Skip to main content
NIS2 · ITALY

NIS2 in Italy — the ACN, a notice-driven phase-in, and clocks already running.

Italy transposed early: the Decreto Legislativo 138/2024 entered into force on 16 October 2024, the ACN (Agenzia per la Cybersicurezza Nazionale) opened its registration portal on 1 December 2024, and entities had to register by 28 February 2025. From April 2025 the ACN began issuing inclusion notices — and those notices start the real clocks: incident-notification obligations attached from January 2026, and the baseline security measures fall due by October 2026.

The institutional readiness is the distinctive part. The ACN already existed as a dedicated national cyber agency when NIS2 arrived, so the transposition extended a working authority with working portals rather than building one. For Italian entities the regime is not incoming — incident duties have been live since January 2026, and the measures deadline is weeks away at most, not years.

Who it applies to

Essential and important entities across the NIS2 sectors, with the ACN's notices doing the classifying: entities registered through the ACN portal, and inclusion notices issued from April 2025 confirm status and start the obligation timeline. Incident notification has applied since January 2026; the baseline security measures must be in place by October 2026 — close enough that the evidence for that deadline has to be real now, not scheduled.

The clock

Competent authority: ACN (Agenzia per la Cybersicurezza Nazionale). Transposition: Decreto Legislativo 138/2024.

NIS2 in Italy · timeline
WhenWhat happens
16 Oct 2024D.Lgs. 138/2024 enters into force
1 Dec 2024ACN registration portal opens · registration due by 28 Feb 2025
Apr 2025ACN begins issuing inclusion notices · obligation clocks start
Jan 2026Incident-notification obligations attach
Oct 2026Baseline security measures due

The notice starts the clock

Italy's phase-in is notice-driven: the obligations that actually bite — incident notification from January 2026, measures by October 2026 — attach to the ACN's inclusion notice, not to the law's publication date. An entity that registered in February 2025 and was notified in June 2025 has been inside the incident regime since January 2026 regardless of how it planned. That is the pattern TruSecure is built for: the notice, the classification and the resulting deadlines held as dated records on the entity, so the October 2026 measures deadline is a live countdown against evidenced controls — not a line in a compliance plan someone has to remember.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Italy transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Italy requirements · how TruSecure answers them
What the law asksWhere it is answered
Register through the ACN portalEntity profile · registration facts and inclusion notice held as records
Implement the baseline security measures by October 2026Control library · continuously evidenced, gap list dated
Report incidents — duty live since January 2026Incident workflow · clocked from awareness, templates per stage
Show management-body oversight and trainingGovernance workspace · approvals, training records, named owners
Keep evidence current for ACN supervisionSupervision export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Italy NIS2 readiness file · excerptSample data
ACN registration
filed · 19 Feb 2025
Inclusion notice
received Jun 2025 · essential, energy sector
Incident regime
live since Jan 2026 · drills run against the clocks
Measures deadline
Oct 2026 · 105/121 evidenced, 16 open with owners
Export
sealed · sha256:3e7a...1c8d

Where teams usually start

With a demo walked through by TruSecure — your ACN notice status confirmed, the controls you already operate mapped against the October 2026 measures deadline, and a sample incident run against the notification clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Italy by ACN (Agenzia per la Cybersicurezza Nazionale). TruSecure determines applicability against Italy's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

Has Italy already transposed NIS2?
Yes — Italy transposed NIS2 via Legislative Decree 138/2024, in force since October 2024, among the earlier member states to do so alongside Belgium and Croatia.