NIS2 compliance means two things for a small or medium business: knowing whether the directive applies to you, directly or through a customer's supply chain, and being able to show the technical measures of Article 21 with evidence. In Italy the directive is transposed by Legislative Decree 138/2024 and supervised by ACN. This page explains the scope, the reporting clock and which Defensio component produces each piece of evidence.
NIS2 is the EU directive that sets a common level of cybersecurity for organisations in sectors the Union considers critical. Each member state transposes it into national law and names a competent authority. In Italy the transposition is Legislative Decree 138/2024 (D.Lgs. 138/2024), in force since 16 October 2024, and the competent NIS authority is ACN, the national cybersecurity agency.
NIS2 compliance reaches SMEs by two routes:
The fastest way to know which route applies to your company is to check in 2 minutes whether NIS2 applies to you: six questions, plain words, no registration. The result is indicative and is not legal advice; confirm the classification with the national authority.
Scope is decided by sector and size together. The Italian scope published by ACN covers 18 sectors, 11 highly critical and 7 critical, with more than 80 types of entity. Examples of highly critical sectors are energy, transport, banking, health, drinking water, digital infrastructure and ICT service management; critical sectors include postal services, waste, chemicals, food, manufacturing, digital providers and research. Public administrations are classified separately in Italy: central bodies as essential entities, regional and local bodies as important entities, regardless of size. The full list is on the ACN portal and in the annexes of the decree.
The size rule follows the EU definition of a medium enterprise (Commission Recommendation 2003/361/EC): 50 or more employees, or an annual turnover and a balance-sheet total both above 10 million euro. Below that line a small or micro company is generally out of direct scope, with specific exceptions listed in the national law (for example certain digital and trust service providers, regardless of size).
In broad terms, the classification into NIS2 essential and important entities works like this:
The exact result for your sector and size is in the ACN scope table (sector by company size). If you operate in another EU country, the national authority publishes the equivalent list and the classification may differ in detail.
Article 21 requires essential and important entities to secure their supply chain, including the relationship with each direct supplier and service provider. In practice this means your NIS2 customer sends a questionnaire or a contractual annex and expects documented answers. ACN has published a FAQ on supply chain measures (24 July 2026), a sign that this is now an active area of supervision in Italy.
What a NIS2 customer, an insurer or an auditor typically asks a supplier to show:
None of these requests depends on you being an essential or important entity yourself. For most suppliers the question "does NIS2 apply to my suppliers" is answered by the customer's obligations rather than by the supplier's own classification. One Italy-specific exception: a supplier that provides ICT or security services to an essential or important entity, or operates systems its service depends on, can be brought into scope regardless of size (D.Lgs. 138/2024, Article 3). For every other supplier the obligation is contractual. This is why NIS2 compliance is a commercial topic for SMEs even outside the direct scope: the evidence is what keeps you on the supplier list.
Article 21 of the directive lists the risk management measures every essential and important entity must adopt, proportionate to its exposure and size. In the Italian decree the same list appears in Article 24, and ACN specifies it further with the basic security measures. In plain words the ten areas are:
For an SME the measures that can be demonstrated with technical evidence are 2, 4, 5, 6, 8, 9 and part of 1 and 10. The rest is organisational work: documents, decisions and training records.
The reporting obligation is the part of NIS2 compliance with a clock attached. When an essential or important entity becomes aware of a significant incident, the sequence is:
In Italy the recipient is CSIRT Italia, through the channel indicated by ACN, and the reporting obligations apply from January 2026. Other member states designate their own CSIRT: check the national authority for the channel and the exact form.
To meet a 24-hour early warning you need three capabilities in place before the incident: something that sees the traffic, a triage that separates a significant incident from noise, and a record of who decided what and when. A SOC as a service built around staged triage gives an SME these three capabilities without building a control room of its own.
The dates below are Italy-specific and come from the ACN NIS portal. For any other EU country, check the national authority: the thresholds are largely the same, the calendar is not.
NIS2 penalties. Administrative fines can reach 10 million euro or 2 percent of worldwide annual turnover for essential entities, and 7 million euro or 1.4 percent for important entities, whichever is higher. The decree also provides for measures against the management body. The figures are those of the directive as transposed in Italy; verify the national text elsewhere.
Most pages on this topic stop at the list of measures. This table goes one step further: each row names the measure, what you must be able to show, the Defensio component that produces it and the file or view you hand over.
All components can be bought separately. The passive network sensor covers the inside of the network, external attack surface management with Defensio XT and the cloud plan for continuous vulnerability scanning cover the public perimeter, the SOC handles detection and notification support, and email spoofing protection closes the email domain. Connecting a component to the SOC is a later decision, nothing has to be redone.
