ITER/ITItaly
What the record establishes for Italy: the bodies an insider event is reported to, the channel each takes, and the act that transposes the NIS2 Directive, Directive (EU) 2022/2555.
Recipients
| Reached under | Body | Channel | Source |
|---|---|---|---|
| Data protection authorityGDPR, article 33 | Garante per la protezione dei dati personali reported | — | edpb members |
| CSIRT or competent authorityNIS2, article 23 | CSIRT Italia, within the Agenzia per la Cybersicurezza Nazionale reported | https://segnalazioni.acn.gov.it/checked 2026-09-03 The Agency's Portale segnalazioni, which carries the incident notification form. The older address, csirt.gov.it/segnalazione, resolves to the same page. The portal states that it is for sending detail about security incidents and not for opening administrative proceedings of any kind. | acn nis faq |
| Financial supervisorDORA, article 19 | Banca d'Italia reported | — | eba competent authorities |
| Market authorityMAR, article 17 | Commissione Nazionale per le Società e la Borsa (CONSOB) reported | — | esma mar nca |
Transposition of NIS2 reported
| Act | Decreto legislativo 4 settembre 2024, n. 138 |
|---|---|
| In force | 16 October 2024 |
| Recipient | CSIRT Italia, under article 25 of the decree |
| Moves a term | Yes. The national authority describes the complete notification as due within 72 hours of the pre-notification, where the Directive puts it within 72 hours of becoming aware. The pre-notification is itself due within 24 hours of becoming aware. Read that way the complete notification falls at 96 hours from awareness rather than at 72, and an organization working from the Directive alone would hold the wrong date. |
| Standing | This is how the Agency describes the obligation, not the wording of the decree. Article 25 has not been read. |
| Source | acn nis faq |
An event in Italy
The five types, each opened on this jurisdiction: the acts it obliges, the term on each, and where the report goes.
