Above 50 employees NIS2 enters scope, and above €10M data sovereignty stops being a slogan.
NIS2 D.Lgs. 138/2024 applies on a combined sector-and-size threshold: an Italian company active in one of the regulated sectors and above the relevant size band falls in the direct scope, and so does a sizeable share of its supply chain. The compliance bar is real, set by the ACN baseline security measures, distinct for essential and important entities, with board-level liability for non-compliance.
Lemnia T3 (sovereign on-prem) runs on a dedicated GPU appliance inside the company's data centre or server room. The entire stack, namely model, graph, ingestion and audit log, lives on the company's hardware. No fragment of customer, supplier or employee data leaves the LAN at query time. Cloud-burst stays opt-in and per-batch, and the audit log is signed.