ACN Italy NIS2 competent authority network infrastructure concept

Italy’s NIS2 Registration Deadline Is June 2026 — ACN’s SPID Portal, Entity Categories, and Supervisory Powers Explained

Italy’s NIS2 implementation has produced two sequential deadlines that are easy to confuse: a February 28 annual registration window on the ACN portal and a June 30 categorisation deadline introduced by ACN’s April 2026 determination. These are not the same process, they require different forms, and missing either carries distinct legal consequences under D.Lgs 138/2024, Italy’s NIS2 implementing law.

This guide covers the full architecture: how the Agenzia per la Cybersicurezza Nazionale (ACN) operates as National Competent Authority, Single Point of Contact, and CSIRT Italia host simultaneously — and why that concentration matters for Italian entities. It also walks through the SPID-authenticated services portal, explains what Determination 127437/2026 requires before June 30, and maps ACN’s supervisory and enforcement powers once those deadlines pass.

ACN’s Institutional Architecture: NCA, SPOC, and CSIRT Italia Under One Agency

Most EU member states distribute the NIS2 institutional roles across multiple bodies. Italy consolidated all three in ACN — a structural decision with direct consequences for how Italian entities experience compliance oversight and incident response.

National Competent Authority (NCA). Under Article 8 of Directive 2022/2555, each member state must designate one or more competent authorities responsible for cybersecurity and NIS2 supervision. Italy designated ACN as its single NCA across all sectors — energy, transport, healthcare, digital infrastructure, public administration, and more. ACN maintains the official registry of essential and important entities, conducts inspections, issues administrative sanctions, and monitors directive implementation nationally.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Single Point of Contact (SPOC). Article 8 of the Directive requires each member state to also designate a Single Point of Contact for cross-border cooperation. Because Italy designated one NCA rather than multiple sector-specific authorities, ACN automatically serves the SPOC function as well. This means information flowing between Italy and other EU member states’ competent authorities — including cross-border incident coordination and ENISA liaison — passes through ACN.

CSIRT Italia Host. Article 10 of the Directive requires member states to designate or establish one or more Computer Security Incident Response Teams. Italy’s national CSIRT, CSIRT Italia, operates within ACN’s institutional structure. Under NIS2, essential and important entities submit their 24-hour early warnings and 72-hour incident notifications directly to CSIRT Italia — which shares the same regulatory house as the supervisory authority. This integration means ACN can directly correlate incident reports with each entity’s compliance status when deciding whether to open supervisory proceedings.

The three-role concentration gives Italian entities a single institutional point of contact for compliance queries, incident reporting, and supervisory correspondence. It also means that an entity with gaps in its security documentation faces the same authority in an incident response conversation as it does in a supervisory audit — there is no organisational separation to navigate.

For the broader EU-wide entity registration framework and how the NCA designation interacts with registration obligations across member states, our NIS2 entity registration guide covers the Directive-level obligations that all member states must implement.

The ACN Services Portal: SPID Authentication and the Three-Phase Registration Process

The ACN portal for NIS2 is at portale.acn.gov.it. The designated contact point — an employee authorised by the organisation’s legal representative — must authenticate before accessing any registration or update functions. Three authentication routes are available.

  • SPID (Sistema Pubblico di Identità Digitale): Italy’s national digital identity system, issued by authorised identity providers to Italian residents. This is the standard route for contact points with Italian fiscal residency.
  • CIE (Carta di Identità Elettronica): Italy’s biometric identity card, which can also authenticate on the portal.
  • Alternative credentials: Contact points who cannot obtain SPID or CIE under applicable regulations — for example, non-Italian residents designated as the organisational contact — may request personal portal credentials directly from ACN. This is an exception, not the standard route, and requires a direct request to ACN support.

The registration process follows three phases:

  1. Contact Point Registration: The contact point authenticates via SPID or CIE, then uploads documentation proving their authorisation from the organisation’s legal representative.
  2. Subject Association: The contact point links their account to the organisation using either the IPA code (for public-sector bodies) or the organisation’s Italian tax ID (codice fiscale). ACN then sends a validation link to the organisation’s certified digital domicile address (PEC — Posta Elettronica Certificata).
  3. NIS Declaration: A four-section form covering company context, characterisation, subject type, and self-assessment. The contact point completes the self-assessment of whether the organisation qualifies as an essential entity, an important entity, or falls out of NIS2 scope.

The annual registration window runs December 1 through February 28 of each year. New organisations meeting NIS2 applicability criteria must register within this window. Existing registered entities must submit a fresh declaration confirming or updating their status. Non-registration carries an administrative fine of up to 0.1% of annual worldwide turnover.

A separate obligation — designating a CSIRT referent within your organisation to liaise with CSIRT Italia — must be completed by December 31 each year. This is handled through the portal’s dedicated “Data Update” section, entirely separate from the annual registration declaration.

