NIS2 Readiness Assessment Tool
Assess your organization's compliance with the NIS2 Directive implemented by D.Lgs. 138/2024. Free wizard: scope Annex I/II + 10 macro-obligations + 2026 ACN calendar + check for 27 EU countries.
Entity Identification
Indicate the EU country of operation, company size, and sector to determine the NIS2 scope.
NIS2 FAQs
Does my company fall under the NIS2 scope?
Depends on sector and size. Companies with ≥250 employees or >50M€ revenue in Annex I sectors (energy, healthcare, banks, transport, PA, digital infrastructures) are essential entities. Medium enterprises (50-249 emp.) in Annex I/II sectors are considered important entities. Micro and small enterprises are excluded except for critical exceptions.
What is the difference between essential and important NIS2 subject?
Essential subjects (Annex I, ≥250 employees or >50M€ revenue) have stricter obligations, proactive supervision, and fines up to 2% of revenue (max 10M€). Important subjects (Annex I/II, medium size) have similar obligations but reactive supervision and fines up to 1.4% (max 7M€). Both must report incidents to the ACN.
What are the 2026 ACN deadlines for NIS2 in Italy?
The ACN 2026 calendar includes: portal registration (Jan–Feb 2026, already passed), organizational obligations take effect (April 18, 2026), and notification of essential or important status categorization (June 30, 2026). Failure to register and categorize results in administrative sanctions.
How do NIS2 obligations change in other EU countries?
NIS2 is an EU directive requiring national implementation - deadlines vary by country. As of 2026-06-20, confirmed implementation includes IT, IE, SE, DK, FI, CZ, LT, LV, EE. However, basic obligations (10 main requirements, incident reporting, technical measures) are harmonized across the EU. For countries still in process, entities must comply as soon as the law takes effect.
What are the 10 key NIS2 obligations (D.Lgs. 138/2024)?
NIS2 obligations (art. 24-25 D.Lgs. 138/2024) include: ICT security policies, risk management, incident response, business continuity (BCP/DRP), supply chain security, secure system development/purchasing, vulnerability management, encryption and MFA, HR security, reporting incidents to ACN within 24h/72h/1 month.
What is the cost of NIS2 non-compliance?
For essential subjects, fines reach up to 2% of annual global turnover (max €10M). For important subjects, up to 1.4% (max €7M). The ACN may also order temporary suspension of certifications or authorizations. The directive also provides for personal liability for management board members in case of severe negligence.
How to use NIS2 Wizard
- Enter country, size and sector
In the first screen, indicate the EU country of operation, the number of employees, annual turnover, and sector of activity. These data determine the applicable NIS2 category.
- Check scope
The wizard automatically determines if you are an essential entity, important entity, or out of the NIS2 scope based on Annexes I and II of D.Lgs. 138/2024.
- Evaluate the 10 major requirements
For each of the 10 NIS2 requirements, indicate the current status: implemented (100%), partial (50%), or absent (0%). The system automatically calculates the overall readiness score.
- Check deadlines
Step 4 shows the ACN 2026 calendar for Italy. If you are operating in another EU country, specific information for that country is displayed (receipt and NCA authority).
- Download PDF report
The final report shows the readiness score, assigned tier, list of gaps, and recommendations. You can request the full PDF by email free of charge.
NIS2 in Italy: what to know in 2026
The NIS2 Directive (Directive (EU) 2022/2555) was transposed into Italian law by D.Lgs. 138/2024, which came into effect on November 9, 2024. It replaces the previous NIS1 and significantly expands the scope of obligated entities, increasing the estimated number of affected organizations in Italy from a few hundred to tens of thousands.
The directive distinguishes between essential entities (Annex I - energy, healthcare, banks, transport, public administration, digital infrastructure, space) and important entities (Annex II - chemical, food, manufacturing, digital suppliers, research). The size thresholds follow the PMI recommendation 2003/361/EC: large enterprises (≥250 employees) and medium-sized enterprises (50-249 employees) are primarily in scope.
NIS2 obligations (Art. 21 Directive, Art. 24-25 L.D. 138/2024) include 10 main areas: ICT risk management, security policies, incident response, operational continuity, supply chain security, encryption and MFA, vulnerability management, human resource security, incident notification to ACN. Fines can be significant: up to 2% of global turnover for essential entities.
The National Cybersecurity Agency (NCA) has published the 2026 calendar for phased implementation: registration on the NCA portal was scheduled for January-February 2026, organizational obligations took effect on April 18, 2026, and the critical deadline for category notification (essential/important) is June 30, 2026.
This free wizard helps organizations quickly identify their NIS2 tier, assess the implementation level of the 10 macro-obligations, and get a PDF report with gap analysis. The tool also covers EU-27 adoption: 9 confirmed countries with updated data (IT, IE, SE, DK, FI, CZ, LT, LV, EE) plus indicative information for other member states.
NIS2 Glossary
- Essential Subject
- Entities in Sector I Annex with Large Scale (≥250 emp or >50M€ rev + >43M€ bal). Proactive Oversight, Fines up to 2% Rev (max 10M€). Source: D.Lgs. 138/2024 art. 6.
- Important subject
- Entities in Sectors I/II with Medium Size (50-249 emp. or 10-50M€ rev.). Reactive Oversight, Fines up to 1.4% Rev. (max 7M€). Source: D.Lgs. 138/2024 art. 6.
- Attachment I / Attachment II
- Relevant Sectors NIS2 List. Annex I = High-Risk Sectors (energy, health, banks, transport, PA, digital infrastructures, space). Annex II = Important Sectors (chemical, food, manufacturing, digital suppliers, research). Source: D.Lgs. 138/2024 (implements NIS2 Annex I/II).
- NIS2 Core Requirement
- One of the 10 security measurement areas required by Art. 21 of the NIS2 Directive (Art. 24-25 D.Lgs. 138/2024): risk management, security policies, incident response, BCP/DRP, supply chain, secure development, vulnerability management, encryption, HR security, incident reporting.
- NCI / INC
- National Competent Authority (NCA) - national competent authority for NIS2. In Italy it is the ACN (National Cybersecurity Agency), supported by CSIRT Italy for incident management. Each EU country has its own NCA.
- Readiness Status
- Score from 0-100% indicating the level of implementation of NIS2 high-level obligations. Calculated as a weighted average: implemented=100%, partial=50%, absent=0%. Not an official ACN score - it is a tool for identifying gaps.