NIS2 in Italy: Who Is in Scope Under Decreto Legislativo 138/2024

Published: · AIPOS OÜ · nis2europe.eu

The scope framework under D.Lgs 138/2024

Italy transposed the NIS2 Directive (direttiva (UE) 2022/2555) through Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2). The national competent authority and single point of contact is the Agenzia per la Cybersicurezza Nazionale (ACN), which also operates CSIRT Italia for incident handling.

Under art 3, the decree applies to public and private entities of the types described in Annexes I, II, III and IV, which are an integral part of the decree, when they fall under national jurisdiction. In particular:

The practical question for most organisations is a combination of two tests: do I operate in a listed sector, and do I meet the size threshold set out below.

Size thresholds: the SME rule

For entities of the types listed in Annexes I and II, the decree applies where they exceed the ceilings for small enterprises under Article 2, paragraph 2, of the Annex to Recommendation 2003/361/EC (art 3, comma 2). In other words, the general rule captures medium-sized and large enterprises in the covered sectors.

Two important technical points from art 3:

Size does not always matter. Under art 3, comma 5, the decree applies regardless of size to, among others:

It also applies, regardless of size, to the public administrations referred to in art 3, comma 6 (Annex III), and to Annex IV entity types (art 3, comma 8). Under art 3, commi 9 and 10, further entities can be brought in regardless of size — for example a sole national provider of an essential service, or a company in the supply chain of an essential or important entity — following the identification procedure run by ACN.

Essential vs important: the statutory classification

Italian law uses two statutory categories, defined in art 6:

Soggetto essenziale (art 6, comma 1) includes, among others:

ACN may also identify, regardless of size, entities under art 3, commi 6, 8, 9 and 10 as essential (art 6, comma 2).

Soggetto importante (art 6, comma 3) is the residual category: entities within scope of art 3 that are not considered essential under art 6, commi 1 and 2.

The distinction matters for supervision and penalties. For important entities, verification and inspection powers apply only where ACN acquires evidence suggesting possible infringements (art 36, comma 2), whereas essential entities are subject to a more proactive supervisory regime (art 34, art 35).

Registration: how you get on the ACN list

Scope is confirmed through a registration cycle managed on ACN's digital platform (art 7):

Self-identification is your starting point, but the formal classification into essential or important is confirmed by ACN on the basis of these registrations and its decisions under art 3, art 4 and art 6.

Not sure where you land? Use our free scoping / gap tool to map your sector against Annexes I–IV and test the size thresholds before the registration window opens.

Why classification matters: obligations and penalties

Both essential and important entities must adopt appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risks (art 24), and their management and governing bodies must approve and oversee those measures, follow cybersecurity training and can be held responsible for infringements (art 23). Both categories must also notify significant incidents to CSIRT Italia (art 25), following the staged timeline of a pre-notification within 24 hours, an incident notification within 72 hours and a final report within one month.

The classification directly affects the penalty ceilings under art 38, comma 9:

CategoryMaximum administrative fine (art 24 / art 25 breaches)
Soggetto essenziale (excluding public administrations)up to €10,000,000 or 2% of total worldwide annual turnover of the previous year, whichever is higher
Soggetto importante (excluding public administrations)up to €7,000,000 or 1.4% of total worldwide annual turnover of the previous year, whichever is higher

For the registration and reporting breaches listed in art 38, comma 10, the ceilings under art 38, comma 11 are up to 0,1% of worldwide annual turnover for essential entities and 0,07% for important entities. Amounts are calculated in accordance with Recommendation 2003/361/EC.

Frequently asked questions

What is the difference between a soggetto essenziale and a soggetto importante?

Under art 6 of D.Lgs 138/2024, a soggetto essenziale (essential entity) includes, among others, Annex I entities that exceed the medium-enterprise ceilings and certain entities regardless of size (e.g. critical entities under the directive (UE) 2022/2557 transposition, qualified trust service providers, TLD registries and DNS providers, and central public administrations in Annex III). A soggetto importante (important entity) is the residual category: entities within scope of art 3 that are not classified as essential (art 6, comma 3).

Does the size of my company decide whether I am in scope?

For entities in Annexes I and II, the general rule (art 3, comma 2) is that the decree applies if you exceed the ceilings for small enterprises under Recommendation 2003/361/EC. However, art 3, comma 5 applies the decree regardless of size to specific entity types (for example trust service providers, DNS service providers and public electronic communications providers), and further entities can be brought in regardless of size under art 3, commi 6, 8, 9 and 10.

How do I confirm my classification as essential or important?

You register on ACN's digital platform between 1 January and 28 February each year and provide your sector and entity-type information (art 7, comma 1). By 31 March, ACN draws up the list of essential and important entities and notifies you of your inclusion (art 7, commi 2 and 3). Self-identification against Annexes I–IV and the size thresholds is your starting point, but the formal classification is confirmed by ACN.

Which authority oversees NIS2 compliance in Italy?

The national competent authority (Autorità nazionale competente NIS) and single point of contact is the Agenzia per la Cybersicurezza Nazionale (ACN), which also operates CSIRT Italia for incident handling. ACN identifies essential and important entities, maintains the list under art 7, comma 2, sets the obligations, supervises compliance and can impose administrative penalties.

Check your NIS2 compliance

Start the free scoping test

Run the free gap analysis Run the free surface scan

This article is general information, not legal advice. A partner lawyer confirms your specific situation.

Back to home