NIS2 Compliance
in Italy
The NIS2 Directive requires verifiable technical security measures. We help you demonstrate compliance with gap analysis and penetration tests tailored for ACN audits.
Scope
Is your organization subject to NIS2?
D.Lgs. 138/2024 transposed the NIS2 Directive into Italian law. Organizations classified as essential service operators (OES) or important service operators (OI) in critical sectors are subject.
Essential Sectors (OES)
- → Energy (electricity, gas, oil)
- → Transport (air, rail, road, maritime)
- → Banking and financial infrastructure
- → Healthcare (hospitals, labs, pharma R&D)
- → Drinking water and wastewater
- → Digital infrastructure and cloud
Important Sectors (OI)
- → Postal and courier services
- → Waste management
- → Chemical and food manufacturing
- → Medical devices and automotive
- → Digital providers (marketplace, cloud, search)
- → Scientific research
Note: SMBs may also be subject if they provide critical services or are part of an OES/OI supply chain. If unsure, our initial gap analysis is free and gives you a clear answer within 24 hours.
Our Approach
How SPECTROSEC supports your NIS2 journey
NIS2 Gap Analysis
Map NIS2 requirements against your current infrastructure. Identifies priority gaps and required actions. From €1,500
Penetration Test for Audit
Technical assessment with ACN audit-ready reporting. Demonstrates the technical due diligence required by the regulation. From €2,500
Continuous Monitoring
Quarterly retest subscription with CVE alerts for your stack. Maintain compliance over time without internal effort. From €600/quarter
Subject to NIS2?
Free initial gap analysis. We tell you within 24 hours whether you're in scope and what you need to do.
Check your compliance