/2024 (European Delegation Law 2022-2023) delegated the transposition; Legislative Decree No. 138/2024 carried it out. ACN then filled in the detail through a series of binding determinations.
Scale
Over 30,000 organisations filed declarations in the first cycle. ACN identified more than 20,000 NIS subjects, over 5,000 of them essential entities. The 2026 list is of comparable size.
| Area | Italian note |
|---|---|
| Sectors covered | 18 sectors — 11 of high criticality and 7 others — spanning more than 80 types of entity, each classified as essential or important. |
| Public sector | A wide range of public administrations is in scope, listed in Annex III to the decree, coordinated with AgID and ACN guidance. |
| National Cybersecurity Perimeter | Operators inside the Perimetro di Sicurezza Nazionale Cibernetica remain subject to that separate, stricter regime as well as to the NIS obligations, both supervised by ACN. |
NIS2 Italy: what you need to know about compliance & certification
Italy follows NIS2’s structure of Essential Entities (EE) and Important Entities (IE), with additional obligations for operators within the National Cybersecurity Perimeter.
Scope criteria
- Operate in one of the sectors in Annex I or II of NIS2 (energy, transport, health, finance, digital infrastructure, etc.).
- Meet size thresholds (≥50 employees or ≥€10M turnover/balance sheet).
- Established in Italy or providing NIS2-relevant services on Italian territory.
- Possible inclusion regardless of size for high-criticality operators.
Obligations
- Risk management and cybersecurity policy (IT/OT).
- Incident reporting in strict timeframes.
- Business continuity and crisis management.
- Supply chain security and contractual controls.
- Access control, encryption, vulnerability handling.
- Board accountability and cybersecurity governance.
Standards & certification
Italy does not mandate compliance with a specific certification standard under NIS2, but recognised frameworks such as ISO/IEC 27001, NIST CSF and IEC 62443 (for industrial environments) are commonly used to structure and demonstrate compliance. Operators in the National Cybersecurity Perimeter are subject to enhanced technical and organisational requirements, including detailed assessments coordinated by ACN.
Registration: who, where, by when
Italy is the only member state that makes registration an annual obligation rather than a one-time filing. The window is the same every year: 1 January to 28 February.
Where
The ACN Services Portal at portale.acn.gov.it. The point of contact signs in with SPID or CIE, the Italian digital identity and electronic ID card. No foreign eID equivalent is offered, so an Italian representative normally has to hold the account.
How
Register the point of contact, link them to the organisation using its IPA code for public bodies or its tax code otherwise, then complete the NIS declaration in four parts: context, characterisation, type of entity and self-assessment.
What happens next
ACN and the sectoral authorities review the declarations, and in April each registered organisation is told, at its digital address, whether it is on the list of NIS subjects and whether it counts as essential or important. That notice starts your compliance clock.
Two further windows follow in the same year, and both are easy to miss because they are separate filings:
- 15 April – 31 May: information update. Administrative and contact data, board members and senior officers, the member states where you provide services, static public IP addresses and domain names. Since the 2026 cycle this also includes your list of relevant NIS suppliers — named, with tax code, country and CPV codes.
- 1 May – 30 June: categorisation. An inventory of your activities and services, mapped across ten macro-areas, from which ACN assigns each one a relevance level of minimum, low, medium or high. This is how proportionality is applied in Italy. The first cycle ran in 2026.
Incident reporting in Italy
Significant incidents go to CSIRT Italia, and the clock has three stages. It is the most operationally demanding part of the regime, because the first deadline is measured in hours.
ACN groups reportable incidents into four types:
- IS-1 and IS-2 — loss of confidentiality or integrity of data or systems.
- IS-3 — loss of availability of a service or system.
- IS-4 — unauthorised access or abuse of privileges.
Incident notification became mandatory in January 2026 for organisations listed in 2025 — nine months after their notice of inclusion. Organisations first listed in 2026 must designate their CSIRT contact by 31 December 2026 and begin notifying from 1 January 2027.
National NIS2 timeline & key dates (Italy)
Sector-specific requirements (Italy)
- Energy: alignment with ARERA and MASE requirements for critical operators. MASE, the Ministry of Environment and Energy Security, replaced the former MITE in 2022.
- Transport: aviation, rail, maritime and road operators under sectoral regulators.
- Digital infrastructure: data centers, CDN, cloud, IXPs, and managed service providers under NIS2 scope.
- Finance: the Ministry of Economy and Finance is the sectoral authority, working with Banca d’Italia and Consob. Where DORA applies, its rules take precedence as lex specialis.
- Health: hospitals, labs and health service operators monitored by the Ministry of Health.
