NIS2 · National implementation

NIS2 in Italy

Italy transposed NIS2 through Decreto Legislativo 4 settembre 2024, n. 138, in force since 16 October 2024 — one of the first major member states in force.

National law
Decreto Legislativo 4 settembre 2024, n. 138
Legislative decree implementing NIS2
Status
In force
In force
16 October 2024
Authority
ACN

Supervision

The ACN (Agenzia per la Cybersicurezza Nazionale) is the single national authority and runs the process end to end through its digital portal.

Registration

Italy runs an annual registration cycle: in-scope entities register (and re-confirm) on ACN's portal during a defined window each year, after which ACN formally notifies entities of their essential/important classification. This “confirmation by the authority” step is an Italian particularity — you register, and ACN tells you what you are.

What is specific to Italy

ACN has issued detailed implementing determinations that phase in the security measures and reporting duties over defined timelines from classification, giving Italian compliance a schedule-driven character. Italy also integrates NIS2 with its pre-existing Perimetro di Sicurezza Nazionale Cibernetica for the most critical entities, which keeps stricter rules.

Official sources

Primary references: the national statute book at www.normattiva.it and the national cybersecurity authority at www.acn.gov.it.

NIS2 in Italy: frequently asked questions

Last reviewed:

Related reading

Definitions

All 27 EU member states