NIS2 deadline: November 2026

For organizations that receive notification from the ACN during 2025, 2026 marks the year when the obligations set out in the NIS2 directive fully enter the operational phase.
Following the initial deadlines related to incident management and governance alignment, the next step involves implementing the baseline security measures defined by the ACN, to be completed by October 31, 2026.
A new phase will therefore begin on November 1, 2026, during which the ACN may conduct verification activities and impose any applicable sanctions for non-compliance with the obligations.

  • January 1, 2026Obligation to verify incidents

    The obligations regarding the verification and management of security incidents come fully into force.

  • March 31, 2026Alignment of governance and policies

    Organizations must have aligned their governance processes and internal policies with the obligations set forth in the regulations.

  • October 31, 2026Implementation of ACN basic security measures

    The security measures required by ACN must be implemented by this date.

  • November 1, 2026Commencement of verification activities and the sanctions regime

    Starting from this date, the ACN may initiate checks on the actual compliance of organizations and apply the sanctions provided for by the regulations.

Please note: this schedule applies exclusively to entities that received notification from the ACN in 2025 regarding their inclusion within the NIS2 scope.

Who is involved

The regulations distinguish the relevant organizations into “essential entities” and “important entities,” based on the sector in which they operate, the size of the organization, and the significance of the services provided.
SECTOR
LARGE ENTERPRISE
SMALL-MEDIUM ENTERPRISE
SECTORS OF HIGH CRITICALITY
Energy
Essential
Important
Banking & Finance
Essential
Important
Healthcare
Essential
Important
Drinking Water
Essential
Important
Waste Water
Essential
Important
Digital infrastructure
Essential
Important
ICT service management (B2B)
Essential
Important
Aerospace
Essential
Important
OTHER CRITICAL SECTORS
Postal and shipping services
Important
Important
Waste management
Important
Important
Manufacture, production and distribution of chemicals
Important
Important
Food production, processing and distribution
Important
Important
Digital service providers
Important
Important
Manufacturing
Important
Important
Digital service providers
Important
Important
Research
Important
Important
ADDITIONAL TYPES OF ENTITIES
Central Public Administration
Essential
Essential
Regional and local public administration
Important
Important
Additional categories
Identification of the Competent Authority
Identification of the Competent Authority

Actions to take by October 31, 2026

  • Verify registration on the ACN portal and the accuracy of the data.
  • Conduct a gap analysis regarding ACN baseline measures: governance and risk analysis, incident management, business continuity and backups, supply chain security, MFA, encryption, and training.
  • Implement a practical notification process: defining who reports what to the CSIRT within the 24-hour and 72-hour windows.
  • Train governing bodies: training for top management is mandatory and entails personal liability.
  • Implement 24/7 monitoring: without continuous visibility, it is impossible to meet notification deadlines.

Sanctions and to whom they apply

Sanctions apply to organizations classified as “essential entities” or “important entities,” based on company size and the importance of the service provided.

For essential entities:
Financial penalties of up to €10 million or up to 2% of total global annual turnover (whichever is higher).

For important entities: Financial penalties of up to €7 million or up to 1.4% of total global annual turnover.

Failure to register: Penalties of up to 0.1% of turnover for failure to register or incorrect registration on the ACN portal.
Examples of violations that may incur penalties include failure to register on the ACN portal, failure to report incidents, inadequate security measures, or failure to cooperate with the ACN (e.g., not appointing a CSIRT contact person).

Classification
Maximum penalty
Percentage of total annual revenue
Essential entity
Up to 10 million euros
Up to 2%
Important entity
Up to 7 million euros
Up to 1.4%
Omitted or incorrect registration
Up to 0.1% of turnover

Responsibility of management bodies

The NIS2 Directive and Legislative Decree 138/2024 impose direct responsibility for cybersecurity on corporate leadership, entailing obligations of due diligence and assurance. Delegating tasks does not exempt management from oversight duties, requiring specific expertise and a proactive approach.

Key obligations for management

  • Approval: Managers must formally approve cybersecurity risk management measures.
  • Supervision: They are required to oversee the actual implementation of these measures within the organization.
  • Training: Completing specific cybersecurity training courses is mandatory, as is facilitating access to such training for employees.

Assess the impact of your NIS2 compliance journey

Reaching the October 31st deadline with a coherent compliance strategy requires translating ACN Security Measures into actions that align with the organization’s technological scope and maturity level.
NIS2do supports this assessment by linking applicable requirements to the necessary compliance activities, enabling you to estimate the required effort and associated costs.
This allows risk managers to build a compliance plan tailored to the organization’s specific context, setting intervention priorities and evaluating financial feasibility in advance.

Recommended Articles

September 8, 2026

Cyber ​​​​Resilience Act: What changes after September 11, 2026

The Cyber ​​Resilience Act (CRA) is the first European Union regulation to introduce mandatory cybersecurity requirements for all connected hardware and software products, applying the principle […]
September 8, 2025

DORA and Business Continuity: the new pillars for banks and insurance companies

The context: why finance cannot afford fragility Operational continuity is now one of the essential conditions for the banking, financial, and insurance world. A prolonged downtime […]