Home  /  NIS2 & DORA Compliance  /  White Paper
White Paper · Complete guide

NIS2: an operational guide to Directive (EU) 2022/2555

Regulatory framing, scope and the size-cap rule, taxonomy of the entities in scope and the penalty regime: the correct reading of Legislative Decree 138/2024 for anyone accountable for compliance in the organisation.

By Valuemate, Cybersecurity Competence CenterReading time about 35 minutesAudience Board, CISO, DPO, Compliance Managers
Share on LinkedIn

Executive summary

Directive (EU) 2022/2555, NIS2, adopted on 14 December 2022, repealed the 2016 NIS Directive and introduced a harmonised cybersecurity framework for the European Union, significantly widening the population of entities in scope and tightening both management accountability and the penalty regime. In Italy the directive was transposed by Legislative Decree No. 138 of 4 September 2024, in force since 16 October 2024, which extends the rules to eighteen sectors and more than eighty types of public and private entities.

This operational guide covers the entire framework of the decree: general regulatory framing and the criterion for identifying the entities in scope, the so-called size-cap rule (Chapters 1-2); governance and personal accountability of management and administrative bodies (Chapter 3); the ten categories of cyber risk management measures (Chapter 4); the notification sequence for significant incidents, 24 hours / 72 hours / one month (Chapter 5); supply chain security (Chapter 6); supervision, ACN enforcement powers and the penalty regime (Chapter 7); a ten-phase operational roadmap (Chapter 8); the mapping to ISO/IEC 27001 (Chapter 9); checklist and cited sources (Chapter 10).

The key starting point: the dimensional criterion for entering the NIS2 perimeter is disjunctive, not cumulative. Crossing a single threshold, namely 50 employees or EUR 10 million in turnover or balance sheet, is enough to fall under the obligations, sector being equal. This difference substantially widens the population of companies involved compared with a cumulative reading of the criterion, and it is the first thing to check in any compliance assessment.

01Introduction and general regulatory framing

1.1 The evolution of cybersecurity in the European Union

Over the past two decades the digital transformation of critical infrastructure and industrial processes has radically changed the attack surface of organisations. The spread of cloud architectures, the integration of IT and OT/ICS systems and the growth of the Internet of Things have produced an unprecedented level of interconnection, but also a new fragility.

Today's cyber threats are no longer isolated episodes. We are talking about operations run by organised ransomware groups, transnational cybercrime networks and, in some cases, state-linked actors, aimed at industrial espionage or systemic sabotage. The European Union has recognised that the disruption of a single critical infrastructure in one Member State can spread rapidly, with economic, social and geopolitical consequences across the entire single market.

1.2 From the NIS Directive (EU 2016/1148) to the NIS2 Directive (EU 2022/2555)

The first directive on the security of network and information systems, the 2016 NIS Directive, was the first step towards a common level of cybersecurity in Europe. Its implementation, however, revealed structural limits:

  • Uneven transposition: each Member State applied different criteria to identify operators of essential services, so that companies of the same sector and size were obliged in one country and exempt in another.
  • Non-harmonised minimum requirements: the 2016 directive did not precisely define the minimum technical and organisational measures, leaving wide discretion to the States.
  • Limited scope: sectors that are central today, such as the food supply chain, medical device manufacturing, postal services and waste management, remained outside the rules.

To overcome these limits, Directive (EU) 2022/2555, NIS2, adopted on 14 December 2022 by the European Parliament and the Council, repealed the 2016 directive and introduced a harmonised framework, widening the population of entities in scope and tightening both management accountability and the penalty regime.

1.3 The European regulatory interconnection framework

NIS2 does not operate on its own, but is part of a broader European strategy:

  • NIS2 (EU 2022/2555): cross-sector resilience and cyber risk management for critical and strategic sectors.
  • DORA, the Digital Operational Resilience Act (Regulation EU 2022/2554): a special regime for the financial sector, applicable from 17 January 2025. Under the principle of speciality, for the financial entities it covers DORA prevails over the corresponding NIS2 provisions on ICT risk management and incident notification. This is a speciality relationship over equivalent requirements, not a full exit of those entities from the overall European resilience design.
  • GDPR (Regulation EU 2016/679): protects personal data and individual privacy, whereas NIS2 protects the integrity, authenticity and availability of systems and services. Where an incident also involves personal data, the notification obligations towards the Data Protection Authority (Garante) and the CSIRT are triggered in parallel.
  • Cyber Resilience Act (CRA): governs the security of hardware and software products placed on the European market, imposing the security-by-design principle on manufacturers.

