Abstract network visualization representing coordinated regulatory oversight between two compliance frameworks

DORA-Only or Still NIS2? Why Intesa Sanpaolo, UniCredit, and Banco BPM Can’t Fully Escape ACN Oversight

Italy’s largest banks spent 2025 treating the Digital Operational Resilience Act as the regulation that took NIS2 off their desk. That’s mostly true — and the part that isn’t true is where compliance teams at Intesa Sanpaolo, UniCredit, Banco BPM, and every smaller Italian credit institution keep tripping. DORA’s lex specialis status genuinely displaces NIS2’s risk-management and incident-notification rules for the entities it covers. But Italy’s own National Cybersecurity Agency (ACN) has said, in its own published guidance, that one NIS2 obligation survives the DORA exemption intact: registration. Layer on Banca d’Italia’s dual role as both DORA supervisor and a body that still has to talk to ACN’s CSIRT, and “DORA-only” turns out to mean something narrower than most generic DORA-vs-NIS2 explainers suggest. This guide maps exactly where the Italian carve-out starts and stops, using D.Lgs 138/2024, D.Lgs 23/2025, and ACN’s and Banca d’Italia’s own published positions — read alongside our broader Italy NIS2 transposition guide for the full country picture.

Which Italian Financial Entities Does This Actually Cover?

In plain terms: if your organisation is a bank, investment firm, insurer, or pension fund supervised under Italian financial law, you almost certainly sit inside DORA’s scope — the open question is which specific NIS2 obligations DORA actually removes, not whether finance as a sector is exempt. The answer depends on which DORA competent authority supervises you, since D.Lgs 10 marzo 2025, n. 23 split that role four ways [8].

Entity type Italian DORA competent authority NIS2/ACN status
Credit institutions — Intesa Sanpaolo, UniCredit, Banco BPM, and other authorised banks, plus Cassa Depositi e Prestiti and Bancoposta Banca d’Italia Registration duty applies (Art. 7, D.Lgs 138/2024); substantive risk-management/incident rules displaced [3][8]
Investment firms, SGR (asset managers), SIM (investment intermediaries) CONSOB Same displacement pattern, CONSOB channel [8]
Insurance and reinsurance undertakings IVASS Same displacement pattern, IVASS channel [8]
Occupational pension funds above DORA’s proportionality thresholds COVIP Same displacement pattern, COVIP channel [8]
Non-financial subsidiaries inside a banking or insurance group — an in-house IT-services company, a data-centre subsidiary, a non-regulated fintech arm None — not a DORA entity type Full NIS2 Article 21 measures and CSIRT Italia reporting apply if Italy’s medium/large size thresholds are met

Notice what the table doesn’t say: it doesn’t say “finance is out of NIS2 scope.” ACN’s own scope guidance frames the DORA carve-out as entity-specific and obligation-specific — it names the exact sectors (banking under Allegato I, point 3; financial market infrastructure under Allegato I, point 4) and the exact obligation that survives (registration), not a blanket sector exemption [3].

The Legal Mechanism: Why “DORA-Only” Isn’t a Full Exemption

In plain terms: the exemption doesn’t come from DORA declaring itself special — it comes from a clause written into NIS2 itself, and that clause only switches off the specific NIS2 provisions that DORA’s own requirements already cover to an equivalent standard.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Article 4 of the NIS2 Directive states that where a sector-specific EU legal act imposes cybersecurity risk-management or incident-notification requirements “at least equivalent in effect” to NIS2’s own, the corresponding NIS2 provisions do not apply to the entities that act covers [1]. That’s the operative switch. DORA’s own preamble adds a framing statement — Recital 16 says “this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555” — but a recital is non-binding legislative intent, not the legal mechanism itself; the actual exemption runs through NIS2’s Article 4, not DORA’s recital [2].

Italy transposed both halves of this separately, on different timelines, which is part of why the boundary confuses even compliance teams that have read both texts. D.Lgs 4 settembre 2024, n. 138 transposed NIS2 into Italian law, in force from 16 October 2024, with ACN as the single national NIS competent authority [9]. D.Lgs 10 marzo 2025, n. 23 came five months later, implementing DORA and naming Banca d’Italia, CONSOB, IVASS, and COVIP as the sector-specific authorities that make Article 4’s equivalence test operative for Italian financial entities [8]. Neither decree, read alone, tells you where the line sits — you need ACN’s own scope guidance, published after both, to see it.

Our general DORA vs NIS2 comparison walks through the EU-wide version of Article 4’s equivalence test in more depth. What’s specific to Italy is what Banca d’Italia and ACN each do with it in practice.

