At one time, compliance referred solely to workplace safety. Then came privacy regulations, corporate criminal liability, cybersecurity, and its various facets such as resilience, business continuity, and more. Meanwhile, sector-specific regulations began to emerge: for financial companies, insurance firms, energy, transportation, healthcare, and IT services. 

In short, compliance is no longer a mere task to be checked off to mitigate the risk of sanctions or a document to showcase; today, compliance means having a clear understanding of interactions, sector-specific requirements, and business objectives, which can never be overlooked.

 

The NIS2 EU Directive

In recent months, many companies and public administrations have been “concerned” with the so-called NIS2 Directive.

The NIS2 Directive (Directive (EU) 2022/2555) is the European regulation that strengthens the cybersecurity framework within EU Member States, imposing stringent obligations on cybersecurity, risk management, and incident notification.

In Italy, NIS2 has been implemented through Legislative Decree No. 138 of 2024 and applies to numerous sectors, including energy, transportation, logistics, healthcare, and IT services, among others.

The primary objective of NIS2 is to enhance resilience and cybersecurity in strategic sectors by expanding the scope of the previous directive and introducing stricter requirements for businesses and public administrations.

The NIS2 sets a very short deadline with respect to the drafting of this note, in fact, whoever is the recipient of the regulation must nominate the cybersecurity contact point (internal or external), register on the ACN (National Cybersecurity Agency) portal, by 28 February 2025, and, subsequently, implement a series of obligations of a certain complexity which presuppose having conducted a preventive “gap analysis”.

This means a significant workload for CEOs, CISOs, CIOs, IT Managers, DPOs, and multiple other corporate roles and departments.

 

The DORA regulation

Another regulation that is dominating discussions in recent months is DORA.

The Digital Operational Resilience Act (DORA), formally Regulation (EU) 2022/2554, is an European Union regulation that came into force on January 16, 2023 and will apply in Italy from January 17, 2025, to:

  • Financial entities
  • Insurance companies
  • Critical ICT service providers operating in the regulated sectors.

DORA aims to ensure digital operational resilience, setting uniform standards for managing IT risks and cybersecurity threats.

What is Digital Operational Resilience?

Digital operational resilience refers to an organization’s ability to withstand, adapt to, and effectively respond to cybersecurity incidents, cyberattacks, IT system disruptions.

This is achieved by:

  1. Implementing ICT risk management strategies to ensure business continuity;
  2. Promptly reporting cybersecurity incidents to the competent authorities;
  3. Undergoing stress tests and simulations to assess their ability to withstand cyberattacks;
  4. Monitoring external ICT service providers and reducing reliance on non-compliant vendors.

While it may seem that DORA applies to a narrower range of entities than NIS2 (as it directly targets financial and insurance entities), both regulations — along with the General Data Protection Regulation (GDPR) — share a key common element: the need for robust supply chain management.

Ensuring supply chain compliance

For too long, companies have sought to avoid compliance measures that require strict supplier oversight, such as:

  • Careful selection of vendors;
  • Evaluation of actual competencies;
  • Verification of their ability to protect information managed on behalf of the client;
  • Regular audits;
  • Demanding adherence to high security standards;
  • Replacing suppliers that fail to meet compliance requirements or refuse to guarantee adequate security measures.

It is no longer possible to avoid this issue. It must be formally regulated (for instance, through organizational procedures and protocols) and properly managed.

However, caution is advised! While reading this note, do not allow room for panic or concern, but rather for a calm and rational awareness that these regulations can be implemented and managed with professionalism, knowledge, and experience


Riccardo Abeti