1.4 Transposition in Italy: Legislative Decree 138/2024, ACN and CSIRT Italia

In Italy the NIS2 Directive was transposed by Legislative Decree No. 138 of 4 September 2024, published in Official Gazette No. 230 of 1 October 2024 and in force since 16 October 2024. The decree comprises 44 articles and 4 annexes and repeals the earlier Legislative Decree 65/2018, which had transposed the 2016 NIS Directive. The Italian legislator significantly widened the personal scope, extending the rules to eighteen sectors, eleven highly critical and seven critical, and more than eighty types of public and private entities, including public administrations down to local level.

The decree confirms the National Cybersecurity Agency, ACN, as the competent national NIS authority and single point of contact, under Article 8(1) of Directive (EU) 2022/2555. ACN is supported by nine Ministries acting as sector authorities for their respective areas of competence.

CSIRT Italia, operating within ACN, is the operational reference point for the technical handling of incidents: it receives mandatory notifications, monitors threats at national scale, issues alert bulletins and cooperates with the European CSIRT network.

On the implementation side, entities in scope had to register on ACN's digital platform in a first window between 1 December 2024 and 28 February 2025, with an obligation to update by 28 February of each following year. By the end of 2025 more than 30,000 organisations were registered. The ACN determinations published during 2025, in particular determination No. 379907/2025 and its guidelines, defined the specific technical and organisational obligations required of essential and important entities.

Operational deadlines to watch. The internal incident-notification procedure must be genuinely usable from the early months of 2026, with roles assigned and timings compatible with the 24 and 72 hour deadlines. Baseline security measures must be operational and documentably demonstrable by 31 October 2026 for entities already listed. From 2026 NIS2 is no longer a project to set up but an obligation to demonstrate under inspection.

02Scope, taxonomy and classification of entities

2.1 The identification criterion: size-cap rule and functional criteria

NIS2 removes the discretion Member States had in selecting the companies in scope, introducing the so-called size-cap rule. The directive applies in general to all organisations, public or private, operating in the sectors listed in Annexes I and II that reach at least the size of a medium-sized enterprise under Recommendation 2003/361/EC.

Technically, Article 3(2) of Legislative Decree 138/2024 anchors the size test to exceeding the ceilings set for small enterprises. Since a small enterprise is defined as an enterprise with fewer than 50 employees and an annual turnover or annual balance-sheet total not exceeding EUR 10 million, the NIS2 perimeter is triggered when even one of these thresholds is exceeded.

The criterion is therefore disjunctive and not cumulative. An entity falls within the perimeter, if it operates in a sector of Annexes I or II, when at least one of the following two conditions is met:

  • it employs at least 50 people; or
  • it has an annual turnover, or an annual balance-sheet total, exceeding EUR 10 million.

In concrete terms, a company with 45 employees but EUR 12 million in turnover is nonetheless subject to NIS2, because it exceeds the financial ceiling of a small enterprise. For the purpose of qualifying as essential or important, a further distinction is drawn between medium-sized enterprises, up to 250 employees and up to EUR 50 million in turnover or EUR 43 million balance-sheet total, and large enterprises that exceed those thresholds.

Why this distinction matters. A cumulative reading of the criterion, i.e. more than 50 employees and over EUR 10 million turnover at the same time, is a common but substantial mistake: it unduly narrows the population of entities in scope. The correct, disjunctive reading, in line with Article 3(2) of the decree and with the definition of small enterprise in Recommendation 2003/361/EC, significantly widens the number of companies that must comply.

