NIS 2 — Italy
NIS 2 IN ITALY
Decreto Legislativo 4 settembre 2024, n. 138 — the national act transposing Directive (EU) 2022/2555 in Italy. Supervised by Agenzia per la Cybersicurezza Nazionale (ACN).
TRANSPOSED — IN FORCE
Key facts
In force
16 October 2024
National law
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities had until 28 February 2025 to register on the ACN portal for the first reporting cycle.
Scope and national nuance
Italy was one of the earliest member states to transpose, with D.lgs. 138/2024 entering into force on 16 October 2024 — one day before the directive's transposition deadline. ACN is the single national competent authority and operates the registration portal.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Banking and financial market infrastructure | Banca d'Italia | BI |
| Electronic communications | Autorità per le Garanzie nelle Comunicazioni | AGCOM |
What is specific to Italy
- Italy expanded the directive's sector list to include additional digital service providers under national discretion — D.lgs. 138/2024 covers some entities outside the directive's explicit eighteen sectors.
- ACN operates as a single national point of contact for registration, incident reporting and supervisory dialogue, with sector supervisors (Banca d'Italia, AGCOM) participating in joint oversight.
- Implementation is phased: registration and governance obligations applied first, with detailed technical security measures rolled out via implementing decrees through 2025-2026.
- Italy's CSIRT (CSIRT Italia) sits inside ACN — incident reports go through a single ACN portal rather than being routed to separate sector CSIRTs.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to ACN’s supervisory expectations.