Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification
D.Lgs. 4 settembre 2024, n. 138, Art. 25
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 16 October 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds an essential or important entity under Article 3, which names an online marketplace, an online search engine and a cloud computing service among the digital providers it reaches expressly; the wider sector classes it also reaches are not separately flagged here, for the reason given on this jurisdiction's companion risk-management row.
- Notify CSIRT Italia without unjustified delay, and in any event within 24 hours of becoming aware of a significant incident, with a pre-notification stating, where possible, whether the incident appears unlawful or malicious and whether it may have a cross-border impact.
- Follow with a full notification within 72 hours of becoming aware, updating the pre-notification and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise.
- Submit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution).
- Where you are a trust-service provider, notify within 24 hours rather than 72 for an incident affecting the trust services you supply.
- Expect CSIRT Italia to respond within 24 hours of your pre-notification with an initial assessment and, on request, guidance or technical support on mitigation measures.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 38's own penalty regime for an Article 25 infringement is an administrative pecuniary sanction; no provision reviewed here makes a failure to notify itself a criminal offence.
Penalty structure
The same Article 38(9)(a) and (b) penalty tiers that govern an Article 24 infringement govern an Article 25 infringement: the greater of EUR 10,000,000 or 2 percent of worldwide turnover for an essential entity, and the greater of EUR 7,000,000 or 1.4 percent for an important entity, both excluding public administrations, which instead face the fixed EUR 25,000 to EUR 125,000 sanction of Article 38(9)(c).
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Agenzia per la Cybersicurezza Nazionale (ACN), as the Autorità nazionale competente NIS, through CSIRT Italia.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.acn.gov.it/portale/nis
- Guidance body
- Agenzia per la Cybersicurezza Nazionale (ACN)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 25 requires an essential or important entity to notify CSIRT Italia, without unjustified delay, of any incident with a significant impact on the provision of its services, on a graduated clock: a pre-notification within 24 hours of becoming aware of the incident, a full notification within 72 hours, an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an ongoing incident, monthly progress reports and a final report within one month of its resolution).
A trust-service provider notifies within 24 hours rather than 72. CSIRT Italia in turn responds within 24 hours of the pre-notification with an initial assessment and, on request, technical guidance, transposing NIS2 Article 23.
When LexLint raises it
operates_social_platform
Read the law
Decreto Legislativo text, Normattiva, D.Lgs. 4 settembre 2024, n. 138, Art. 25