Decreto Legislativo 138/2024 — the Italian NIS2 transposition
Published by Zero Hunt, an autonomous AI red team on an on-premise appliance running private AI: automated penetration testing for networks and infrastructure, black-box or gray-box, with a human approving every step that matters.
Short definition
Decreto Legislativo 138 of 4 September 2024 is the Italian transposition of NIS2 (Directive (EU) 2022/2555). It identifies essential and important entities, defines technical and organizational measures, attaches personal liability to top management, and operationalizes ACN as the competent national authority and CSIRT Italia as the national CSIRT.
Why this matters now
Decreto 138 became enforceable through 2024-2025, with phased registration of in-scope entities. Thousands of Italian organizations — utilities, healthcare ATS/ASL, regional and large municipal administrations, telco, banking, transport — are now under personal-liability obligations for cybersecurity adequacy. The standard of proof is documentary evidence of effective controls, not best-effort attestation.
Key points
- ▸Transposes Directive (EU) 2022/2555 (NIS2) into Italian law as of 16 October 2024.
- ▸Distinguishes essential entities (highest obligations) from important entities.
- ▸Personal liability of governing-body members — non-compliance is administratively sanctioned at corporate level AND can trigger personal responsibility.
- ▸Mandatory registration with ACN; mandatory designation of contact points.
- ▸Incident reporting: 24h early warning, 72h notification, 1-month final report (NIS2 Article 23 timeline).
- ▸Annual self-assessment plus on-demand inspections by ACN.
Who is in scope?
Decreto 138 expanded the scope significantly compared to the previous NIS regime. In scope as essential entities: energy, transport, banking, financial market infrastructures, healthcare, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration (central and regional). Important entities: postal/courier, waste management, chemicals, food, manufacturing of medical devices/electronics/machinery/vehicles, digital providers, research.
In practice, most medium-to-large Italian organizations in regulated sectors are now in scope. The exact threshold is determined by the implementing acts and the ACN registry; if you are not sure, the safe operational assumption for 2026 is that you are in.
The personal-liability shift
Article 23 of the decreto introduces a meaningful shift: governing-body members (board, CdA, top management) are now personally responsible for ensuring that the cybersecurity measures are appropriate, proportionate and effective. Non-compliance can trigger administrative sanctions at the corporate level AND personal responsibility.
This changes the procurement conversation. A CISO bringing a security-tooling proposal to the board is no longer arguing technical merit alone — the board has a direct, personal interest in seeing documentary evidence that the chosen tooling demonstrably reduces the gap between declared and operating effectiveness of controls.
The incident-reporting timeline
NIS2 Article 23 of the decreto operationalizes the NIS2 incident reporting cadence:
- 24 hours from becoming aware of a significant incident: early warning to ACN/CSIRT Italia with preliminary classification.
- 72 hours from the same start: full notification with impact assessment, indicators of compromise, initial root-cause analysis.
- 1 month after the 72-hour notification: final report with full root cause, remediation status, lessons learned.
Article 23 counts from "becoming aware", not from internal confirmation. Supervisors will test the date you claim against your own alerts and logs, and an alert nobody triaged is a weak argument for a late start. That is the operational reason continuous detection (not batch SIEM cadence) becomes a regulatory necessity, not just a technical preference.
ACN, CSIRT Italia, and how inspections work
ACN (Agenzia per la Cybersicurezza Nazionale) is the competent authority. CSIRT Italia, sitting under ACN, is the national CSIRT — the recipient of incident notifications and the source of sectoral threat intelligence.
ACN can conduct on-site or remote inspections, request documentation, and audit the effectiveness of declared measures. The most common practical request is to see the chain of evidence for a specific control over a defined period — exactly the artifact that a Trust Center with signed evidence (ECDSA, time-stamped logs) produces by default and a manual GRC process struggles to assemble.
Cross-references and adjacent regimes
Decreto 138 does not exist in a vacuum. It interacts with:
- AgID circulars on cloud qualification for PA (QC1-QC4 tiers, data locality requirements).
- Perimetro di Sicurezza Nazionale Cibernetica (PSNC) — separate, narrower regime for nationally-critical operators; products in production require CVCN evaluation.
- DORA — for financial entities, runs in parallel to NIS2 with its own timelines and TLPT requirements.
- GDPR — every incident involving personal data also fires the Art. 33 72h notification regime; multi-regime notifications are common.
In-scope organizations should map their controls once and re-use the evidence chain across regimes, rather than rebuild it per audit.
Goes deeper
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.