NIS2 and Legislative Decree 138/2024: sanctions and risks for companies

NIS2 e D.Lgs. 138 2024: sanzioni e rischi per le aziende

Failure to comply with the NIS2 Directive within the deadlines established by the ACN (National Cybersecurity Agency) exposes companies to significant consequences in terms of penalties, operations, and reputation.

Penalties provided by Legislative Decree 138/2024

Violation of notification obligations

Legislative Decree 138/2024 establishes a strict penalty regime: the omission, incompleteness, or late transmission of significant incident notifications (pre-notification within 24 hours, notification within 72 hours, final report within one month) as required by Art. 25 entails significant administrative penalties.

Violation of communication obligations

Failure to register on the ACN portal or failure to designate the CSIRT Contact Person by December 31, 2025, are considered violations of the communication obligations set forth in Art. 24 and are subject to financial penalties.

Scale of fines

Penalties can reach millions of euros or be based on a significant percentage of the affected organization’s total annual worldwide turnover. The exact amount varies according to the severity of the violation and the type of entity (essential or important).

Operational and reputational risks

  • Operational interruptions: Without an expert CSIRT Contact Person and a response plan, any cyberattacks will cause prolonged downtime and financial losses due to the failure to provide services.
  • Reputational damage: Inadequate incident management or the receipt of penalties from the ACN can threaten the trust of customers and partners, jeopardizing corporate competitiveness.
  • Inspections and oversight: Failure to appoint a contact person is a critical signal that may trigger inspections and direct oversight by the National Cybersecurity Agency.
  • Loss of compliance: Without the contact person, the notification chain is broken, and the organization is considered non-compliant with the directive.

The danger of the human single point of failure

  • Appointment of substitutes: Determination 333017/2025 allows for the designation of one or more substitutes for the CSIRT Contact Person with similar technical requirements. This option prevents the organization from being left exposed in the event of the primary contact’s unavailability.
  • 24/7 availability: Contact persons (or their substitutes) must always be reachable to ensure timely notifications and compliance with legal deadlines.
  • Decision-making paralysis: Without clear internal procedures and designated substitutes, even a few minutes of uncertainty regarding “who does what” can exacerbate damage in the event of an attack.

Deadlines and requirements

  • Designation of Contact Person: Registration on the ACN portal is available from November 20 to December 31, 2025.
  • December 2025: During this month, it is not possible to submit 2025 declarations for registration purposes.
  • New 2026 registration: From January 1 to February 28, 2026, NIS organizations must submit a new declaration to confirm or update the data entered in the previous year.

Consequences of superficial management

Neglecting the appointment of the CSIRT Contact Person or operating without adequate procedures exposes the organization to legal penalties and operational impacts that seriously jeopardize business survival in the current digital economy.

Analogy

A company’s defense system can be compared to a fire protection system. The Point of Contact acts as the manager handling external relations, while the CSIRT Contact Person is the head of the internal emergency team, ready to act. Failing to provide substitutes is like having alarms but no one who knows how to intervene, leaving the company vulnerable when it is needed most.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!