How Italy differs from the NIS2 Directive
Italy did not simply restate the Directive. It built an administrative machine around it, and that machine is what you actually comply with.
- Compliance is annual, not once. Most member states ask you to register and then leave you alone. Italy reopens the declaration every 1 January, asks for an information update between 15 April and 31 May, and a categorisation of your activities between 1 May and 30 June. Three filings a year, every year.
- The security measures are prescriptive and counted. Where the Directive lists ten broad areas, ACN publishes a specific control set: 37 measures across 87 requirements for important entities, and 43 measures across 116 requirements for essential ones. They are built on the Italian National Framework for Cybersecurity and Data Protection. You are measured against a list, not a principle.
- Your deadline depends on the year you were listed. Obligations run 9 and 18 months from your own notice of inclusion, so organisations added in 2026 are on a different timetable from those added in 2025 — and organisations added in 2027 will be on another one again.
- Proportionality is assigned, not assumed. The categorisation model rates each of your activities and services at minimum, low, medium or high relevance. Your obligations scale to that rating rather than to your headcount alone.
- You must name your suppliers. Since 2026, entities report a list of relevant NIS suppliers to ACN, with tax code, country of establishment and CPV codes. Few member states collect supply-chain data at this granularity.
- One authority, not many. ACN is the single competent authority and single point of contact. The nine ministries support it; they do not supervise you in parallel.
- The Perimetro survives. Italy’s pre-existing national cybersecurity perimeter continues alongside NIS2, so a small number of strategically critical operators carry both sets of obligations.
Operating in more than one EU country?
If you are a DNS service provider, TLD name registry, cloud computing provider, data centre provider, content delivery network provider, managed service provider or managed security service provider, you answer to the regulator of the country where your main establishment sits — under Article 26 of the Directive, usually where decisions on cybersecurity risk management are taken. Not to every country you serve. If you have no establishment in the EU, you must designate a representative.
For those same entity types, Implementing Regulation (EU) 2024/2690 applies directly and is not transposed into national law, so the technical requirements read identically in Italy and in every other member state. Where it applies, it is the common denominator across your EU footprint.
Penalties for non-compliance
Italy applies the NIS2 ceilings, and adds a separate penalty for staying invisible:
- Essential entities: up to €10 million or 2% of worldwide annual turnover, whichever is higher.
- Important entities: up to €7 million or 1.4% of worldwide annual turnover, whichever is higher.
- Failure to register: an administrative fine of up to 0.1% of worldwide annual turnover. This one is charged for the omission itself, regardless of how good your security is.
ACN may also impose corrective measures, binding instructions, mandatory remediation and temporary suspension of activities. Operators inside the Perimetro di Sicurezza Nazionale Cibernetica face supervision under that regime in addition.
How to prepare for NIS2 in Italy
- Build the calendar first: put 1 January, 15 April, 1 May and your own October 2026 date in the compliance diary, with an owner against each.
- Gap-assess against the actual control set: not against the Directive, but against the 87 or 116 requirements in the ACN annex that applies to you.
- Strengthen governance: management bodies approve the risk measures and are accountable for them under Article 23.
- Map the supply chain: you will have to name your relevant suppliers to ACN, so identify them before the update window rather than during it.
- Rehearse the 24-hour clock: decide now who declares an incident significant, who files the pre-notification and who covers nights and weekends.
- Document and evidence: keep records of controls, assessments and remediation. From October 2026 ACN moves to verification, and verification means evidence.
Official links & resources
FAQ: NIS2 in Italy
Has Italy implemented the NIS2 Directive?
Who is the main authority for NIS2 in Italy?
Are operators in the National Cybersecurity Perimeter covered by NIS2?
When exactly must we register, and where?
What is the deadline for the security measures?
How quickly must we report an incident?
Will Italy follow NIS2 size thresholds?
Are we required to get ISO 27001 certified?
Sources & verification
Every date and figure on this page was checked against the Italian primary sources below on 2 August 2026. Public NIS2 trackers contradict each other, so we do not use them.
- Gazzetta Ufficiale n. 230, 1 October 2024 — the decree, its publication and its entry into force.
- ACN — Registration — the annual window, the portal, SPID and CIE, the four-part declaration, the April notice and the 0.1% penalty.
- ACN — Obligations — the 15 April to 31 May update window and the 9-month and 18-month clocks.
- ACN — Basic measures and specifications — Determination 379907/2025, the annexes for essential and important entities, and the measure and requirement counts.
- ACN — Categorisation — the 1 May to 30 June window, Determination 155238/2026, the ten macro-areas and four relevance levels.
- ACN determinations 127434/2026 and 127437/2026 of 13 April 2026 — the timetable for newly listed entities and the relevant-supplier list.