Banca d’Italia’s Two Hats: DORA Supervisor and ACN’s Financial-Sector Counterpart

In plain terms: Banca d’Italia isn’t one of ACN’s nine sector ministries — it runs a parallel supervisory track that DORA created, and its own recent rulemaking shows that track is now fully operative, not just a directive-level abstraction.

ACN coordinates NIS2 implementation through nine sector ministries — covering energy, transport, health, digital infrastructure, and similar domains — each contributing sector expertise without independent binding supervisory or sanctioning power of their own [9], a structure our Italy competent-authority guide covers in full. Finance isn’t one of those nine. Instead, D.Lgs 23/2025 gave Banca d’Italia direct DORA supervisory authority over banks, financial intermediaries, Cassa Depositi e Prestiti, and Bancoposta — a mandate that sits alongside ACN’s structure rather than inside it, with CONSOB, IVASS, and COVIP running the equivalent tracks for investment firms, insurers, and pension funds [8].

Banca d’Italia’s own site confirms it “engages with ACN, national authorities and other institutions” on cybersecurity matters, while carrying the DORA mandate directly [4]. The clearest evidence that mandate is now fully live: Banca d’Italia’s 51st update to Circolare 285, its core banking-supervision rulebook, adopted 3 February 2026 and published in the Gazzetta Ufficiale on 18 February 2026 [5][6]. That update stripped the bank’s own ICT-governance chapter — Chapter 4 of Title IV, previously Banca d’Italia’s home-grown rules on information systems and outsourcing — and replaced it with a direct reference to DORA’s own requirements and technical standards [6]. Circolare 285 no longer duplicates ICT governance rules alongside DORA; as of February 2026, DORA is the only rulebook a supervised Italian bank reads for that chapter.

The Co-Supervision Reality: What Residual NIS2 Obligations Actually Require

In plain terms: “DORA-only” doesn’t mean ACN disappears from a bank’s compliance picture — it means ACN’s role shrinks to a registration record and a data-relay function that Banca d’Italia, not the bank, actually carries out.

Four mechanics make up what’s realistically left of NIS2 for a DORA-covered Italian bank:

Registration survives the exemption. ACN’s own scope FAQ is explicit: for banking and financial-market-infrastructure entities meeting Italy’s medium/large thresholds, the Article 7 registration obligation under D.Lgs 138/2024 still applies even though the substantive risk-management and incident-notification provisions do not [3]. A DORA-covered bank still shows up on ACN’s national register — it just doesn’t carry the full Article 21 measure set once it’s there.

No dual incident reporting — but a relay obligation for the authority, not the bank. A DORA-covered institution reports a major ICT incident once, to its own sector authority (Banca d’Italia, CONSOB, or IVASS), on DORA’s own phased timeline. It is not also filing separately to CSIRT Italia under NIS2’s four-phase structure — the 24-hour early warning, 72-hour notification, intermediate report, and one-month final report that Article 23 sets for entities still fully on the NIS2 track [7]. What survives is an obligation on the sector authority itself: Banca d’Italia, CONSOB, and IVASS retain a duty to transmit relevant incident information onward to national CSIRTs and ENISA [7]. The bank’s compliance burden is lighter; the information still reaches ACN’s operational structure, CSIRT Italia — just via Banca d’Italia’s desk, not the bank’s own filing.

Cross-sector crisis coordination doesn’t stop at the DORA boundary. NIS2’s broader cooperation ecosystem — national crisis-management structures and EU-level mechanisms for incidents that cross sectors or member states — still reaches financial entities when an event’s blast radius goes beyond banking alone, independent of day-to-day DORA supervision.

Non-financial subsidiaries get none of this. The exemption attaches to the DORA-covered legal entity, not to the corporate group. An in-house IT-services company, data-centre subsidiary, or non-regulated fintech arm inside a banking group is not itself a DORA entity type — it sits on ACN’s national NIS list in full, with Article 21 measures and direct CSIRT Italia reporting, if it clears Italy’s own size thresholds.

The Subsidiary Trap Named Banks Can’t DORA Their Way Out Of

Intesa Sanpaolo, UniCredit, and Banco BPM are each credit institutions squarely inside DORA’s Article 2(1) entity list — their core banking ICT risk management and incident rules run through DORA, supervised by Banca d’Italia. None of that is in dispute, and nothing above changes it.

What’s easy to miss is structural. Large Italian banking groups typically operate through multiple separate legal entities — payment-processing subsidiaries, data-analytics units, insurance-distribution arms, in-house technology companies — and DORA’s carve-out from NIS2 attaches to the specific entity DORA actually supervises, not to the group as a whole. A compliance programme built only around the parent bank’s DORA obligations can miss a subsidiary that owes ACN full NIS2 compliance in its own right.

