NIS 2 and Model 231: Synergy That Supports Compliance

NIS 2 and Model 231: Synergy That Supports Compliance

We have outlined the scope of application of the NIS 2 Directive, analyzed the 2026 compliance deadlines, and reviewed the significant consequences for entities that are unprepared when enforcement begins.

Today we bring things full circle by introducing the relationship between NIS 2 and the 231 Organizational Model; in the next post, we’ll also discuss the synergy with ISO/IEC 27001.

This is not merely an academic exercise; rather, it is the very “core” of any integrated compliance strategy for Italian organizations that simultaneously—as is often the case—fall within the scope of NIS 2, are subject to criminal liability under Legislative Decree 231/2001, and hold (or are in the process of obtaining) ISO/IEC 27001 certification (usually, for entities subject to Legislative Decree 231, this is in addition to a potential ISO 37001 certification).

Let’s see how these three worlds interact, where they overlap, and, above all, where they generate synergistic value when addressed together rather than in separate silos.

The Key Point: Law No. 90 of 2024 and the New Article 24-bis of the Legislative Decree 231/2001

The link between NIS 2 and Model 231 is not merely a theoretical suggestion: it is explicitly stated in Law 90/2024, which also amended Article 24-bis of Legislative Decree 231/2001—the provision listing the cybercrimes relevant to the administrative liability of legal entities (one of the many Special Sections of the Model).

The reform has had at least three consequences of immediate practical significance for those who manage or oversee a Model 231.

  • First, the fines imposed on the entity for “traditional” cybercrimes—unauthorized access (Article 615-ter of the Italian Criminal Code), unlawful interception (Articles 617-quater and 617-quinquies of the Italian Criminal Code), and damage to systems (Articles 635-bis, ter, quater, and quinquies of the Italian Criminal Code) – have been increased, raising the statutory range to up to 700 units.

  • Second, a new paragraph 1-bis has been introduced specifically addressing the offense of cyber extortion (Art. 629, paragraph 3, of the Italian Criminal Code), a newly defined crime that punishes anyone who, through conduct typical of ransomware, forces someone to do or refrain from doing something. For this offense, the entity faces a fine of up to 800 daily penalty units and disqualification sanctions of no less than two years. This is no minor detail: for many organizations, the ransomware risk is already the first or second-highest cyber risk, and now that risk also has a 231 dimension.

  • Third, paragraph 2 of Article 24-bis has updated its references: the repealed Article 615-quinquies of the Criminal Code has been replaced by the new Article 635-quater.1 of the Criminal Code, alongside the retained reference to Article 615-quater. Anyone who had built their risk-crime mapping around the repealed provision now finds a gap in their model, regardless of the quality of the rest.

The practical conclusion is simple: a Model 231 that has not been updated in light of Law 90/2024 is no longer an adequate model. And an inadequate model does not exempt the entity from liability. But this conclusion has been undisputed since the introduction of Legislative Decree 231 and is supported by well-established case law on the ineffectiveness of static models and failure to update them (so-called “paper compliance”).

What is the relationship between NIS2 and ISO/IEC 27001?

We will deal with that in the next episode!

Contact us

If you would like more information about our services, please fill out the form below. We will respond as soon as possible.

Contact us

If you would like more information about our services, please fill out the form below. We will respond as soon as possible.

Contact us

If you need further information about our services, please fill in the form below. We will get back to you as soon as possible.