Cos’è la normativa Cybersecurity NIS2 e tutti i nuovi adempimenti

ISGroup Cybersecurity

The NIS2 directive represents the new heart of European cybersecurity, designed to strengthen organizational resilience against increasingly sophisticated threats, from AI-driven malware to supply chain ransomware attacks.

Over the last decade, cyber incidents have demonstrated that even well-established entities—both public and private—can suffer severe consequences in the absence of adequate technical and organizational controls. For this reason, NIS2 aims to raise minimum security standards across Europe by expanding the scope of application, strengthening supply chain management, and introducing stricter penalties.

In this guide, you will discover:

Continue reading to understand if your organization is affected and what concrete actions to take to become compliant.

What is NIS2

The NIS2 (Network and Information Security Directive 2) is the new European directive on cybersecurity, designed to update and replace the previous NIS1. It aims to create a common security regulatory framework across all European Union member states, with the goal of increasing the digital resilience of critical organizations against cyberattacks, operational disruptions, and emerging technological threats such as offensive artificial intelligence.

Unlike the NIS1 regulation, NIS2:

  • Significantly expands the number of organizations subject to obligations
  • Strengthens requirements for governance and digital governance
  • Introduces stricter risk management and incident reporting measures
  • Expands the competencies and powers of national supervisory authorities
  • Provides for higher penalties in case of non-compliance

Having entered into force at the European level in 2023, the NIS2 directive was required to be transposed by member states by October 2024. From that moment on, all EU countries—including Italy—are required to adopt internal laws or regulations that translate European rules into binding obligations for entities, businesses, and services.

In essence, it is a next-generation cybersecurity regulation, designed to respond to the challenges of an increasingly connected, digital, and interdependent ecosystem.

Who the NIS2 directive applies to

One of the most significant changes introduced by NIS2 concerns its scope of application. While NIS1 was more limited in its focus on certain essential service operators, NIS2 drastically expands the subjects involved.

The regulation distinguishes between two broad groups of organizations:

  1. Essential Entities
  2. Important Entities

Both categories are subject to cybersecurity requirements, but governance and accountability requirements vary based on the criticality and size of the entity.

This category includes entities that provide fundamental services for the security and functioning of society, for example:

  • Energy: electricity and gas production, transmission, and distribution
  • Transport: airports, railways, ports, and mobility services
  • Health: hospitals, clinics, digital health services
  • Banking and Financial Services: critical financial system infrastructure
  • Water: water distribution and treatment
  • Public Administration: entities with centralized digital responsibility

These are organizations that, while not essential, perform activities with a significant impact on the digital value chain or socio-economic resilience, such as:

  • ICT (Information & Communication Technology) service providers
  • Data center and cloud platform operators
  • Manufacturing companies with critical digitized processes
  • Critical software providers
  • Digital intermediary operators

A key element is that NIS2 does not apply automatically to all businesses: the directive uses size criteria (e.g., number of employees, turnover) and impact criteria (e.g., critical role for public service or national chain) to determine if an organization falls into one of the categories.

To better understand if your organization falls under the scope of the NIS2 directive, consider some concrete examples: a regional public hospital or a national electricity utility are clearly classified as essential entities, given their critical function for the community.

A data center of national importance or an SaaS provider with clients in multiple EU countries falls under important entities, as they provide strategic digital services. Conversely, a small SME that does not operate in critical sectors might not be subject to it, while an IT consulting firm without critical infrastructure falls into the borderline cases, to be evaluated based on the impact of the services offered. This type of assessment is fundamental to precisely establish NIS2 compliance obligations.

Obligations under NIS2

Once you have identified that the directive applies to your organization, you need to understand what cybersecurity obligations it entails. NIS2 is not just a bureaucratic text: it establishes concrete and binding requirements with a strong focus on risk management and operational continuity.

1. Technical and organizational security measures

Every entity subject to NIS2 must prepare a set of protection measures to minimize cyber risks. These cover:

  • Access and authentication controls
  • Continuous infrastructure monitoring
  • Advanced defense technologies (IDS/IPS, EDR, XDR)
  • Backup and recovery plans
  • Isolation of critical systems

These measures must be proportionate to the nature, size, and specific risks of the organization.

2. Incident management and reporting

The directive requires the establishment of rigorous procedures for:

  • Detecting and classifying security incidents
  • Notifying significant events to competent authorities
  • Providing detailed reports within set deadlines

The goal is to ensure transparency and timeliness, so that the impact of an attack is contained and the response is coordinated.

3. Supplier assessment and supply chain management

One of the most relevant novelties is the focus on supply chain security. NIS2 mandates:

  • Supplier/third-party risk assessment
  • Minimum contractual security requirements
  • Continuous monitoring of partner security levels

This is because numerous incidents occur through vulnerabilities in supplier systems.

