Back to blog
NIS2

NIS2 in Italy: "Compliant on Paper" Won't Survive October

Italy's NIS2 deadline lands at the end of October 2026, and it's forcing a decision most organizations have been putting off. Legislative Decree 138/2024 requires organizations notified as in-scope by ACN to have their basic security measures fully in place by then. That's splitting the market into two clear camps.

18.09.26
8'
Laura Santeusanio

Laura Santeusanio

Regional Director Southern Europe

An international executive with 20+ years of experience driving business growth, market expansion, and transformation across Europe. Proven General Manager skilled in scaling operations, building high-performing teams, and executing strategy to deliver measurable results.

Key takeaways:

  • Italy's NIS2 deadline lands at the end of October 2026, when in-scope organizations need basic security measures fully in place.

  • The market has split into two camps: organizations that treated the deadline as a formal exercise, and those using it to actually modernize how compliance work gets done.

  • The real gap isn't on paper. A spreadsheet can show a control exists. It's much worse at showing who owns it, when it was last checked, and what happens the next time something changes.

  • NIS2 won't be the last framework on the desk. Building a real operating habit now, ownership, evidence, recurring reviews, sets up the DORA, ISO 27001, and GDPR work still to come.

Organizations that registered, documented, and checked the box are in one camp. Organizations that used the deadline as a reason to actually modernize how compliance work gets done are in the other. Both camps can look identical on paper. The difference shows up the moment a supervisory audit, a supply chain review, or an actual incident asks for evidence, not just a policy document.

The operational reality behind the paperwork

NIS2 didn't just add a new checklist. It added a volume of ongoing work most teams haven't sized correctly: ten categories of security measures under Article 24, a three-stage incident reporting cascade (a 24-hour early warning, a 72-hour detailed notification, and a final report within one month, all routed through CSIRT Italia), and supply chain oversight that extends to suppliers most organizations never formally tracked before.

A surprising number of organizations are still running this on email threads and Excel. That works, for a while, when the obligation is a one-time registration. It stops working once the obligation becomes a continuous operating rhythm: incidents that need reporting on a deadline, supplier reviews that need repeating annually, evidence that needs to exist before an auditor asks for it, not assembled afterward.

That's the real gap between "compliant on paper" and "not vulnerable in practice." A spreadsheet can show that a control exists. It's much worse at showing who owns it, when it was last checked, and what happens the next time something changes.

The 10 security measures Article 24 actually requires

Article 24 of Legislative Decree 138/2024 transposes Article 21 of the EU NIS2 Directive directly. Every in-scope organization needs to cover all ten categories, proportionate to its own risk profile:

#

Measure category

1

Risk analysis and information system security policies

2

Incident handling

3

Business continuity: backup management, disaster recovery, crisis management

4

Supply chain security, including direct suppliers and service providers

5

Security in the acquisition, development, and maintenance of systems, including vulnerability handling

6

Policies to assess the effectiveness of risk management measures

7

Basic cyber hygiene practices and cybersecurity training

8

Policies on cryptography and encryption

9

Human resources security, access control, and asset management

10

Multi-factor authentication and secured emergency communications

"Proportionate to risk" is doing real work in that sentence. It doesn't mean smaller organizations can skip categories. It means the depth of each measure should match actual exposure, and that judgment needs to be documented and defensible, not assumed.

Why this decision matters beyond October

NIS2 is unlikely to be the last framework on an Italian compliance team's desk. DORA already applies to financial entities. ISO 27001 keeps coming up in procurement requirements. The GDPR never left. Organizations that build a real operational habit around NIS2, ownership, evidence, recurring reviews, on one platform rather than one more spreadsheet, aren't just solving October's problem. They're building the foundation the next framework will need anyway.

See your gap before the deadline does

Explore Formalize's NIS2 compliance platform to see how a real operational setup replaces the spreadsheet, or book a demo to walk through your own gap before the deadline does it for you.

Book a demo
Try for free

Treated this way, compliance stops being a cost center that shows up once a year and becomes part of how the organization is actually governed: something a board can see the state of, not just something a compliance officer can attest to.

Where to start before the deadline

Picking a side doesn't require solving everything before October. It requires an honest answer to one question: if an auditor, a regulator, or an incident asked for evidence today, would it already exist, or would someone need to go build it?

For the EU-wide requirements behind Italy's version, see our NIS2 requirements guide. For the source material behind this article, see ACN's own overview of the legislation.

Frequently asked questions

Book a demo