NIS2 in Italy — the ACN, a notice-driven phase-in, and clocks already running.
Italy transposed early: the Decreto Legislativo 138/2024 entered into force on 16 October 2024, the ACN (Agenzia per la Cybersicurezza Nazionale) opened its registration portal on 1 December 2024, and entities had to register by 28 February 2025. From April 2025 the ACN began issuing inclusion notices — and those notices start the real clocks: incident-notification obligations attached from January 2026, and the baseline security measures fall due by October 2026.
The institutional readiness is the distinctive part. The ACN already existed as a dedicated national cyber agency when NIS2 arrived, so the transposition extended a working authority with working portals rather than building one. For Italian entities the regime is not incoming — incident duties have been live since January 2026, and the measures deadline is weeks away at most, not years.
Who it applies to
Essential and important entities across the NIS2 sectors, with the ACN's notices doing the classifying: entities registered through the ACN portal, and inclusion notices issued from April 2025 confirm status and start the obligation timeline. Incident notification has applied since January 2026; the baseline security measures must be in place by October 2026 — close enough that the evidence for that deadline has to be real now, not scheduled.
The clock
Competent authority: ACN (Agenzia per la Cybersicurezza Nazionale). Transposition: Decreto Legislativo 138/2024.
| When | What happens |
|---|---|
| 16 Oct 2024 | D.Lgs. 138/2024 enters into force |
| 1 Dec 2024 | ACN registration portal opens · registration due by 28 Feb 2025 |
| Apr 2025 | ACN begins issuing inclusion notices · obligation clocks start |
| Jan 2026 | Incident-notification obligations attach |
| Oct 2026 | Baseline security measures due |
The notice starts the clock
Italy's phase-in is notice-driven: the obligations that actually bite — incident notification from January 2026, measures by October 2026 — attach to the ACN's inclusion notice, not to the law's publication date. An entity that registered in February 2025 and was notified in June 2025 has been inside the incident regime since January 2026 regardless of how it planned. That is the pattern TruSecure is built for: the notice, the classification and the resulting deadlines held as dated records on the entity, so the October 2026 measures deadline is a live countdown against evidenced controls — not a line in a compliance plan someone has to remember.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Italy transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register through the ACN portal | Entity profile · registration facts and inclusion notice held as records |
| Implement the baseline security measures by October 2026 | Control library · continuously evidenced, gap list dated |
| Report incidents — duty live since January 2026 | Incident workflow · clocked from awareness, templates per stage |
| Show management-body oversight and training | Governance workspace · approvals, training records, named owners |
| Keep evidence current for ACN supervision | Supervision export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- ACN registration
- filed · 19 Feb 2025
- Inclusion notice
- received Jun 2025 · essential, energy sector
- Incident regime
- live since Jan 2026 · drills run against the clocks
- Measures deadline
- Oct 2026 · 105/121 evidenced, 16 open with owners
- Export
- sealed · sha256:3e7a...1c8d
Where teams usually start
With a demo walked through by TruSecure — your ACN notice status confirmed, the controls you already operate mapped against the October 2026 measures deadline, and a sample incident run against the notification clocks. A Resilience Sprint produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Italy by ACN (Agenzia per la Cybersicurezza Nazionale). TruSecure determines applicability against Italy's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.