The NIS2 Directive has introduced a series of stringent measures to improve the cybersecurity of critical infrastructure and essential services across the European Union. In Italy, the National Cybersecurity Agency (ACN) is the body responsible for implementing the legislation, tasked with defining the definitive list of entities that must comply.
With the deadline for registration set for February 28, 2025, many companies are now called upon to finalize the adjustment process. However, it is possible to complete the registration until March 10, 2025, provided that the census has already been carried out. By March 31, 2025, the ACN will publish the definitive NIS2 list, officially identifying the organizations required to meet the new security requirements.
What does the NIS2 Directive provide for?
Compared to the previous NIS1 Directive, the NIS2 (EU Directive 2022/2555) imposes more rigorous obligations for cybersecurity management, risk identification, and incident notification. The main innovations include:
- Expansion of the range of subjects involved, including not only essential service providers but also many private companies.
- Greater focus on the supply chain, with obligations to control supplier security.
- Reporting obligations for security incidents within precise timeframes.
- Heavy sanctions for those who do not comply, with fines of up to 2% of total annual global turnover.
ACN and the NIS2 list: the stages of adjustment
The implementation of the NIS2 Directive has been divided into three main phases:
- Transposition phase (February 2023 – October 2024): period necessary for the adoption of the legislation at the national level.
- First implementation phase (October 2024 – April 2025): period during which companies must register and prepare for compliance.
- Second implementation phase (April 2025 – April 2026): practical implementation of security measures.
- Third implementation phase (from April 2026 onwards): full operation of NIS2, with periodic checks and compliance audits.
The census and mandatory registration
Companies subject to NIS2 are required to register on the ACN digital platform by February 28, 2025. Those who have not yet completed the procedure have one last opportunity until March 10, 2025. However, to qualify for this extension, it is necessary to have already carried out the preliminary census by the first deadline.
Publication of the definitive NIS2 list on March 31, 2025
One of the key moments in the adjustment process is the publication of the definitive list of entities that must comply. This list, drawn up by the ACN, will be published on March 31, 2025, and will include:
- Companies and public bodies required to comply with the legislation.
- Categories of essential operators that fall within the NIS2 perimeter.
- Specific obligations for each category of subject.
Once the list is published, the included companies will have until April 2026 to implement the necessary security measures.
Main NIS2 compliance measures
Companies that fall under the NIS2 list must adopt a series of measures to ensure compliance, including:
- Cyber risk management: implement a structured approach to prevent and mitigate cyber attacks.
- Supply chain protection: verify the security of suppliers and adopt adequate controls.
- Mandatory incident notification: promptly report any breach or cyber attack to the ACN and CSIRT Italia. For organizations included in the list, the designation of a CSIRT contact person is one of the operational tasks to be completed in the implementation phase.
- Periodic audits and checks: undergo regular security checks to avoid sanctions.
For organizations that need to structure this path, it is useful to start with an assessment of the current state: ISGroup’s NIS2 compliance support guides companies from gap analysis to the implementation of the measures required by the regulation.
Sanctions for non-compliance
Failure to comply with the NIS2 Directive entails severe sanctions. In particular, non-compliant companies risk:
- Fines of up to 10 million euros or 2% of total annual global turnover.
- Accessory sanctions for executives, including temporary suspension from positions of responsibility.
- Obligation to adopt corrective measures immediately, with potential surprise inspections.
What to do now if your company is on the NIS2 list
The NIS2 Directive represents a fundamental turning point for cybersecurity in Europe. The ACN NIS2 list, published by March 31, 2025, definitively defines the companies and entities required to comply with the new rules.
Companies that have not yet started the adjustment process must act immediately to avoid sanctions and ensure the protection of their digital infrastructure.
NIS2 compliance is not just a regulatory obligation, but an essential strategy to ensure business resilience in the face of increasingly sophisticated cyber threats. To learn more about the regulatory framework, the official document of the NIS2 Directive is also available.
Frequently asked questions about NIS2 compliance
- I am on the NIS2 list published by ACN: where should I start?
- The starting point is a gap analysis against the requirements of the regulation: governance, risk management, supply chain protection, and incident notification procedures. Only after this assessment is it possible to define a realistic implementation plan by the April 2026 deadline.
- What happens if I did not register by the ACN deadlines?
- Failure to register does not exempt you from the obligation of compliance if the organization falls within the dimensional and sectoral criteria provided for by the regulation. The ACN can still include the entity on the list ex officio and initiate checks. It is advisable to regularize your position as soon as possible.
- By when must I implement the security measures required by NIS2?
- Companies included in the definitive list have until April 2026 to implement the required technical and organizational measures. From that date, periodic checks and compliance audits will begin, with related sanctions in case of non-compliance.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