DORA-covered bank entity Non-financial group subsidiary
Risk-management measures DORA’s ICT risk framework (Banca d’Italia-supervised) Full NIS2 Article 21(2), ten measures
Incident reporting DORA phased reporting to Banca d’Italia; no separate CSIRT Italia filing NIS2 Article 23: 24h/72h/1-month, direct to CSIRT Italia
ACN registration Required (Art. 7, registration only) [3] Required in full, with essential/important self-classification
Penalty exposure D.Lgs 23/2025 sanctions: €30,000 up to 10% of turnover for governance/management failures [8] D.Lgs 138/2024 Art. 38 ceiling — see full breakdown on our Italy penalties guide

Reader Playbook by Role

Compliance officer or legal: map every legal entity in the group against Banca d’Italia’s, CONSOB’s, IVASS’s, or COVIP’s DORA supervision — not just the parent bank — and document which entities remain on ACN’s register for full NIS2 versus registration-only. That classification record is the evidence a supervisor asks for first.

CISO or IT security lead: don’t assume “we’re DORA-compliant” answers the NIS2 question for every subsidiary. Confirm, entity by entity, whether Circolare 285’s February 2026 update (or the CONSOB/IVASS/COVIP equivalent for non-bank entities) actually covers that entity’s ICT governance — or whether it’s a non-financial subsidiary still running on full Article 21.

Board or C-suite: ask which entities in the group sit on ACN’s national NIS list independent of the parent bank’s DORA status, and get the answer confirmed in board minutes alongside DORA governance sign-off.

SME owner or smaller financial entity — a small SGR, a regional insurance intermediary: don’t assume “financial sector” alone earns any exemption. Check where your entity type actually sits against DORA’s own scope list and Italy’s registration thresholds before ruling NIS2 out.

Compliance Checklist

  • Confirm the supervising DORA authority for every legal entity in your group — Banca d’Italia, CONSOB, IVASS, or COVIP — not just the parent.
  • Register with ACN for every DORA-covered entity meeting Italy’s medium/large thresholds — the registration duty survives the exemption [3].
  • Identify non-financial subsidiaries — IT-services companies, data-centre units, fintech arms — and assess them against Article 21 and CSIRT Italia registration independently.
  • Document incident-routing: DORA-phased reports to your sector authority for DORA entities; Article 23’s 24h/72h/1-month chain, direct to CSIRT Italia, for anything still on the full NIS2 track.

Frequently Asked Questions

Does DORA remove Intesa Sanpaolo, UniCredit, and Banco BPM from NIS2 entirely? No. It displaces the substantive risk-management and incident-notification obligations for the DORA-covered banking entity, but ACN’s own guidance confirms the registration duty still applies [3].

Do these banks still report incidents to ACN’s CSIRT Italia directly? Not directly for DORA-covered incidents — they report to Banca d’Italia under DORA’s own timeline. Banca d’Italia, as the sector authority, retains the obligation to relay relevant information to CSIRT Italia and ENISA [7].

What about a bank’s IT subsidiary or fintech arm? If that entity isn’t itself a DORA entity type, it gets no displacement — it’s assessed for NIS2 on its own, against Italy’s standard size thresholds.

Legal Disclaimer

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive, Article 4 — nis-2-directive.com, Article 4 (sector-specific Union acts / binding equivalence mechanism)
  2. DORA, Regulation (EU) 2022/2554, Recital 16 — EUR-Lex, full text (non-binding lex specialis statement)
  3. ACN, “Domande frequenti NIS — Ambito” — acn.gov.it official FAQ (FAQ AMB.NO.2 — registration survives the DORA exemption for banking/FMI entities)
  4. Banca d’Italia, “Cybersicurezza” — bancaditalia.it (DORA role, engagement with ACN)
  5. Banca d’Italia, Circolare 285 update archive — bancaditalia.it (51° aggiornamento, 3 February 2026)
  6. Diritto Bancario, “La circolare 285 di Banca d’Italia aggiornata a Regolamento e Direttiva DORA” — dirittobancario.it (Gazzetta Ufficiale publication date, ICT-governance chapter replacement)
  7. Diritto Bancario, “La gestione degli incidenti ICT tra DORA e NIS2” — dirittobancario.it (no dual notification; sectoral authority relay obligation)
  8. Agenda Digitale, “DORA, ecco come l’attua l’Italia: sanzioni e vigilanza” — agendadigitale.eu (D.Lgs 23/2025 authority allocation, sanctions framework)
  9. NIS2 Directive 2 Wiki, “NIS 2 status in Italy” — nisd2.eu (D.Lgs 138/2024 transposition, ACN structure, registration window)
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: