Check in 60 seconds whether NIS2 applies to you
NIS2 compliance in Italy — clarity in three minutes
The NIS2 Directive (EU) 2022/2555 and the Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2) impose obligations on thousands of companies in Italy. Check for free whether and how it applies to you — and what you need to do next.
Start the test — enter your details
The result with reasoning is shown immediately after answering. We use your details only for providing the NIS2 service.
Ask the NIS2 assistant A free expert assistant answers your questions about the Directive and Decreto NIS2.
Take the free gap assessment 20 questions on the Article 21(2) measures — see instantly where the gaps are.
Free surface scan — your domain's security picture in one minute
What is NIS2 and who does it affect in Italy?
NIS2 is the European Union cybersecurity directive (EU) 2022/2555, transposed in Italy by the Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2). It significantly widens the scope of obligations: energy, transport, healthcare, digital infrastructure, manufacturing, food industry and many other sectors must implement risk management measures and report incidents to the Agenzia per la Cybersicurezza Nazionale (ACN), CSIRT Italia (ACN (Agenzia per la Cybersicurezza Nazionale)).
The deadlines are strict: a significant incident requires an early warning within 24 hours, a full notification within 72 hours and a final report within one month. Non-compliance can cost an essential entity up to 10 million euros or 2% of worldwide turnover, and an important entity up to 7 million euros or 1.4%.
Our portal takes you to compliance in practice: the free scoping test shows whether NIS2 applies to your company, and the document package together with a local partner lawyer gets the requirements done. Start with the test — it takes three minutes.
The results are an indicative assessment, not legal advice. Final confirmation comes from a local partner lawyer.
Consultants and firms with a legal background who want flexible, remote work — including experienced, in-house, retired or non-practising professionals.