NIS2

NIS2

Sector

D.Lgs. 138/2024, Allegato I, n. 2; Allegato IV, n. 1

Updated 23 September 2026

by Alessandro Truffo

NIS2 and transport: who must comply and what to do

Air, rail, water, road and local public transport: who falls under D.Lgs. 138/2024 and who, often to their surprise, does not.

Transport is a sector of high criticality (Annex I of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition), but the list is precise: air carriers, airports, air traffic control, railways, shipping companies, ports and operators of road traffic management and intelligent transport systems. Medium-sized companies are important, large ones essential. Road haulage of goods and logistics, as such, are not on the list.

Who is in scope

Annex I, point 2, has four subsectors:

  • Air transport: air carriers used for commercial purposes; airport managing bodies and airports, including entities operating ancillary installations at airports; operators providing air traffic control services;
  • Rail transport: infrastructure managers; railway undertakings, including operators of service facilities;
  • Water transport: inland, sea and coastal passenger and freight water transport companies (not the individual vessel); port managing bodies, with their port facilities and the entities operating works and equipment within ports; operators of vessel traffic services (VTS);
  • Road transport: road authorities responsible for traffic management control (excluding public entities for which this is a marginal activity); operators of intelligent transport systems (ITS).

Then there is Annex IV, point 1: entities providing local public transport services. They are in scope regardless of size, but only if identified by ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) on a proposal from the sector authority (Article 3(8) and (13)).

Essential or important

  • large enterprise (at least 250 employees, or turnover above €50 million and balance sheet above €43 million) → essential;
  • medium-sized enterprise (at least 50 employees, or turnover and balance sheet above €10 million) → important;
  • small enterprise → out of scope, unless designated by ACN.

For local public transport identified by ACN, the Agency sets the category (Article 6(2)). Local public transport companies owned or controlled by public bodies also face fixed-amount fines, like public administrations (Article 38(9)(c) and (d)).

Specific risks and obligations

  • Services that depend on availability. Ticketing, bookings, passenger information, fleet management: these are the services where an outage immediately becomes a significant incident. To notify it you must have defined the expected service levels beforehand (DE.CM-01): a breach of those levels is type IS-3.
  • On-board and ground systems. The hardware inventory includes IoT, OT and mobile devices (ID.AM-01): ticket validators, tracking systems, signalling equipment managed by the company.
  • Technology suppliers. Many services (ITS, electronic ticketing, cloud) are outsourced: they must be listed, assessed and contracted with security requirements (GV.SC-04, GV.SC-05, GV.SC-07), and the relevant suppliers must be reported to ACN every year.
  • Sector authority: the Ministry of Infrastructure and Transport, including for local public transport (Article 11).

Deadlines

  • Registration or update on the ACN portal: every year from 1 January to 28 February. ACN publishes the list by 31 March.
  • Annual update (IP addresses and domains, management bodies, deputy point of contact, relevant suppliers): from 15 April to 31 May.
  • Categorisation of activities and services: from 1 May to 30 June.
  • Basic measures: 18 months from ACN's notice for those added to the list in 2025 (October 2026); 31 July 2027 for those added in 2026.
  • Incident notification: already in force for the 2025 cohort; from 1 January 2027 for the 2026 cohort.
  • Any change to the registered data must be reported within 14 days.

All the dates, ready to add to your calendar: NIS2 deadline calendar.

How Epic Assess helps

Epic Assess is the Mokka Studios platform for SMEs that need to comply with NIS2. It starts from the catalogue of ACN measures (43 for essential entities, 37 for important entities), shows you what is missing, keeps the deadline calendar, tracks the incident notification windows and prepares the files for the ACN portal, such as the list of relevant suppliers, in a format that follows the ACN template. The platform's proposals are drafts that you approve: compliance remains your company's decision.

Frequently asked questions

We are a road haulage company: does NIS2 concern us?

Not as part of the transport sector: the road subsector of Annex I covers only road authorities that manage traffic and operators of intelligent transport systems. Do check the other sectors, though: courier services fall under postal and courier services (Annex II). And if you work for NIS2 customers, their requests will arrive all the same.

We run local public transport: are we automatically in scope?

No, not automatically. Local public transport is in Annex IV: it is in scope regardless of size, but only if ACN identifies you, on a proposal from the Ministry of Infrastructure and Transport, and notifies you.

Is a company that runs a service inside an airport in scope?

It can be: Annex I covers entities operating ancillary installations located at airports and, in ports, those operating works and equipment. The size threshold still applies: below a medium-sized enterprise, as a rule, no.

Do we also have to notify a failure, not just an attack?

Yes, if it falls under a type of significant incident. Under the decree an incident is any event that compromises availability, integrity, authenticity or confidentiality, even accidentally. An outage that breaches the expected service levels is an IS-3 incident.

Further reading

The pages for the other sectors:

Sources

The sources are official texts, published in Italian.