On 16 October 2024, the legislative decree transposing the NIS2 Directive (Network and Information Security), which aims to strengthen cyber resilience and the protection of critical infrastructures.
Under the supervision of the Agency for National Cybersecurity (ACN), designated as the competent authority, the Directive sets new standards for security and crisis management, requiring companies and public authorities to make a concrete commitment to mitigate cyber threats.
Among the main novelties:
- increased security measureslegislation requires strict adaptation of protection measures and incident reporting, while the ACN acquires new powers to control and manage IT emergencies;
- sectors concernedWith 18 sectors involved, 11 of which are highly critical, and more than 80 categories of actors, the legislation distinguishes between essential and important services to ensure protection according to the level of risk;
- collaboration tools: Introduces coordinated disclosure of vulnerabilities, fostering cooperation at national and European level.
The compliance process will be progressive. By 28 February 2025, public and private entities to which the Directive applies must make themselves known to the competent national authority by registering on the digital platform, which will be made available by ACN from 1 December 2024.
In April 2025, entities that have registered will receive a communication to confirm, or not, their inclusion in the NIS list.
For further details: