Threat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mapping

Italy's National Cybersecurity Agency (ACN), essential and important entitiesmedium

NIS2 in Italy: on 31 October the declaring-only phase ends

Italy's NIS2 calendar reaches its most demanding milestone. After registration on the ACN platform, submission of the relevant supplier list, and categorisation of activities and services — all of which fell due in the first half of 2026 — what remains is the substantive obligation: having the baseline security measures required by Legislative Decree 138/2024 operational by October 2026. This is the point where compliance stops being paperwork. From then on the agency holds inspection and enforcement powers, and the difference between organisations that prepared and organisations that filled in forms becomes checkable.

Where we are in the calendar

NIS2 is the European directive that extends cybersecurity obligations to a far wider set of organisations than the 2016 NIS directive, and that shifts the centre of gravity from incident reporting to risk management. Italy transposed it through Legislative Decree 138 of 2024, which tasks the National Cybersecurity Agency (ACN) with setting out the detail of timing and content.

The method ACN chose is gradualism: not every obligation starts at once, and duties have been distributed across successive time windows. The result is a calendar that is particularly dense in 2026, and whose most visible part — the one made of registrations and forms — is now behind us.

  1. January-February 2026
    Registration

    Window to register or renew registration on the ACN platform.

  2. April-May 2026
    Suppliers

    Submission of the list of relevant suppliers with the required information.

  3. May-June 2026
    Categorisation

    Listing and categorising activities and services, closing on 30 June.

  4. October 2026
    Baseline measures

    Baseline security measures must be fully operational.

Why October is different from everything else

The first-half milestones share one characteristic: they are discharged by filling something in. You register, you list suppliers, you categorise activities and services. These take time, internal coordination and some non-trivial decisions — categorisation especially, which asks you to declare how much each area of activity weighs — but they remain operations on the documentary plane.

The October deadline is not like that. It requires baseline security measures to be operational: multi-factor authentication, access control, backup, vulnerability management, incident response procedures. Those are things you demonstrate by working, not by declaring.

Until October
you declared
registration, suppliers, categorisation
From October
you demonstrate
the measures must actually be running
Then
you get checked
the agency's inspection and enforcement powers

There is also a difference in legal nature worth keeping in view. A declaratory duty is either discharged or not: either the form went in on time, or it did not. A security measure, by contrast, is a continuum. Multi-factor authentication on every administrative login is not the same thing as multi-factor authentication on email only. A backup that exists is not a backup that was tested. A written response procedure is not a procedure anyone has rehearsed.

This is where organisations split in two, and the split does not follow size but a choice made months earlier: those who used the NIS2 path as an occasion to put their house in order, and those who used it as a compliance exercise.

A detail that matters more than it looks: notifications

One obligation with no autumn deadline because it is already live — and in practice the one most often got wrong — is the notification of significant incidents to CSIRT Italia.

The reason it goes wrong is almost always the same: at the moment of the incident, nobody knows who notifies, what counts as significant, and by when. Those three facts are recovered badly under pressure and perfectly well on a quiet August afternoon.

They are worth checking now, in this order: who holds the credentials to access the notification platform (and what happens if that person is on holiday); where the threshold above which an incident becomes significant for your organisation is written down; which internal procedure connects the person who spots the problem to the person who files the notification.

What is verified and what is not

An explicit statement is owed here, because it concerns source quality.

Solid and verifiable: the existence and general content of Directive (EU) 2022/2555, the Italian transposition through Legislative Decree 138/2024, the role of ACN and CSIRT Italia, and the gradual structure of the compliance path.

Consistent across several independent professional sources, but not read by us in the original text: the numbers and exact dates of the individual ACN Director General determinations setting the 2026 windows, and the precise October date fixed for the baseline measures. The agency's portal responds unreliably to automated requests, and we could not consult the acts directly.

Anyone making operational decisions — especially if their organisation falls inside the perimeter — must verify dates and duties on the ACN platform and in the acts published by the agency, not on this page and not in a press round-up. This holds as a general rule: for regulatory obligations, the source is the act.

What to do in the weeks that remain

Revisit the categorisation you already submitted. If it was filled in hastily in June, it is the document telling the agency how much your activities weigh. The measures you will be asked for are calibrated on it. Worth rereading with the knowledge that it is the lens through which you are seen.

Take an honest inventory of the baseline measures. Not "we have MFA", but: on which systems, for which users, with which factor, and what happens to those who do not have it. Not "we take backups", but: when was the last restore actually tested, and how long did it take.

Rehearse the notification before you need it. Even just confirming the access works and that somebody knows who logs in is a half-hour exercise worth a full day at the wrong moment.

Look at the supplier chain. The list went in during spring; the next question — the substantive one — is what happens if one of them stops. NIS2 puts supply chain security among the risk management measures, and it is the part that builds worst in a hurry.

The point

Compliance is a date. Security is what is left the following day, when there is nothing more to submit.

The organisations in better shape in November will not be the ones that met the most deadlines: they will be the ones that used the deadlines to do things that were needed anyway.

More dossiers