Skip to content
NIS2 Compliance — D.Lgs. 138/2024

NIS2 Compliance
in Italy

The NIS2 Directive requires verifiable technical security measures. We help you demonstrate compliance with gap analysis and penetration tests tailored for ACN audits.

Scope

Is your organization subject to NIS2?

D.Lgs. 138/2024 transposed the NIS2 Directive into Italian law. Organizations classified as essential service operators (OES) or important service operators (OI) in critical sectors are subject.

Essential Sectors (OES)

  • → Energy (electricity, gas, oil)
  • → Transport (air, rail, road, maritime)
  • → Banking and financial infrastructure
  • → Healthcare (hospitals, labs, pharma R&D)
  • → Drinking water and wastewater
  • → Digital infrastructure and cloud

Important Sectors (OI)

  • → Postal and courier services
  • → Waste management
  • → Chemical and food manufacturing
  • → Medical devices and automotive
  • → Digital providers (marketplace, cloud, search)
  • → Scientific research

Note: SMBs may also be subject if they provide critical services or are part of an OES/OI supply chain. If unsure, our initial gap analysis is free and gives you a clear answer within 24 hours.

Our Approach

How SPECTROSEC supports your NIS2 journey

01

NIS2 Gap Analysis

Map NIS2 requirements against your current infrastructure. Identifies priority gaps and required actions. From €1,500

02

Penetration Test for Audit

Technical assessment with ACN audit-ready reporting. Demonstrates the technical due diligence required by the regulation. From €2,500

03

Continuous Monitoring

Quarterly retest subscription with CVE alerts for your stack. Maintain compliance over time without internal effort. From €600/quarter

Subject to NIS2?

Free initial gap analysis. We tell you within 24 hours whether you're in scope and what you need to do.

Check your compliance