Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures
D.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 16 October 2024.
A sector security regimes rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds an essential or important entity under Article 3, which names an online marketplace, an online search engine and a cloud computing service among the digital providers it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, water, digital infrastructure and public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
- Adopt technical, operational and organisational measures adequate and proportionate to the risks facing the network and information systems you use in your activities or in providing your services, and to prevent or minimise the impact of an incident on the recipients of your services and on other services.
- Cover at least: risk-analysis and information-system security policies; incident handling, including the procedures and tools to carry out the Article 25 and 26 notifications; business continuity, including backup management, disaster recovery and crisis management; and supply-chain security.
- Have your management body approve and oversee these measures; expect its members to face liability for an infringement of this duty.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Criminal exposure note
Article 38's own penalty regime for an Article 24 infringement is an administrative pecuniary sanction (and, on repeated non-compliance with a formal order, a temporary disqualification of a manager); no provision reviewed here makes the infringement itself a criminal offence.
Penalty structure
Article 38(9)(a) sets the maximum administrative pecuniary sanction for an essential entity's infringement of Article 24 (excluding public administrations) at the greater of EUR 10,000,000 or 2 percent of total worldwide annual turnover for the preceding financial year, calculated per Commission Recommendation 2003/361/EC, with a floor of one-twentieth of that maximum. Article 38(9)(b) sets an important entity's maximum at the greater of EUR 7,000,000 or 1.4 percent, with a floor of one-thirtieth of that maximum, mirroring NIS2 Article 34(4) and (5). A public administration or publicly controlled entity within Annex III or Annex IV point 1 or 4 instead faces a fixed EUR 25,000 to EUR 125,000 sanction under Article 38(9)(c).
- Rule
- Higher of
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
Agenzia per la Cybersicurezza Nazionale (ACN), as the Autorità nazionale competente NIS, through CSIRT Italia and the Article 37 inspection and enforcement powers.
Settledness
- As of
- 12 September 2026
- Guidance link
- https://www.acn.gov.it/portale/nis
- Guidance body
- Agenzia per la Cybersicurezza Nazionale (ACN)
What it reaches
Obligation class
Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 24 requires an essential or important entity, defined by Article 3 against the sector annexes and including the digital providers those annexes name (an online marketplace, an online search engine, a cloud computing service), to adopt technical, operational and organisational measures adequate and proportionate to the risks its network and information systems face, on a multi-risk approach covering at least risk-analysis and security policy, incident handling (including the procedures for the Article 25 and 26 notifications), business continuity and disaster recovery, and supply-chain security, transposing NIS2 Article 21.
Article 23 places approval and oversight of these measures on the entity's own management body, whose members can be held liable for an infringement under Article 38.
When LexLint raises it
operates_social_platform
Read the law
Decreto Legislativo text, Normattiva, D.Lgs. 4 settembre 2024, n. 138