NIS2 compliance is not only technical. The following items are documents and decisions, not telemetry, and Defensio does not produce them:
For this part Fidem, the company behind Defensio, offers NIS2 and GDPR consulting. The two halves fit together: the consulting work produces the policies, the Defensio components produce the evidence that the policies are applied.
The cost of NIS2 compliance for an SME has three parts: the organisational work (consulting and internal time), the technical measures, and the recurring effort to keep the evidence current. The first and the last depend on the size of the company and on how much is already in place, so no honest page gives a single figure.
For the technical measures on the public perimeter the pricing is public. The Defensio cloud scanning plan costs 59 €/month for Starter (5 targets, 5 email addresses, scheduled scans and alerts, audit-ready reports), 149 €/month for Professional (10 targets, 15 email addresses, API and webhooks, CI/CD pipeline) and from 299 €/month for MSP (20 to 250 targets, white-label reports, multi-tenant dashboard). Annual billing is available, prices are VAT excluded, and every plan includes all scanning capabilities.
The passive network sensor and the SOC connection are sized after a review of your network topology, because the observation point (SPAN, TAP or mirror port) and the traffic volume decide the appliance. Contact us with a short description of your sites and we return a quotation, not a generic price list.
Team Fidem S.r.l.
You are directly subject if your company operates in one of the listed sectors (18 in the Italian scope, 11 highly critical and 7 critical) and is at least a medium enterprise under the EU definition: 50 or more employees, or an annual turnover and a balance-sheet total both above 10 million euro. Small and micro companies are generally out of direct scope, with specific exceptions. Even out of scope, you may have to prove security measures to a NIS2 customer. Check in 2 minutes whether NIS2 applies to you with the Defensio scope check, then confirm the classification with the national authority.
Essential entities are, in broad terms, large enterprises in highly critical sectors such as energy, transport, banking, health and digital infrastructure. Important entities are medium enterprises in those sectors and large or medium enterprises in critical sectors such as food, chemicals, manufacturing, waste and digital providers. Public administrations are classified separately in Italy: central bodies as essential entities, regional and local bodies as important entities, regardless of size. In Italy the exact sector-by-size table is published by ACN; other member states publish their own.
An SME in scope must register with the competent authority (in Italy on the ACN platform, between 1 January and 28 February), keep the registration updated each year, adopt the Article 21 risk management measures and notify significant incidents within 24 hours, 72 hours and one month. An SME outside the direct scope usually has no legal obligation under NIS2 (with the Italian exception for ICT and security providers of an in-scope entity), but has a contractual one whenever a NIS2 customer asks for evidence of its security measures.
Article 21 lists ten areas of risk management measures: risk analysis and policies, incident handling, business continuity, supply chain security, secure acquisition and vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, human resources security with access control and asset management, and multi-factor authentication with secure communications. The Italian decree carries the same list in Article 24, further specified by the ACN basic security measures.
A significant incident requires an early warning within 24 hours of becoming aware of it, a notification with an initial assessment within 72 hours, and a final report within one month of the 72-hour notification. In Italy the recipient is CSIRT Italia, through the channel indicated by ACN, and the obligation applies from January 2026. The practical requirement is to have detection and triage in place before the incident, so that the 24-hour clock does not start with a blank page.
Usually not by virtue of being a supplier, with the exception above for ICT and security providers of an in-scope entity in Italy. For everyone else it applies through the supply chain measure of Article 21: your essential or important customer must assess and manage the risk you bring, so it asks for evidence of your measures and can make them a contract condition. ACN published a dedicated FAQ on supply chain measures in July 2026. For a supplier, NIS2 compliance is therefore a question of what you can show, not of your own classification.
For essential entities administrative fines can reach 10 million euro or 2 percent of worldwide annual turnover, whichever is higher. For important entities the ceiling is 7 million euro or 1.4 percent. The Italian decree also provides for measures against the management body. The directive sets these as minimum ceilings: every member state must provide for maximums of at least these amounts and may set higher ones in national law, so check the national authority for the figures and the procedure that apply to you.
With artefacts an auditor can open: a maintained asset inventory, a prioritised vulnerability report with a remediation plan, scheduled compliance reports that show the checks are repeated, an incident record with an audit trail of decisions, and an email evidence report showing the DMARC policy and the spoofing test results. Defensio produces each of these from the passive network sensor, the external and cloud scanners, the SOC and Identity Shield. Sensor, XT and cloud-plan reports are included in the product; the signed Identity Shield evidence report is part of the Compliance plan.
Find out where your company stands before a customer, an insurer or an auditor asks. Check in 2 minutes whether NIS2 applies to you: six questions, no registration, an indicative result you can act on the same day. If the answer is yes, or if a NIS2 customer is already waiting for your evidence, contact us and we will map the Article 21 measures to the Defensio components you actually need.