Directive (EU) 2022/2555

Check whether NIS2 applies to your company

Last updated 30 September 2026. A summary, not legal advice. Always check the official text for your case.

What does NIS2 ask a company?

NIS2 asks medium and large organisations in critical sectors, including the manufacturing of machinery, to manage cybersecurity risk, secure their supply chain and report significant incidents within 24 hours. Management approves the measures and can be held liable. Each Member State has its own law: in Italy it is Legislative Decree 138/2024.

24 h
Early warning of a significant incidentArticle 23(4)(a)
€10 M
Or 2% of worldwide turnover, whichever is higher, for essential entities. National law may set moreArticle 34(4)
€7 M
Or 1.4% of worldwide turnover, whichever is higher, for important entities. National law may set moreArticle 34(5)
Who is covered

Medium and large organisations in the listed sectors

Sectors in Annex I and II, from medium size up. Manufacturing is in Annex II:

  • Machinery and equipment n.e.c. (NACE division 28)
  • Computer, electronic and optical products (26) and electrical equipment (27)
  • Motor vehicles (29), other transport equipment (30), medical devices

Article 2 · Annex II

Article 21

Take ten risk-management measures, at least

Appropriate and proportionate to the risk, the size of the entity and the state of the art.

  1. Risk analysis and information system security policies
  2. Incident handling
  3. Business continuity, backups, disaster recovery
  4. Supply chain security
  5. Security in acquisition, development and maintenance, including vulnerability handling
  6. Assessing the effectiveness of the measures
  7. Basic cyber hygiene and training
  8. Cryptography and encryption
  9. Human resources security, access control and asset management
  10. Multi-factor authentication and secured communications

Article 21(2)

Article 23

Report a significant incident in three steps

To the national CSIRT or the competent authority. Where appropriate, also tell the recipients of your services.

  1. Early warning within 24 hoursSay whether it may be malicious or cross-border.
  2. Notification within 72 hoursA first assessment, severity and impact.
  3. Final report within one monthRoot cause and the measures taken.

Article 23(4)

In Italy

Legislative Decree 138/2024

In force since 16 October 2024. The Agenzia per la Cybersicurezza Nazionale (ACN) is the competent authority. Entities in scope register on the ACN platform and keep the registration up to date.

The NIS legislation on the ACN site

the management bodies of essential and important entities approve the cybersecurity risk-management measures […] oversee its implementation and can be held liable for infringements
Article 20(1)

What to do first

  • Check whether your company is in scope in your country
  • Map the assets and flows of the OT network
  • Segment by process, starting from the most critical line
FAQ

Questions about NIS2

Is a machine builder in scope of NIS2?

A medium or large company that manufactures machinery and equipment (NACE Rev. 2, division 28) is in Annex II, so it is in scope, as an important entity unless it is designated essential (Article 2, Annex II). Check your national law for the details.

What is the law in Italy?

Legislative Decree 138/2024, in force since 16 October 2024. The competent authority is the Agenzia per la Cybersicurezza Nazionale (ACN), and entities in scope register on its platform (ACN).

Does NIS2 affect me if I am a small supplier?

Not directly. But your customers in scope must manage the security of their supply chain (Article 21(2)(d)), so they ask their suppliers for security documentation and a vulnerability process.

Are the managers personally responsible?

The management bodies approve the risk-management measures, oversee them and can be held liable for infringements. They must also follow training (Article 20).

Where are you against 20 January 2027?

Seven questions about how you work today. Three minutes. You get a score out of 10 and what is missing for you.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026