Who needs to consider these requirements?
NIS2's transport categories include railway infrastructure managers and railway undertakings, subject to the directive's scope rules and national implementation. A supplier does not automatically inherit the operator's legal classification, but may need to support its supply-chain risk management and evidence requirements. Assess the legal entity and the service, not just the technology brand or group name.
Key regulations and frameworks
Legislative Decree 138/2024
Law — in force from 16 October 2024
Italy's official gazette records Legislative Decree 138/2024 as the national NIS2 transposition measure, in force from 16 October 2024. The national framework covers entity identification, cybersecurity risk management and incident notification. Follow the applicable ACN implementation measures and the entity's registration or classification communications when determining which requirements and transition periods apply.
NIS2 risk management and rail scope
EU directive — implemented through national law
NIS2 includes railway infrastructure managers and railway undertakings in its transport categories. Its risk-management provisions address areas including incident handling, continuity and supply-chain security. The directive is useful for understanding the framework, but Italy's implementing law and authority measures determine the national procedure. Do not assume that every newly identified entity shares the same transition dates.
Practical steps for rail teams
Use these engineering and project-planning actions to prepare evidence for the requirements that apply to your organisation.
- Confirm the entity's NIS classification, registration owner and applicable ACN communications. Maintain a dated list of the requirements and implementation milestones that actually apply.
- Connect each important railway service to its supporting IT, operational networks and suppliers. Identify where an external maintenance connection could affect service availability.
- Agree how suppliers will provide vulnerability information and incident evidence. Exercise the operator's notification and recovery process with engineering and operational decision-makers.
Using this guide
This is an introduction to selected frameworks, not a complete legal assessment. Applicability depends on your organisation, systems and contracts. Check the linked official texts and obtain advice for your project before relying on a requirement or deadline.
