Back to home
    Deep Dive7 min read

    NIS2 in Italy: What ACN Actually Checks

    When ACN opens your NIS file, it does not ask for a certificate. It asks for dated documents. In practice it looks at four things. Your registration on the ACN portal and its annual update. The approval of the measures by the management and administrative bodies. The state of each cybersecurity risk-management measure, with the evidence attached. The traceability of your significant-incident notifications. Everything else is decoration. This article lines up, obligation by obligation, the document you must be able to put on the table.

    Monitoring, checks and inspections are three different activities

    The ACN FAQs on monitoring, supervision and enforcement separate three layers. Monitoring is continuous and largely passive from your side: the Agency collects, analyses and supports. Checks and inspections are discrete, document-driven activities. Enforcement measures come afterwards, as an outcome.

    The operational difference is the trigger. For essential entities, checks may be ordered ex ante, without a triggering event. For important entities, the Agency moves when it holds evidence, indications or information. Same law, two different doors.

    Practical consequence: if you are an essential entity, the file has to be coherent all the time, not only after an incident.

    Essential or important is not your choice

    The tier follows from the sector, not from a self-declaration. High-criticality sectors sit in Annex I (Annex 1) of the Directive, other critical sectors in Annex II (Annex 2). On top of the sector comes the size test: 50 employees or more, or more than EUR 10 million in turnover or annual balance-sheet total.

    Some entities are in regardless of size — among others DNS service providers, top-level domain name registries and qualified trust service providers. That is why the Italian list of NIS entities also contains very small companies.

    An Annex II (Annex 2) entity is never essential. Inside Annex I (Annex 1), essential status belongs to entities above the medium-enterprise ceilings, plus the categories captured regardless of size.

    The calendar the Agency already holds

    ACN starts from data you supplied. Registration or update of registration for NIS entities runs from 1 January to 28 February every year. From 15 April to 31 May, NIS entities carry out the annual update of their information.

    Then come the substantive deadlines. For entities added to the list in 2025, ACN points to January 2026 as the start of the incident-notification duty. The deadline for completing the basic cybersecurity measures is October 2026. Entities entering the list in 2026 get their own clock: notifications from 1 January 2027, basic measures by 31 July 2027.

    The European context tells you where we are. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice. The ground was the failure to notify full transposition of the Directive. The Commission asked the Court for a lump sum and daily penalties. The Court has not ruled and no penalty has been imposed. Italy, by contrast, transposed against the 17 October 2024 deadline. Legislative Decree 138/2024 was published in the Official Gazette on 1 October 2024 and has been in force since 16 October 2024. Here the question is no longer whether there will be a law, but what you will be asked to show.

    The evidence for each Art. 21(2) measure

    Art. 21(2), points (a) to (j), lists the cybersecurity risk-management measures. A check does not want one master document. It wants, measure by measure, a status, a responsible role, a link to the evidence and a next-review date.

    Two concrete examples.

    Supply chain. On 24 July 2026 ACN updated its FAQs on supply-chain security measures (MSB.13-MSB.19). The expected process has defined phases: risk assessment of the supply, identification of the security requirements, enforcement of the requirements and their verification. Requirements must be modulated for proportionality, relevance and adequacy against the services actually contracted. One identical questionnaire for every supplier is not the answer.

    Business continuity. "We have a plan" does not survive a check. A plan with a stated RPO and RTO, the date of the last test and the test outcome does.

    The same applies to cryptography: a policy with no review date is a policy nobody has looked at.

    24-hour early warning, 72-hour notification, one-month final report

    The chain sits in Art. 23(4) of the Directive. Early warning without undue delay and in any event within 24 hours of becoming aware of the significant incident. Incident notification within 72 hours. An intermediate report on request. And a final report not later than one month after the notification.

    In Italy, ACN determination 379907 of 19 December 2025 applies from 15 January 2026. It renders the same chain towards CSIRT Italia: pre-notification within 24 hours, full notification within 72 hours.

    The evidence asked for is not the message you sent. It is the moment you became aware, who assessed significance and on what criterion, and the timestamp of each leg. Without those three elements, a punctual notification proves nothing.

    A note of realism. In July 2026 alone, CSIRT Italia sent 8,952 communications to Italian public bodies and companies about potential compromises or risk factors. In the same month it recorded 188 incidents and 305 total events. That is an operational figure, not an enforcement statistic. It still says something useful: statistically, your first contact with the Agency is an inbound communication, not an inspection.

    Notifying the recipients of your services

    The duty to inform recipients of services about significant incidents is proven by two objects. The first is the communication template approved before the incident. The second is the dispatch ledger with date, recipient count and acknowledgements.

    Approval by the management body

    This is where ACN has been clearest recently. On 14 July 2026 it updated the FAQs on the duties of administrative and management bodies. Approving the documents required by art. 23 of the Italian NIS decree is the exclusive competence of the body, whether collegiate or single-member. That approval cannot be delegated; carrying out the operational activities remains delegable.

    The same FAQs clarify what goes to the body for approval. The documents submitted must set the direction and strategic planning of the measures. Technical and operational documentation may be produced by the competent functions without the body's approval. The documentation may be a single document or a coordinated set. Updating the technical documents does not require re-approving the strategic part.

    Translated into evidence: a dated resolution, referring to an identified version of the measure set. It carries the scope described and the next review date.

    What to fix, in order

    Registration first, with its last update date. Then the board resolution, with version and date. Then the measure matrix, with evidence attached. Last, the notification chain, proven on a real incident or on a dated exercise.

    If you also run AI systems, the same documentary logic applies under the AI Act: the EU AI Act checklist uses the same evidence-and-owner structure.

    Frequently asked questions

    What does an ACN check look at first?

    The documentary file. Typically: the registration on the ACN portal and the date of its last update. Then the management body's resolution on the measures. Then the status of each measure with the evidence attached, and the traceability of incident notifications. Not a certificate.

    Can ACN inspect without an incident?

    For essential entities, yes: the ACN FAQs on monitoring, supervision and enforcement state that checks may be ordered ex ante. For important entities the Agency acts when it holds evidence, indications or information. The tier follows from the sector, not from a choice.

    What are the notification deadlines for a significant incident?

    The Directive sets an early warning within 24 hours of becoming aware and an incident notification within 72 hours. The final report is due not later than one month after the notification. In Italy, ACN determination 379907 of 19 December 2025 applies from 15 January 2026. It sets a pre-notification within 24 hours and a full notification within 72 hours to CSIRT Italia.

    By when must I complete the basic security measures?

    It depends on when you entered the list. For entities added in 2025, ACN points to October 2026 for completing the basic cybersecurity measures. The notification duty for that cohort started in January 2026. For entities entering the list in 2026: measures by 31 July 2027, notifications from 1 January 2027.

    Can the management body delegate the approval of the documents?

    No. The ACN FAQs updated on 14 July 2026 state that approving the documents required by art. 23 of the Italian NIS decree is the exclusive competence of the body, whether collegiate or single-member, and cannot be delegated. Carrying out the underlying operational activities remains delegable.

    Related resources

    This article is information, not legal advice. Your organisation's qualification, its NIS tier and the significance of an incident must be confirmed with your legal adviser. Check them against the official ACN and EUR-Lex sources.

    On LandingRed the notification chain is already wired. The NIS2 clocks sit on the incident: 24-hour early warning and 72-hour notification. The final report falls one month after the notification is submitted, computed from the submission date you record on the incident. Filing with CSIRT Italia stays your step: the platform records the reference you obtain. See the NIS2 page.

    LandingRed automates all of this

    Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.