Guide — NIS2
NIS2 for SMEs: what to do, in practice.
The European NIS2 directive, transposed in Italy with Legislative Decree 138/2024, extends cybersecurity obligations to thousands of companies — many SMEs included, even just as suppliers. This guide explains who is in scope, what the rule actually requires and where to start, without legalese.
What NIS2 is, in two lines
It is the EU directive on the security of networks and information systems (2022/2555), second edition. In Italy it has been law since 2024 and the reference authority is ACN, the National Cybersecurity Agency. The core idea: cybersecurity stops being voluntary good practice and becomes an obligation with accountability and fines.
Who is in scope (more companies than you think)
The rule distinguishes essential and important entities across a long list of sectors: energy, transport, healthcare, water, digital infrastructure, public administration, but also manufacturing of critical products, food, chemicals, waste management, postal and digital services. As a general rule, companies from 50 employees or €10 million in revenue in the listed sectors are in scope — but note the point many miss: even companies not directly in scope get involved as suppliers of an obligated entity, because NIS2 requires securing the supply chain.
The real obligations, without legalese
Governance: responsibility sits with management — the owner or the board — who must approve the measures and receive training. It cannot be fully delegated to IT.
Technical and organisational measures: risk analysis, incident management, business continuity and backups, supply chain security, encryption, multi-factor authentication, staff training.
Registration: entities in scope must register on the ACN portal within the annual window.
Incident notification: early warning within 24 hours of a significant incident, full notification within 72 hours, final report within one month.
The fines
Up to €10 million or 2% of annual worldwide turnover for essential entities, up to €7 million or 1.4% for important ones. Plus personal liability for management, up to temporary bans from executive roles in the most serious cases. The legislator's message is clear: this is not a box-ticking exercise.
Checklist: 10 questions to see where you stand
- 01Do you know whether your company is in scope, directly or as a supplier of an obligated entity?
- 02Do you have an up-to-date inventory of systems, devices and access?
- 03Is multi-factor authentication active on email, VPN and critical systems?
- 04Do backups follow the 3-2-1 rule, and have you ever tested a restore?
- 05Is there a written incident plan (who does what, who alerts whom)?
- 06Could you notify an incident to the authority within 24 hours?
- 07Have you assessed the security of your critical suppliers (and they yours)?
- 08Does your staff receive periodic training on phishing and security?
- 09Are security updates applied systematically?
- 10Has management formally approved the security measures?
Where to start
Not with panic, nor with a binder of policies: with an honest snapshot. Our IT Diagnosis maps infrastructure, access, backups and suppliers and tells you where you fall short of the requirements — free. From there, measures line up by priority, at SME-sized costs.
FAQ
NIS2 frequently asked questions
We are an SME: does NIS2 really affect us?+
It depends on sector and size, but the most common route is indirect: if you supply an obligated entity, security requirements reach you via contract. Checking takes little and removes the doubt.
What do we actually risk by doing nothing?+
If in scope: fines up to millions of euros and personal liability for management. If a supplier: losing obligated clients, who will pick compliant partners. Either way, the operational risk of an incident remains.
How much does compliance cost?+
Less than feared, if you start from priorities: many NIS2 measures — MFA, verified backups, training, patch management — are good IT hygiene that pays off regardless. The diagnosis estimates the path with your numbers.
Can you guide us through compliance?+
Yes: gap analysis against the requirements, a priority-ordered plan and implementation of technical measures with our Managed IT. For strictly legal aspects we work alongside your counsel, or suggest one.