Skip to main content

The European Directives NIS2 and CER, implementing the DORA Regulation, have been transposed in Italy with the Legislative Decrees 134 and 138 of 2024, to introduce into the national legislation the regulatory updates issued by the European Union in the field of Cyber Security

How the EU Cyber Security Directives NIS2 and CER have been implemented in Italy?

Before presenting how the European Directives implementing the DORA Regulationthe Digital Operational Resilience Act for the financial sector – have been implemented within the Italian legislation, it is necessary to introduce the main elements included in the documents issued by the EU.

First, the Directive (EU) 2022/2555, known as “NIS2” (from Network and Information Security), is the document defining the measures to ensure a common high level of Cyber Security within the European Union.

The NIS2 establishes measures aimed at ensuring a high level of information security, which must be implemented by those already obliged to comply with the DORA Regulation, namely banking and financial operators, to improve the functioning of the internal market in the EU.

In addition to NIS2, also the Directive (EU) 2022/2557, identified with the acronym “CER” (from Critical Entities Resilience), is focused on the resilience of critical subjects (namely entities providing essential services of critical importance for the maintenance of vital functions of society, economic activities, public safety and health and the environment), by establishing rules to ensure the provision of essential services in the internal market, enhancing the resilience of critical entities and cross-border cooperation between competent authorities.

In addition, the CER Directive sets out rules for the supervision of critical entities and the identification of critical entities of particular relevance at European level.

Legislative Decree 134/2024: the transposition of the European CER Directive in Italy

Once clarified these key elements of the two European Directives, it is possible to introduce the two regulatory documents that have transposed them into the Italian legislation.

The first is the Legislative Decree of 4 September 2024, n. 134, published in the Official Journal no. 223 of 23 September 2024. This document is the decree implementing the CER Directive in Italy and establishing the Inter-ministerial Committee for Resilience (CIR) at the Presidency of the Council of Ministers, which directs resilience policies and exercises high-level oversight over the implementation of the national resilience strategy for critical entities.

The same decree also defines the Competent Sectoral Authorities (ASCs), namely the ministries responsible for each area, from energy to transport, from health care to water, banking and financial market infrastructures.

The ASCs’ task is to identify for each sector and subsector the subjects considered critical by 17 January 2026 and to communicate them to the PCU (Single Point of Contact) within the framework of the Presidency of the Council of Ministers.

The ASCs and PCUs are also the recipients of reports of major incidents – which disrupt or may significantly disrupt the provision of essential services – by critical entities.

In particular, the significance of incidents shall be assessed on the basis of the number and percentage of users affected, the duration of the disturbance and the geographical area affected, taking into account any geographical isolation of the disturbance.

In addition, the ASCs are responsible for supervising the implementation of resilience measures by critical entities and for imposing sanctions for failure to implement the Decree transposing the CER Directive.

The ASCs may impose an administrative fine of between 25.000 and 125.000 euros on critical subjects who prove to be non-compliant.

It is also important to clarify here that the provisions on resilience of critical entities, identification of critical entities of particular European relevance and supervision do not apply to critical entities in the banking sector, financial market infrastructures and digital infrastructures, to which the specific sector-specific framework applies.


Learn more

Legislative Decree 138/2024: the transposition of the NIS2 European Directive in Italy

Immediately after the enactment of Legislative Decree n. 134, also the Legislative Decree 4 September 2024, n. 138, was published in the Official Gazette n. 230 of 1 October 2024.

This document transposes the NIS2 Directive, which, as already mentioned, introduces the measures to be followed to ensure a common high level of Cyber Security in the EU, repealing Directive (EU) 2016/1148, the so-called “NIS”.

The Decree 138, structured in six chapters, therefore establishes measures to increase the high level of Cyber Security at national level, helping to increase the common level of security in the EU.

In particular, the Decree implementing the NIS2 introduces some relevant definitions in the area of Cyber Security, such as those of Information and network systems security, Information security, Cyber Security, Incident, Near-miss, Large-scale Cyber Security Incident, Incident Management, Cyber Threat, Significant Cyber Threat, ICT Product, ICT Service, ICT Process, and more.

The entities obliged under the Decree implementing the NIS2 Directive are public and private entities operating in sectors considered critical and highly critical, such as banking and financial market infrastructures, but also some categories of Public Administrations (including central PAs) and other types of entities (such as private entities that exceed the community ceilings for small enterprises), but those involved in national security, Public security and defence, the Parliament, the Judicial Authority and the Central Bank are excluded.

All the involved stakeholders are required to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of information and network systems, which such entities use in their activities or in the provision of their services, and to prevent or minimise the impact of accidents on the recipients of their services.

By way of example, the required technical measures include risk analysis and security policies for information and network systems, incident management, the use of encryption and multi-factor authentication, and so on.

The Decree implementing the NIS2 also establishes the competent national authorities, namely the National Cyber Security Agency (ACNS) – a contact for cross-border cooperation of the national authorities with the relevant national authorities of other Member States, the Commission and the ENISA – and the CSIRT Italia (National Cyber Security Incident Response Team) – the IT security incident management body for the designated entities.

Finally, the Decree implementing the NIS2 Directive also defines the penalties for non-compliance, with respect to which the ACNS may specify the criteria for determining the amount, taking the necessary measures to ensure its effectiveness, proportionality, deterrence and enforcement.

In particular, the penalties for key entities, excluding PAs, can be up to 10 million euros or 2% of the total annual worldwide turnover for the previous year, while for major entities, the penalties may be up to a maximum of 7 million euros or 1,4% of the entity’s total annual worldwide turnover for the previous financial year.

Assessing the impacts of regulatory updates is easier than ever with Aptus

Considering what has just been described, it is therefore clear that the regulatory analysis and impact assessment work required from financial institutions’ compliance teams in the Cyber Security field will be very challenging.

That’s why a technological solution like Aptus – capable of automating the steps of compliance processes where human capabilities cannot add value – is really necessary.

Using a proprietary machine-readable format of the regulatory texts, Aptus.AI’s RegTech platform offers an enhanced version of the legal texts, which automatically identifies the regulatory requirements and obligations, also taking into account the internal processes and policies of the specific organisation.

In a complex environment like the European Union, Aptus allows organizations not only to reduce the time and cost required to implement the regulatory updates, but also to anticipate regulatory trends and to turn compliance into a business lever.


Book a demo

Discovering Aptus’ features created for compliance professionals

To better understand how Aptus.AI’s RegTech solution optimizes financial institutions’ compliance processes, it is useful to present the main functionalities of the platform.

First, Aptus.Outlook allows users to analyse regulatory documents even before their official publication, so that you can prepare in advance for future updates that the EU will issue in the field of Cyber Security, to plan the necessary compliance activities.

Aptus.Alert offers automatic updates via email, customized according to users’ preferences, exploiting a real-time monitoring of the institutional websites of the authorities, to speed up and streamline compliance workflows.

Aptus.Search then provides an advanced search both inside and outside the European regulatory documents, helping to immediately identify the obligations introduced, the possible sanctions and all the useful information for the transposition of the EU regulations.

Finally, Aptus.Chat has been designed to provide an even more intuitive, fast and effective consultation of the legal documents about Cyber Security, exploiting the Generative AI service integrated in Aptus which allows users to ask directly to the regulations through a conversational interface. Aptus.Chat leverages a regulatory analysis based on requirements objectively translated into a digital format and follows the official hierarchy of standards, being the first reliable and hallucination-free Generative AI for the legal sector.

Request a demo

Fill out the form to be contacted by our team.

By clicking on “Submit” you will give your consent to the treatment of your data as described in the terms and conditions of our Privacy Policy.