NIS2 · National implementation
NIS2 in Italy
Italy transposed NIS2 through Decreto Legislativo 4 settembre 2024, n. 138, in force since 16 October 2024 — one of the first major member states in force.
- National law
- Decreto Legislativo 4 settembre 2024, n. 138
- Legislative decree implementing NIS2
- Status
- In force
- In force
- 16 October 2024
- Authority
- ACN
Supervision
The ACN (Agenzia per la Cybersicurezza Nazionale) is the single national authority and runs the process end to end through its digital portal.
Registration
Italy runs an annual registration cycle: in-scope entities register (and re-confirm) on ACN's portal during a defined window each year, after which ACN formally notifies entities of their essential/important classification. This “confirmation by the authority” step is an Italian particularity — you register, and ACN tells you what you are.
What is specific to Italy
ACN has issued detailed implementing determinations that phase in the security measures and reporting duties over defined timelines from classification, giving Italian compliance a schedule-driven character. Italy also integrates NIS2 with its pre-existing Perimetro di Sicurezza Nazionale Cibernetica for the most critical entities, which keeps stricter rules.
Official sources
Primary references: the national statute book at www.normattiva.it and the national cybersecurity authority at www.acn.gov.it.
NIS2 in Italy: frequently asked questions
Last reviewed:
Related reading
Definitions
