October 2026 marks an important turning point for NIS2 in Italy. Almost two years after the European deadline for transposing the directive, attention is shifting more and more toward enforcement. For many of the companies involved, this period also coincides with the deadline set to adopt the required security measures.
Adopted by the European Union in 2022, NIS2 is the directive created to strengthen the cybersecurity level of organizations considered essential or important for the functioning of the economy and of services. It expanded the number of sectors involved compared to the previous NIS and introduced more precise requirements on risk management, incident response and internal responsibilities. After the transposition phase and the identification of the entities concerned, 2026 is bringing more and more companies into the phase of operational implementation.
You might also be interested in:
ServiceOps: what it means and why ITSM and IT Operations are converging

October 2026 changes the perspective on NIS2
In Italy this shift is particularly evident. Many entities added to the NIS list in 2025 are reaching, in these weeks, the end of the 18 months allowed to adopt the baseline security measures. The exact date depends on the communication received from the National Cybersecurity Agency, so October does not coincide with a single deadline valid for all organizations.
The meaning of this period remains very clear, however. In 2025 much of the work was focused on reading the obligations and on internal organization. In 2026 the point becomes verifying what has actually been implemented. NIS2 entered into force in the European Union in January 2023, and member states had until 17 October 2024 to transpose it. Now the regulatory phase is leaving more and more room for verifying what companies have really put into practice.
NIS2 enters the daily work of IT
The directive requires cybersecurity to find room in everyday business processes. This means having an up-to-date view of the technological environment and knowing which systems support the organization’s services. IT environments are increasingly distributed between internal infrastructure and cloud services, while part of the activities is entrusted to external suppliers.
When information stays scattered across different tools, obtaining a reliable picture becomes more difficult. Having up-to-date data on assets and on service dependencies therefore becomes an important part of risk management, because it makes it possible to understand more quickly which components may be involved in a problem.
Assets, CMDB and suppliers become more relevant
IT Asset Management makes it possible to keep the information on the assets present in the organization up to date, while the CMDB helps understand how these elements connect to business services. During an incident, this relationship makes it possible to move from the component involved to the service that could suffer the consequences.
The same logic applies to suppliers. NIS2 also pays attention to supply chain security and makes it more important to know the dependencies on external parties. Knowing which services depend on technologies managed by third parties helps assess the impact of a problem and identify the parties involved more quickly.
Incidents and changes require more traceability
NIS2 introduces precise timelines for notifying significant incidents. A first communication must take place within 24 hours of becoming aware of the incident, followed by the notification required within 72 hours. Before reaching the communication, however, the team must be able to understand what happened and which services are involved.
Change Management enters this process as well. An incident can be linked to a recent update or change in the infrastructure, so being able to trace the activities carried out helps identify any relationships more quickly. Traceability also becomes useful for management, which under NIS2 must approve and supervise the measures adopted for managing cybersecurity risks.
Compliance depends on the continuity of processes
Complying with NIS2 means being able to retrieve reliable information when it is needed. You need to know which assets are present in the IT environment and which services depend on them. During an incident you need to quickly reconstruct what happened, while in ordinary management it becomes important to keep the information on changes and external dependencies up to date.
For many companies, October 2026 makes this shift particularly evident. Preparation gives way to verifying what has actually been done, and compliance depends more and more on the ability to keep processes up to date and traceable in daily work.
With Deepser, assets and services can be managed within the same platform and connected to Service Management processes. The team can keep a clearer view of the IT environment and retrieve the needed information more quickly when it has to analyze an incident or check a change. ITAM, CMDB, Incident Management, Change Management and supplier management work on the same data, reducing the fragmentation of information and improving the traceability of activities. This helps the organization manage, in a more orderly way, many of the processes that also become central on the path toward NIS2.
Try our free demo and discover how we can support your company.



