NIS2 and Its Italian Transposition Law: What D.Lgs 138/2024 Means for Your Business
From EU directive to Italian law
The NIS2 Directive (EU) 2022/2555 is an EU-wide framework for cybersecurity. A directive, however, does not apply directly in the same way a regulation does — each Member State must transpose it into its own national legislation.
In Italy, that transposition is the Decreto Legislativo 4 settembre 2024, n. 138 (commonly referred to as the Decreto NIS2). This is the law that actually creates binding obligations for organisations operating under Italian jurisdiction.
In practice this means:
- The directive sets the objectives and minimum requirements (governance, risk management, incident reporting).
- The Italian law (D.Lgs 138/2024) turns those requirements into concrete national duties, names the responsible authority, sets the registration mechanics, and defines administrative penalties.
When you assess your obligations, the reference point that binds you is the Italian text of D.Lgs 138/2024.
Who is the competent authority in Italy?
The Italian law designates a single national authority for NIS2.
- The Agenzia per la Cybersicurezza Nazionale (ACN) is the national competent NIS authority (*Autorità nazionale competente NIS*) pursuant to art 10, comma 1. It oversees implementation of the decree, adopts guidelines and recommendations, identifies essential and important entities under art 3 and art 6, and draws up the list under art 7, comma 2.
- The ACN is also the single point of contact (Punto di contatto unico NIS) under art 10, comma 2, handling cross-border cooperation with authorities of other Member States, the Commission and ENISA.
- CSIRT Italia, operating within the ACN (art 2, lettera i; art 15), is the national body responsible for handling cybersecurity incidents. Essential and important entities notify significant incidents to CSIRT Italia (art 25, comma 1).
So in Italy, one agency — the ACN, together with CSIRT Italia inside it — carries out the supervisory, coordination and incident-response roles.
How does the law classify entities?
The directive distinguishes between two categories of regulated organisation, and D.Lgs 138/2024 gives them their Italian statutory names:
- soggetto essenziale (essential entity)
- soggetto importante (important entity)
Under art 6, comma 1, essential entities include, among others, the entities listed in Allegato I that exceed the ceilings for medium-sized enterprises under the referenced Recommendation 2003/361/CE, entities identified as critical under the law transposing Directive (EU) 2022/2557, qualified trust service providers and certain domain-related providers, and central public administrations listed in Allegato III. Under art 6, comma 3, entities under art 3 that are not considered essential are treated as soggetti importanti.
The scope of application is set out in art 3, covering public and private entities of the types listed in Allegati I, II, III and IV that fall under national jurisdiction (art 3, comma 1). As a general rule, the decree applies to entities in Allegato I and II that exceed the ceilings for small enterprises (art 3, comma 2), with a number of size-independent cases also captured (art 3, commi 5–10).
What the Italian law adds on top of the directive
Beyond restating the directive's core duties, D.Lgs 138/2024 provides the operational detail that makes NIS2 workable in Italy:
A national registration and listing cycle (art 7). Every year, from 1 January to 28 February, entities under art 3 register or update their registration on the digital platform made available by the ACN, providing company name, contact details, a designated point of contact and, where applicable, the relevant sectors and entity types (art 7, comma 1). By 31 March the ACN draws up the list of essential and important entities (art 7, comma 2). From 15 April to 31 May listed entities provide or update their public IP address space and domain names (art 7, comma 4).
Governance duties (art 23). Management and governing bodies of essential and important entities approve the implementation of risk-management measures under art 24, oversee compliance, and can be held liable for infringements. They must also follow cybersecurity training and promote it for staff.
Risk-management measures (art 24). Entities take appropriate and proportionate technical, operational and organisational measures — mirroring the directive's all-hazards catalogue — with implementation terms set through art 30, 31 and 32.
Incident reporting to CSIRT Italia (art 25). Significant incidents are notified with a pre-notification within 24 hours, an incident notification within 72 hours, an intermediate report on request, and a final report within one month of the incident notification (art 25, comma 5).
Supervision and penalties (art 34–38). The ACN monitors compliance, carries out inspections, and can impose administrative fines. Under art 38, comma 9, breaches of the obligations at comma 8 are punished for essential entities (excluding public administrations) up to a maximum of EUR 10,000,000 or 2% of total worldwide annual turnover, whichever is higher, and for important entities (excluding public administrations) up to a maximum of EUR 7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher. For breaches under comma 10, the ceilings are 0.1% (essential) and 0.07% (important) of worldwide annual turnover (art 38, comma 11).
What this means for your compliance planning
The practical takeaway for a business is straightforward:
- Determine whether you fall within scope under art 3 and, if so, whether you are a soggetto essenziale or soggetto importante under art 6.
- Prepare for the annual registration window on the ACN platform (art 7).
- Build risk-management measures (art 24) and ensure your management body (art 23) is trained and accountable.
- Set up your incident-notification process toward CSIRT Italia (art 25) with the 24h / 72h / one-month timeline in mind.
Because classification and scope depend on your sector, size and role in the supply chain, a structured self-assessment is the fastest way to see where you stand. Use our free scoping and gap tool to map your situation against D.Lgs 138/2024 and identify your next steps.
Frequently asked questions
What is the Italian law that transposes NIS2?
It is the Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), which transposes Directive (EU) 2022/2555 into Italian law and creates the binding national obligations.
Who is the competent authority for NIS2 in Italy?
The Agenzia per la Cybersicurezza Nazionale (ACN) is the national competent NIS authority and single point of contact (art 10). CSIRT Italia, operating within the ACN, handles cybersecurity incidents and receives incident notifications (art 15, art 25).
What are the deadlines for reporting a significant incident?
Under art 25, comma 5, entities must submit a pre-notification within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, an intermediate report on request, and a final report within one month of the incident notification.
What fines can apply under the Italian NIS2 law?
For breaches under art 38, comma 8, essential entities (excluding public administrations) face fines up to EUR 10,000,000 or 2% of worldwide annual turnover, and important entities up to EUR 7,000,000 or 1.4%, whichever is higher (art 38, comma 9).
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.