Published on
NIS2: does it apply to your company? A practical guide
Sectors, size thresholds, supply chain and obligations of the NIS2 directive (Italian Legislative Decree 138/2024) explained in practice: how to tell whether your company is in scope and what to do about it.
The question I get asked most often about NIS2 is the simplest one: “does it actually concern me?”. The honest answer: it depends on three things — sector, size and customers. This guide goes through them in the right order, from the perspective of the Italian transposition (Legislative Decree 138/2024).
Want the quick answer? The free NIS2 check gives it to you in six questions, no email required. This guide explains the why behind those questions.
What NIS2 is, in one sentence
NIS2 is the EU cybersecurity directive (2022/2555), transposed in Italy by Legislative Decree 138/2024: it requires organizations providing services relevant to the economy and society to adopt cyber risk management measures, report incidents, and makes management directly accountable.
First filter: your sector
The law lists sectors in two annexes:
- Annex I — high-criticality sectors: energy, transport, banking and financial market infrastructure, health, drinking water and waste water, digital infrastructure, B2B ICT service management, space, public administration.
- Annex II — other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of critical products (medical devices, electronics, machinery, motor vehicles), digital providers (marketplaces, search engines, social networks), research.
If you operate in none of these sectors, you are most likely not directly in scope — but don’t close the page yet: the supply chain section is about you.
Second filter: your size
The general rule (the size-cap) is that NIS2 applies to organizations in the listed sectors that are at least medium-sized: 50 employees or more, or over €10 million in annual turnover. Above 250 employees or €50 million you tend to fall among essential entities; below that, among important ones.
There are, however, special cases where size does not matter: DNS service providers, domain name registries, trust service providers, communication network providers — and sole national providers of an essential service. In those cases even a micro-enterprise can be in scope.
Essential vs important: what changes
Both categories share the same core obligations, but supervision and penalties differ:
- essential entities are subject to proactive supervision and risk fines of up to €10 million or 2% of worldwide annual turnover (whichever is higher);
- important entities are mainly supervised after the fact, with fines up to €7 million or 1.4%.
In both cases the decree provides for direct accountability of management bodies: cybersecurity stops being “an IT problem” and becomes a board-level topic.
The filter that surprises people: the supply chain
This is where many small companies convinced they are out of scope get caught. Among the measures required of NIS2 entities is supply chain security: in-scope organizations must assess and manage the risk posed by their suppliers. In practice, this turns into contractual requirements — security questionnaires, clauses, audits — flowing down the chain.
Translated: if you supply software, IT services, logistics or components to a company subject to NIS2, it is realistic that sooner or later you will be asked for documented security guarantees. You are not a “NIS2 entity”, but its effects reach you anyway — and being ready is a concrete commercial advantage over competitors.
If you are in scope: the main obligations
- Registration on the ACN portal (Italy’s National Cybersecurity Agency), within the applicable time windows.
- Risk management measures (Article 24 of the decree): risk analysis, incident handling, business continuity and backups, supply chain security, encryption, access control, training, MFA where appropriate.
- Notification of significant incidents: early warning within 24 hours of becoming aware of the incident and notification within 72 hours, followed by a final report.
- Training for management bodies, which must approve and oversee the risk management approach.
Compliance is phased: ACN has defined a staged timeline, with the first operational deadlines already underway. The point is not to do everything at once, but to know where you stand along the path.
Where to start, in practice
- Check your scope: sector + size + special cases. The free check is a good first step.
- If you are in: register with ACN if you haven’t, then run a gap analysis against the Article 24 measures to understand distance and priorities.
- If you supply someone who is in: get ahead on the baseline measures (MFA, tested backups, access management, patching) — they are exactly what your customers will ask you for by contract.
This guide is general orientation, not legal advice: a formal scope determination must be made on each organization’s specific situation. If you want an opinion on yours, let’s talk.