NIS2 in Italy
Italy transposed NIS2 via Decreto Legislativo 138/2024, with ACN (Agenzia per la Cybersicurezza Nazionale) as the central authority. Enforcement is phased through 2026.
Key Deadlines
Competent Authority
ACN operates a phased registration programme. Entities first identified by ACN must register; subsequent waves open self-registration. Italy has a dedicated NIS2 registry portal and a sector-based regulatory framework.
Registration Process
Registration via the ACN Piattaforma NIS2 at nis2.acn.gov.it. You will need your VAT number (Partita IVA/Codice Fiscale), ATECO sector code, and contact details for the NIS2 point of contact and security officer.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Registration on the ACN NIS2 portal (Piattaforma NIS2)
- 224-hour early warning and 72-hour full notification for significant incidents
- 3Minimum security measures defined in ACN guidelines (MISURE MINIME)
- 4Annual cybersecurity risk assessment
- 5Supply chain security management
- 6Board-level accountability for cybersecurity
- 7Use of qualified/certified products where required by ACN
National Additions
FAQ: NIS2 in Italy
What are Italy's MISURE MINIME?
Is Italy's NIS2 enforcement phased?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.