NIS2 and cybersecurity for businesses
NIS2: does it apply to you?
It is the European directive on network security: it applies across the whole Union, and each country writes it into its own law. Those inside its scope must register, adopt risk-management measures and report incidents within windows measured in hours, not days. Fines are calculated as a percentage of turnover. The part that surprises almost everyone: it is not only about large companies. The scope covers the sectors named in the directive — energy, transport, health, water, digital infrastructure, food, certain kinds of manufacturing — and it extends down the supply chain. If you supply a company that is in scope, its obligations become contractual requirements on you: that is why many discover they are involved through a questionnaire sent by a customer, not through an official notice. Whether it reaches you depends on your sector, your size, your country and who you serve — not something a web page can settle.
Who has to comply, and how you find out
The law splits those in scope into two groups: essential entities and important entities. What counts is the sector — energy, transport, health, banking, digital infrastructure, water, waste, food, manufacturing, postal services, chemicals, space, digital providers and public administration — and the size of the company. You don't decide on your own: Italy's National Cybersecurity Agency (ACN) enters entities on a list and notifies them. Those in scope register on the ACN portal, and the registration is renewed every year between 1 January and 28 February. This page explains the law, it does not establish whether it applies to you: that is settled on your own figures, with the Agency and with whoever advises you legally.
The deadlines that matter
The European directive is 2022/2555. Italy transposed it with legislative decree 138 of 4 September 2024, in force since 16 October 2024, and precise deadlines run from there. Since January 2026, entities in scope must be able to recognise a significant incident and report it to the Agency: an early warning within 24 hours, the actual notification within 72 hours, a final report within one month. And one date is close: by 31 October 2026 the baseline security measures set by ACN must be operational, not planned. From that day the Agency can start inspecting.
If you supply a company that has to comply
This is the part that surprises almost everyone, and it reaches far more companies than the list itself. NIS2 requires those in scope to secure their supply chain: map the relevant IT suppliers, revise contract clauses, monitor them over time. You may not be on the ACN list and still receive a questionnaire, a new clause at renewal, or a request to show how you keep the data they pass you. It isn't the law addressing you: it's your client, who answers for that data including the part sitting with you. Whoever can't answer gets replaced, and it usually happens at renewal, without discussion.
What is at stake
Fines are calculated on turnover, not on a fixed rate: up to 10 million euro or 2% of worldwide annual turnover for essential entities, up to 7 million or 1.4% for important ones, whichever is higher. But one consequence weighs more than money: responsibility sits with the management bodies, which must approve the measures and oversee how they are applied, and in serious cases can be temporarily barred from managerial functions. It is not a fine you hand over to the IT department.
What we take care of
Anyone running a business holds their customers' addresses, orders and spending habits. If those get out, the damage isn't the business down for a day: it's trust, and that can't be bought back. We handle three things — who can get in, what stays on record when someone tries, and how you get going again if something goes wrong.
Why you won't find the list here
We don't publish which defences we use, and it isn't coyness: a supplier who puts their measures in the shop window is working for the people studying them. With anyone evaluating seriously we discuss it face to face, with the references and the logs to hand. Write to us and we'll tell you what we can show and on what terms.
How it starts
An introductory call, half an hour, no commitment and no charge. We look at what you do, who your customers are and how your systems stand today: from there it becomes clear whether NIS2 reaches you and what you actually need. We ask for no access and no documents just to talk — those come later, if we go ahead.
What it costs
Decided case by case, and that is not an evasion: a business with ten computers in one office and one with three sites and a system wired into its suppliers are not facing the same work. What pushes the cost up is how many systems there are, how old they are and how tight the deadline is; what brings it down is arriving before the problem is urgent. After the call you know a number, before committing to anything.
What you are probably wondering
"I already have someone who looks after the computers." You need them, and it is a different job: keeping machines running is not the same as answering to an authority for a legal obligation. The two roles coexist. — "We're small, who would attack us?" Almost no attack picks its target: automated programs try addresses at random and get in wherever they find something open. Small does not mean invisible, it means easier. — "We'll think about it later." It is the most common answer, and the reason things then get done in a rush and badly: a legal deadline is not negotiable, and whoever arrives last pays more.
Request a quote
Two fields, everything else optional. A person replies.