ACN registration, the October deadline, and the scope gaps that UK, US and Irish operators consistently overlook
URL: https://panatolawfirm.com/en/italy-nis2-compliance-foreign-companies-2026
ABSTRACT: Italy transposed the EU's NIS2 Directive through Legislative Decree 138/2024, creating cybersecurity obligations that bind any company providing essential or important services inside Italy — regardless of where it is incorporated. The ACN (Agenzia per la Cybersicurezza Nazionale — Italy's National Cybersecurity Agency) is the single competent authority, and a hard compliance deadline falls in October 2026. This guide explains what foreign operators must do, in what order, and what most of them are missing.
In January 2026, the inbox of many compliance officers at UK, US and Irish tech companies doing business in Italy quietly filled with a notification from the
ACN portale NIS2. Some opened it. Many did not recognise the sender. A handful assumed that their EU-wide NIS2 programme, drafted in Brussels and reviewed by a Big Four firm, already covered them. That assumption is worth testing carefully, because Italy has added obligations to the EU baseline that most group-level compliance frameworks do not address.
Does Italy's NIS2 Law Apply to Non-Italian Companies?The short answer is yes, and the jurisdictional logic is territorial, not corporate. Directive 2022/2555 of the European Parliament and of the Council (the NIS2 Directive) requires each member state to regulate entities that provide services within its territory. Italy transposed this through Legislative Decree no. 138 of 4 September 2024 (D.Lgs. 4 settembre 2024, n. 138), which came into force on 16 October 2024.
Article 3 of that decree catches / captures any essential or important entity — as defined by Annex I and Annex II of the underlying EU directive — that operates in Italy, regardless of where it is incorporated. A UK software-as-a-service provider with Italian customers, a US managed security service provider with Italian public-sector contracts, or an Irish cloud company whose Italian subsidiary is above the size thresholds: all three are potentially in scope.
Unlike in most common-law jurisdictions, where regulatory reach is typically anchored to incorporation or physical establishment, Italian cybersecurity law follows the market. The concept is analogous to how the GDPR operates under Regulation (EU) 2016/679, but the scope here is not limited to data processing: it covers the resilience of networks, information systems, and supply chains. A foreign company that has no Italian legal entity but provides a digital service to Italian critical-infrastructure operators may still be caught.
Italy then goes further than the EU baseline. Four national annexes to D.Lgs. 138/2024 extend mandatory scope / the scope of the obligation to categories the NIS2 Directive left to member state discretion: Italian municipalities above certain population thresholds, local public transport operators, cultural institutions managing significant digital collections, and entities in the waste management sector. For foreign companies, the practical consequence is that a service contract with any of these Italian bodies may pull the foreign provider into scope as a supply-chain participant, even if the provider itself would not otherwise meet the essential or important entity definition.
What Is the ACN Registration Portal and Who Must Register?The
ACN portale NIS2 (the online registration platform managed by the Agenzia per la Cybersicurezza Nazionale) is the single gateway through which in-scope entities identify themselves, submit information, receive their formal classification, and subsequently report security incidents. There is no paper alternative and no delegation to sector regulators: the ACN is the sole competent authority under Article 10 of D.Lgs. 138/2024.
The annual registration window runs from 1 January to 28 February. Entities that fall within scope must self-register through the portal, providing organisational details, a description of their services, size criteria (headcount and turnover), and the identity of senior management responsible for cybersecurity governance. For foreign companies without an Italian legal entity, the question … is not clearly answered in the implementing guidelines published by the ACN in late 2025, and legal advice on this point is advisable / we recommend seeking legal advice before the next window opens.
Once registered, entities await formal notification from the ACN classifying them as essential or important. That notification starts the clock on full compliance.
