NIS2
Guide
Legislative Decree 138/2024
NIS2, explained without the jargon.
Understand whether it applies to you, what you have to do and by when - in plain language, no legalese.

What NIS2 is
NIS2 (Legislative Decree 138/2024) raises the minimum cybersecurity bar for companies and public bodies in critical sectors. Those in scope must adopt security measures, report incidents and be able to prove they did so if inspected.
Who is in scope
- Essential entities: Typically large companies in highly critical sectors: energy, transport, healthcare, digital infrastructure. A broader catalogue of measures.
- Important entities: Mid-sized companies in those sectors, plus companies in other critical sectors such as manufacturing and digital services. Proportionate obligations.
The path
A guided path in 6 steps: from your company data to an inspection-ready pack.
- Profile and classification
Enter your company data: we work out whether you’re an essential or important entity and which measures you must adopt. - Processes and assets
Map what the organisation does and what you have to protect, so it’s clear how much each asset matters. - Risks and measures
For each risk you link the ACN measure that covers it, with source and rationale behind the choice. - Documents and policies
Prepare policy drafts from your data, for the management bodies to review and approve. - Operations and incidents
Collect evidence, keep recurring deadlines under control and prepare CSIRT notifications within the legal deadlines. - Inspection pack
An always-up-to-date index, ready to show: no archives assembled at the last minute.
What’s at stake
Fines up to €10 million or 2% of worldwide annual turnover, whichever is higher (€7 million / 1.4% for important entities). Management bodies are personally accountable and, if the company ignores an ACN warning order, can be suspended from their management functions.
The deadlines
- Registration on the ACN platform in the annual windows (January–February).
- Incident notification capability operational within 9 months and security measures adopted within 18 months of the ACN communication.
Source: Legislative Decree 138/2024 (transposition of EU Directive 2022/2555).