NIS2 in practice: who is in scope, what changes, how to prepare
Directive (EU) 2022/2555 widens the perimeter and puts accountability on management bodies. An operational reading, without alarmism.

NIS2 — Directive (EU) 2022/2555 — replaces the original 2016 NIS directive and substantially widens the number of companies required to manage cyber risk in a structured way. In Italy it was transposed through Legislative Decree 138/2024, which designates the National Cybersecurity Agency (ACN) as the competent authority. The European transposition deadline was 17 October 2024.
The point is not the acronym but the shift in centre of gravity: security stops being a technical matter delegated to IT and becomes a governance obligation with explicit accountability sitting with management bodies. Let us look concretely at who is in scope, what changes and where to start.
Who is in scope: essential and important entities
NIS2 drops the old distinction between operators of essential services and digital service providers and introduces two categories: essential entities and important entities. The difference is not in the security obligations — which are essentially the same — but in the intensity of supervision and the sanctions regime: essential entities face proactive supervision, important ones mostly ex post oversight.
Scope is defined by sectors (Annexes I and II: energy, transport, health, water, digital infrastructure, public administration, but also manufacturing, food, waste management, postal services) combined with a size threshold: as a general rule medium and large enterprises are covered, meaning at least 50 employees or more than EUR 10 million in turnover. There are, however, exceptions that apply regardless of size, for instance for certain digital infrastructure providers or entities critical to a given territory.
The first useful exercise is trivial yet often skipped: establish your qualification in a documented way, including the knock-on effect along the supply chain, because a company outside the perimeter can still be pulled in as a relevant supplier to an in-scope entity.
Risk management: the minimum measures
Article 21 of the directive sets out a set of minimum measures that entities must adopt with a risk-proportionate approach. It is not a shopping list of products but a list of areas to govern: risk analysis and information system security policies, incident handling, business continuity and recovery, supply chain security, security in system acquisition and maintenance, assessment of the effectiveness of measures, basic cyber hygiene and training, cryptography, access control and asset management, and the use of multi-factor authentication.
The key word is proportionality: the directive asks for measures appropriate to the actual risk, the size and the exposure. A hospital and a regional postal operator do not face the same scenarios, and NIS2 does not expect them to respond in the same way.
Incident notification: the 24-hour window
For significant incidents the directive lays out a staged path. Within 24 hours of becoming aware of the incident an early warning must be sent; within 72 hours a fuller notification with an initial severity and impact assessment; on request, an intermediate report; and within one month a final report with root-cause analysis, measures taken and any cross-border impact. An incident is significant when it can cause severe operational disruption or financial loss, or affect other entities.
The practical lesson is that these deadlines are not met by improvising during a crisis. They require detection processes, classification criteria decided in advance and clear roles on who decides and who communicates: most companies fail on time, not on content.
The accountability of management bodies
This is the real cultural change in NIS2. Management bodies approve the risk-management measures, oversee their implementation and can be held accountable for them. The directive also requires members of those bodies to undergo appropriate training, and that training to be extended to staff. Security stops being something that happens in the IT department and becomes a decision the leadership is aware of and demonstrably responsible for.
How to prepare, in order
A sensible path starts from qualification (am I in scope? as essential or important?), continues with an honest gap assessment against Article 21, and results in a roadmap prioritised by risk rather than by ease of execution. In parallel, two capabilities the directive makes non-negotiable must be built: a genuinely tested incident handling and notification process, and supply-chain oversight based on contractual requirements and verification, not on filed questionnaires.
The takeaway
NIS2 does not demand exotic technology: it demands governance, proportionality and evidence. Those who treat it as a formal compliance project produce paper; those who use it to bring order to real risk end up with a more defensible company — and, not least, a leadership that knows what it is accountable for.