4. Vulnerability verification

Entities must activate processes for:

  • Regular vulnerability assessments
  • Periodic penetration tests
  • Timely fixing of identified critical issues

These controls must be documented and integrated into internal risk management processes.

5. Internal training and awareness

The human element is central to incident prevention. NIS2 requires continuous training programs for:

  • IT and cybersecurity personnel
  • Operational and managerial staff
  • Users with access to critical resources

Training must not be occasional or purely formal, but structured, periodic, and documented. Constant updates on emerging threats, common attack techniques (such as targeted phishing, social engineering, or ransomware), internal reporting procedures, and individual responsibilities are necessary.

For technical staff, training must include in-depth looks at vulnerability management, incident response, patch management, and proactive monitoring. For managers and corporate leadership, it is fundamental to understand their role in security governance and strategic decisions related to cyber risk.

For all users with access to critical systems, practical activities such as phishing simulations, incident response exercises, and periodic awareness tests are recommended. The directive values the organization’s ability to demonstrate not only the existence of training programs but also their effectiveness in concretely reducing operational risk.

6. Designation of a cybersecurity officer

A further obligation concerns the designation of an internal figure formally responsible for cybersecurity. This involves assigning a strategic role with adequate skills and real powers within the organization.

This figure must be able to coordinate all activities related to regulatory compliance, ensuring that the required technical and organizational measures are effectively implemented, monitored, and updated over time.

They must also act as a point of reference in relations with competent authorities, managing communication in the event of significant incidents and ensuring compliance with the notification timelines provided by the regulation.

In addition to this, they are called upon to oversee risk management activities, promoting a continuous assessment of cyber risks, supervising mitigation strategies, and ensuring the integration of security into corporate decision-making processes.

Deadlines for NIS2 compliance

The European NIS2 directive officially entered into force on January 16, 2023, with the obligation for all European Union member states to transpose it into their respective national laws by October 17, 2024. In Italy, this is done through a legislative decree that establishes roles, responsibilities, penalties, and implementation methods, also defining the competent authorities for supervision (e.g., ACN – National Cybersecurity Agency).

But beware: the October 2024 deadline is not a starting point, but an arrival point. Potentially subject organizations must already today begin (or have already started) a concrete path to compliance, based on:

  • Impact analysis regarding their critical activities;
  • Classification assessment (essential or important entity);
  • Regulatory gap analysis and risk assessment of the current security posture;
  • Implementation or update of technical and organizational security measures;
  • Designation of an internal cybersecurity officer;
  • Planning for incident management and notification within the provided timelines (within 24 hours of detection, as indicated by the directive);
  • Contractual and technical adjustment of the supply chain;
  • Adoption of formalized policies and mandatory training for involved personnel.

After transposition, a full application period of the rules is expected with the official start of inspections and the application of penalties, which could extend between late 2024 and early 2025, depending on the calendar and Italian implementing decrees.

In practice, those operating in critical or important sectors—such as energy, transport, health, ICT, cloud, PA, or high-intensity digital manufacturing—cannot afford to wait until the last minute. The NIS2 compliance process is complex, involves governance, compliance, IT security, and training, and requires months of work and internal coordination.

ISGroup, as a partner specialized in cybersecurity and compliance, recommends considering July 2024 as the internal deadline to complete at least the fundamental activities: risk analysis, asset mapping, appointment of representatives, and activation of minimum security measures. Only in this way will you be able to face authority inspections with awareness, avoiding operational blocks or penalties.

What are the penalties for non-compliance

One of the elements that make the NIS2 directive particularly relevant is the new sanctioning regime, which is much stricter than the previous regulation. The directive provides that national supervisory authorities have strengthened powers: they can conduct inspections, audits, and verifications even without notice, and in case of non-compliance, they are authorized to apply significant administrative penalties.

The fines are not symbolic: they are calculated taking into account the severity of the non-compliance, the recurrence of violations, the impact on essential services, and the economic size of the organization. In particularly critical situations, authorities can also impose operational limitations: for example, the temporary suspension of a critical service until the minimum required security conditions are restored.

Beyond the economic aspect, the directive also introduces individual responsibilities for corporate leadership. Figures such as the CEO, the IT manager, or the Chief Security Officer can be held personally liable in case of gross negligence, especially if this has led to significant damage or the compromise of critical infrastructure. In certain cases, civil or criminal consequences are also provided for.

This approach shifts the entire management of cybersecurity from a purely technical dimension to a strategic and organizational level. It is no longer sufficient to delegate everything to the IT department: responsibility for NIS2 compliance falls on the entire corporate structure, starting from governance. Decisions made regarding cybersecurity must be formalized, traceable, and supported by concrete evidence, such as documents, policies, internal audits, incident reports, and remediation plans.

