Alessandro AleddaInsider Threat and Risk

ITER/ITItaly

What the record establishes for Italy: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.

Recipients
4 of 4
Reporting address
Recorded
NIS2
In force 16 October 2024
Terms moved
Yes
Sources cited
4
Last read
3 SEPTEMBER 2026

Recipients

Reached underBodyChannelSource
Data protection authorityGDPR, article 33Garante per la protezione dei dati personali reportededpb members
CSIRT or competent authorityNIS2, article 23CSIRT Italia, within the Agenzia per la Cybersicurezza Nazionale reported

https://segnalazioni.acn.gov.it/checked 2026-09-03

The Agency's Portale segnalazioni, which carries the incident notification form. The older address, csirt.gov.it/segnalazione, resolves to the same page. The portal states that it is for sending detail about security incidents and not for opening administrative proceedings of any kind.

acn nis faq
Financial supervisorDORA, article 19Banca d'Italia reportedeba competent authorities
Market authorityMAR, article 17Commissione Nazionale per le Società e la Borsa (CONSOB) reportedesma mar nca

Transposition of NIS2 reported

ActDecreto legislativo 4 settembre 2024, n. 138
In force16 October 2024
RecipientCSIRT Italia, under article 25 of the decree
Moves a termYes. The national authority describes the complete notification as due within 72 hours of the pre-notification, where the Directive puts it within 72 hours of becoming aware. The pre-notification is itself due within 24 hours of becoming aware. Read that way the complete notification falls at 96 hours from awareness rather than at 72, and an organization working from the Directive alone would hold the wrong date.
StandingThis is how the Agency describes the obligation, not the wording of the decree. Article 25 has not been read.
Sourceacn nis faq

An event in Italy

The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.