NIS2: what companies in critical sectors actually have to do
4 min read
NIS2 is the European directive on the security of network and information systems, transposed into Italian law by Legislative Decree 138/2024. Unlike the first NIS Directive, it no longer applies to a narrow list of operators: it draws in thousands of Italian companies, many of which only discovered this when it came time to register. This note explains who falls within scope, what is really being asked, and — above all — where to start.
Who falls within scope
The directive distinguishes two categories: essential and important entities. The logic is simple: high-criticality sectors (energy, transport, health, water, digital infrastructure, public administration) and other critical sectors (manufacturing of certain products, chemicals, food, waste management, postal services, among others), cross-referenced with company size — as a rule, from 50 employees or €10 million in turnover upwards.
The point that surprises many businesses: manufacturing includes manufacturers of medical devices, electronics, machinery and motor vehicles. In a region such as Emilia-Romagna — mechanical engineering and automotive, biomedical, plant engineering — this means a substantial share of the productive fabric falls within the perimeter, often without realising it. And even those not directly in scope are reached through the supply chain: NIS2 entities must assess the security of their suppliers.
What it actually asks for
Stripped of the legalese, the obligations come down to four families:
-
Governance and accountability. Management bodies approve the risk-management measures, oversee their implementation and are accountable for breaches. It can no longer be delegated wholesale to IT: security becomes a responsibility of senior management, with a mandatory training obligation.
-
Risk management. Proportionate technical and organisational measures: risk analysis, supply-chain security, incident handling, business continuity, encryption, access control, basic cyber hygiene. The key word is proportionate: no one expects a 60-employee company to run a bank’s SOC — what is expected is that risks have been understood and are being kept under control.
-
Incident notification. Significant incidents must be notified to the National Cybersecurity Agency (ACN, Agenzia per la Cybersicurezza Nazionale): an early warning within 24 hours, notification within 72, a final report within one month. Meeting these deadlines requires noticing the incident in the first place — and this is where most organisations discover they have no visibility over their own systems.
-
Registration and updating. Entities register on the Agency’s platform and keep their information up to date, with annual windows for confirmation.
The penalties are not symbolic: up to €10 million or 2% of worldwide turnover for essential entities, up to €7 million or 1.4% for important ones.
The real prerequisite: knowing what you have
The most useful way to read NIS2 is not as “yet another compliance exercise” but as a forced inventory. You cannot protect what you do not know you have, and you cannot notify an incident within 24 hours if you cannot see it happening. Before any security technology, the directive requires — implicitly but inevitably — three basic capabilities:
- A real inventory of systems, data and flows: which machines talk to which systems, where the data resides, who accesses it.
- Continuous visibility: the ability to notice that something has changed — an anomalous access, an unexpected flow, a system behaving differently — as it happens, not in the quarterly report.
- A response process in which roles and decisions are clear before the incident, not during it.
These are the same foundations underpinning any serious use of data. An organisation that has connected its systems into a single operating model — who produces which data, what it means, how it flows — has already done the hard part of NIS2. And the continuous monitoring the directive requires rests on the same foundation as operational AI: agents that read flows in real time and bring anomalies to an operator’s attention.
Where to start
If your company falls within scope (or you are not sure), the sensible order is this:
- Verify the perimeter: sector and size thresholds. If in doubt, checking costs an hour; finding out from the Agency costs a great deal more.
- Carry out the inventory of critical systems and data — the real one, not the IT organisation chart from three years ago.
- Measure the gap between what the directive requires and what you have: an honest gap analysis, with priority given to the greatest risks.
- Build visibility: without continuous monitoring, the notification deadlines are unreachable.
- Formalise governance and the response process, and bring them to the board: that is where accountability sits.
Compliance can be treated as a cost or as an opportunity to put your own data in order — and to let everything else follow from that order, from security to automation. Our view, by design, is the second: it is the same principle behind our dual-use compliance approach, where the regulatory constraint is part of the project, not an obstacle to it.
Want to understand where you stand against the NIS2 perimeter and what is missing? A 30-minute session with one of our experts is the fastest way to find out.