The calculation of employees, turnover and balance sheet does not stop at the perimeter of the single company. The Recommendation requires that associated and linked enterprises also be considered, so an SME controlled by a large group may fall within the perimeter through the consolidation of data at group level.

Finally, the size criterion has significant exceptions. Some categories fall within the rules regardless of size, because of the intrinsic criticality of the service offered: among them trust service providers, top-level domain name registries and Domain Name System (DNS) service providers. Functional criteria also remain applicable that may draw below-threshold entities into the perimeter, for example where the entity is the sole provider of a critical service in a Member State or where a disruption would have systemic impact.

2.2 Penalty regime and accountability: why classification matters

Correctly placing an entity between essential and important is not a mere classification exercise, because it determines the intensity of supervision and the ceiling of the fines. Decree 138/2024 builds a differentiated system by category, described in the table in the following paragraph.

In addition to fines, ACN can impose mandatory corrective measures, security audits and, in the most serious cases and only for essential entities, temporary suspension of the activity. The personal accountability dimension should be stressed: management and administrative bodies approve the risk management measures, oversee their implementation and are liable for infringements, with an obligation of specific training for senior leadership and of promoting training programmes for staff.

03Governance, management accountability and training

3.1 From IT to the Board of Directors

With NIS2, cybersecurity stops being a delegable technical competence and becomes, by law, a governance matter. Article 20 of Directive (EU) 2022/2555, tellingly headed "Governance", assigns to management bodies the approval of risk management measures and the supervision of their implementation. Responsibility cannot be delegated upwards, nor can a lack of technical competence be invoked as an excuse.

The Italian legislator transposed this principle in Article 23 of Legislative Decree 138/2024, with a terminological choice that has practical consequences: where the directive speaks of "management bodies", the Italian decree distinguishes between administrative bodies (typically the Board of Directors, responsible for strategic decisions: approval of security policies, resource allocation, definition of objectives) and management bodies. A distinction that introduces a multi-level supervision model, not an attenuation of responsibility.

3.2 The four duties of Article 23

Article 23 of the decree assigns to the administrative and management bodies of essential and important entities four specific tasks:

  • Approval: formally approve how the cybersecurity risk management measures adopted under Article 24 are implemented (see Chapter 4).
  • Oversight: oversee the implementation of the obligations under Chapter IV of the decree and Article 7 (registration with ACN), exercising active and continuous supervision, not a full delegation to the CISO or external providers.
  • Liability: be liable for infringements of the decree. This is not an abstract risk: it translates into personal penalties and, in the most serious cases for essential entities, the possible temporary suspension from the exercise of management functions (see Chapter 7).
  • Training: undertake specific cybersecurity training and promote the periodic provision of consistent training to the organisation's staff.

What it means in practice. The system does not aim to turn the Board of Directors into a technical committee. Strategic responsibility stays anchored at the top, while technical management retains the speed and specialisation it needs: the Board approves, supervises and is kept informed, periodically or promptly when needed, about incidents and their notifications; it does not configure or implement the technical controls itself.

3.3 Training: a documentable obligation, not a one-off event

The training required by Article 23 is not exhausted in a single course. To be defensible under inspection, a training plan should: be adopted as a structural risk management measure; differentiate the content for senior bodies (regulatory framework, penalty implications, role in governance, incident-handling procedures and notification flows) from that for operational staff; provide a documented periodic cadence, not an isolated initiative; leave a verifiable record of participation, useful both in an ACN audit and as an element of personal protection for directors and managers.

04Cyber risk management measures

4.1 A "multi-risk" approach, not a shopping list of products

Article 24 of Decree 138/2024, transposing Article 21 of the directive, requires essential and important entities to adopt "appropriate and proportionate" technical, operational and organisational measures to manage the risks to the security of network and information systems, following a multi-risk approach aimed at protecting both the systems and their physical environment. No specific technological standard is required, but a continuous risk management system, proportionate to the size and exposure of the entity.

