Skip to main content

Entity Identification

Indicate the EU country of operation, company size, and sector to determine the NIS2 scope.

Business size
Essential threshold: > 50M€. Important threshold: 10–50M€.
Required with invoice to classify as an essential entity (>43M€).

NIS2 FAQs

Does my company fall under the NIS2 scope?

Depends on sector and size. Companies with ≥250 employees or >50M€ revenue in Annex I sectors (energy, healthcare, banks, transport, PA, digital infrastructures) are essential entities. Medium enterprises (50-249 emp.) in Annex I/II sectors are considered important entities. Micro and small enterprises are excluded except for critical exceptions.

What is the difference between essential and important NIS2 subject?

Essential subjects (Annex I, ≥250 employees or >50M€ revenue) have stricter obligations, proactive supervision, and fines up to 2% of revenue (max 10M€). Important subjects (Annex I/II, medium size) have similar obligations but reactive supervision and fines up to 1.4% (max 7M€). Both must report incidents to the ACN.

What are the 2026 ACN deadlines for NIS2 in Italy?

The ACN 2026 calendar includes: portal registration (Jan–Feb 2026, already passed), organizational obligations take effect (April 18, 2026), and notification of essential or important status categorization (June 30, 2026). Failure to register and categorize results in administrative sanctions.

How do NIS2 obligations change in other EU countries?

NIS2 is an EU directive requiring national implementation - deadlines vary by country. As of 2026-06-20, confirmed implementation includes IT, IE, SE, DK, FI, CZ, LT, LV, EE. However, basic obligations (10 main requirements, incident reporting, technical measures) are harmonized across the EU. For countries still in process, entities must comply as soon as the law takes effect.

What are the 10 key NIS2 obligations (D.Lgs. 138/2024)?

NIS2 obligations (art. 24-25 D.Lgs. 138/2024) include: ICT security policies, risk management, incident response, business continuity (BCP/DRP), supply chain security, secure system development/purchasing, vulnerability management, encryption and MFA, HR security, reporting incidents to ACN within 24h/72h/1 month.

What is the cost of NIS2 non-compliance?

For essential subjects, fines reach up to 2% of annual global turnover (max €10M). For important subjects, up to 1.4% (max €7M). The ACN may also order temporary suspension of certifications or authorizations. The directive also provides for personal liability for management board members in case of severe negligence.

How to use NIS2 Wizard

  1. Enter country, size and sector

    In the first screen, indicate the EU country of operation, the number of employees, annual turnover, and sector of activity. These data determine the applicable NIS2 category.

  2. Check scope

    The wizard automatically determines if you are an essential entity, important entity, or out of the NIS2 scope based on Annexes I and II of D.Lgs. 138/2024.

  3. Evaluate the 10 major requirements

    For each of the 10 NIS2 requirements, indicate the current status: implemented (100%), partial (50%), or absent (0%). The system automatically calculates the overall readiness score.

  4. Check deadlines

    Step 4 shows the ACN 2026 calendar for Italy. If you are operating in another EU country, specific information for that country is displayed (receipt and NCA authority).

  5. Download PDF report

    The final report shows the readiness score, assigned tier, list of gaps, and recommendations. You can request the full PDF by email free of charge.

NIS2 in Italy: what to know in 2026

The NIS2 Directive (Directive (EU) 2022/2555) was transposed into Italian law by D.Lgs. 138/2024, which came into effect on November 9, 2024. It replaces the previous NIS1 and significantly expands the scope of obligated entities, increasing the estimated number of affected organizations in Italy from a few hundred to tens of thousands.

The directive distinguishes between essential entities (Annex I - energy, healthcare, banks, transport, public administration, digital infrastructure, space) and important entities (Annex II - chemical, food, manufacturing, digital suppliers, research). The size thresholds follow the PMI recommendation 2003/361/EC: large enterprises (≥250 employees) and medium-sized enterprises (50-249 employees) are primarily in scope.

NIS2 obligations (Art. 21 Directive, Art. 24-25 L.D. 138/2024) include 10 main areas: ICT risk management, security policies, incident response, operational continuity, supply chain security, encryption and MFA, vulnerability management, human resource security, incident notification to ACN. Fines can be significant: up to 2% of global turnover for essential entities.

The National Cybersecurity Agency (NCA) has published the 2026 calendar for phased implementation: registration on the NCA portal was scheduled for January-February 2026, organizational obligations took effect on April 18, 2026, and the critical deadline for category notification (essential/important) is June 30, 2026.

This free wizard helps organizations quickly identify their NIS2 tier, assess the implementation level of the 10 macro-obligations, and get a PDF report with gap analysis. The tool also covers EU-27 adoption: 9 confirmed countries with updated data (IT, IE, SE, DK, FI, CZ, LT, LV, EE) plus indicative information for other member states.

NIS2 Glossary

Essential Subject
Entities in Sector I Annex with Large Scale (≥250 emp or >50M€ rev + >43M€ bal). Proactive Oversight, Fines up to 2% Rev (max 10M€). Source: D.Lgs. 138/2024 art. 6.
Important subject
Entities in Sectors I/II with Medium Size (50-249 emp. or 10-50M€ rev.). Reactive Oversight, Fines up to 1.4% Rev. (max 7M€). Source: D.Lgs. 138/2024 art. 6.
Attachment I / Attachment II
Relevant Sectors NIS2 List. Annex I = High-Risk Sectors (energy, health, banks, transport, PA, digital infrastructures, space). Annex II = Important Sectors (chemical, food, manufacturing, digital suppliers, research). Source: D.Lgs. 138/2024 (implements NIS2 Annex I/II).
NIS2 Core Requirement
One of the 10 security measurement areas required by Art. 21 of the NIS2 Directive (Art. 24-25 D.Lgs. 138/2024): risk management, security policies, incident response, BCP/DRP, supply chain, secure development, vulnerability management, encryption, HR security, incident reporting.
NCI / INC
National Competent Authority (NCA) - national competent authority for NIS2. In Italy it is the ACN (National Cybersecurity Agency), supported by CSIRT Italy for incident management. Each EU country has its own NCA.
Readiness Status
Score from 0-100% indicating the level of implementation of NIS2 high-level obligations. Calculated as a weighted average: implemented=100%, partial=50%, absent=0%. Not an official ACN score - it is a tool for identifying gaps.