How to prepare for NIS2: recommended actions

Preparing for NIS2 means tackling a structured process that goes beyond simple technical adjustment. The directive imposes a structural revision of how organizations manage their cybersecurity. To be compliant, it is necessary to activate a path that starts from the analysis of critical assets and processes, to reach the implementation of technical, organizational, and cultural measures fully in line with regulatory obligations.

The first step consists of a detailed mapping of relevant systems, data, and infrastructure, in order to identify what is actually critical for operational continuity. Following this, it is essential to conduct a gap analysis against NIS2 requirements, to highlight any gaps—both technical and organizational—and define a compliance roadmap based on risk priorities.

A key element of compliance is the drafting and updating of formalized security policies, which include risk management processes, access control, vulnerability management, operational continuity, business continuity, and incident response. These policies must be integrated into business processes and documented in a traceable manner, in view of future inspection activities by competent authorities.

It is also mandatory to proceed with the designation of an internal cybersecurity officer, a figure who must coordinate cybersecurity activities, manage relations with the national authority (in Italy, the ACN), and ensure compliance with notification timelines in case of incidents. Where sufficient internal skills are lacking, it is possible to resort to external figures such as the vCISO – Virtual Chief Information Security Officer, which guarantees expert governance focused on regulatory requirements.

The adoption of managed cybersecurity services, such as continuous monitoring (SOC-as-a-Service), vulnerability management, threat intelligence, and DFIR support, represents a strategic lever for many organizations, especially in the private sector. These tools allow for quickly raising the level of maturity and responsiveness of the organization in the face of the most evolved threats.

A further element provided by the directive is the need to regularly test the effectiveness of existing defenses, through penetration tests, security assessments, and attack simulations (e.g., red teaming). These tests not only serve to validate technical measures but also to train the organization’s response capabilities in the event of a real emergency.

Finally, NIS2 insists on personnel training and awareness, considered essential for building a widespread security culture. Training must involve both technical teams and all corporate staff, with programs that include threat awareness, phishing simulations, management of human errors, and safe behaviors in the use of systems.

NIS2 and GDPR: differences and synergies

It is common for the NIS2 directive to be confused with GDPR, as both regulations deal with security-related aspects, but in reality, they have distinct purposes, scopes, and approaches. The General Data Protection Regulation (GDPR) has as its primary objective the protection of personal data and the privacy of individuals, while NIS2 focuses on the protection of information systems, operational resilience, and the continuity of essential and important digital services.

The differences are also clearly visible in the scope of application: GDPR applies to any organization—public or private—that processes personal data of European Union citizens, regardless of the sector or size. Conversely, NIS2 concerns only entities and businesses that operate in sectors considered critical or important for the functioning of the country or the European economy, according to precise impact and size criteria established by the directive itself.

Despite the different purposes, there are important points of contact and operational synergies between the two regulations:

  • both require the adoption of technical and organizational measures adequate to ensure the security of the systems and data processed;
  • in the event of incidents, they provide for the obligation to notify competent authorities within precise timelines, albeit with different methods and recipients;
  • both value risk management as a structural approach, requiring continuous and traceable documentation of assessment and mitigation activities.

In essence, NIS2 emphasizes the protection of digital infrastructure and the ability to ensure service continuity even in attack scenarios, while GDPR focuses on the protection of the identity and confidentiality of natural persons. Organizations subject to both regulations must therefore integrate the requirements into their security management systems, avoiding redundancies but without neglecting adherence to both frameworks. A unified vision between cybersecurity and privacy is becoming increasingly necessary to ensure solid and sustainable compliance.

Examples and concrete application cases

Case 1 – ISGroup SRL: protection of intellectual property and digital risk management

Problem

ISGroup regularly publishes proprietary technical content of high strategic value. Over time, anomalous access and systematic attempts at unauthorized replication of the company website’s content were detected, with potential impact on intellectual property, reputation, and competitive advantage.

In a NIS2 context, the protection of information assets—even public ones—falls under structured cyber risk management and governance responsibility.

Intervention

The approach was not merely legal or communicative, but structured according to a risk management logic compliant with NIS2 principles.

A technical analysis of access was conducted, with correlation of IP addresses, verification of scraping patterns, and collection of digital evidence. Logging and tracking mechanisms were strengthened, improving evidence preservation for forensic purposes.

In parallel, an internal procedure for managing digital abuse was formalized, integrated into the security governance system. The legal message regarding copyright protection and IP monitoring was included as a deterrent measure within a broader asset protection framework.

