Italy
← All Member States
Italy
✅ NIS2 transposed and in force.
NIS2 transposition
- National law: Decreto Legislativo 4 settembre 2024, n. 138 (Gazzetta Ufficiale n. 230 of 2024-10-01)
- Status / entry into force: In force 2024-10-16 (met the EU deadline)
Competent authority & CSIRT
- Competent authority: Agenzia per la Cybersicurezza Nazionale (ACN), with sector-specific authorities
- CSIRT / incident response: CSIRT Italia (ACN)
- Registration: Rolling annual registration via the ACN platform from 2024-12-01 (deadline 28 Feb each year)
Incident reporting
Follows the NIS2 cascade: early warning within 24h, notification within 72h, final report within one month, submitted to the national CSIRT / competent authority. Assume national-language submission unless the authority states otherwise.
Penalties & board liability
- Essential entities: up to €10M or 2% of worldwide turnover (directive minimum, adopted here).
- Important entities: up to €7M or 1.4% of worldwide turnover.
- Management-body accountability applies per NIS2 Art. 20; national enforcement mechanisms vary.
CER Directive
Critical-entities resilience is transposed in parallel (often via the same or a connected authority). Member States had to identify critical entities by 2026-07-17. ⚠️ VERIFY national CER instrument.
Notes
Added more sectors than the directive minimum. ACN may impose a temporary ‘incapacity to perform managerial functions’ on board members of repeat-offender essential entities. Security requirements to be met by Oct 2026 under the FNCS framework.
Sources
- https://www.acn.gov.it/portale/en/nis/la-normativa
- NIS2 Directive (EU) 2022/2555: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Commission transposition tracker: https://digital-strategy.ec.europa.eu/en/policies/nis-transposition