When Is the Deadline for NIS2 Cybersecurity Compliance in Italy?Incident reporting obligations took effect from 1 January 2026 for all entities that had already been formally notified by the ACN. From that date, any significant security incident must be handled through a three-stage sequence / three-step procedure: an early warning to the ACN within 24 hours of becoming aware of the incident; a detailed incident notification within 72 hours; and a final incident report within one month. Italy adds a fourth element not present in all member-state transpositions: for incidents still unresolved at the one-month mark, monthly progress updates are required until the incident is closed. This is not a standard requirement under the Directive itself and is easy to miss if your incident response playbook was written to the EU minimum.
Full Article 24 compliance — meaning documented implementation of the security measures across risk management, access controls, supply-chain security, cryptography, and business continuity — is required by October 2026, eighteen months after the ACN issues formal entity notifications. For most companies that registered in early 2025 and received their classification letters in spring 2025, that October 2026 date is not far away.
Board-level governance is a distinctive feature of the Italian transposition. Article 23 of D.Lgs. 138/2024 requires that the management body of each in-scope entity approve the cybersecurity risk-management measures, oversee their implementation, and receive periodic training. This approval must be evidenced in board minutes and the fact of compliance logged in the ACN portal. A group cybersecurity policy signed off at parent-company level in London or New York, without a board resolution at the Italian operating entity or a documented delegation chain, is unlikely to satisfy this requirement.
What Are the NIS2 Penalties in Italy for Non-Compliance?The ACN has investigative and supervisory powers under Chapter VI of D.Lgs. 138/2024. Fines for essential entities reach up to €10 million or 2% of total global annual turnover, whichever is higher — the same ceiling as a GDPR fine under Article 83(4). For important entities, the ceiling is €7 million or 1.4% of global turnover. The percentages apply to the worldwide group turnover, not just Italian revenues. For a US or UK parent company with a modest Italian operation but substantial global revenues, the financial exposure is therefore calibrated to global scale, not local footprint.
Beyond fines, the ACN may issue binding instructions requiring immediate remediation, suspend certifications, and — for essential entities — temporarily prohibit a named manager from exercising management functions. This last measure, modelled on powers available under some banking supervisory regimes, has no direct equivalent in the cybersecurity laws of most common-law countries and tends to surprise in-house counsel when they first encounter it.
Vigilantibus non dormientibus iura subveniunt — the law assists those who are watchful, not those who sleep. The maxim captures the posture this regime rewards: proactive engagement with the ACN, documented governance, and early registration will all weigh in an entity's favour if enforcement proceedings are ever opened.
The Gap Most Foreign Operators Miss: Supply Chain and Sector OverlapThe legal theorist Lon Fuller observed in
The Morality of Law that rules fail not because they are unclear in themselves, but because those subject to them have no accurate picture of the system as a whole. That observation fits the Italy NIS2 picture precisely.
The gap that UK, US and Irish operators most commonly overlook is the supply-chain dimension combined with Italy's extended national annexes. A foreign managed service provider that is below the standard NIS2 size thresholds — fewer than 50 employees, annual turnover under €10 million — would ordinarily fall outside the directive's scope. But if that provider supplies services to an Italian municipality or local transport operator caught by one of Italy's four national annexes, the ACN's implementing guidance indicates that the contractual chain can draw the provider into compliance obligations as a relevant third party. The ACN published its first sector-specific guidance notes in late 2025, and the supply-chain provisions have not yet been tested in enforcement proceedings, but the structural risk is real and warrants a contractual review.
A practical checklist for any foreign company with Italian exposure runs as follows. First, map every service delivered to Italian customers or Italian-contracting entities against the scope criteria in Annex I and Annex II of Directive 2022/2555 and Italy's four national annexes. Second, apply the size thresholds honestly across the group, not just the Italian entity. Third, if in scope, register on the ACN portal during the January–February window. Fourth, prepare a documented board resolution approving the cybersecurity risk-management framework and ensure it references D.Lgs. 138/2024 specifically. Fifth, build the three-stage incident reporting cascade into your incident response plan and add Italy's monthly progress update requirement. Sixth, review all service contracts with Italian public-sector or regulated entities for NIS2 supply-chain clauses.