Full registration guidance, including a step-by-step portal walkthrough, is available on ACN’s official NIS registration page.

Does NIS2 Apply to Your Organisation in Italy?

Italy applies the standard EU NIS2 thresholds plus additional coverage through two national annexes. Use this table to identify which framework applies before registering.

Entity Type Coverage Source Size Threshold Classification
Entities in Annex I sectors (energy, transport, banking, health, digital infrastructure, etc.) NIS2 Directive + D.Lgs 138/2024 Annex I 250+ employees or €50M+ turnover Essential
Entities in Annex II sectors (postal, waste, food, manufacturing, digital providers) NIS2 Directive + D.Lgs 138/2024 Annex II 50+ employees or €10M+ turnover Important
Critical infrastructure regardless of size (DNS providers, TLD registries, cloud, data centres at scale) NIS2 Directive directly No threshold Essential or Important
Central and regional government bodies D.Lgs 138/2024 Annex III As defined by Italian law Essential
Local government entities above population threshold D.Lgs 138/2024 Annex III Population threshold set by ACN guidance Important
Local public transport operators D.Lgs 138/2024 Annex IV As defined by ACN guidance Important
Universities and public research institutions D.Lgs 138/2024 Annex IV As defined by ACN guidance Important
Publicly-controlled companies in non-Annex I/II sectors D.Lgs 138/2024 Annex IV As defined by ACN guidance Important

Italy went further than the EU baseline with Annexes III and IV, adding local government, universities, local public transport, cultural organisations, and publicly-controlled companies. Entities in these categories that would be out of scope under a standard EU NIS2 reading are in scope under Italian law. The self-assessment in Phase 3 of the registration process is where you declare which classification applies — and ACN has the authority to challenge self-assessments it considers inaccurate.

For the full essential vs important classification logic across all EU sectors, see our guide on NIS2 essential vs important entity classification.

ACN’s April 2026 Categorisation Decision: Determination 127437/2026

On April 13, 2026, ACN issued Determination 127437/2026 establishing how NIS entities must identify and categorise their activities and services. This is not a continuation of the annual registration — it is a legally distinct exercise with its own deadline, its own portal workflow, and its own consequences for non-compliance.

The purpose is to enable ACN to calibrate which additional cybersecurity measures will apply proportionately to each entity. An organisation that categorises the majority of its operations as high-impact will face more demanding security requirements than one where most activities fall under minimal or low relevance. The categorisation exercise establishes the baseline from which post-October 2026 compliance obligations are derived.

The submission window is May 1 through June 30, 2026. After June 30, the submitted list is final and cannot be amended, except in cases of documented technical failure not attributable to the entity. This finality provision means errors made in the June submission cannot be quietly corrected later — if you under-categorise activities and ACN identifies the discrepancy during a review, the inaccuracy will be on record.

The 10 Macro-Areas

ACN provides a reference framework with ten macro-areas into which entities must aggregate their activities and services:

  1. Monitoring and control
  2. Production of goods and services
  3. Research, development, and design
  4. Financial management
  5. Customer management
  6. Human resources management
  7. Logistics
  8. Communication and marketing
  9. Administrative management
  10. Other services and activities

ACN’s Clusit guidance (April 2026) established default relevance assignments: monitoring and control activities default to high relevance; production and research to medium; HR, customer management, and financial management to low. These defaults reflect a general model — entities may deviate from them, but deviations require documented internal justification that must withstand ACN scrutiny. The instruction from ACN is clear: decision traceability matters more than strict adherence to the defaults, but undocumented deviations will not survive a review.

The Four Relevance Categories

Category Impact Definition Default Macro-Areas
High Compromise disrupts essential service continuity with broad societal or economic effects Monitoring and control
Medium Appreciable consequences for customers or suppliers, significant economic impact Production, R&D, logistics
Low Limited perimeter; disruption is recoverable in the short term HR management, customer management, financial management
Minimal No significant effects even if the activity is compromised Administrative management, communication and marketing

Five Steps to Complete the Categorisation Exercise

  1. Verify your contact point: The same contact point used for registration handles the categorisation submission. Confirm they are active in the portal and their authorisation has not lapsed.
  2. Map your actual activities: Involve operations, cybersecurity, legal, and management teams — not just the formal organisational chart. The categorisation must reflect operational reality, not paperwork structures.
  3. Aggregate into macro-areas: Use ACN’s reference categories. Where an activity does not fit a named macro-area, use category 10 (Other services and activities) and document the reasoning.
  4. Run a simplified impact analysis: For each activity, estimate the effect of a disruption on your ability to deliver NIS2-covered services. This is a focused business impact assessment — it documents reasoning, not a full quantitative probability analysis.
  5. Submit and archive: Complete the portal submission by June 30, and retain internal documentation supporting your categorisation. After ACN’s review (up to 90 days, extendable by 60 days), you have 30 days to respond to any modification requests ACN issues.

