NIS2
Glossary
art. 24 D.Lgs. 138/2024
Updated 23 September 2026
by Alessandro Monego
Article 24: risk management measures
Article 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, requires essential and important entities to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems, and sets ten elements that these measures must cover as a minimum.
The ten elements
Paragraph 2 lists them, with an "all-hazards" approach (theft, fire and power cuts too):
- a) risk analysis and information system security policies;
- b) incident handling, including the notification procedures;
- c) business continuity: backups, disaster recovery, crisis management;
- d) supply chain security;
- e) security in the acquisition, development and maintenance of systems, including vulnerability handling;
- f) assessment of the effectiveness of the measures;
- g) basic cyber hygiene and training;
- h) cryptography and encryption;
- i) personnel security, access control, asset management;
- l) multi-factor authentication, secured communications and emergency communication systems.
There are ten letters even though the last one is "l": the Italian alphabet used in the text has no j and no k.
In practice
Article 24 says *what* to cover, not *how*. The how is set by the basic measures of ACN (Italy's National Cybersecurity Agency): the Agency's reading guide (Appendix A) shows which measures cover each letter. Paragraph 4 adds an often forgotten obligation: if you find that you are not compliant, you must adopt the corrective measures without undue delay. A documented remediation plan is the way to prove it.
Failure to comply with Article 24 is among the breaches punished with the highest fines of Article 38(9).
Legal reference
Article 24 of D.Lgs. 138/2024 (transposing Article 21 of Directive (EU) 2022/2555); Article 38(8)(a).
Related terms
Further reading
Sources
The sources are official texts, published in Italian.