NIS2
In depth
D.Lgs. 138/2024, art. 38
Updated 23 September 2026
by Alessandro Truffo
NIS2 fines in Italy: how much is at stake and who is liable
The maximums and minimums in Article 38 of D.Lgs. 138/2024, what worldwide turnover counts for, the consequences for directors and a worked example.

In brief
For the most serious NIS2 violations, Article 38 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, sets fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities. For important entities the maximum is €7 million or 1.4%. The most serious violations concern governance, security measures and incident notification. The law also sets a minimum. On top of the fine, if the company fails to comply with a formal warning (diffida) from the ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency), the people who run it can be declared temporarily unfit to perform management functions.
Below we cover the two tiers of violations, how to read “whichever is higher”, what individuals risk and an example with made-up numbers.
The two tiers of violations
Article 38 splits violations into two groups.
First tier (paragraphs 8 and 9): breaches of the obligations of management bodies (Article 23), of the risk management measures (Article 24) and of incident notification (Article 25), plus failure to comply with the ACN's instructions and formal warnings (Article 37). The fines are:
- essential entities: up to €10,000,000 or 2% of total worldwide annual turnover in the previous financial year, whichever is higher. The minimum is one twentieth of the maximum.
- important entities: up to €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher. The minimum is one thirtieth of the maximum.
Second tier (paragraphs 10 and 11): more “administrative” violations. For example, failing to register or to update your information on the ACN platform, failing to communicate the categorisation of activities and services, or failing to cooperate with the ACN or with CSIRT Italia (Italy's national CSIRT). The fines are:
- essential entities: up to 0.1% of total worldwide annual turnover;
- important entities: up to 0.07%.
Paragraph 11 adds “without prejudice to the statutory minimums referred to in paragraph 9”. How those minimums will combine in practice with such low percentages will be clarified by the ACN's practice. For now, it is wiser not to assume that second-tier violations will be cheap.
For public administrations the amounts are fixed and different: from €25,000 to €125,000 in the first tier for essential entities, reduced by one third for important ones.
How to read “whichever is higher”
The maximum is the higher of the fixed amount and the percentage of worldwide turnover. For an SME the fixed amount almost always applies:
- 2% exceeds €10 million only with worldwide turnover above €500 million;
- 1.4% exceeds €7 million only above €500 million.
Turnover is calculated on the previous financial year, under the rules of Recommendation 2003/361/EC. So if you have linked or partner enterprises, the accounts of the single company are not the only thing that counts.
This does not mean the fine will be close to the maximum. The maximum is a ceiling. Article 34(6), referred to in Article 38, lists the factors to be taken into account. They include the seriousness and duration of the violation, previous violations, the damage caused, intent or negligence, the measures taken to limit the damage and the degree of cooperation with the ACN. The ACN can also specify through its own determinations how the amounts are calculated (Article 38(2)).
A worked example (hypothetical)
The numbers below are made up and serve only to explain the mechanism. They are not an estimate of what you would pay.
Take a fictional company, Alfa S.r.l., an important entity with €40 million of worldwide turnover in its last financial year. During a check it emerges that it has not adopted the required security measures. This is a first-tier violation.
- Maximum. 1.4% of €40 million is €560,000, less than €7 million. The fixed amount therefore applies: the maximum is €7,000,000.
- Minimum. One thirtieth of €7 million is about €233,000.
- If Alfa were an essential entity, with the same turnover the maximum would be €10 million and the minimum one twentieth, that is €500,000.
This is the arithmetic of the legal text: the minimum and maximum are calculated as above. The actual figure depends instead on the ACN's assessment of the individual case and on the tools described further on.
What directors and managers risk
NIS2 also looks at people, not only at the company.
- Liability of management bodies. They approve how the measures are implemented, oversee their application and “are liable for the violations” (Article 23). They must also follow cybersecurity training.
- Natural persons in essential entities. Anyone who represents or controls an essential entity must ensure compliance with the decree and can be held liable for non-compliance (Article 38(5)).
- Unfitness to perform management functions. If the company does not comply with an ACN formal warning within the deadline, the ACN can apply to the administrative and executive bodies, the chief executive or the legal representative of an essential or important entity the ancillary sanction of unfitness to perform management functions in that same entity. It lasts until the company brings itself into compliance (paragraph 6).
- Suspension of certificates and authorisations. For essential entities that fail to comply with a formal warning, the ACN can suspend, or have suspended, a certificate or authorisation relating to the services concerned (paragraph 4).
The point of contact registered on the ACN portal does not take on these responsibilities in place of senior management: the ACN makes this clear in FAQ PDC.3.
What pushes the bill up or down
- Repeat violations. If you repeat the same violation, the fine can be doubled. If you commit a different one, the fine for the most serious violation applies, increased up to threefold (paragraph 12).
- Failure to register, or late registration. All the violations under paragraphs 8 and 10 are charged and the most serious fine applies, increased up to threefold (paragraph 13). This is why registration on the ACN portal is the first step.
- Invitation to comply. The decree provides that the ACN, having established a non-repeated violation, may set a deadline for you to bring yourself into compliance. If you meet it, the proceedings stop. This does not apply if you have already received a formal warning (paragraph 15, letter (a)).
- Reduced payment. The proceedings can be closed by paying a reduced sum within 60 days, linked to the maximum or the minimum of the fine (paragraph 15, letter (b)).
The tools in paragraph 15 must be implemented in the manner set out in Article 40 of the decree: before relying on them, check how the ACN applies them.
How a fine comes about
Fines follow supervisory activity. Under Article 36 and the ACN FAQs on monitoring and supervision, essential entities can be checked even without any suspicion, through document checks, on-site or remote inspections and random checks. Important entities are checked only when the ACN receives information suggesting a violation. Formal warnings and fines are separate powers: using enforcement powers, such as formal warnings, does not prevent the ACN from charging the violations (Article 38(3)).
In a check, what counts is what you can demonstrate. That is why we suggest you also read the guide to evidence for ACN inspections and the one on the basic measures.
Where Epic Assess can help
Epic Assess helps you keep in order what the ACN may ask you for: the status of the measures, policies approved by the management bodies, evidence, the incident register with the notification windows, and annual deadlines. It does not remove the risk of fines and does not guarantee compliance: it makes it easier to demonstrate what you have done.
Sources
The sources are official texts, published in Italian.
- D.Lgs. 138/2024, Article 38 (sanctions)
- D.Lgs. 138/2024, Article 23 (management bodies)
- D.Lgs. 138/2024, Article 36 (checks and inspections)
- ACN, FAQ “Monitoraggio, vigilanza ed esecuzione” (monitoring, supervision and enforcement)
- ACN, FAQ “Ruoli e procedure” (roles and procedures) (PDC.3)
- Recommendation 2003/361/EC on the definition of SMEs