๐Ÿ“ Europe ยท NIS2 Directive (EU) 2022/2555 ๐Ÿ‡ฎ๐Ÿ‡น Italian Version
โš–๏ธ Obligations

NIS2 Obligations for Companies

What essential and important entities must do to comply with Directive (EU) 2022/2555 (NIS2).

๐Ÿ›ก๏ธ Security Measures (Art. 21)

Entities must implement appropriate technical, operational, and organisational measures to manage cybersecurity risks.

๐Ÿ“‹ Security Policy

High-level document approved by management, plus specific policies for each sector or topic

๐Ÿšจ Incident Management

Procedures for identification, classification, handling, and reporting. Initial notification within 24 hours.

๐Ÿ”„ Business Continuity

BCP and DRP, off-site/cloud backups, disaster recovery plans

๐Ÿ”— Supply Chain

Risk assessment across the entire ICT supply chain, security requirements for suppliers

๐Ÿ”ง Procurement and Maintenance

Pre-production vulnerability assessment, patch management, secure support

๐Ÿ”‘ Access and Identity

Least privilege principle, privileged access management (PAM), multi-factor authentication (MFA)

๐Ÿ” Encryption

Encryption for sensitive data, protection of communications

๐Ÿ” Testing and Auditing

Periodic security testing, vulnerability assessments, annual penetration testing

๐Ÿ“ก Detection

IDS/IPS, SIEM, continuous threat monitoring

๐Ÿข Physical Security

Data centre access control, protection against natural disasters and physical attacks

๐Ÿ“… Reporting Obligations (Art. 23)

โฑ๏ธ Mandatory Timeframes
24 hours Initial report โ€” from discovery of a significant incident to your national CSIRT
Immediately Update โ€” when substantial new information becomes available
1 month Final report โ€” complete report with all details

โš ๏ธ What is a "Significant Incident"?

โŒ NOT a significant incident

๐Ÿ“ Registration Obligations

Entities must register with the competent national authority and provide:

๐Ÿ”— Supply Chain (Art. 21)

Entities must assess and manage risks across the entire ICT supply chain:

โš–๏ธ Essential vs Important

Aspect๐Ÿ”ด Essential๐ŸŸก Important
SupervisionStricterLighter
NotificationsMandatoryMandatory
Maximum penaltiesโ‚ฌ10M or 2% of turnoverโ‚ฌ7M or 1.4% of turnover
AuthorityNational authority + sectoralNational authority only
AuditAt any timeOnly when necessary

๐Ÿ‡ช๐Ÿ‡บ Implementation in EU Member States

๐Ÿ›๏ธ National Cybersecurity Authority

Each Member State designates a competent national authority for NIS2 supervision.

๐Ÿ›ก๏ธ National CSIRT

Receives incident reports and provides operational support โ€” part of the national cybersecurity authority.

๐Ÿ“… Staged Compliance

๐Ÿ’ฐ Penalties (Art. 34)

๐Ÿšซ Failure to implement measures

โ‚ฌ10M or 2% of turnover for Essential entities

โ‚ฌ7M or 1.4% of turnover for Important entities

โš ๏ธ Late or missing notification

Administrative financial penalty scaled according to severity and duration

๐Ÿ‘” Management Liability

Possible personal liability for managers in cases of violations resulting from strategic business decisions.