4.2 The ten categories of minimum measures

Article 24(2) lists ten categories of measures that every essential or important entity must consider and, where relevant to its risk profile, adopt:

#Category of measureWhat it covers in practice
aRisk analysis and information system securityRisk assessment policies, inventory of assets and systems, periodic threat evaluation.
bIncident handlingDetection, classification, response and notification (see Chapter 5).
cBusiness continuityBackup management, disaster recovery and crisis management.
dSupply chain securitySecurity relationships with direct suppliers and service providers (see Chapter 6).
eSecurity in acquisition, development and maintenance of systemsVulnerability management and disclosure across the lifecycle.
fAssessment of the effectiveness of measuresPolicies and procedures to measure whether risk management controls actually work.
gBasic cyber hygiene and trainingMinimum practices (patching, password management, awareness) and staff training.
hCryptographyPolicies and procedures on the use of cryptography and, where appropriate, encryption.
iHuman resources security and access controlStaff vetting, access management and asset management.
jAuthentication and secure communicationsMFA or continuous authentication, secured voice/video/text communications, emergency systems.

4.3 The principle of proportionality

Article 31 of the decree provides that, for the purposes of the obligations under Articles 23, 24, 25, 27, 28 and 29, the competent national NIS authority calibrates the manner and timing of implementation taking into account the degree of exposure to risk, the size of the entity and the likelihood and severity of incidents, including their social and economic impact. In practice: the same ten categories of measures apply to all entities in scope, but the intensity and timing of implementation are calibrated case by case, not uniform between an SME and a large group.

05Security incident handling and notification

5.1 What a significant incident is

Article 25 of Decree 138/2024 requires essential and important entities to notify CSIRT Italia, without undue delay, of any incident that has a significant impact on the provision of their services. An incident is considered significant when: it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; or it has affected or is capable of affecting other natural or legal persons, causing considerable material or immaterial damage.

In the initial application phase, ACN defined specific sets of "baseline significant incidents" with Determination No. 164179 of 14 April 2025, through two separate annexes: one for essential entities and one for important entities, to provide an immediate operational criterion pending the secondary regulation at full regime.

5.2 The notification sequence: three deadlines, not one

Article 25 structures the notification into a precise timeline, running from the moment the entity becomes aware of the significant incident:

PhaseDeadlineContent
Early warningWithout undue delay, within 24 hoursFirst communication to CSIRT Italia, indicating whether the incident is suspected to result from unlawful or malicious acts or could have cross-border impact.
NotificationWithin 72 hoursUpdate of the initial information with an assessment of the incident: severity, impact and, where available, indicators of compromise.
Interim reportAt CSIRT Italia's requestRelevant updates on the state of handling, between the notification and the final report.
Final reportWithin one month of the notificationDetailed description of the incident, root cause, mitigation measures adopted and ongoing, cross-border impact where known.
Monthly reportIf the incident is still ongoing at the month's deadlinePeriodic update of progress, until the final closing report.

Why knowing them in advance is the only way to meet them. The timelines are tight and do not take office hours into account: an organisation must have an identified CSIRT contact (with named deputies to ensure availability), criteria for classifying significant incidents already validated against the baseline definitions, and an escalation path tested before the clock starts with a real incident.

5.3 Voluntary notification

Entities may notify CSIRT Italia on a voluntary basis of incidents other than those with significant impact, in particular cyber threats and near misses, without this entailing any additional burden on the notifying entity.

06Supply chain security

6.1 The most insidious attack vector of the last decade

Recital 21 of the NIS2 Directive identifies the supply chain as one of the most significant risks to the security of information systems: many notable attacks start from suppliers chosen for efficiency or cost, rarely subjected to rigorous security checks. Article 24(1)(d) of Decree 138/2024 explicitly includes supply chain security among the minimum measures, with specific reference to the security relationships between each entity and its direct suppliers or service providers.

6.2 What it requires in concrete terms

Paragraph 3 of the same article specifies that, in assessing which measures are appropriate, entities must take into account: the specific vulnerabilities of each direct supplier and service provider; the overall quality of the products and cybersecurity practices of their suppliers, including their secure development procedures; the results of the coordinated security risk assessments of critical supply chains carried out by the NIS Cooperation Group at European level.

It is therefore not a matter of generically requiring "secure suppliers", but of actively managing and documenting the security relationship with each relevant supplier, throughout the entire contract lifecycle.

