Resources

NIS2

Guide

Det. ACN 379907/2025

Updated 23 September 2026

by Alessandro Monego

How to choose NIS2 software for an SME

The criteria that really matter, an honest comparison of consultants, kits, international platforms and Italian platforms, and the questions to ask in a demo.

Who is writing and why

This article is written by the team at Mokka Studios, which develops Epic Assess, a NIS2 platform. So we are not neutral. That is why you will not find rankings or a “best” here: you will find the criteria we would use, a comparison by category and a section on when Epic Assess is not the right choice. The facts about other vendors come from their websites, accessed on 22 September 2026. If something has changed, write to us and we will correct it.

In brief

NIS2 software for an Italian SME must work on the basic measures of the ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency), not just on the European directive. It must be in Italian, produce evidence you can show during a check and handle incidents and suppliers according to the Italian rules. It must also have a price you understand before you sign. No software makes you compliant on its own: it organises the work, but the decisions and approvals remain yours and your directors'.

The criteria that matter

  • ACN measures, not just the directive. In Italy the concrete requirements are in ACN Determination 379907/2025: 43 measures and 116 requirements for essential entities, 37 measures and 87 requirements for important entities. Ask to see the requirement, not just the directive's “area”. Also ask whether the version changes depending on your category (see the ACN basic measures).
  • Precise legal references. Articles of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, and ACN determination numbers, updated when ACN publishes a new text.
  • Italian language. Interface, document templates and support. Policies must be approved by your board of directors: they must be readable by the people who sign them.
  • Evidence and an inspection package. Every requirement must lead to a document or a piece of evidence, with a date and an approval. Ask to see what you export for a check (see evidence for ACN inspections).
  • Incident management. The 24-hour pre-notification (pre-notifica, the early warning), the notification within 72 hours and the final report within one month, sent to CSIRT Italia (Italy's national CSIRT) (Article 25). You need a workflow that tells you what to write and when (see the notification guide).
  • Suppliers. Security questionnaires and the list of relevant suppliers with the five fields and the CPV codes that ACN requires.
  • Obligations on the ACN portal. Registration, the annual update and categorisation are done on the ACN digital platform. Ask which data the software prepares for you and in what format.
  • Pricing model. Per company, per user or per asset? Are there set-up fees or a minimum term? How much does the second year cost?
  • Exit. Can you export documents and evidence in open formats if you change tool?
  • Honesty about AI. If the software “writes the policies”, ask who reviews them and how you can see the difference between a draft and an approved text.

The four routes compared

There is no single right route for everyone. Here are the pros and cons of each.

1. The consultant. A consultancy firm or an IT integrator does the analysis, writes the documents and often also works on the technical side.

  • Pros: takes work off your hands, knows your context, can also handle firewalls, backups and other technical tasks.
  • Cons: high and hard-to-predict cost. The estimates published by the firms themselves range from a few thousand euros for an initial analysis to tens of thousands for the first year (see how much compliance costs). In addition, the work has to be maintained every year.

2. Document kits and packaged software. Document templates, spreadsheets or small software tools you use on your own.

  • Pros: low, known price. For example, Edirama sells a kit of six software tools for NIS2 inspections for €1,200 plus VAT, a discounted price seen on the website on 22 September 2026. Its software tool for relevant suppliers cost €399 on the same day.
  • Cons: you do the work. Separate tools do not talk to each other, and updates, deadlines and approvals have to be managed by hand.

3. International GRC platforms. Multi-framework compliance software built for ISO 27001, SOC 2 and similar standards, which has added NIS2.

  • Pros: mature products, often with technical integrations and continuous monitoring. For example, Vanta states that it offers automated tests, continuous monitoring and expert support for NIS 2. Formalize states that it has more than 8,000 client companies in over 80 countries, and pages in Italian.
  • Cons: the starting point is the European directive. Check how they translate the 43 or 37 ACN measures, the Italian time windows and the obligations on the ACN portal. They are often designed for larger companies, with prices on request.

4. Italian NIS2 platforms. Products built on D.Lgs. 138/2024 and the ACN determinations.

  • Pros: Italian legal references, language, ACN obligations. For example, Teseo Toolkit states that it offers exports for relevant suppliers (with over 400 CPV codes and VIES checks, the EU VAT number validation system), for categorisation and for domains and IP addresses, as well as management of multiple companies. TechLabItalia's NIS2 Platform states that it is among the suppliers for the MIMIT (Italy's Ministry of Enterprises and Made in Italy) voucher for cloud and cybersecurity.
  • Cons: they are young products, like ours, because the ACN rules are recent. Many do not publish their price. Ask how long they have been on the market, how they update when a new determination comes out and what they do not do.

Where Epic Assess fits

Epic Assess is an Italian NIS2 platform, so it falls into the fourth category. In short, facts and limits:

  • it contains the text of the ACN measures requirement by requirement, in the version for essential entities and for important entities, linked to the lettered points of Article 24;
  • it links each requirement to policies and evidence. Draft policies must be completed, reviewed and approved by you;
  • it manages incidents with the 24-hour, 72-hour and one-month windows, suppliers with VIES checks and questionnaires, and an export that follows the ACN template for relevant suppliers. It is not an official ACN template;
  • it prepares a package to show in the event of an inspection;
  • it is in Italian, with support in Italian;
  • it does not have a public price: there is a single plan, with a price tailored to each company that we set in a call;
  • it is not certified or approved by ACN and does not guarantee compliance.

When Epic Assess is not the right choice

  • You want someone to do the work for you. A platform organises, but you need someone in the company to decide and approve. If you have nobody, start with a consultant.
  • You need the technical side. Epic Assess does not install firewalls or EDR, does not run vulnerability scans and does not monitor the network. For that you need an IT or security provider.
  • Your budget is a few hundred euros. A document kit costs less. Just factor in the time you will spend on it.
  • Your main goal is a certification such as ISO 27001 or SOC 2. A platform built for those certifications might be more useful to you.
  • You are not a NIS entity, but a supplier that has to answer a client's questionnaire. Often you need less than a full platform (see “Your client asks you for NIS2”).
  • You want to buy online straight away at a list price. With us that is not possible today: the price is set in a call.

The questions to ask in every demo

  1. Can you show me requirement 2 of measure PR.AA-03 in the version for my type of entity?
  2. When ACN replaced Determination 164179/2025 with 379907/2025, what changed in the product, and when?
  3. What do I export for an inspection, and in what format?
  4. How does incident notification work at 3 a.m. on a Saturday?
  5. How do I prepare the list of relevant suppliers, with one row per CPV code?
  6. How much do I pay in the first and the second year, and what happens to my data if I stop?

Ask everyone the same questions, us included.

Sources

The official texts and most of the vendor pages are published in Italian.