Skip to content
GlabIT
GlabIT

Compliance · Italy · Romania · EU

NIS2 & DORA readiness

A plain-language explanation of who NIS2 and DORA may apply to, what they require, where Italy and Romania stand — and a three-step way to prepare, remediate and keep your evidence current. Technical readiness work in your language and your regulator's framework; legal conclusions stay with your counsel.

Key facts

01
Scope
Sector + size (medium/large, linked enterprises counted) + national rules and exceptions — "may apply", never automatic
02
Article 21 measures
Risk analysis · incident handling · continuity & backups · supply-chain security · secure development & vulnerability handling · effectiveness testing · cyber hygiene & training · cryptography · access control & MFA — implemented and evidenced
03
Significant incidents
24 h early warning · 72 h notification · intermediate report on request · final report ~1 month, via the national process
04
Italy
D.Lgs. 138/2024 · ACN · baseline measures ~18 months after inclusion notice (April 2025 cohort → around October 2026)
05
Romania
OUG 155/2024 · DNSC · registration & risk-assessment orders 2025; timing depends on when the rules apply to you
06
DORA
Applies from 17 January 2025 to covered financial entities; ICT providers reached mainly through contracts

Timeline

NIS2 timeline Four milestones from the directive entering into force in January 2023 to Italy's October 2026 deadline. JAN 2023 NIS2 (EU 2022/2555) enters into force OCT 2024 Member-state transposition deadline NOW Registration, gap assessment, Article 21 measures ~OCT 2026 Italy — baseline measures due for entities notified April 2025

Who NIS2 applies to

NIS2 — Directive (EU) 2022/2555 — replaced the first NIS directive across the EU. Whether it applies to a given organisation depends on several things together, and it is safer to think “may apply” than “applies”:

  • Sector. The Directive lists sectors of high criticality (Annex I) and other critical sectors (Annex II).
  • Size. As a rule, medium-sized and large organisations in those sectors — the size test uses the EU SME definition, so linked and partner enterprises are counted, which pulls many subsidiaries into scope.
  • Special categories. Some entities are in scope regardless of size — for example certain digital-infrastructure and trust-service providers, public administrations, and entities a Member State designates because a disruption would have significant effects.
  • National implementation. Each Member State transposes the Directive with its own thresholds, lists, exceptions and procedures, and identifies entities through registration and notification.

Two categories, two levels of supervision: essential entities (larger organisations in Annex I sectors; supervised proactively) and important entities (the rest; supervised after the fact). If you supply an essential or important entity, expect their supply-chain requirements to land on you even if you are not directly in scope.

What NIS2 requires (Article 21)

Article 21 lists the minimum cybersecurity risk-management measures. In practical terms:

  1. Policies on risk analysis and information-system security
  2. Incident handling
  3. Business continuity — backups, disaster recovery, crisis management
  4. Supply-chain security, including the security of relationships with direct suppliers and service providers
  5. Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of the measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on cryptography and, where appropriate, encryption
  9. Human-resources security, access control policies and asset management
  10. Multi-factor or continuous authentication, secured communications and secured emergency communications

Alongside these: reporting of significant incidents to the national CSIRT or competent authority — an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report when the CSIRT or authority requests one, and a final report normally within one month of the incident notification, all through the applicable national process (ACN/CSIRT Italia in Italy, DNSC in Romania) — management accountability — governing bodies must approve the measures, oversee their implementation and be trained — and registration with the national authority.

Italy — ACN

Italy transposed NIS2 with Legislative Decree 138/2024, in force since 16 October 2024, with the Agenzia per la Cybersicurezza Nazionale (ACN) as the competent authority. Entities registered on the ACN portal (first window January–February 2025) and received their inclusion notifications; ACN’s Determination no. 164179 of 14 April 2025 set out the baseline technical, operational and organisational security measures. Baseline measures generally become due about 18 months after an entity’s inclusion notification — for the many entities notified in April 2025, that falls around October 2026 — with further long-term obligations phased in afterwards. There is no single universal deadline: your date follows your notification. That is why the homepage points at October 2026, and why Italian companies are asking now.