6.3 The clauses to bring into the contract

In practice, defensible supply chain management requires: a complete inventory of all the organisation's suppliers, classified by level of criticality (ICT supply, non-fungible supply, non-fungible ICT supply); a preliminary security assessment of new suppliers, with periodic risk-based review; specific cybersecurity contractual clauses, supplier business-continuity obligations aligned to the organisation's RTO/RPO, a right to audit and an obligation to notify incidents involving the supplier; transparency on sub-supply, with notification of changes in the Tier 2 and Tier 3 chain that may affect the risk level.

07Supervision, inspections and the penalty regime

7.1 Three powers, one authority

Chapter V of Decree 138/2024 (Articles 34-39) assigns to ACN, as competent national NIS authority, three distinct areas of intervention: monitoring (analysis and support directed at essential and important entities), supervision (checks and inspections on the implementation of obligations) and enforcement (corrective and penalty measures).

7.2 Enforcement powers (Art. 37)

In exercising its enforcement powers, ACN may require entities, stating the purpose, to provide data demonstrating the implementation of their cybersecurity policies, such as the results of security audits and the related evidence, as well as the information needed to verify compliance with the transmission, communication and notification obligations. The Authority may also order entities to carry out, on a periodic or targeted basis, security audits, in particular in the event of a significant incident or an identified non-compliance.

7.3 The penalty regime (Art. 38)

As illustrated in Chapter 2, breach of the obligations on risk management and incident notification (Articles 23, 24 and 25) exposes essential entities (excluding public administrations) to administrative fines of up to EUR 10 million or, if higher, up to 2% of total worldwide annual turnover of the previous financial year; and important entities to up to EUR 7 million or up to 1.4% of total worldwide annual turnover. Alongside the fine there are measures that directly affect operational continuity and the personal position of senior leadership: for essential entities, in the most serious cases, ACN can order the temporary suspension from the exercise of management functions, lasting until the entity adopts the measures needed to remedy the shortcomings identified or complies with the requirements imposed.

7.4 ACN implementing determinations

The penalty and supervision framework is completed by a series of technical determinations that ACN publishes progressively to make the decree's obligations operational, including: Determination No. 38565 of 26 November 2024, on the terms and methods of access to the digital platform; Determination No. 136117 of 10 April 2025, on the registration of entities; Determination No. 164179 of 14 April 2025, on baseline significant incidents; Determination No. 379907/2025, which defines further specific technical and organisational obligations for essential and important entities. This body of secondary regulation is evolving and should be checked on ACN's official channels at the time of the assessment.

08A ten-phase operational alignment roadmap

Building on the previous chapters, the alignment path we follow with our clients unfolds in ten operational phases, designed to run in sequence but with several phases able to proceed in parallel where resources allow.

PhaseActivityReference
1Verify applicability: sector, size-cap rule, functional criteriaChapter 2
2Registration on the ACN digital platform within the set windowChapter 1, Art. 7
3Classification as an essential or important entity and mapping of the resulting obligationsChapter 2
4Technical gap analysis on the ten categories of risk management measuresChapter 4
5Definition of internal governance: roles, responsibilities, training plan for leadership and staffChapter 3
6Design and testing of the incident handling and notification process, with a designated CSIRT contactChapter 5
7Inventory and classification of relevant suppliers, review of contractual clausesChapter 6
8Implementation and documentation of technical controls (cryptography, MFA, access control, backup)Chapter 4
9Alignment with a structured ISMS (ISO/IEC 27001) where already present or being adoptedChapter 9
10Continuous monitoring, periodic internal audits and preparation for ACN supervisionChapter 7

The principle of proportionality (Art. 31) allows the duration and depth of each phase to be calibrated according to the size, risk exposure and criticality of the entity: an SME just above threshold and a large enterprise in a highly critical sector do not travel the same roadmap at the same speed.

