By October 31, 2026, organizations subject to NIS2 (Network and Information Security 2) must implement the basic measures. ACN inspections will follow.
- Key deadline: October 31, 2026, for the baseline measures of entities on the list starting in 2025.
- New Entities for 2026: Deadline Extended to July 31, 2027.
- Scope: more than 20,000 organizations, including 5,000 essential organizations and approximately 15,000 important organizations.
- Incident Reporting: Preliminary alert within 24 hours and notification within 72 hours to CSIRT Italia.
- 2026 Milestone: The ACN transitions from the support phase to the inspection phase.
The NIS2 Directive is no longer a future requirement but a concrete deadline. In 2026, Italian organizations will enter the actual implementation phase. The timeline established by the National Cybersecurity Agency (ACN) sets precise deadlines that can no longer be postponed. Furthermore, the new ACN Determination 379907/2025, effective January 15, 2026, updates and consolidates the required security measures. The implementation framework as of July 2026 is structured around deadlines to be met, stakeholders involved, and operational obligations that are now in effect. Understanding the status of progress is essential for those responsible for managing cybersecurity at companies subject to these regulatory requirements.
The NIS2 Directive for Businesses: What Will Change in 2026
In 2026, NIS2 will enter its operational phase. Companies must implement security measures according to the schedule established by the ACN.
NIS2 (Network and Information Security 2): European Directive 2022/2555 on cybersecurity. It strengthens the protection of businesses and public administrations in critical sectors.
2026 is the year of implementation. Once entities have registered on the ACN platform, substantive obligations will take effect. Specifically, ACN Determination 379907/2025 replaces the previous regulation from April 2025. It sets forth the basic measures and notification procedures in a binding manner. Therefore, every organization must translate these requirements into concrete plans. This regulatory push is also being driven by market forces. Companies are increasing their investments in security to address threats and comply with European regulations. However, the time available has been significantly reduced.
According to IDC, European spending on cybersecurity will reach $84 billion by 2027, driven by NIS2 and DORA (Digital Operational Resilience Act).
What are the NIS2 deadlines by October 2026?
The 2026 calendar outlines various compliance requirements by category and year of entry. Below are the key milestones to keep in mind.
- January 1 – February 28, 2026: Registration and update period on the ACN platform.
- May 1 – June 30: Annual submission of the list of activities and services.
- October 31, 2026: Basic operational measures for entities on the list as of 2025.
- July 31, 2027: Deadline for individuals enrolled for the first time in 2026.
Who must comply, and what measures are required?
The essential and critical entities identified by the ACN must comply. The measures cover governance, risk management, the supply chain, and incident response.
The ACN has already identified the entities involved and notified them of their status. The scope exceeds 20,000 organizations. Essential entities operate in highly critical sectors and provide services vital to the economy. Important entities carry out significant activities in sectors that are nonetheless critical. Furthermore, the obligations effectively extend throughout the supply chain. In fact, NIS2 entities must require security guarantees from their suppliers. Consequently, even companies not directly designated are affected by the directive. Those who fail to comply risk being excluded from strategic supply chains.
- Key elements: 116 requirements organized into 43 security measures.
- Key elements: 87 requirements broken down into 37 security measures.
- Incident Reporting: Preliminary alert within 24 hours and notification within 72 hours to CSIRT Italia.
Who are the essential and important NIS2 entities?
The distinction depends on the sector and the criticality of the service provided. Essential entities are subject to a more stringent oversight regime. Important entities are subject primarily to ex post controls. Both, however, must manage supply chain risk.
The 16 areas required by the NIS2 Directive
The NIS2 Directive organizes the measures into 16 areas. They cover technological, organizational, governance, and compliance aspects.
The requirements are not solely of a technological nature. They also pertain to processes, roles, and internal controls. There are 116 requirements for critical entities. For significant entities, there are 87. In both cases, they are distributed across the following areas.
