Compliance
NIS2
What the EU directive asks of the entities it binds and of their suppliers, and what the platform does for each measure of article 21, including what is not in place yet.
Last updated: 2026-10-03
NIS2 is the EU directive 2022/2555 on the security of network and information systems. It binds essential and important entities in sectors such as energy, transport, banking, health, digital infrastructure and public administration. Member States had to apply it from 18 October 2024; in Italy it is transposed by Legislative Decree 138/2024.
If you are one of those entities, the AI service you use is part of your supply chain, and article 21 asks you to manage the security of your suppliers too. This page lists what the platform behind ITS INCOM AI does for each measure of article 21, and what it does not do yet.
ITS INCOM AI is run by Internet One Srl for the ITS INCOM Foundation. Whether the operator is itself bound by NIS2, and what the contract commits to, depends on ITS INCOM AI: write to segreteria@itsincom.it.
Article 21, measure by measure
| Art. 21(2) | In place | Not yet |
|---|---|---|
| (a) Risk analysis and security policies | written policies: drafts, not published | |
| (b) Incident handling | every failed attempt is recorded, with the machine and the zone | a written incident procedure: being written |
| (c) Business continuity and backups | a copy of the database every night, the last 30 kept, in Switzerland; a health check every 30 seconds takes a failing machine out of routing; if a machine fails before the first token, the request moves to another one in the same zones; the API works from its own copy of the configuration and does not wait for the control plane | |
| (d) Supply chain security | no third party processes requests; the providers are listed in Sub-processors | |
| (e) Security in development and maintenance | the full test suite runs before every release, and a failing test stops it | signed releases |
| (f) Assessing effectiveness | an independent test of the measures; a certification: the platform holds no ISO 27001 certificate and no SOC 2 report | |
| (g) Basic cyber hygiene and training | a documented programme | |
| (h) Cryptography | HTTPS on every public address; API keys stored only as a keyed hash, passwords only as a hash; the content of conversations, of the request log and of the administration log encrypted by the application | an encrypted tunnel between the API and the model machines: today they talk over the private network of the datacenter |
| (i) Human resources, access control, asset management | an inventory of every machine, kept in the control plane; administrator roles with separate permissions; an administration log that the database keeps append-only | a register of who may access which machine, and from which country |
| (j) Multi-factor authentication | two-factor authentication for administrators: not enforced yet |
Where the data are, what is kept and for how long: Sovereignty.
Incidents
An entity bound by NIS2 must report a significant incident to its CSIRT or competent authority: an early warning within 24 hours of becoming aware of it, a notification within 72 hours, and a final report within one month of the notification (article 23). To meet those times it needs its suppliers to tell it quickly.
The incident procedure of the platform is still being written. Until it is published, this page promises no notification times. What the contract commits to: ask segreteria@itsincom.it.
Questionnaires and vulnerabilities
For a security questionnaire, or an annex to a contract in your own format, write to segreteria@itsincom.it. Report a vulnerability to the same address.