The NIS2 Directive introduces stricter cybersecurity obligations for a wide range of companies and Public Administrations. For the organizations involved, these new requirements mean translating regulatory compliance into an effective capability to manage cyber risk, protect networks and assets, and ensure business continuity.
The first step in navigating the evolving NIS2 landscape is understanding the main obligations and deadlines, the applicable penalties, and the potential incentives available to support the compliance journey.

The content on this page is provided for informational purposes only and does not replace an assessment of your specific situation by qualified specialists.
What does the NIS2 directive provide for? Main obligations for companies.
IN SUMMARY – NIS2 gives management/executives direct responsibilities in cybersecurity governance: they must approve how to implement cyber risk management measures and oversee their implementation.
The NIS2 directive provides for the strengthening of cybersecurity obligations for companies and organizations considered essential or important to the operation of critical services, infrastructure and supply chains.
It aims to increase the level of cybersecurity in the production fabric and public administration by introducing obligations in three main areas:
- Responsibilities of governing bodies (Management, administrative and executive bodies)
- cyber risk management
- notification of significant incidents
These three areas are referenced in Articles 23, 24 and 25 of Legislative Decree 138/2004, which transposes the European directive.
For their application, a useful operational reference is the ACN guide to reading the NIS2 Basic Specifications. You can find it at the end of the article.