Results obtained

The company gained greater visibility into anomalous behaviors, technical attribution capability of events, and documentary traceability of actions taken. Event management was formalized and integrated into the corporate risk management model.

Case 2 – European ICT provider: NIS2 compliance and strengthening of cybersecurity governance

Problem

An ICT service provider with public and private clients in the European sphere found itself in a situation common to many organizations potentially classified as an “Important Entity” under NIS2: technical measures present but not integrated into a formalized governance model.

The main critical issues concerned distributed logging, unstructured vulnerability management, cybersecurity responsibilities not clearly attributed, and the absence of a tested incident reporting procedure.

Furthermore, automated access and attempts at massive extraction of public content had been detected, with possible impacts on the reputation and security of services.

Intervention

ISGroup initiated a complete gap analysis against NIS2 requirements, starting from the classification of critical assets and the analysis of internal responsibilities.

A figure responsible for cybersecurity was formally designated with direct reporting to management. A centralized log system with continuous monitoring and event correlation was implemented, accompanied by a manual penetration test focused on exposed surfaces and authentication mechanisms.

The vulnerability management program was structured with risk-based priorities and defined remediation SLAs. Finally, an incident reporting procedure compliant with the timelines provided by the directive was drafted and tested, with event simulation and collection of documentary evidence.

Results obtained

The organization achieved a clear attribution of responsibilities, a significant reduction in critical vulnerabilities, and a greater capacity for early detection of anomalous events.

Above all, it acquired the ability to demonstrate—in the event of an audit or inspection by the competent authority—not only the existence of technical measures but the effective integration of cybersecurity into corporate governance.

This is the true goal of NIS2: to transform cybersecurity from an isolated technical function into a traceable and verifiable strategic responsibility.

Recommendations for choosing a partner for NIS2 compliance

Choosing the right partner for the NIS2 compliance journey is not a secondary decision: it can determine the overall effectiveness of the compliance strategy and the level of security achieved over time. The regulation requires a complex set of skills—technical, regulatory, organizational—and not all players on the market are capable of providing complete and specialized support.

A good starting point is to evaluate the provider’s direct experience in the field of cybersecurity, verifying not only the certifications obtained but also the projects managed in high-criticality contexts. It is fundamental that the partner knows the NIS2 directive in detail, knows how to interpret it in an operational key, and has already accompanied companies—perhaps in your same sector—on cyber-regulatory compliance paths.

What distinguishes a truly effective provider is the ability to combine:

  • an advanced technical vision, based on threat intelligence, governance, and risk management;
  • a solid regulatory approach, aligned with NIS2 requirements, but also integrable with other standards (e.g., GDPR, ISO 27001, DORA);
  • a structured yet flexible operational methodology that takes into account the organizational context and the digital maturity level of the client company.

When it comes to choosing a partner for NIS2 compliance, we recommend prioritizing entities that operate with internal, qualified, and stable teams because this guarantees greater confidentiality, continuity, and quality over time.

It is also important to have an interlocutor capable of covering the entire path: from governance to operational activities and incident management, up to personnel training and the definition of internal policies. Only in this way does NIS2 compliance become a coherent process and not a set of isolated interventions.

Another aspect that we consider fundamental is clarity: understandable reports, measurable indicators, concrete roadmaps, and the ability to dialogue not only with IT but also with management.

It is precisely on these principles that the approach of ISGroup is based: internal technical skills, real offensive experience, and a model oriented towards quality, not standardization.

If you want to understand better how we work and why we can be the right partner for your NIS2 compliance, you can learn more here: https://www.isgroup.biz/en/index.htmlit/perche-isgroup.html

An operational checklist for compliance

The NIS2 directive represents the new pillar of European cybersecurity. If your organization is subject—and it most likely will be—you must already today:

  • Understand your risk profile
  • Structure a strong compliance program
  • Activate advanced managed services
  • Train and empower internal resources

Related services section and conclusions

To support you on this path, ISGroup offers specialized services in cybersecurity and regulatory compliance, including:

➡️ Discover how we can help you comply with the NIS2 regulation and protect your digital infrastructure from advanced risks.

FAQ

  • Does NIS2 also apply to SMEs?
  • Yes, if the SME operates in critical sectors or provides digital services with high impact, it can be subject to the regulation.
  • What happens if I don’t comply with NIS2?
  • Administrative penalties, operational restrictions, and liability for executives are provided for.
  • How do I verify if my company is involved?
  • A regulatory gap analysis and an internal risk assessment are the first fundamental steps.
  • Who checks for NIS2 compliance?
  • The national authorities designated in your country (e.g., ACN in Italy) exercise inspection and enforcement powers.
  • Is it mandatory to appoint a security officer?
  • Yes, the directive requires internal figures with clear responsibilities for cybersecurity.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!