- Risk Management: Identification, assessment, and mitigation of cyber risks, integrated into processes and kept up to date with emerging threats.
- Roles and responsibilities: formally defined, approved by governing bodies, and updated to ensure accountability and efficiency.
- Reliability of Human Resources: Staff selected for their experience and reliability, with security obligations that remain in effect even after the employment relationship ends.
- Security Compliance and Audits: Policies and measures are regularly reviewed and audited to ensure regulatory compliance.
- Supply Chain Risks: Safety Requirements in Contracts with Suppliers, with Monitoring and Assessment Throughout the Entire Supply Chain.
- Asset Management: Key assets are identified, inventoried, and managed based on their business value and risk strategy.
- Vulnerability Management: Structured processes for identifying, resolving, and monitoring vulnerabilities, with timely corrective actions.
- Business Continuity: Documented, maintained, and tested disaster recovery and crisis management plans to ensure operational resilience.
- Digital identities and access control: management based on the principle of least privilege, separation of duties, and multi-factor authentication.
- Physical security: areas protected against unauthorized access, with controls commensurate with the level of risk.
- Training and Awareness: Ongoing training for all staff, including administrators, on cybersecurity risks.
- Data Security: Protection of data at rest and in transit through secure encryption and appropriate backup measures.
- System lifecycle: secure development, configuration, maintenance, and decommissioning, with timely updates and the removal of obsolete technologies.
- Network and Communications Protection: Adequate perimeter security measures and strict controls on remote access.
- Event Monitoring: Continuous monitoring systems to promptly detect anomalies and incidents.
- Incident Response and Recovery: An operational plan with clear procedures for notification, response, and recovery.
The breadth of these areas ensures comprehensive coverage. However, it introduces a high degree of complexity and requires technological, organizational, and governance expertise.
Quanto è matura la cybersecurity della tua azienda?
Spunta le voci che corrispondono alla tua situazione: ottieni un punteggio e un consiglio.
From the support phase to the assessment: how to prepare
Starting in October 2026, the ACN may begin inspections. Companies should complete a gap analysis and address any gaps before the inspections.
The most significant change in 2026 concerns the audit method. Until now, the ACN has guided organizations toward compliance. Starting in October, however, it will be able to conduct inspections and document reviews. Therefore, supporting evidence must be ready, traceable, and verifiable. A systematic approach begins with an analysis of deviations from the requirements. It then proceeds with a remediation plan covering governance, technologies, and processes.
It pays to get a head start on compliance checks: planning ahead reduces risks, costs, and the time needed to comply with the NIS2 Directive.
How Retelit Supports Companies on Their NIS2 Journey
Retelit supports businesses and organizations throughout the entire NIS2 process. It provides assistance during both the preparatory and implementation phases.
Addressing NIS2 isn’t just about complying with a European directive. It’s also an opportunity to rethink your security posture in a modern context. Retelit operates as a hub of expertise. It brings together internal resources, strategic compliance and governance partners, and carefully selected technologies. During the preparatory phase, it conducts a gap analysis. This identifies the shortest and most effective path to compliance. During the implementation phase, it supports activities covering the 16 areas described. As a result, the organization tackles complexity with continuous and integrated support.
Would you like to assess your level of NIS2 compliance? A cybersecurity gap analysis is the first step toward full compliance with the directive.
Frequently Asked Questions About the NIS2 Directive for Organizations
The Ruling, effective as of January 15, 2026, updates the basic measures and notification procedures. It makes the obligations binding and defines the required documentation. The official sources are available on the ACN portal.
The model provides for an initial alert within 24 hours of the incident being detected. A more detailed notification follows within 72 hours. Communications are routed through CSIRT Italia, which is housed at the ACN.
Designated entities are subject to penalties and inspections. Furthermore, noncompliance jeopardizes access to strategic supplies. As a result, security becomes a competitive requirement, not just an obligation.
In collaboration with Andrea Priviero, Product Marketing, Retelit