YOUR
Search

    02.10.2024

    NIS2 is ready to go!


    Article by Giulio Uras, Francesco Fidel Camera e Matteo Pagliarulo.

    Legislative Decree No. 138/2024 (“NIS2 Decree”), transposing Directive (EU) 2022/2555, known as the “NIS2 Directive” was published in the Official Gazette.

    The NIS2 Decree, in addition to repealing Legislative Decree No. 65/2018 – which transposed Directive 2016/1148, the so-called NIS Directive –also provided for the repeal of Articles 40 (“Security of networks and services”) and 41 (“Implementation and control”) of Legislative Decree No. 259/2003 (“Electronic Communications Code”), with the consequence that now providers of public electronic communications networks or publicly available electronic communications services are subject only to the provisions set out in the NIS2 Decree.

    To whom does it apply?

    The NIS2 Decree applies to both public and private entities operating in “critical” sectors (e.g. energy, transport, banking, healthcare, digital infrastructure, space, waste management, manufacturing of medical devices, machinery, motor vehicles, etc.). 

    Moreover, the obliged entities are distinguished into “essential” and “important”, according to their importance for the sector or type of services they provide, as well as their size. Belonging to one or the other category is relevant for the application of sanctions in the event of breach of the obligations under the NIS2 Decree, which are higher for essential entities (equal to a maximum of at least EUR 10 million or a maximum of at least 2% of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher).

    What are the obligations?

    The main obligations incumbent on the obliged parties are the adoption of IT security risk management measures and the notification of significant incidents.

    With regard to the obligations in the area of IT security risk management, essential and important entities are required to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the information and network systems used in their activities or in the provision of their services. 

    With regard to reporting obligations, the NIS2 Decree requires essential and important entities to notify the CSIRT (Computer Security Incident Response Team) of incidents that have a significant impact on the provision of their services. 

    Notification is phased and involves: a pre-notification within 24 hours of the incident, the actual notification within 72 hours of the incident, and a final report within 1 month of the notification.

    Both IT security risk management and reporting obligations will be set in detail (also with regard to terms, modalities, specifications and gradual implementation timeframes) by the NCA (National Cybersecurity Authority), through its own decisions based on gradualness and proportionality criteria.

    The responsibility for ensuring compliance with the obligations laid down in the NIS2 Decree lies with administrative and management bodies of essential and important entities, which are responsible for breach of the NIS2 Decree.

     

    For more information, see our Guide on Cybersecurity (updated in accordance with NIS2 Decree, CER Decree and the Cybersecurity Law) or contact our dedicated professionals.

    Raffaele Giarda joins ADVANT Nctm as new Partner
    ADVANT Nctm announces that Raffaele Giarda has joined the Firm as…
    Read more
    2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace
    On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian…
    Read more
    AI Enters Trade Secret Protection
    On 10 June 2026, the Italian Council of Ministers approved two draft legislative…
    Read more
    Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)
    The context and purpose of the National Space Policy Strategic Document…
    Read more
    Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation
    The football club as a data ecosystem (and as a media company) From a personal…
    Read more
    Tracking pixels in e-mails: the Data Protection Authority's new rules
    1. Introduction By Order No. 284 of 17 April 2026, published in the Official…
    Read more
    THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS
    The context and structure of the Guidelines Regulation (EU) 2024/1689 (“AI…
    Read more
    WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?
    Summary of the judgement On 18 March 2026, the Court of Rome annulled in its…
    Read more
    Cyber Resilience Act: the countdown has started
    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European…
    Read more