Italy’s NIS2 Decree Makes Registration the First Compliance Test
Italy’s NIS2 implementation begins with a deceptively simple question: has the organisation correctly identified itself, its services and the entities connected to it before it tries to prove the quality of its controls?
Legislative Decree No. 138 of 4 September 2024 was published on 1 October and entered into force on 16 October 2024. It transposed the NIS2 Directive and designated the National Cybersecurity Agency, ACN, as the central competent authority and single point of contact, alongside sectoral cooperation.
The decree broadens the sectors and entities subject to national cybersecurity duties. It also creates a formal identification and registration process. That administrative step is strategically important because a poor scope decision contaminates everything that follows.
Scope is a service map, not an industry label
NIS2 distinguishes essential and important entities across highly critical and other critical sectors. Size is a major part of the default rule, but special cases and sector definitions matter. An organisation may provide multiple services, operate through subsidiaries or support a regulated activity from a shared technology company.
The Italian framework requires entities that believe they fall within scope to use ACN’s digital platform during the annual registration window and provide prescribed information. ACN then develops the list of covered entities and communicates classification.
An accurate filing depends on corporate, service and technical knowledge. Legal should not complete it from a company registration extract alone. The team should map legal entities to the services they provide, where those services operate, and which networks and systems support them.
Registration creates a maintained record
Names, addresses and contacts are not static compliance data. A merger, new managed service, reorganisation or change of security contact can alter the record and the organisation’s obligations. The registration process therefore needs an owner and a change trigger.
A useful evidence pack includes the scope analysis, employee and financial data used for size assessment, service descriptions, special inclusion or exclusion reasoning, platform submission and subsequent ACN communications. It should also identify who must update the information and within what period when facts change.
This is particularly important for corporate groups. A central security team can coordinate the work, but each legal entity’s role needs to remain visible. One group-level registration assumption should not silently erase a regulated subsidiary.
Management responsibility is operational
The decree makes governing bodies responsible for approving cybersecurity risk-management measures and overseeing their implementation. Members must receive training, and entities must encourage appropriate training for staff.
Board approval should therefore be tied to concrete information: the services in scope, significant risks, control maturity, supplier dependencies, incidents and funded remediation. A slide stating that the organisation “aligns with NIS2” does not show oversight.
Management also needs to understand the reporting model. Significant incidents require an early warning, incident notification and final reporting on the NIS2 timetable, with ACN acting through CSIRT Italia. The first alert may be due before impact is fully understood, so the reporting threshold and authority to act must be embedded in the incident plan.
Suppliers belong in the control story
Risk-management measures include supply-chain security, vulnerability handling, business continuity, access control, cryptography and multi-factor authentication where appropriate. These are not independent checkboxes.
If a managed-service provider administers identities, hosts backups and monitors alerts, one supplier affects several statutory measures at once. The entity needs contractual rights, technical visibility and tested escalation. It should know which provider evidence it can rely on and which controls remain its own responsibility.
Procurement should request service-specific evidence rather than a pile of certificates. The relevant questions are whether the regulated service can be restored, whether privileged access is controlled, whether material vulnerabilities are disclosed and whether the supplier can meet the customer’s reporting clock.
The first compliance review
An organisation should be able to answer:
- Which legal entities and services were assessed for scope?
- What evidence supports the essential or important classification?
- Is the ACN registration current, with monitored contacts?
- Which systems and suppliers support each regulated service?
- What did management approve, and how is implementation tracked?
- Can the incident team produce the early warning with incomplete facts?
Italy’s decree makes registration the opening control because it forces the organisation to define what it is protecting. That definition should become the spine of the NIS2 programme, connecting legal scope to services, systems, suppliers, reporting and management oversight.
Official sources
- Italian Official Gazette: Legislative Decree No. 138 of 4 September 2024
- Italian Official Gazette: authenticated issue of 1 October 2024
Continue the series
- Also in Italy: Italy’s Law 90/2024 Connects Public-Sector Deadlines to Cybercrime Enforcement
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.