The October 2026 deadline is a hard one. The ACN has signalled that it will move to active supervision once the eighteen-month implementation period expires, and early enforcement actions are more likely to target entities that did not register at all than those that registered and are demonstrably working towards compliance.
Image prompt: A glass-walled European office boardroom at dusk, warm amber light filtering through floor-to-ceiling windows. Around a long conference table, three business professionals in formal attire study a laptop screen showing a government portal interface. On the table, a printed document headed 'D.Lgs. 138/2024' sits beside a coffee cup. The mood is focused and slightly urgent. Colour palette: deep navy, warm amber, cool white. Documentary realism style, no text visible in the image.
Image file: italy-nis2-compliance-foreign-companies-2026-cover
JSON-LD:
LANGUAGE QA: entered into force on 16 October 2024 -> came into force on 16 October 2024 · brings into scope any essential or important entity -> catches / captures any essential or important entity · obligatory scope -> mandatory scope / the scope of the obligation · the question of which legal representative registers is not answered with full clarity -> the question … is not clearly answered · a three-stage cascade -> a three-stage sequence / three-step procedure · That notification triggers the countdown to full compliance -> That notification starts the clock on full compliance · irrespective of where it is registered -> regardless of where it is incorporated · legal advice on this point is worth taking -> legal advice on this point is advisable / we recommend seeking legal advice
CHECK:
AUTHORITY 1: Directive 2022/2555 (NIS2 Directive) / EXISTS? Yes — confirmed on EUR-Lex / CONTENT MATCHES? Yes — scope, incident reporting timelines (24h/72h/1 month), penalty ceilings confirmed.
AUTHORITY 2: D.Lgs. 4 settembre 2024, n. 138 / EXISTS? Yes — confirmed in Gazzetta Ufficiale and widely reported in Italian legal press / CONTENT MATCHES? Yes — ACN as competent authority, Article 23 board obligations, Article 24 security measures, fine ceilings (€10m/2% for essential; €7m/1.4% for important), national annexes extending scope all confirmed. Note: the four national annexes covering municipalities, local transport, cultural institutions and waste management are confirmed in the transposition text; their precise interaction with the supply-chain provisions in enforcement guidance is not yet tested in case law — flagged appropriately in the article as structural risk rather than settled law.
AUTHORITY 3: ACN guidance notes and portale NIS2 / EXISTS? Partially verifiable — the ACN portal exists and the January–February registration window is confirmed in official ACN communications. The specific late-2025 sector guidance notes on supply-chain obligations cited are plausible and consistent with the ACN's published work programme but the exact document titles and publication dates should be verified against the ACN document library before publication. TO VERIFY.
OVERALL: AMBER — the two primary legislative authorities are fully confirmed; the ACN operational guidance detail requires one final check against the ACN portal document library.
LOCALNOTE:
1. Search intent targeted: informational with transactional undertone — a compliance officer or in-house counsel at a foreign company with Italian exposure, searching for what they need to do and by when.
2. Local-market framing: pitched to UK, US and Irish legal and compliance audiences; uses familiar reference points (GDPR analogy for territorial scope, Big Four compliance programmes, common-law expectation of incorporation-based jurisdiction) to make the Italian-specific rules feel concrete and urgent.
3. Italian terms kept untranslated: <i>ACN portale NIS2</i> (used once to match actual search behaviour around the portal name), <i>Agenzia per la Cybersicurezza Nazionale</i> (official institutional name with no English equivalent in common use), <i>vigilantibus non dormientibus iura subveniunt</i> (Latin maxim, explained inline). All other Italian legal terms translated on first use per locked terminology rules.
Do you need legal assistance or a free estimate?
Author: Editorial Team — Panato Law Firm
Editorial Team — Panato Law Firm Staff