Does NIS2 apply to your company?
Six questions, two minutes: find out whether your organisation falls within the scope of the NIS2 directive (Italian transposition: Legislative Decree 138/2024) as an essential or important entity, and what that means.
- Free
- Instant result
- No email required
- 2-3 minutes
Your result
Likely an ESSENTIAL entity
Given your sector and size, your organisation most likely qualifies as an essential entity: the highest tier of obligations (and supervision) under NIS2.
Essential entities are subject to proactive supervision by the Italian cybersecurity agency (ACN) and to fines of up to €10 million or 2% of worldwide annual turnover. Key obligations: registration on the ACN portal (1 January – 28 February window), risk management measures with accountability at board level, notification of significant incidents to CSIRT Italia (early warning within 24 hours, notification within 72, final report within 30 days) and baseline security measures with documented evidence within ACN deadlines (first cohort: 31 October 2026).
Likely an IMPORTANT entity
Given your sector and size, your organisation most likely qualifies as an important entity: full NIS2 obligations, with ex-post rather than proactive supervision.
Important entities carry the same core obligations as essential ones — ACN registration (1 January – 28 February), risk management, incident notification to CSIRT Italia (24h/72h/30 days), baseline security measures within ACN deadlines (first cohort: 31 October 2026) — with fines of up to €7 million or 1.4% of worldwide annual turnover. Supervision is ex post: it kicks in after an incident or a report, but sanctions are just as real.
Public entity: likely in scope
Public administrations and entities under Annexes III and IV fall within NIS2 scope based on their type, in many cases regardless of size: your specific category needs a targeted check.
Central government bodies are essential entities regardless of size; regional and local administrations, local public transport, universities, cultural heritage entities and publicly controlled companies fall in scope through the designation procedures set by the decree. Obligations mirror those of private entities: ACN registration, risk management, incident notification. The first step is verifying which Annex III/IV category your organisation falls under.
Outside direct scope, but involved via the SUPPLY CHAIN
Your organisation is probably not a NIS2 entity itself, but your clients are: their supply chain security obligations will reach you through contracts.
NIS2 entities must assess and manage the security of their suppliers: in practice that means security questionnaires, contractual clauses on minimum measures and incident notification, and in some cases audits. Being ready — documented baseline measures, a named security contact, the ability to answer a questionnaire without scrambling — turns your clients’ obligation into a commercial advantage over competitors.
Likely out of scope
Based on your answers, your organisation does not appear to fall within NIS2 scope, either directly or as a supplier to obligated entities.
Two caveats: scope should be re-checked whenever your size, activities or clients change (the ACN registration window reopens every year from 1 January to 28 February), and being outside NIS2 does not mean being safe — threats don’t read the decree’s annexes. A baseline level of cyber hygiene is worth having anyway, and you can measure yours in three minutes with the Cyber Security Check.
This test is a preliminary orientation based on the criteria of Legislative Decree 138/2024, not legal advice: the definitive classification depends on the self-assessment on the Italian ACN portal and on the specifics of your business.
Want a professional opinion?
This test is a first orientation. If you want to know what to actually do in your situation, let’s talk: 30 minutes, no commitment.
Request an assessmentFrequently asked questions
Is the check result legal advice?
No: it is a preliminary orientation based on Italian Legislative Decree 138/2024 (the Italian transposition of the NIS2 directive). It helps you understand whether the topic concerns you and how urgently; a formal scope determination requires a specific analysis of your situation.
Do I have to leave my email to see the result?
No: the summary result is shown immediately, without providing any data. Your email is only needed if you want the full report with an analysis of your answers.
What happens to my answers?
They stay in your browser: the test runs entirely client-side. Only if you request the report by email are your answers and address transmitted — and used exclusively to send it. No newsletter, no sharing with third parties.
What are the penalties for non-compliance with NIS2?
For essential entities, fines reach up to €10 million or 2% of worldwide annual turnover (whichever is higher); for important entities, up to €7 million or 1.4%. The directive also provides for direct accountability of management bodies.
I am in scope: where do I start?
With the formal steps — registration on the Italian ACN portal within the applicable deadlines — and a gap analysis of the risk-management measures required by the decree. From there you get a compliance plan with priorities and costs proportionate to your company’s size.