nis 2​

​The NIS 2 Directive identifies two categories of public and private operators: “essential entities” and “important entities”.

NIS 2 applies to the essential sectors of energy, transport, banking, financial infrastructure, water, healthcare and digital infrastructure, including digital service providers (e-commerce, search engines, cloud computing, ICT services), public administration and space.

NIS 2 lists “other critical sectors” which include postal services, waste management, production and distribution of chemicals, food production, manufacturing of medical devices, manufacturing of computers and electronics, manufacturing of electrical equipment, manufacturing of machinery, manufacturing of motor vehicles, digital service providers, research organisations. NIS 2 also applies to providers of communications networks, electronic communications services, providers of domain name registration services and certain public administration entities. With Legislative Decree 4 September 2024, n. 138, Italy has implemented into national law Directive (EU) 2022/2555, relating to measures for a high common level of cybersecurity in the Union, repealing the previous directive. The articles of the Directive have been reproduced, with a different numbering, and are in force and binding.

Legislative Decree 138 has officially set the deadlines for compliance.

iqons has developed a methodology based on an incremental adaptation path, divided into phases.​​

iqons, in collaboration with Cybera, has developed significant skills in the healthcare and pharmaceutical sector (Annex I - 5. healthcare sector, Annex II - 5.a manufacturing of medical devices) and in the operating processes of purification and waste management plants (Annex I - 6. drinking water, 7. waste water, Annex II - 2. waste management).

This has made it possible to study new risk and control elements and to identify threats and vulnerabilities: in processes and on IT and OT networks and systems, which can lead to "significant incidents" NIS 2.