Menu Close

NIS2 Deadline October 2026: What SMBs Must Do

This article’s text was created with the help of AI systems and reviewed by the WIT ICT team, in accordance with Article 50 of the EU AI Act (Regulation (EU) 2024/1689) on the transparency of AI-generated content. The featured image was also generated using AI.

For a great many Italian companies, October 2026 is no longer an abstract date on a compliance roadmap. It is the point by which the security measures required under the NIS2 directive must be fully operational. Transposed into Italian law through Legislative Decree 138/2024, NIS2 is reshaping how businesses handle cyber risk — and it reaches well beyond large corporations. Smaller firms that assume they are exempt often discover they are drawn in through their supplier relationships. Understanding what is happening, on what timeline, and what to do about it is now a practical necessity rather than a legal curiosity.

What NIS2 Actually Changes in Italy

NIS2 is the second generation of the European directive on the security of network and information systems. Compared with its predecessor, it widens the range of sectors and entities covered and raises the bar on obligations. Italy transposed it through Legislative Decree 138 of 4 September 2024, which entered into force on 16 October of the same year and appointed the National Cybersecurity Agency (ACN) as the competent authority.

The underlying shift is cultural before it is technical. Cybersecurity stops being a discretionary investment and becomes a legal duty, complete with oversight, deadlines and penalties. Organisations are classified as “essential” or “important” entities according to their sector and size, and each category carries obligations scaled to the risk it poses to the wider system.

The 2026 Dates Worth Marking on Your Calendar

2026 is the year the obligations move from paper to practice. Companies that registered on the ACN platform between late 2024 and early 2025 now work to a defined schedule, punctuated by a few milestones that are hard to overlook:

  • January 2026: risk-management obligations and the procedures for reporting significant incidents become applicable.
  • 31 May 2026: the first submission to the ACN of the list of relevant NIS suppliers.
  • October 2026: baseline security measures must be fully implemented, and from this point the Agency can begin its first inspections.

Anyone reaching the deadline without having started the work risks opening too many fronts at once. Compliance cannot be improvised in a matter of weeks, because it touches processes, contracts and technology all together.

Are You Actually in Scope? How to Tell

The first step is to check whether your business falls directly under the rules. The general test combines two criteria: belonging to one of the sectors listed in the directive’s annexes — energy, transport, healthcare, digital infrastructure, waste management, food production and others — and crossing size thresholds, set broadly at 50 or more employees or an annual turnover of at least 10 million euros.

Reading those numbers, many small firms breathe a sigh of relief. This is where the most common mistake hides: staying below the thresholds does not automatically place you outside NIS2. The assessment deserves care, because a company’s position depends not only on what it is, but on whom it serves.

The Domino Effect on Suppliers: Where Small Firms Come In

The most underestimated aspect of NIS2 is supply-chain security. The directive requires essential and important entities to assess and monitor the security posture of their suppliers, mapping the critical ones and adding specific contractual clauses. The ACN has formalised the concept of the “relevant supplier”, which regulated companies must register on its platform, listing tax code, country of establishment and service categories.

The practical consequence is direct. A small software house, a studio that manages websites, a cloud provider or an IT maintenance firm may be required to demonstrate adequate security standards in order to keep working with a client bound by NIS2 — not because the state imposes it on them, but because the client, who must answer to the ACN, demands it. In effect, the obligation cascades down the chain like a row of falling dominoes.

From Principles to Practice: The Security Measures Required

For firms classified as important, the reference framework is the National Framework for Cybersecurity and Data Protection, Italy’s adaptation of the NIST model. The ACN’s provisions organise the obligations into a structured set of organisational and technical measures, each broken down into dozens of specific requirements. These are not box-ticking formalities; they shape day-to-day operations.

Areas that typically demand attention include:

  • risk analysis and management policies, with clearly assigned roles and responsibilities;
  • incident handling and notification procedures within the mandated timeframes;
  • business continuity, tested backups and recovery plans;
  • access control, multi-factor authentication and encryption of sensitive data;
  • supply-chain security and staff awareness training.

The gap between a measure that exists only on paper and one that genuinely defends the business comes down to how consistently it is applied and maintained over time.

Security Becomes a Boardroom Responsibility

One provision that shifts the internal balance is the direct involvement of management bodies. NIS2 requires directors and executives to approve risk-management measures and oversee their implementation, and it allows them to be held personally accountable in cases of serious breaches. Cybersecurity thus leaves the confines of the IT department and takes its place among the responsibilities of those who run the company.

Reinforcing that commitment is a penalty regime with significant fines, differentiated between essential and important entities. Yet beyond the financial sanction, the more tangible risk for a smaller business is reputational and commercial: losing a strategic client because you cannot guarantee the required standards often hurts more than a fine.

Building Compliance One Step at a Time

NIS2 can be approached in an orderly way, provided it is not reduced to a last-minute sprint. A sensible path begins with an honest picture of where things stand today: which data and systems are genuinely critical, where the vulnerabilities lie, which clients might soon ask for guarantees. From there, priorities are set, the most urgent gaps are closed, and the choices made are documented — because when an inspection comes, being able to show what you have done matters as much as having done it.

For many small and mid-sized companies the real obstacle is not willingness but the absence of dedicated in-house expertise. Working with a partner who understands both the technical and the organisational sides turns an obligation that feels like a burden into a chance to make the business sturdier, more trustworthy in the eyes of clients, and less exposed to the incidents that, the figures show, increasingly target smaller organisations.


Want to know more? Contact us for a free consultation.