Romania — DNSC

Romania transposed NIS2 with Government Emergency Ordinance 155/2024, with the Directoratul Național de Securitate Cibernetică (DNSC) as the competent authority. In 2025 DNSC issued its implementing orders on the registration/notification of entities and on the methodology for assessing an entity’s risk level, opening registration for entities in the ordinance’s annexes. Timing depends on when the rules become applicable to a given entity — do not assume a single window applies to everyone. If you have not registered or assessed your risk level, that is step one; further technical norms follow.

DORA — financial entities and their ICT providers

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies from 17 January 2025 and directly regulates covered financial entities — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and others. It requires an ICT risk-management framework, incident classification and reporting, digital operational resilience testing (including threat-led penetration testing for larger entities), ICT third-party risk management with specific contractual terms, and information-sharing arrangements.

For ICT providers the picture is different: an ordinary ICT supplier is not automatically directly regulated by DORA merely because it supplies a financial entity — it is affected through its customers’ contracts and due diligence (the mandatory contractual clauses, exit and audit rights, concentration-risk assessments), it may have another direct regulatory status of its own, and providers designated as critical ICT third-party providers by the European Supervisory Authorities fall under DORA’s direct oversight framework. Financial entities remain responsible for their own DORA obligations. If you sell software or IT services to a financial entity, expect DORA to arrive through your contracts.

Our approach — three steps

1. Gap assessment. We assess how the scope tests apply to your facts (a technical scoping, not a legal determination — that stays with your counsel and the authority), then assess your current controls against Article 21 (or DORA’s pillars) using your regulator’s framework and vocabulary — ACN’s determinations in Italy, DNSC’s methodology in Romania. Interviews, evidence review, technical checks. Output: a gap report with a risk-ranked list, in the language your board and your regulator use.

2. Remediation roadmap. A sequenced plan — quick wins, the measures that need budget, and the ones that need engineering — with owners and dates. We can execute the technical parts through Secure Engineering and penetration testing.

3. Ongoing support through CaaS. NIS2 and DORA are continuous obligations on you. Cybersecurity-as-a-Service supports the implementation, operation and evidence of the agreed measures: policy upkeep, vulnerability management, training records, supplier reviews, incident readiness and — with SOC — monitoring and reporting capability designed to support your incident-notification process. Whether you are compliant remains a legal conclusion for you, your counsel and the authority.

Sources and last reviewed

Last reviewed August 2026. This page explains the frameworks in plain language; it is not legal advice. National implementing acts and guidance continue to evolve and your counsel should confirm your specific obligations.

FAQ

Questions we get asked

How do we know if we are in scope?

Sector, size (including linked and partner enterprises under the EU SME definition), national implementation, and a set of exceptions and special categories all play a part — there is no single headcount test, and the answer is a legal one. The gap assessment starts with a technical scoping analysis you can put in front of your board and your counsel, who make the determination. If the analysis points to out-of-scope we say so — many companies still need the controls because their customers are in scope.

How long does a gap assessment take?

It depends on the size of the organisation and how quickly evidence and interviews can be scheduled; the proposal states the range for your case.

Do you provide the registration with ACN or DNSC?

We prepare the information and walk you through the portal; the submission is made by your legal representative as the regulations require.

Is this legal advice?

No. We assess and implement security controls against the regulatory requirements and produce the evidence. Legal interpretation of your obligations sits with your counsel; we work well alongside them.

We are a supplier to a bank. Does DORA apply to us?

An ordinary ICT supplier is not automatically directly regulated by DORA merely because it supplies a financial entity — but the entity must impose specific contractual terms, due diligence and exit arrangements on its ICT third-party providers, so the requirements usually arrive through your contract; you may also have another direct regulatory status of your own, and providers designated as critical by the European Supervisory Authorities fall under DORA's oversight framework. We help you meet and evidence the contractual requirements; the legal analysis is for your counsel.

Start with a gap assessment

A risk-ranked gap report in your language and your regulator's framework, and a roadmap you can act on; the timeline depends on your organisation and is stated in the proposal. Ongoing support for the agreed measures through CaaS if you want it.