Cybersecurity for the Digital & IT Sector

Software houses, system integrators, MSPs and tech companies. 10-500 employees.

Applicable Regulations

ACN Determination - NIS2 Security Measures

0 guides

Determina ACN 38565/2025

Soggetti essenziali e importanti registrati presso ACN. Authority: ACN - Agenzia per la Cybersicurezza Nazionale.

Penalties: Sanzioni previste dal D.Lgs. 138/2024
Authority: ACN - Agenzia per la Cybersicurezza Nazionale
Deadline: April 14, 2025
Explore guides

AI Act

4 guides

EU Regulation 2024/1689

Regulation of artificial intelligence systems in the EU with a risk-based approach. Phased application: prohibited practices from Feb 2, 2025, GPAI obligations from Aug 2, 2025, high-risk systems from Aug 2, 2026

Penalties: Up to €35M or 7% of turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (inaccurate information). SMEs: proportionate caps
Authority: AI Office (EU Commission) + AgID (Italy)
Deadline: August 2, 2026
Explore guides

eIDAS

2 guides

EU Regulation 910/2014 + EU Regulation 2024/1183 (eIDAS 2.0)

Digital identity and qualified trust services (digital signature, certified email, time stamp)

Penalties: Up to €5M or 2% of annual turnover
Authority: AgID - Agency for Digital Italy
Deadline: May 20, 2026
Explore guides

GDPR

4 guides

EU Regulation 2016/679

Personal data protection in the European Union

Penalties: Up to €20M or 4% of annual global turnover
Authority: Data Protection Authority (Garante per la Protezione dei Dati Personali)
Explore guides

ISO 27001

2 guides

ISO/IEC 27001:2022 - International standard

Information Security Management System (ISMS)

Penalties: N/A (voluntary standard)
Authority: Accredited certification bodies (Accredia in Italy)
Explore guides

Legislative Decree 138/2024 - NIS2 Transposition

0 guides

D.Lgs. 138/2024

Soggetti essenziali e importanti nei 18 settori NIS2 (50+ dipendenti o 10M+ fatturato). Authority: ACN - Agenzia per la Cybersicurezza Nazionale.

Penalties: Fino a 10 milioni di euro o 2% del fatturato mondiale annuo
Authority: ACN - Agenzia per la Cybersicurezza Nazionale
Deadline: October 16, 2024
Explore guides

Loi pour la Confiance dans l'Economie Numerique (Loi n.2004-575)

0 guides

LCEN

Digital economy operators, e-commerce, ISPs. Authority: Gouvernement.

Penalties: National penalties apply
Authority: Gouvernement
Deadline: June 21, 2004
Explore guides

NIS2

4 guides

EU Directive 2022/2555 - Legislative Decree 138/2024

Network and information security for essential and important entities

Penalties: Up to €10M or 2% of annual turnover
Authority: ACN - National Cybersecurity Agency
Deadline: October 17, 2024
Explore guides

SecNumCloud - Referentiel de qualification ANSSI

0 guides

SECNUMCLOUD

Cloud service providers handling sensitive/government data. Authority: ANSSI.

Penalties: National penalties apply
Authority: ANSSI
Deadline: January 1, 2016
Explore guides

Discover Your Compliance Level for Digital & IT

Check in just a few minutes which regulations apply to your digital & it business and the priority actions to become compliant.

Start Free Assessment

Audit your website automatically

Scan your public website for GDPR cookie banner, accessibility (WCAG 2.1 AA), legal transparency and security headers — AI generates copy-pasteable fixes and a PDF report.

Discover the Website Compliance Audit