Country guide

Rail cyber security regulations in Italy

Italy has transposed NIS2 through Legislative Decree 138/2024. Rail organisations must assess their classification and the national implementation requirements, rather than simply applying an EU headline deadline. The operator's regulatory obligations also need to be translated into clear responsibilities for equipment vendors, maintainers and external service providers.

Official sources checked

Who needs to consider these requirements?

NIS2's transport categories include railway infrastructure managers and railway undertakings, subject to the directive's scope rules and national implementation. A supplier does not automatically inherit the operator's legal classification, but may need to support its supply-chain risk management and evidence requirements. Assess the legal entity and the service, not just the technology brand or group name.

Key regulations and frameworks

Legislative Decree 138/2024

Law — in force from 16 October 2024

Italy's official gazette records Legislative Decree 138/2024 as the national NIS2 transposition measure, in force from 16 October 2024. The national framework covers entity identification, cybersecurity risk management and incident notification. Follow the applicable ACN implementation measures and the entity's registration or classification communications when determining which requirements and transition periods apply.

Official source: Legislative Decree 138/2024

NIS2 risk management and rail scope

EU directive — implemented through national law

NIS2 includes railway infrastructure managers and railway undertakings in its transport categories. Its risk-management provisions address areas including incident handling, continuity and supply-chain security. The directive is useful for understanding the framework, but Italy's implementing law and authority measures determine the national procedure. Do not assume that every newly identified entity shares the same transition dates.

Official source: NIS2 risk management and rail scope

Practical steps for rail teams

Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.

  1. Confirm the entity's NIS classification, registration owner and applicable ACN communications. Maintain a dated list of the requirements and implementation milestones that actually apply.
  2. Connect each important railway service to its supporting IT, operational networks and suppliers. Identify where an external maintenance connection could affect service availability.
  3. Agree how suppliers will provide vulnerability information and incident evidence. Exercise the operator's notification and recovery process with engineering and operational decision-makers.

Using this guide

This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.