09Mapping international standards, ISO/IEC 27001 and NIS2

9.1 Why it pays to start from a mature ISMS

About 70% of NIS2 requirements find a correspondence in the controls of the ISO/IEC 27001:2022 standard, according to industry analyses based on the ENISA mapping published in 2025. For an organisation that has already implemented a certified or certifiable Information Security Management System (ISMS), building the NIS2 posture largely means realigning what already exists, not starting from scratch.

9.2 Indicative correspondence table

Measure, Art. 24(2)ISO/IEC 27001:2022 reference
a) Risk analysisClauses 6.1, 8.2, 8.3 (risk assessment and treatment)
b) Incident handlingClause 8.1 and Annex A controls 5.24-5.28
c) Business continuityAnnex A controls 5.29-5.30
d) Supply chain securityAnnex A control 5.21 (information security in supplier relationships)
h) CryptographyAnnex A control 8.24
i) Access controlAnnex A controls 5.15-5.18

The mapping is indicative and should always be verified case by case against the Statement of Applicability (SoA) and Implementing Regulation (EU) 2024/2690, which sets out the technical NIS2 requirements for specific categories of entities.

9.3 Where the correspondence is not automatic

ISO/IEC 27001 certification covers the organisation's security management system, but does not on its own satisfy some specific NIS2 elements: the personal accountability and training obligations of administrative and management bodies (Chapter 3); the binding notification timelines to public bodies, 24 hours, 72 hours, one month (Chapter 5); the distinction between a NIS entity and a supplier of a NIS entity, with the related cascading clauses (Chapter 6). A mature ISMS is an important accelerator, not a substitute for NIS2 compliance.

10Annexes, operating templates and compliance checklist

10.1 Quick checklist by phase

  • Applicability: have we verified sector (Annexes I-IV) and the size-cap rule with the disjunctive criterion?
  • Registration: are we registered on the ACN platform and do we update the data by 28 February each year?
  • Governance: has the Board formally approved the risk management measures and does it follow a documented training plan?
  • Technical measures: for each of the ten categories of Art. 24, do we have an implemented control or a documented justification of non-applicability?
  • Incidents: do we have a designated CSIRT contact (with a deputy) and a tested procedure for 24h early warning / 72h notification / 1-month final report?
  • Suppliers: do we have a supplier register classified by criticality and up-to-date security clauses in existing contracts?
  • Evidence: do we have audit trails, access logs and security audit results ready to produce on an ACN request?

10.2 Sources cited in this white paper

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 (NIS2); Legislative Decree No. 138 of 4 September 2024, transposing Directive (EU) 2022/2555 (Official Gazette No. 230 of 1 October 2024); Regulation (EU) 2022/2554 (DORA); Implementing Regulation (EU) 2024/2690; determinations of the Director General of ACN Nos. 38565/2024, 136117/2025, 164179/2025, 379907/2025; ISO/IEC 27001:2022 standard.

Methodological note. This white paper is for information purposes and does not constitute legal advice. The NIS2 regulatory framework is evolving, with ACN determinations published progressively: to apply the obligations to your own organisation it is always necessary to refer to the official text of the directive, to Decree 138/2024 and to the up-to-date guidance of ACN and CSIRT Italia, with the support of a qualified adviser for the legal aspects.

Essential glossary

ACN (National Cybersecurity Agency)
The competent national NIS authority and single point of contact under Directive (EU) 2022/2555.
CSIRT Italia
The operational structure within ACN that receives incident notifications, monitors threats and cooperates with the European CSIRT network.
Size-cap rule
The dimensional, disjunctive criterion that determines an organisation's entry into the NIS2 perimeter: an employee threshold or a turnover/balance-sheet threshold.
Essential / important entities
The two categories into which Decree 138/2024 classifies the entities in scope, with differentiated supervision intensity and penalty ceilings.
DORA
Digital Operational Resilience Act (Regulation EU 2022/2554): a speciality regime for the financial sector, applicable from 17 January 2025.

Want to know whether your company falls within the NIS2 perimeter?

Let's check together the size-cap rule applied to your case, the correct classification between essential and important entities and the concrete steps for a gap analysis. The complete framework, with governance, risk measures and the ten-phase roadmap, will come in the next updates of this white paper.

Request a free gap analysis
Share on LinkedIn