Compliance. Credibility. Competitiveness.

NIS2 compliance consulting for businesses

The NIS2 Directive is not just an obligation: it's an opportunity to make your business more secure and trustworthy. Since January 2026, the operational obligations are in effect: acting now is essential. AtWorkStudio, based in Piacenza, guides you through compliance with dedicated consulting and a free assessment based on NIST CSF 2.0, backed by a management system certified to ISO/IEC 27001, 27017, 27018 and ISO 9001.

Free online assessment

Is your business ready for NIS2?

Find out in 15 minutes with our assessment based on the NIST Cybersecurity Framework 2.0, the international standard for cyber risk management.

106 questions · Instant report · No commitment

2026 Operational Deadlines

NIS2 obligations are in effect: what to do now

Since 1 January 2026, the operational obligations of the NIS2 Directive are active. Organisations classified as essential or important entities must comply immediately. Full compliance is required by October 2026. Penalties can reach 10 million euros or 2% of global turnover for essential entities, and 7 million euros or 1.4% for important entities.

Incident notification

Pre-notification within 24 hours to CSIRT Italia, formal notification within 72 hours and a final report within 1 month. ACN clarified that the 24 hours start from evidence of the incident, not from the moment it physically occurred: incident management plans must distinguish between occurrence, detection, evidence, materiality assessment and pre-notification activation.

Governance and accountability

The board of directors and management approve and supervise cyber risk management measures. ACN clarified that supervision of implementation can be delegated, but responsibility remains collective and cannot be delegated.

Business continuity

Business continuity and disaster recovery plans are mandatory, not optional. Organisations must ensure the resilience of essential services even in the event of a serious incident.

Relevant suppliers: ICT and non-fungible

It is not enough to assess ICT suppliers. ACN clarified that the key is fungibility: hard-to-replace non-ICT suppliers (raw materials, specific industrial components, critical logistics services) whose absence would compromise NIS activities must be included as well.

Expanded scope

NIS2 covers many more sectors and now includes medium-sized enterprises. Energy, transport, healthcare, digital infrastructure, public administration and many others must comply.

October 2026 deadline

Full compliance with all directive requirements is required by October 2026. Time to comply is limited: starting today means avoiding penalties and protecting your business.
ACN clarifications April 2026

Categorisation, scope and proportionality

After the clarifications from the Clusit/ACN event of 29 April 2026, NIS2 is entering the phase of real risk governance: it is no longer enough to know whether you are an essential or important entity, you must demonstrate the ability to govern activities, services, information systems and suppliers. We summarised the operational points in our news «NIS2: ACN clarifications from the Clusit event of 29 April 2026».

Categorisation of activities and services

We identify the NIS activities and services delivered, map them to the macro-areas defined by ACN and assign the relevance category, motivating each choice. Decision traceability, not bureaucracy: the basis on which ACN will calibrate future obligations.

Scope: information and network system

NIS2 measures apply to the information and network system as a whole, not the individual asset. We build the inventory starting from activities and services, then the systems that support them, finally assets and dependencies. Inverse logic compared to traditional inventories.

Operational proportionality

Proportionality does not stop at the essential/important distinction. It applies to the activities delivered, the systems that support them and the relevance category assigned. Baseline measures already cover part of the long-term framework: every step counts.
EU Directive 2022/2555

What is the NIS2 Directive and who needs to comply

The NIS2 Directive is the European regulation that broadens cybersecurity obligations for organisations in essential and important sectors. Italy transposed it through D.Lgs. 138/2024, introducing requirements on risk management, incident reporting and security governance. Penalties can reach 10 million euros or 2% of global turnover.

NIST CSF 2.0 Assessment

We start with a free assessment based on the NIST framework to capture your current cyber maturity level. 106 questions, an instant report and a concrete action plan to close the gaps.

Consulting and implementation

We support you through risk analysis, security policy definition, incident management and staff training. A tailored path, from gap analysis to full compliance.

ISO 27001 Certifications

Our management system is certified to ISO/IEC 27001, 27017, 27018 and ISO 9001. We support you in achieving the certifications that demonstrate compliance and strengthen the trust of clients and partners.
Our service

NIS2 consulting: how we support you

A structured NIS2 compliance journey, from the initial snapshot to verifiable compliance. We act as your single consultant across gap analysis, categorisation, security measures and dealings with ACN (the Italian National Cybersecurity Agency), backed by a management system certified to ISO/IEC 27001, 27017, 27018 and ISO 9001.

1. Gap analysis and assessment

We start with the NIST CSF 2.0 assessment to capture your maturity level and identify the gaps against NIS2 obligations. Output: a prioritised compliance plan.

2. Categorisation and suppliers

We identify NIS activities and services (article 30 of D.Lgs. 138/2024), map them to the ACN macro-areas and register relevant suppliers, both ICT and non-fungible, motivating each choice.

3. Measures, governance, incidents

We define security measures, policies, governance roles and the incident notification plan (pre-notification 24h, notification 72h, report within 1 month), embedding them into business processes.

4. Ongoing support and audits

We support you in maintaining compliance over time and preparing for audits, with traceable documentary evidence. Serious independent verification, no «miraculous certification».

Frequently asked questions about the NIS2 Directive

Answers to the most common questions about NIS2 compliance for businesses.

NIS2 as an opportunity: strengthen your business and stay ahead of change

Contact us for dedicated consulting on NIS2 Directive compliance. We will guide you step by step through the compliance journey.