NIS2
Sector
D.Lgs. 138/2024, Allegato I, nn. 8 e 9; Allegato II, n. 6
Updated 23 September 2026
by Alessandro Truffo
NIS2 for ICT, cloud and MSPs: who must comply and what to do
Cloud, data centres, telcos, DNS, managed services and managed security services: the sector where NIS2 looks least at size and where customers ask the most.

Digital infrastructure and ICT service management are highly critical sectors (Annex I to Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, points 8 and 9). If you are a medium-sized or large cloud provider, data centre or MSP, NIS2 applies to you: important if medium-sized, essential if large. Telecommunications operators, trust services, registries and DNS providers are covered regardless of size.
Who is in scope
Digital infrastructure (Annex I, point 8): internet exchange point (IXP) providers; DNS service providers (excluding root name servers); top-level domain (TLD) name registries; cloud computing service providers; data centre service providers; content delivery network (CDN) providers; trust service providers; providers of public electronic communications networks and of publicly available electronic communications services.
ICT service management, B2B (Annex I, point 9): managed service providers (MSPs) and managed security service providers (MSSPs). For the decree an MSP provides services related to the installation, management, operation or maintenance of customers' ICT products, networks, infrastructure or applications, through assistance or active administration, on the customer's premises or remotely (Article 2(iii)).
Digital providers (Annex II, point 6): online marketplaces, online search engines, social networking service platforms, domain name registration service providers.
Essential or important
Here the rules are the most detailed in the decree:
- cloud, data centres, CDN, IXP, MSP, MSSP: general rule. Large → essential; medium-sized → important; small → out, unless designated by ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency);
- qualified trust services, TLD registries, DNS providers → essential regardless of size;
- public electronic communications networks and services: in scope regardless of size; essential from medium-sized enterprise upwards, otherwise important;
- non-qualified trust services: in scope regardless of size; essential if large, otherwise important;
- digital providers (Annex II): medium-sized and large → important. Those that only register domain names are in scope regardless of size, but do not have the obligations of Articles 24 and 25 (Article 32(3)).
Jurisdiction: DNS, TLD, registrars, cloud, data centres, CDN, MSP, MSSP and digital providers fall under the Member State of their main establishment in the EU, where cybersecurity decisions are taken (Article 5).
Specific risks and obligations
- You hold your customers' keys. An MSP with administrative access to its customers' systems is one target worth many targets. The ACN measures require individual, recorded accounts (PR.AA-01), multi-factor authentication on the relevant systems (PR.AA-03), separation between administrative and ordinary accounts (PR.AA-05), and documented, logged remote access (PR.IR-01, PR.PS-04).
- You are everyone else's "ICT supplier". Every NIS2 entity must report its relevant suppliers to ACN, and a supply covered by Annex I, points 8 and 9, is an "ICT supply" by definition. Expect questionnaires, contract clauses and periodic checks (GV.SC-05, GV.SC-07) from every NIS2 customer.
- Vulnerabilities and development. A vulnerability management plan approved by the management bodies (ID.RA-08), timely updates (PR.PS-02), secure development practices if you develop software (PR.PS-06).
- In groups: a linked enterprise that provides ICT or security services to a NIS entity in the group is covered regardless of size (Article 3(10)).
- Sector authority: the Ministry of Enterprises and Made in Italy (MIMIT) for digital infrastructure and digital providers; the Presidency of the Council of Ministers, with ACN, for ICT service management (Article 11).
Deadlines
- Registration or update on the ACN portal: every year from 1 January to 28 February. For DNS, TLD, registrars, cloud, data centres, CDN, MSP, MSSP and digital providers the first registration was set for 17 January 2025 (Article 42).
- Annual update (IP addresses and domains, management bodies, deputy point of contact, relevant suppliers, establishments in the EU): from 15 April to 31 May.
- Categorisation of activities and services: from 1 May to 30 June.
- Basic measures: 18 months from ACN's notice for those added to the list in 2025 (October 2026); 31 July 2027 for those added in 2026.
- Incident notification: already in force for the 2025 cohort; from 1 January 2027 for the 2026 cohort.
- Any change to the registered data must be communicated within 14 days.
All the dates, ready to add to your calendar: NIS2 deadline calendar.
How Epic Assess helps
Epic Assess is the Mokka Studios platform for SMEs that need to comply with NIS2. It starts from the catalogue of ACN measures (43 for essential entities, 37 for important entities), shows you what is missing, keeps the deadline calendar and tracks the incident notification windows. For those who provide ICT services to NIS2 customers there is also the Trust Center: a public page with the policies you have adopted, to share instead of answering from scratch every time. The platform's proposals are drafts that you approve: compliance remains your company's decision.
Frequently asked questions
We are a software house: are we an MSP?
It depends on what you do. If you install, manage, operate or maintain customers' systems and applications with active administration, even remotely, you fall within the definition of managed service provider. If you develop and sell licences without managing customers' systems, as a rule no. If in doubt, start from the definition in Article 2(iii).
We are a small MSP with 20 employees: does NIS2 not concern us?
As an entity, as a rule no: managed services follow the size rule. But your NIS2 customers will list you as a relevant ICT supplier and ask you for contractual guarantees. And ACN can identify systemic elements of the supply chain as NIS entities (Article 3(9)(f)).
Is a small telecommunications operator out because it is small?
No. Providers of public electronic communications networks and publicly available services are in scope regardless of size: below medium-sized they are important, from medium-sized upwards essential.
Further reading
- Your client asks you for NIS2: what to do if you are a supplier
- NIS2 relevant suppliers: how to compile the list for ACN
- NIS2 deadline of October 2026: what you need to have ready
The pages for the other sectors:
Sources
The sources are official texts, published in Italian.