Directive (EU) 2022/2555, transposed in Italy by Legislative Decree 138/2024. We take you from gap analysis to compliance, with certifiable technical, organisational and incident response measures.
A five-phase programme to bring your company to full compliance.
Check of applicability (essential/important), assessment of existing technical and organisational measures, report with a prioritised list of non-compliances.
Mapping of critical assets and suppliers (supply chain), threat analysis, risk assessment using the ISO/IEC 27005 methodology, treatment plan.
Definition of roles and responsibilities (CISO, DPO), drafting of operational policies and internal rules, accountability of the management body as required by Article 23.
Implementation of the 10 minimum measures required: MFA, encryption, backup, vulnerability management, network segregation, EDR, access control.
Incident management procedure, integration with CSIRT Italia, early warning within 24h, notification within 72h, final report within 30 days.
Mandatory awareness training for employees and the management body, periodic maintenance audits, attack simulation exercises (red team / tabletop).
The directive applies to essential and important entities in these sectors:
Directive (EU) 2022/2555, known as NIS2, is the new European cybersecurity legislation replacing the previous NIS. In Italy it was transposed by Legislative Decree 138/2024 and imposes stricter requirements for cyber risk management and incident reporting.
NIS2 applies to essential and important entities in 18 sectors that exceed certain size thresholds (generally 50 employees or EUR 10 million turnover). BAIT Service offers a free gap analysis to check whether it applies to you.
For essential entities, up to EUR 10 million or 2% of global annual turnover. For important entities, up to EUR 7 million or 1.4% of turnover. Personal liability is also provided for management bodies.
Find out in 30 minutes whether your company is in scope and what your current level of compliance is. Free preliminary gap analysis.
Request a gap analysisFill in the form and one of our consultants will get back to you