NIS2 in Italy: Who Is in Scope Under Decreto Legislativo 138/2024
The scope framework under D.Lgs 138/2024
Italy transposed the NIS2 Directive (direttiva (UE) 2022/2555) through Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2). The national competent authority and single point of contact is the Agenzia per la Cybersicurezza Nazionale (ACN), which also operates CSIRT Italia for incident handling.
Under art 3, the decree applies to public and private entities of the types described in Annexes I, II, III and IV, which are an integral part of the decree, when they fall under national jurisdiction. In particular:
- Annexes I and II describe, respectively, the highly critical and critical sectors, together with their subsectors and entity types.
- Annex III lists the categories of public administrations covered.
- Annex IV lists further entity types to which the decree applies.
The practical question for most organisations is a combination of two tests: do I operate in a listed sector, and do I meet the size threshold set out below.
Size thresholds: the SME rule
For entities of the types listed in Annexes I and II, the decree applies where they exceed the ceilings for small enterprises under Article 2, paragraph 2, of the Annex to Recommendation 2003/361/EC (art 3, comma 2). In other words, the general rule captures medium-sized and large enterprises in the covered sectors.
Two important technical points from art 3:
- Article 3, paragraph 4, of the Annex to Recommendation 2003/361/EC does not apply for the purposes of this decree (art 3, comma 3).
- To determine whether an entity is a medium or large enterprise, art 3, comma 4 applies Article 6, paragraph 2, of that Annex — unless this is disproportionate, taking into account the entity's independence from linked enterprises in terms of the network and information systems it uses and the services it provides.
Size does not always matter. Under art 3, comma 5, the decree applies regardless of size to, among others:
- entities identified as critical entities under the decree transposing directive (UE) 2022/2557;
- providers of public electronic communications networks or of publicly available electronic communications services;
- trust service providers;
- top-level domain name registries and DNS service providers;
- domain name registration service providers.
It also applies, regardless of size, to the public administrations referred to in art 3, comma 6 (Annex III), and to Annex IV entity types (art 3, comma 8). Under art 3, commi 9 and 10, further entities can be brought in regardless of size — for example a sole national provider of an essential service, or a company in the supply chain of an essential or important entity — following the identification procedure run by ACN.
Essential vs important: the statutory classification
Italian law uses two statutory categories, defined in art 6:
- soggetto essenziale (essential entity)
- soggetto importante (important entity)
Soggetto essenziale (art 6, comma 1) includes, among others:
- entities in Annex I that exceed the ceilings for medium-sized enterprises under Article 2, paragraph 1, of the Annex to Recommendation 2003/361/EC;
- regardless of size, entities identified as critical entities under the decree transposing directive (UE) 2022/2557;
- providers of public electronic communications networks and of publicly available electronic communications services that qualify as medium-sized enterprises;
- regardless of size, qualified trust service providers, TLD name registries and DNS service providers;
- regardless of size, the central public administrations listed in Annex III, paragraph 1, letter a).
ACN may also identify, regardless of size, entities under art 3, commi 6, 8, 9 and 10 as essential (art 6, comma 2).
Soggetto importante (art 6, comma 3) is the residual category: entities within scope of art 3 that are not considered essential under art 6, commi 1 and 2.
The distinction matters for supervision and penalties. For important entities, verification and inspection powers apply only where ACN acquires evidence suggesting possible infringements (art 36, comma 2), whereas essential entities are subject to a more proactive supervisory regime (art 34, art 35).
Registration: how you get on the ACN list
Scope is confirmed through a registration cycle managed on ACN's digital platform (art 7):
- From 1 January to 28 February each year (following the decree's entry into force), entities under art 3 register or update their registration on the platform, providing at least the company name, address and contacts, a designated point of contact and, where applicable, the relevant sectors, subsectors and entity types under Annexes I–IV (art 7, comma 1).
- By 31 March, ACN draws up the list of essential and important entities (art 7, comma 2) and notifies each entity of its inclusion, retention or removal (art 7, comma 3).
- From 15 April to 31 May, listed entities provide or update their public IP address space and domain names (art 7, comma 4).
Self-identification is your starting point, but the formal classification into essential or important is confirmed by ACN on the basis of these registrations and its decisions under art 3, art 4 and art 6.
Not sure where you land? Use our free scoping / gap tool to map your sector against Annexes I–IV and test the size thresholds before the registration window opens.
Why classification matters: obligations and penalties
Both essential and important entities must adopt appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risks (art 24), and their management and governing bodies must approve and oversee those measures, follow cybersecurity training and can be held responsible for infringements (art 23). Both categories must also notify significant incidents to CSIRT Italia (art 25), following the staged timeline of a pre-notification within 24 hours, an incident notification within 72 hours and a final report within one month.
The classification directly affects the penalty ceilings under art 38, comma 9:
| Category | Maximum administrative fine (art 24 / art 25 breaches) |
|---|---|
| Soggetto essenziale (excluding public administrations) | up to €10,000,000 or 2% of total worldwide annual turnover of the previous year, whichever is higher |
| Soggetto importante (excluding public administrations) | up to €7,000,000 or 1.4% of total worldwide annual turnover of the previous year, whichever is higher |
For the registration and reporting breaches listed in art 38, comma 10, the ceilings under art 38, comma 11 are up to 0,1% of worldwide annual turnover for essential entities and 0,07% for important entities. Amounts are calculated in accordance with Recommendation 2003/361/EC.
Frequently asked questions
What is the difference between a soggetto essenziale and a soggetto importante?
Under art 6 of D.Lgs 138/2024, a soggetto essenziale (essential entity) includes, among others, Annex I entities that exceed the medium-enterprise ceilings and certain entities regardless of size (e.g. critical entities under the directive (UE) 2022/2557 transposition, qualified trust service providers, TLD registries and DNS providers, and central public administrations in Annex III). A soggetto importante (important entity) is the residual category: entities within scope of art 3 that are not classified as essential (art 6, comma 3).
Does the size of my company decide whether I am in scope?
For entities in Annexes I and II, the general rule (art 3, comma 2) is that the decree applies if you exceed the ceilings for small enterprises under Recommendation 2003/361/EC. However, art 3, comma 5 applies the decree regardless of size to specific entity types (for example trust service providers, DNS service providers and public electronic communications providers), and further entities can be brought in regardless of size under art 3, commi 6, 8, 9 and 10.
How do I confirm my classification as essential or important?
You register on ACN's digital platform between 1 January and 28 February each year and provide your sector and entity-type information (art 7, comma 1). By 31 March, ACN draws up the list of essential and important entities and notifies you of your inclusion (art 7, commi 2 and 3). Self-identification against Annexes I–IV and the size thresholds is your starting point, but the formal classification is confirmed by ACN.
Which authority oversees NIS2 compliance in Italy?
The national competent authority (Autorità nazionale competente NIS) and single point of contact is the Agenzia per la Cybersicurezza Nazionale (ACN), which also operates CSIRT Italia for incident handling. ACN identifies essential and important entities, maintains the list under art 7, comma 2, sets the obligations, supervises compliance and can impose administrative penalties.
Check your NIS2 compliance
This article is general information, not legal advice. A partner lawyer confirms your specific situation.