Italy’s Legislative Decree 138/2024, transposing the EU NIS2 Directive, comes into force today, significantly widening the number of Italian organisations subject to mandatory cyber security requirements.
Key points
- Expands the range of essential and important entities subject to cyber security duties.
- Entities must register with the National Cybersecurity Agency (ACN).
- Risk management measures and incident reporting apply.
- Sits alongside the National Cybersecurity Perimeter law and Law 90/2024.
UK organisations with Italian subsidiaries, or supplying managed services, software or cloud services to in-scope Italian entities, should prepare for registration questions, contractual security clauses and supply chain assessments from their customers.
Source: Legislative Decree 138/2024 (Gazzetta Ufficiale)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.