ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting
1.2 Cybersecurity Laws The Italian cybersecurity legal framework is com - posed of EU regulations with direct applicability, EU directives implemented through national legislation and domestic instruments rooted in national security. The core of the cross-sector framework derives from the implementation of Directive (EU) 2022/2555, com - monly referred to as NIS2, which establishes a harmo - nised regime for cybersecurity risk management and incident reporting. Through its transposition, Italy has adopted a model that applies to a wide range of pub - lic and private entities and that is explicitly grounded in proportionality, managerial accountability and risk- based governance. The NIS2-derived framework identifies categories of entities operating in critical and important sectors and subjects them to obligations relating to governance arrangements, technical and organisational meas - ures, supply-chain security and incident notification. Scope is defined primarily by reference to the nature and relevance of the services provided rather than by formal legal status, reflecting the EU policy choice to prioritise functional importance over institutional form. This approach ensures that cybersecurity obligations attach to activities capable of generating systemic risk, irrespective of the organisational model adopted. Alongside the NIS2 framework, Italy maintains a dis - tinct national regime designed to protect strategic assets and services whose disruption may prejudice national security. The national cybersecurity perimeter applies to public and private entities whose networks, information systems and ICT services support essen - tial State functions. This regime imposes enhanced organisational and technical obligations and operates through implementing measures that specify security requirements, notification categories and superviso - ry interaction. The perimeter therefore introduces a security-driven layer of compliance that complements EU-derived obligations and reflects national risk pri - orities. Institutional consolidation of cybersecurity govern - ance has been achieved through the establishment of the Agency for National Cybersecurity, which centra - lises national functions relating to strategy, supervision and incident response. This institutional architecture
supports coherence between preventative regulation and operational response, and reduces fragmenta - tion in public intervention. The Agency operates at the intersection of policy development, supervisory oversight and technical co-ordination, reinforcing the effectiveness of the overall framework. Sector-specific regimes further enrich the legal land - scape. In the financial sector, the Digital Operational Resilience Act (DORA) applies directly and governs ICT risk management, incident reporting, resilience testing and third-party oversight. In the domain of products and digital supply chains, the Cyber Resilience Act introduces horizontal security-by-design obligations for products with digital elements, extending cyber - security compliance beyond organisational measures to the entire product life cycle. Italian cybersecurity law is therefore characterised by the coexistence of principle-based statutory obligations and operation - ally decisive regulatory expectations, which together define the effective standard of diligence required from regulated entities. 1.3 Cybersecurity Regulators Cybersecurity oversight in Italy is exercised through a co-ordinated system of authorities, within which the Agency for National Cybersecurity occupies a cen - tral position. The Agency acts as the institutional hub for national cybersecurity governance and combines strategic co-ordination, supervisory responsibilities and operational incident-response capabilities. With - in the NIS2 framework, it serves as the competent authority and single point of contact, ensuring con - sistency in supervision and information exchange at national and European level. The Agency also hosts and operates the national Computer Security Incident Response Team, which supports incident handling, technical co-ordination and situational awareness. This integration enables a direct link between regulatory supervision and opera - tional response, and strengthens the effectiveness of incident notification and follow-up activities. Cyberse - curity incidents are thus treated not only as compli - ance events but also as matters of systemic resilience requiring co-ordinated management.
215 CHAMBERS.COM
Powered by FlippingBook