NIS2 Incident Reporting Deadlines and Notification Duty in Italy
Who must report incidents under Italy's NIS2 law?
Italy transposed the NIS2 Directive through Decreto Legislativo 4 settembre 2024, n. 138 (the "Decreto NIS2"). The incident notification duty applies to two categories of organisation defined by the law:
- soggetto essenziale (essential entity)
- soggetto importante (important entity)
Both categories are required to notify significant incidents. Under art 25, comma 1, essential and important entities must notify CSIRT Italia, without undue delay, of every incident that has a significant impact on the provision of their services.
CSIRT Italia is the national computer security incident response team operating within the Agenzia per la Cybersicurezza Nazionale (ACN) (art 2, art 15). ACN also acts as the Autorità nazionale competente NIS and the single point of contact (art 10). In practice, this means your notifications go to CSIRT Italia, which sits inside ACN.
If you are unsure whether your organisation qualifies as a soggetto essenziale or soggetto importante, a quick scoping check is the fastest way to find out — you can use our free scoping/gap tool to get an initial classification.
What counts as a "significant" incident?
You only have to notify significant incidents, not every technical glitch. Under art 25, comma 4, an incident is considered significant if:
- a) it has caused or is capable of causing a serious operational disruption of the services or financial losses for the entity concerned; or
- b) it has affected, or is capable of affecting, other natural or legal persons by causing considerable material or non-material damage.
This mirrors the criteria in the NIS2 Directive (art 23(3)). The key takeaway: the trigger is impact and potential impact, not merely whether an attack succeeded. Even an incident that is *capable of* causing severe disruption can meet the threshold.
Because the assessment is impact-based, having a clear internal procedure to evaluate severity quickly is essential — the clock for the first deadline starts running from the moment you become aware of the significant incident.
The three (plus) reporting deadlines under art 25
Article 25, comma 5 of D.Lgs 138/2024 sets out a staged reporting timeline to CSIRT Italia. Every deadline runs from when the entity *becomes aware* of the significant incident:
| Stage | Deadline | Content |
|---|---|---|
| Pre-notification (pre-notifica) | Without undue delay, and within 24 hours | Where possible, indicate whether the incident may result from unlawful or malicious acts, or may have a cross-border impact |
| Incident notification (notifica) | Without undue delay, and within 72 hours | Update the earlier information; provide an initial assessment including severity and impact, plus indicators of compromise where available |
| Intermediate report (relazione intermedia) | On request of CSIRT Italia | Relevant status updates |
| Final report (relazione finale) | Within one month of submitting the 72-hour notification | Detailed description, severity and impact; type of threat or root cause; mitigation measures applied and ongoing; cross-border impact where applicable |
If the incident is still ongoing when the final report is due, the entity provides a progress report at that point and then a final report within one month of the conclusion of incident handling (art 25, comma 5, lett. e).
Special rule for trust service providers: By derogation from the 72-hour rule, a qualified/trust service provider must, for significant incidents affecting its trust services, notify within 24 hours of becoming aware of the incident (art 25, comma 6).
CSIRT Italia, in turn, aims to respond to the pre-notification within 24 hours where possible, providing initial feedback and, on request, guidance on technical mitigation measures (art 25, comma 7).
How and where you submit the notification
Notifications go to CSIRT Italia, operating within ACN. The official CSIRT Italia reference point is published by the authority itself.
The law specifies that the notification methods and timing are established according to articoli 30, 31 e 32 of the decree. The exact telematic channel/operational portal used to file the notification is [TÄPSUSTAB PARTNER-JURIST] — this is defined by CSIRT Italia and cannot be derived from the text of art 25 alone.
A few practical points that are grounded in the law:
- Notifications must include the information that allows CSIRT Italia to determine any cross-border impact of the incident (art 25, comma 2).
- The act of notifying does not expose the reporting entity to greater liability than that arising from the incident itself (art 25, comma 3).
- Where appropriate and possible, and after consulting CSIRT Italia, entities must inform the recipients of their services of significant incidents that may adversely affect service provision (art 25, comma 9), and of corrective or mitigation measures where a significant cyber threat is involved (art 25, comma 10).
Management and governance bodies of essential and important entities must be kept informed of incidents and notifications on a periodic or, where appropriate, timely basis (art 23, comma 3).
Penalties for failing to report incidents
Failing to comply with the incident notification obligation under art 25 is expressly listed among the violations subject to administrative fines (art 38, comma 8).
Under art 38, comma 9, the maximum fines are:
- soggetto essenziale (excluding public administrations): up to a maximum of EUR 10,000,000 or 2% of total worldwide annual turnover for the previous financial year, whichever is higher, with a minimum set at one-twentieth of the maximum.
- soggetto importante (excluding public administrations): up to a maximum of EUR 7,000,000 or 1.4% of total worldwide annual turnover for the previous financial year, whichever is higher, with a minimum set at one-thirtieth of the maximum.
Amounts are calculated according to Commission Recommendation 2003/361/CE. Governance bodies can also be held responsible for infringements (art 23, comma 1; art 38, comma 6).
Given the size of these fines, mapping your incident-handling procedures against art 25 now — before an incident occurs — is a sensible investment. Our free scoping/gap tool can help you identify where your reporting readiness falls short.
Frequently asked questions
What are the NIS2 incident reporting deadlines in Italy?
Under art 25, comma 5 of D.Lgs 138/2024, essential and important entities must submit to CSIRT Italia: a pre-notification within 24 hours of becoming aware of a significant incident; an incident notification within 72 hours; and a final report within one month of the 72-hour notification. An intermediate report may be requested by CSIRT Italia.
Which authority receives NIS2 incident notifications in Italy?
Notifications go to CSIRT Italia, the national computer security incident response team operating within the Agenzia per la Cybersicurezza Nazionale (ACN). ACN is also the Autorità nazionale competente NIS and the single point of contact (art 10, art 15, art 25 comma 1).
When is an incident 'significant' and therefore reportable?
Under art 25, comma 4, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss for the entity, or if it has affected or is capable of affecting other persons by causing considerable material or non-material damage.
What is the penalty for not reporting an incident under NIS2 in Italy?
Under art 38, comma 9, a soggetto essenziale can face fines up to a maximum of EUR 10,000,000 or 2% of total worldwide annual turnover (whichever is higher), and a soggetto importante up to EUR 7,000,000 or 1.4% of turnover (whichever is higher), excluding public administrations.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.