From requirement to operational control.
LECS® helps turn monitoring, anomalies and response
into readable information for those who must oversee risk.
Categorization of NIS activities and services: update April 20, 2026.
IN SUMMARY – ACN publishes the NIS 2 categorization of assets and services, affirming an important operational principle: first identify the assets and services to be secured, then link assets to these systems.
The recent categorization of NIS activities and services shifts the focus from the individual technical asset to the service the organization needs to secure. First you understand which activities are relevant to the NIS perimeter then you link systems, assets, vendors, risks, and security measures.
External vendors and services that support NIS activities or services are also part of this logic: they are not separate elements from the risk, but dependencies to be linked to processes, systems and security measures, as they can potentially increase the attack exposure surface of the network.
This makes adaptation less documentary and more operational: inventory, risk assessment, and risk management must reflect what really sustains continuity of services.
“Those who continue to work as if the first brick is still the asset risk producing documents that are neat, but already old by the time they close them.”
At the bottom of the article you will find Sandro Sana’s in-depth Cybersecurity360 article on asset categorization.
Which companies are subject to NIS2? Sectors, criteria, and supply chain.
IN SUMMARY – NIS2 entities are public and private organizations active in sectors relevant to the continuity of essential services. The assessment must also consider the supply chain: when external suppliers or services expand the attack surface they become part of the risk to be mapped, assessed and governed.
NIS2 covers public entities and companies active in areas relevant to the continuity of essential and digital services.
Specifically, subjects are identified through four main blocks:
- high criticality sectors
- other critical areas
- Public Administrations
- additional types of subjects
Several factors intervene in defining whether an organization falls under NIS2: sector, size, activity performed, role and services provided. Therefore, prior verification with technical and legal specialists is necessary before determining whether or not a company is subject to the regulations.
In general, the scope covers medium and large organizations operating in the sectors covered by the regulations. However, some categories may also be covered regardless of size (this may apply to critical entities, providers of publicly accessible electronic communications networks or services, trust service providers, TLD registry operators, DNS providers, and some public administrations.
| Category | Employees | Annual turnover | Total annual budget |
| Mirco-enterprise | < 10 | ≤ 2 Mln € | ≤ 2 Mln € |
| Small business | < 50 | ≤ 10 Mln € | ≤ 10 Mln € |
| Medium Enterprise | < 250 | ≤ 50 Mln € | ≤ 43 Mln € |
| Great Enterprise | ≥ 250 or more economic choices | > 50 Mln € | > 43 Mln € |
Supply chain NIS2: why external suppliers and services enter risk management
The regulations also require consideration of the supply chain because vendors, external services, and connected environments can expand the attack surface and require continuous monitoring of the network, assets, and abnormal events.
Therefore, supply chains can no longer be treated as secondary elements: they must be linked to the organization’s critical processes and integrated into ongoing, auditable cyber risk management.
Govern the risk in your network.
When external vendors and services impact network and processes, you need visibility
into what impacts business continuity.
NIS2 2026 deadlines: registration, updates and upcoming obligations
IN SUMMARY – NIS2 2026 deadlines depend on the location of the organization. Different entities may have different deadlines and requirements, which should be checked with trusted technical and legal professionals.
NIS2 deadlines should be read differently depending on the position of the organization.
For those who have already completed the required compliances in the first part of the year, 2026 is primarily a preparation phase: it is used to structure the compliance path, plan technical and organizational measures, and arrive ready for the next deadlines.
If, on the other hand, as of today you have not yet verified your position or have not registered or updated on the ACN platform, the priority is to check whether you need to cure any delays.
DISCLAIMER: These deadlines are not a one-size-fits-all timetable: they depend on where your organization is located. Always evaluate your compliance with with trusted specialists and attorneys.
| Deadline | Who concerns | What does it involve |
| January 1 – February 28, 2026 | Subjects affected by the NIS2 regulations | Registration or updating registration on the ACN digital platform. |
| January 1, 2027 | Subjects included in the NIS list for the first time in 2026 | Occurrence of basicsignificant incident reporting requirement . |
| July 31, 2027 | Subjects included in the NIS list for the first time in 2026 | Deadline to take basic security measures. |
What do those who do not comply with NIS2 risk?
IN SUMMARY – Failure to comply with NIS2 exposes top management to penalties, audits, liability, and concrete problems with continuity, supply chain, and reputational damage.
Breaking or ignoring the provisions of NIS2 exposes the company to direct economic consequences through penalties.
- Economic penalties: up to 10 million or 2 percent of global turnover for essential players; up to 7 million or 1.4 percent for important players.
But the indirect consequences of noncompliance, including reputational and operational consequences, must be taken into account .
- Accountability of governing bodies: direct involvement of top management can affect the perceived accountability, governance, and control of the organization.
- Reputational damage: incidents, deficiencies, or mandatory disclosures can reduce the trust of customers, partners, and stakeholders.
- Supply chain risk: critical issues related to suppliers, technology partners or external services can damage trust in the company and its ability to govern risk.
Slowdowns in workflows, loss of control over processes, and difficulties in ensuring continuity of services can have significant impact on the organization, customer relations, and turnover.
Are there incentives to comply with NIS2 for SMEs?
IN SUMMARY – Measures to be evaluated include the Cloud & Cyber Security Voucher but there is no one-size-fits-all bonus. Solutions should be checked with trained professionals. Also check the MIMIT and ACN sites for updates.
Compliance with NIS2 may require investments in cybersecurity, from anomaly monitoring as a risk management measure, to protection of network assets and even response measures in case of incidents or attacks.
This is why many SMEs wonder if there are incentives, grants or subsidies that can be used to support part of the costs.
The most consistent measure to consider is the Cloud & Cybersecurity Voucher for the purchase of new, additional or more advanced cybersecurity services and products than those already in use.
You can read an in-depth discussion of our Cloud and Cybersecurity Voucher here.
Other solutions, such as subsidized finance instruments, regional calls or measures related to digital transformation, should be evaluated together with specialized professionals. Facilities often have short deadlines and stringent access criteria: monitoring the official MIMIT and ACN websites is essential.
LECS support to NIS2 adaptation.
LECS® supports the NIS2 compliance journey by transforming some of the measures required by
into concrete operational capabilities: asset inventory, risk management, vulnerability detection, continuous monitoring, logs and evidence.
Through continuous detection LECS helps in the classification and detection of anomalies and through timely response, supports your organization in guarding and defending digital assets.

Conclusions
In conclusion, NIS2 should be read as a pathway for cybersecurity governance and continuous improvement.
Obligations, deadlines, penalties, and possible incentives should be evaluated according to the organization’s specific position, industry, services provided, assets involved, and supply chain dependencies.
So compliance requires coordinated work between management, technical managers, legal advisers and cybersecurity specialists, with the goal of turning regulatory requirements into verifiable processes, operational measures and concrete risk management capabilities.
This article will be updated over time to reflect evolving legislation, ACN operational guidance, deadlines and any support measures available to organizations.
Sources

Close the cybersecurity loop.
LECS® supports continuous, automated and auditable security,
helping to turn regulatory requirements into operational capabilities.