NIS2: Are You Compliant? From 1 January You Face Serious Risk
Digital Cybersecurity

NIS2: Are You Compliant? From 1 January You Face Serious Risk

The new European cybersecurity directive is already in force. It affects more than 20,000 Italian companies. And perhaps yours too.

A126 Team 7 min read

The Bad News? It Has Already Started

If you run a company and the term "NIS2" means nothing to you, we have a problem. Since 1 January 2026 the obligation to report cyber incidents has come into force for all organisations covered by the NIS2 Directive. By October 2026 all the required security measures will have to be implemented. We are not talking about guidelines. We are talking about law. With fines that reach up to 10 million euros or 2% of global turnover. And the worst part? Many business owners do not even know they are affected.

What Is NIS2 (Explained Simply)

NIS2 stands for Network and Information Security 2. It is a European directive on cybersecurity, transposed in Italy with Legislative Decree 138/2024 and in force since 16 October 2024. The message coming from Brussels is clear: if your company operates in certain strategic sectors or exceeds certain size thresholds, you must equip yourself with serious, documented and verifiable cybersecurity measures. It is no longer a choice, it is an obligation.

The National Cybersecurity Agency (ACN), the authority responsible for implementing the directive in Italy, has already identified more than 20,000 organisations that fall within its scope. Of these, more than 5,000 are classified as "essential entities", that is, organisations whose malfunction would have serious impacts on national security and the economy.

Who Is Affected? Probably More Companies Than You Think

NIS2 significantly broadens the scope of application compared with the previous directive, extending to 18 sectors split into two categories.

The highly critical sectors include energy (electricity, gas, oil), transport (air, rail, maritime, road), banking and financial markets, healthcare, drinking water and wastewater, digital infrastructure such as cloud and data centres, Public Administration and even the space sector. Companies operating in these areas are classified as "essential entities" and are subject to the most stringent requirements.

The other critical sectors instead include postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, machinery, automotive), digital service providers and research organisations. Those operating here fall among the "important entities".

But there is one aspect many overlook: the supply chain effect. When a company falls within the NIS2 scope, it is obliged to verify the security of its own supply chain. In practice, if you are an SME working for a client subject to the regulation, that client will ask you to demonstrate that your company is "secure". Security questionnaires, audits, certifications, minimum requirements to meet. If you do not comply with them, you risk losing the contract.

In 2026 many small and medium-sized enterprises are already receiving compliance requests from clients, large companies and Public Administrations, even without being directly within the scope of the directive.

What You Actually Have to Do

NIS2 does not generically ask you to "pay attention to security". It requires specific, documented and verifiable measures, defined by the ACN Determination 164179/2025 that establishes the baseline specifications for fulfilling the obligations.

The first pillar is governance. Cybersecurity is no longer just "IT stuff": it becomes the direct responsibility of management. The administrative bodies must approve the security measures, oversee their implementation and — a significant novelty — receive specific training on cyber risks. Top management can no longer delegate everything and lose interest.

The second pillar concerns risk management. Every organisation must identify, assess and document its own cyber risks. Which data is critical? Which systems must remain operational in the event of an incident? Where are the weak points? Knowing it by heart is not enough: it must be written down, formalised and periodically updated.

The third pillar is incident reporting, already operational since 1 January 2026. In the event of a significant incident — a ransomware attack, a data breach, a system compromise — the company must send an early warning to CSIRT Italia within 24 hours, followed by a full notification within 72 hours and a detailed final report within one month. If you do not have a structured incident response plan, you are already technically non-compliant.

The fourth pillar comprises the technical security measures to be implemented by October 2026: password and access management policies, regular and tested backups, business continuity procedures, supply chain control, staff training, threat monitoring and detection systems. For important entities this amounts to 37 measures and 87 requirements; for essential entities it rises to 43 measures and 116 requirements.

The Penalties: This Is No Joke

NIS2 introduces a decidedly more severe penalty regime than the previous rules, designed to be genuinely dissuasive.

On the financial front, essential entities risk fines of up to 10 million euros or 2% of annual worldwide turnover (whichever is higher applies). For important entities the figures drop to 7 million euros or 1.4% of global turnover. Numbers that can bring even well-structured companies to their knees.

But financial penalties are only part of the problem. The ACN can order the suspension of certifications and authorisations, effectively blocking some or all of the company's services until it complies. Even more relevant is the personal liability of directors: top executives can be temporarily suspended from their management functions in the event of serious non-compliance. Finally, violations can be made public, with consequent reputational damage.

In short: if you do not comply, you risk being unable to operate any longer, and your directors risk their seats.

The Deadlines to Mark on Your Calendar

The compliance process is already well under way. Registration on the ACN platform was due by February 2025, and in April the Agency notified organisations of their inclusion in the list of NIS entities. By May 2025 the company Point of Contact had to be designated.

Since 1 January 2026 the obligation to report significant incidents has been active. By October 2026 all the security measures provided for by the regulation will have to be implemented and operational.

If your company was supposed to register and did not, you already have a problem to resolve urgently.

"But I'm an SME, It Doesn't Concern Me"

This is one of the most frequent objections, and it is almost always wrong.

First of all, you might fall directly within the scope without knowing it. NIS2 applies to medium-sized enterprises (50-250 employees, turnover between 10 and 50 million euros) and to large enterprises operating in the sectors indicated. If you have a manufacturing company with 60 employees, you could be in.

Secondly, there is the supply chain effect already described: your clients subject to NIS2 will ask you for guarantees about your cybersecurity. If you are unable to provide them, you will lose contracts.

Finally, there is a matter of pure business common sense. Regardless of the regulation, 43% of cyberattacks hit SMEs, with an average cost of around 59,000 euros per incident that can reach 300,000 euros in the most serious cases. NIS2 is not bureaucracy for its own sake: it is a structured framework to protect you when — not if — your turn comes.

Where to Start

If you are worried, and at this point you should be, here are the first steps to take.

First of all, check whether you are within the scope by looking at your business sector and company size. If in doubt, consult an expert or check directly on the ACN portal. Then carry out an assessment of the current state of your cybersecurity to understand where you are vulnerable and what is missing.

Appoint someone responsible for cybersecurity: the matter must have a clear owner, internal or external (there are Virtual CISO services for those who cannot afford a dedicated figure). Document everything — policies, procedures, response plans — because in NIS2 logic, what is not written does not exist.

Train your staff: 58% of employees do not recognise a phishing email, and training is no longer optional. Prepare an incident management plan that answers the fundamental questions: what do you do if tomorrow you find your systems locked? Who do you call? How do you communicate? How much time do you have to get back up and running?

Finally, test your backups. Having them is not enough: you must be sure they work. When was the last time you did a full restore test?

NIS2 Is Not a Cost. It's an Investment.

Yes, complying takes time and resources. But consider the alternative: a ransomware attack that shuts the company down for weeks, a fine of millions of euros, the loss of customers who no longer trust you, directors suspended from their functions.

NIS2 forces you to do what you should already have done: protect your business in a structured way. The companies that comply not only avoid penalties, but gain a concrete competitive advantage. They become reliable partners in the eyes of clients and suppliers, reduce operational risks, and build that digital trust which in 2026 has become a strategic asset.

In Conclusion

NIS2 is already a reality. Since 1 January 2026 the reporting obligations are active, and by October you must be fully compliant.

If you don't know whether you are affected, find out right away. If you are affected and have done nothing, move now. If you think it doesn't concern you because you are "small", think again: the supply chain does not forgive, and neither do cybercriminals.

Cybersecurity is no longer an optional. It is a requirement for staying on the market.

The train has left. Are you on board?

Share this article