Skip to content

NIS 2 IN ITALY

Decreto Legislativo 4 settembre 2024, n. 138 — the national act transposing Directive (EU) 2022/2555 in Italy. Supervised by Agenzia per la Cybersicurezza Nazionale (ACN).

TRANSPOSED — IN FORCE

Key facts

In force
16 October 2024
National law
Decreto Legislativo 4 settembre 2024, n. 138
Primary supervisor
Agenzia per la Cybersicurezza Nazionale (ACN)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Covered entities had until 28 February 2025 to register on the ACN portal for the first reporting cycle.

Scope and national nuance

Italy was one of the earliest member states to transpose, with D.lgs. 138/2024 entering into force on 16 October 2024 — one day before the directive's transposition deadline. ACN is the single national competent authority and operates the registration portal.

Sector supervisors

SectorAuthorityAcronym
Banking and financial market infrastructureBanca d'ItaliaBI
Electronic communicationsAutorità per le Garanzie nelle ComunicazioniAGCOM

What is specific to Italy

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to ACN’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →