An Obligation to be addressed and developed as an Opportunity for 2026.
The next NIS2 deadlines have been established by Directive DetACN 164179/2025 as follows:
• By December 31, 2025: adopt and formalize an internal procedure for managing security incidents. Appointment of the CSIRT contact.
• January 2026: begin basic incident reporting obligations.
• April 2026: complete the development of the activity and service categorization model.
• September 2026: Fully implement basic security measures by adopting a cybersecurity policy compliant with the directive’s requirements.
The mandatory requirements for Italian companies under the NIS2 directive include assessing cyber risks, implementing technical and organizational security measures (such as multi-factor authentication and backups), managing supply chain security, managing security incidents (with reporting obligations to CSIRT Italia), and adopting a business continuity plan.
The BT INGENIUM team continues to support companies that must comply with the NIS2 directive in 2026 by providing services aimed at creating a corporate policy for managing NIS2 requirements, including the creation of a document system of procedures and records specifically tailored to the size and actual capabilities of the organization and its IT resources.
How to transform NIS2 compliance into an opportunity for Cybersecurity improvement?
Once the NIS2 management policy has been created, the organization is only a short step away from achieving a compliant and ISO 27001-certified cybersecurity management system.
BT INGENIUM engineers have operational experience in ISO 27001 and ISO 9001 management systems and can facilitate and support the integration of an NIS2 management policy with the additional requirements and procedures needed to have a more mature and ISO 27001-certified cybersecurity management policy.
GO BT INGENIUM GO!
