NIS2

NIS2

Sector

D.Lgs. 138/2024, Allegato I, n. 5; Allegato II, n. 5, lett. a)

Updated 23 September 2026

by Alessandro Monego

NIS2 and healthcare: who must comply and what to do

Private healthcare facilities, laboratories, pharmaceutical research and manufacturing, medical devices: who falls under D.Lgs. 138/2024.

Health is a sector of high criticality (Annex I of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition). It covers healthcare providers, such as private clinics, nursing homes, outpatient centres and laboratories, and companies doing pharmaceutical research or manufacturing, if they are medium-sized or large enterprises: important if medium-sized, essential if large. Local health authorities (ASL) follow the rules for public administrations instead.

Who is in scope

Annex I, point 5, lists:

  • healthcare providers: anyone legally providing healthcare (as defined in Directive 2011/24/EU), so private hospital and outpatient facilities, testing laboratories and diagnostic centres;
  • EU reference laboratories (Regulation (EU) 2022/2371);
  • entities carrying out research and development of medicinal products;
  • entities manufacturing basic pharmaceutical products and pharmaceutical preparations (NACE Rev. 2, division 21);
  • entities manufacturing medical devices considered critical during a public health emergency (the list under Article 22 of Regulation (EU) 2022/123).

Other manufacturers of medical devices and in vitro diagnostic medical devices are in Annex II (manufacturing, letter a): same obligations, but at most important entities. We cover them on the NIS2 and manufacturing page.

ASL (local health authorities) appear in Annex III among local administrations: they are in scope regardless of size, under the public administration regime.

Essential or important

  • large enterprise in Annex I (at least 250 employees, or turnover above €50 million and balance sheet above €43 million) → essential;
  • medium-sized enterprise (at least 50 employees, or turnover and balance sheet above €10 million) → important;
  • medium-sized or large manufacturers of non-critical medical devices (Annex II) → important;
  • small enterprise → out of scope, unless designated by ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency).

In healthcare groups, size is as a rule calculated by adding up the linked enterprises: a single small clinic can be in scope because it belongs to a group.

Specific risks and obligations

  • Health data and two notifications. An incident that exposes patient data can be both a NIS2 significant incident (type IS-1, loss of confidentiality towards the outside) and a personal data breach under the GDPR. These are two separate obligations, towards two different authorities: CSIRT Italia (Italy's national CSIRT) and the Garante (Italy's data protection authority).
  • Continuity of care. Bookings, medical records, reporting, laboratory systems: if they stop, the service stops. You need business continuity, disaster recovery and crisis management plans approved by the management bodies (ID.IM-04) and offline backups of the relevant systems with restore tests (PR.DS-11).
  • Networked equipment. Diagnostic equipment and connected devices are part of the hardware inventory (ID.AM-01, which includes IoT and OT) and must be updated, or protected if they cannot be updated (PR.PS-02, with the "justified and documented reasons" and compensating measures).
  • Sector authority: the Ministry of Health (Article 11), including for medical devices.

Deadlines

  • Registration or update on the ACN portal: every year from 1 January to 28 February. ACN publishes the list by 31 March.
  • Annual update (IP addresses and domains, management bodies, deputy point of contact, relevant suppliers): from 15 April to 31 May.
  • Categorisation of activities and services: from 1 May to 30 June.
  • Basic measures: 18 months from ACN's notice for those added to the list in 2025 (October 2026); 31 July 2027 for those added in 2026.
  • Incident notification: already in force for the 2025 cohort; from 1 January 2027 for the 2026 cohort.
  • Any change to the registered data must be reported within 14 days.

All the dates, ready to add to your calendar: NIS2 deadline calendar.

How Epic Assess helps

Epic Assess is the Mokka Studios platform for SMEs that need to comply with NIS2. It starts from the catalogue of ACN measures (43 for essential entities, 37 for important entities), shows you what is missing, keeps the deadline calendar, tracks the incident notification windows and prepares the files for the ACN portal, such as the list of relevant suppliers, in a format that follows the ACN template. The platform's proposals are drafts that you approve: compliance remains your company's decision.

Frequently asked questions

We are a private outpatient centre with 60 employees: are we in scope?

Very probably yes, as an important entity: you are a healthcare provider (Annex I) and you exceed the small-enterprise thresholds. Confirmation comes from registration on the ACN portal and the Agency's notice.

Does a theft of patient data have to be notified to CSIRT Italia or to the Garante?

Potentially to both. NIS2 requires the pre-notification (pre-notifica) to CSIRT Italia within 24 hours of evidence and the notification within 72; the GDPR requires the personal data breach to be notified to the Garante within 72 hours. It is worth having a single procedure that handles both deadlines.

We make medical devices: are we healthcare or manufacturing?

It depends on the device. If it is on the list of devices critical for public health emergencies (Regulation (EU) 2022/123) you are in Annex I, health sector; otherwise in Annex II, manufacturing, and at most an important entity.

Are ASL (local health authorities) NIS2 entities?

Yes: they are in Annex III among local administrations, in scope regardless of size. They follow the rules for public administrations, fines included.

Further reading

The pages for the other sectors:

Sources

The sources are official texts, published in Italian.