NIS2 Incident Reporting Deadlines and Notification Duty in Italy

Published: · AIPOS OÜ · nis2europe.eu

Who must report incidents under Italy's NIS2 law?

Italy transposed the NIS2 Directive through Decreto Legislativo 4 settembre 2024, n. 138 (the "Decreto NIS2"). The incident notification duty applies to two categories of organisation defined by the law:

Both categories are required to notify significant incidents. Under art 25, comma 1, essential and important entities must notify CSIRT Italia, without undue delay, of every incident that has a significant impact on the provision of their services.

CSIRT Italia is the national computer security incident response team operating within the Agenzia per la Cybersicurezza Nazionale (ACN) (art 2, art 15). ACN also acts as the Autorità nazionale competente NIS and the single point of contact (art 10). In practice, this means your notifications go to CSIRT Italia, which sits inside ACN.

If you are unsure whether your organisation qualifies as a soggetto essenziale or soggetto importante, a quick scoping check is the fastest way to find out — you can use our free scoping/gap tool to get an initial classification.

What counts as a "significant" incident?

You only have to notify significant incidents, not every technical glitch. Under art 25, comma 4, an incident is considered significant if:

This mirrors the criteria in the NIS2 Directive (art 23(3)). The key takeaway: the trigger is impact and potential impact, not merely whether an attack succeeded. Even an incident that is *capable of* causing severe disruption can meet the threshold.

Because the assessment is impact-based, having a clear internal procedure to evaluate severity quickly is essential — the clock for the first deadline starts running from the moment you become aware of the significant incident.

The three (plus) reporting deadlines under art 25

Article 25, comma 5 of D.Lgs 138/2024 sets out a staged reporting timeline to CSIRT Italia. Every deadline runs from when the entity *becomes aware* of the significant incident:

StageDeadlineContent
Pre-notification (pre-notifica)Without undue delay, and within 24 hoursWhere possible, indicate whether the incident may result from unlawful or malicious acts, or may have a cross-border impact
Incident notification (notifica)Without undue delay, and within 72 hoursUpdate the earlier information; provide an initial assessment including severity and impact, plus indicators of compromise where available
Intermediate report (relazione intermedia)On request of CSIRT ItaliaRelevant status updates
Final report (relazione finale)Within one month of submitting the 72-hour notificationDetailed description, severity and impact; type of threat or root cause; mitigation measures applied and ongoing; cross-border impact where applicable

If the incident is still ongoing when the final report is due, the entity provides a progress report at that point and then a final report within one month of the conclusion of incident handling (art 25, comma 5, lett. e).

Special rule for trust service providers: By derogation from the 72-hour rule, a qualified/trust service provider must, for significant incidents affecting its trust services, notify within 24 hours of becoming aware of the incident (art 25, comma 6).

CSIRT Italia, in turn, aims to respond to the pre-notification within 24 hours where possible, providing initial feedback and, on request, guidance on technical mitigation measures (art 25, comma 7).

How and where you submit the notification

Notifications go to CSIRT Italia, operating within ACN. The official CSIRT Italia reference point is published by the authority itself.

The law specifies that the notification methods and timing are established according to articoli 30, 31 e 32 of the decree. The exact telematic channel/operational portal used to file the notification is [TÄPSUSTAB PARTNER-JURIST] — this is defined by CSIRT Italia and cannot be derived from the text of art 25 alone.

A few practical points that are grounded in the law:

Management and governance bodies of essential and important entities must be kept informed of incidents and notifications on a periodic or, where appropriate, timely basis (art 23, comma 3).

Penalties for failing to report incidents

Failing to comply with the incident notification obligation under art 25 is expressly listed among the violations subject to administrative fines (art 38, comma 8).

Under art 38, comma 9, the maximum fines are:

Amounts are calculated according to Commission Recommendation 2003/361/CE. Governance bodies can also be held responsible for infringements (art 23, comma 1; art 38, comma 6).

Given the size of these fines, mapping your incident-handling procedures against art 25 now — before an incident occurs — is a sensible investment. Our free scoping/gap tool can help you identify where your reporting readiness falls short.

Frequently asked questions

What are the NIS2 incident reporting deadlines in Italy?

Under art 25, comma 5 of D.Lgs 138/2024, essential and important entities must submit to CSIRT Italia: a pre-notification within 24 hours of becoming aware of a significant incident; an incident notification within 72 hours; and a final report within one month of the 72-hour notification. An intermediate report may be requested by CSIRT Italia.

Which authority receives NIS2 incident notifications in Italy?

Notifications go to CSIRT Italia, the national computer security incident response team operating within the Agenzia per la Cybersicurezza Nazionale (ACN). ACN is also the Autorità nazionale competente NIS and the single point of contact (art 10, art 15, art 25 comma 1).

When is an incident 'significant' and therefore reportable?

Under art 25, comma 4, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss for the entity, or if it has affected or is capable of affecting other persons by causing considerable material or non-material damage.

What is the penalty for not reporting an incident under NIS2 in Italy?

Under art 38, comma 9, a soggetto essenziale can face fines up to a maximum of EUR 10,000,000 or 2% of total worldwide annual turnover (whichever is higher), and a soggetto importante up to EUR 7,000,000 or 1.4% of turnover (whichever is higher), excluding public administrations.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home