Law / Italy

Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Risk-Management Measures

D.Lgs. 4 settembre 2024, n. 138, Artt. 23 e 24

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 16 October 2024.

A sector security regimes rule binding public and private bodies.

As of 12 September 2026.

What it requires

  • This binds an essential or important entity under Article 3, which names an online marketplace, an online search engine and a cloud computing service among the digital providers it reaches expressly; the wider sector classes it also reaches (energy, transport, banking, health, water, digital infrastructure and public administration) are a designation and sector class no activity in this vocabulary expresses, so they are not separately flagged here.
  • Adopt technical, operational and organisational measures adequate and proportionate to the risks facing the network and information systems you use in your activities or in providing your services, and to prevent or minimise the impact of an incident on the recipients of your services and on other services.
  • Cover at least: risk-analysis and information-system security policies; incident handling, including the procedures and tools to carry out the Article 25 and 26 notifications; business continuity, including backup management, disaster recovery and crisis management; and supply-chain security.
  • Have your management body approve and oversee these measures; expect its members to face liability for an infringement of this duty.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Article 38's own penalty regime for an Article 24 infringement is an administrative pecuniary sanction (and, on repeated non-compliance with a formal order, a temporary disqualification of a manager); no provision reviewed here makes the infringement itself a criminal offence.

Penalty structure

Article 38(9)(a) sets the maximum administrative pecuniary sanction for an essential entity's infringement of Article 24 (excluding public administrations) at the greater of EUR 10,000,000 or 2 percent of total worldwide annual turnover for the preceding financial year, calculated per Commission Recommendation 2003/361/EC, with a floor of one-twentieth of that maximum. Article 38(9)(b) sets an important entity's maximum at the greater of EUR 7,000,000 or 1.4 percent, with a floor of one-thirtieth of that maximum, mirroring NIS2 Article 34(4) and (5). A public administration or publicly controlled entity within Annex III or Annex IV point 1 or 4 instead faces a fixed EUR 25,000 to EUR 125,000 sanction under Article 38(9)(c).

Rule
Higher of
As of
12 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

Agenzia per la Cybersicurezza Nazionale (ACN), as the Autorità nazionale competente NIS, through CSIRT Italia and the Article 37 inspection and enforcement powers.

Settledness

As of
12 September 2026
Guidance link
https://www.acn.gov.it/portale/nis
Guidance body
Agenzia per la Cybersicurezza Nazionale (ACN)

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 24 requires an essential or important entity, defined by Article 3 against the sector annexes and including the digital providers those annexes name (an online marketplace, an online search engine, a cloud computing service), to adopt technical, operational and organisational measures adequate and proportionate to the risks its network and information systems face, on a multi-risk approach covering at least risk-analysis and security policy, incident handling (including the procedures for the Article 25 and 26 notifications), business continuity and disaster recovery, and supply-chain security, transposing NIS2 Article 21.

Article 23 places approval and oversight of these measures on the entity's own management body, whose members can be held liable for an infringement under Article 38.

When LexLint raises it

  • operates_social_platform

Read the law

Decreto Legislativo text, Normattiva, D.Lgs. 4 settembre 2024, n. 138

Back to the example  ·  Lint your app