
Security
NIS2 without panic: what changes for a small company
The NIS2 directive, transposed in Italy by legislative decree 138/2024, greatly widens the set of companies with cybersecurity obligations and puts management bodies on the hook. Companies outside the scope are drawn in as suppliers. The requirements are organisational before they are technological: no product makes you compliant.
NIS2 is usually discussed in two unhelpful ways: as a requirement affecting only large enterprises, or as an emergency to be solved by buying something. It is neither.
It is a European directive on the security of network and information systems, transposed in Italy by legislative decree 138 of 4 September 2024, which makes the National Cybersecurity Agency the competent authority. Compared with the previous regime it widens the scope considerably, and above all it moves accountability onto the people running the company.
What follows is practical orientation, not legal advice: deadlines and scope must be checked against the text in force and the Agency's communications, which periodically update lists and requirements.
Who is in scope (and why you may be without knowing)
Scope is built by crossing two criteria: the sector you operate in and the size of the company. The listed sectors go well beyond classic critical infrastructure: energy, transport, banking, health and water, but also waste management, food production and distribution, manufacturing of devices and equipment, digital services, post and couriers, research.
On size, the medium-enterprise threshold applies: broadly, organisations with at least fifty staff or turnover or balance sheet above ten million. Companies identified this way fall into two categories, essential and important entities: obligations are largely the same, what changes is the intensity of supervision and the ceiling on penalties.
Note the point that surprises most: being in scope is not an informal self-assessment. The decree requires registration on the Agency's platform within an annual window, and from there inclusion in official lists. Not having registered is not a way out: it is itself a breach.
What is actually required
The obligations reduce to three families, and none of the three can be bought.
- Manage risk. Risk analysis and security policies, incident handling, business continuity and recovery, supply chain security, access control and multi-factor authentication, encryption, staff training, procedures to assess the effectiveness of measures.
- Report incidents. Significant incidents must be reported to the authority on tight timelines: an early warning within hours of becoming aware, a fuller notification in the following days and a final report. You need to know this beforehand: nobody reads the rules in the middle of an attack.
- Involve the board. The heaviest novelty: management bodies approve the measures, oversee their implementation and must be trained. Security stops being delegated to the IT department and becomes the responsibility of whoever governs the company.
On penalties the rules set significant amounts, differentiated between essential and important entities, with ceilings linked to worldwide turnover. But for a small company the most concrete consequence is rarely the fine: it is the large customer asking for guarantees and no longer able to accept vague answers.
If one of your customers is in scope, so are you — not by law, but by contract.The effect that reaches more companies than the law obliges
The supply chain effect
This is the part that concerns most small Italian companies. The rules require in-scope entities to manage the risks coming from their suppliers. Translated: whoever is in scope must be able to demonstrate that whoever serves them is not a weak link.
In practice this shows up as increasingly detailed questionnaires, contract clauses on notification and recovery times, requests for evidence and — more and more often — the question of whether you are certified. A supplier who cannot answer is not fined: they are replaced.
It is also why many companies formally outside the scope are starting a certification path: not out of obligation, but because it is the fastest way to answer those questions once instead of at every tender.
Where to actually start
None of these steps requires a large budget, and all of them are worth doing even if you turn out to be out of scope.
- Establish whether you are in scope, crossing sector and size, and check your position on the Agency's platform. It is a documentation check, not a project.
- Take inventory. Which systems you need to work, where the data is, who holds credentials, which suppliers have access. The list is almost always longer than anyone remembers.
- Write the incident plan. Who decides, who tells whom, on what timeline, and who speaks to the authority. Two clear pages are worth more than a manual nobody opens.
- Put second factor everywhere that matters and run a restore drill. They are the two measures with the best cost-to-effect ratio, and both appear in every control list.
- Take the topic to the board. A minuted meeting approving the measures and scheduling training is, literally, one of the requirements.
What is not needed
- A "NIS2-compliant" product. No such thing: compliance is organisational, and no software certifies it on your behalf.
- Rebuilding the infrastructure. In most cases what is needed is documenting and tidying what you have, not replacing it.
- Deadline panic. Obligations come into force in phases. The real risk is not being a month late: it is reaching your first incident without knowing who calls whom.
If a customer has already sent you a security questionnaire, NIS2 already concerns you — regardless of how the scope check turns out. That is where to start: the answers that questionnaire needs are the same ones the rules need.