DORA-regulated financial institutions are exempt from the CSIRT contact point appointment obligation and from certain administrative body member reporting requirements under Determination 127434/2026. They remain subject to the broader NIS2 framework in Italy, including the categorisation exercise, unless specifically carved out.

Sector-Specific Addenda: Mandatory Under Italian Law

Italy’s implementing framework gives sector regulators authority to issue supplementary cybersecurity requirements that NIS2-registered entities in their sectors must meet alongside ACN’s national baseline. These addenda are not sector guidance — they are legally binding measures under Italy’s transposition framework.

The relevant sector regulators include ARERA for energy and water utilities, Banca d’Italia for banking and payment institutions, the Ministry of Health and regional health authorities for healthcare providers, and the Ministry of Infrastructure and Transport for certain transport operators. Each regulator may issue requirements that go beyond — but cannot contradict — ACN’s national baseline. Where sector requirements and ACN baseline requirements address the same control, entities must meet the stricter of the two.

For a compliance officer, this creates a two-register problem. You need to document how your organisation satisfies ACN’s Article 21 transposition (Article 24 of D.Lgs 138/2024) and separately document compliance with your sector regulator’s addendum. Where both address the same domain — for example, network security or incident notification timelines — document the cross-reference explicitly, noting which requirement is more demanding and how you satisfy it.

Entities operating across multiple sectors face the same logic compounded. A publicly-controlled entity operating both energy infrastructure and digital services faces ACN baseline obligations, ARERA sector requirements, and any digital-sector-specific measures — three regulatory conversations that may not always align. In those cases, ACN’s SPOC function becomes the natural coordination point for resolving conflicts between sector regulator positions.

For the supply chain dimension — including how to identify and document relevant suppliers under Determination 127434/2026 — our guide on NIS2 supply chain security requirements covers the full Article 21(2)(d) obligation.

ACN’s Supervisory Framework: Differentiated Oversight, Penalties, and Management Accountability

ACN operates a two-track supervisory regime based on entity classification, with meaningfully different oversight intensities for essential and important entities.

Essential entities are subject to both proactive and reactive supervision. ACN may initiate inspections, request documentation, and commission conformity assessments without a triggering incident. This proactive authority is significant: ACN does not need to wait for a breach or a third-party complaint to open proceedings. Essential entities should treat their compliance documentation as permanently audit-ready, not as something prepared in response to an investigation.

Important entities face primarily reactive oversight. Supervisory activity is typically triggered by a reported incident, a third-party complaint, or evidence of potential non-compliance surfaced through other means. Proactive audits of important entities are possible but less routine than for essential entities.

Penalty Structure

Entity Type Infringement Type Maximum Fine Turnover Alternative
Essential entity Serious (security failures, incident reporting, registration) €10,000,000 2% of global annual turnover (if higher)
Important entity Serious €7,000,000 1.4% of global annual turnover (if higher)
Essential entity Administrative deficiency (incomplete documentation, late updates) 0.1% of global annual turnover
Important entity Administrative deficiency 0.07% of global annual turnover
Public institution Any €125,000 Minimum €25,000

Italy distinguishes between serious infringements — substantive failures in security measures, incident reporting, or registration — and administrative deficiencies, which cover procedural incompleteness such as late updates or missing documentation. The lower administrative-deficiency scale means organisations that are broadly compliant but procedurally incomplete face a narrower exposure than those with substantive security failures. The distinction matters when prioritising remediation: fix the security gaps first, then address the documentation backlog.

Management accountability is a direct feature of Italy’s NIS2 framework. Board members and senior managers are personally accountable for approving and overseeing cybersecurity risk management measures. ACN can direct governance obligations at natural persons within management structures, not only at the legal entity. Minutes of management body meetings demonstrating that NIS2 compliance was reviewed and approved form a critical part of the audit trail — their absence signals that governance obligations were delegated without oversight rather than exercised.

For the complete map of ACN’s supervisory tools — including the administrative inspection process, corrective orders, and escalation from provisional to definitive sanctions — see our guide on NIS2 supervisory measures and enforcement powers.

Italy NIS2 Compliance Timeline 2026

The deadlines below apply to entities registered in Italy’s first cohort (registered between December 2024 and February 2025). Entities newly registered in 2026 follow a shifted schedule: incident notification obligations begin January 1, 2027, and full security measure compliance is due by July 31, 2027.

Deadline Obligation Who Owns It Effort
February 28, 2026 Annual registration declaration or status update on portale.acn.gov.it (SPID/CIE authentication) Designated contact point Low
June 30, 2026 Activity/service categorisation submission — 10 macro-areas, 4 relevance levels — via ACN portal (Determination 127437/2026) Contact point + operations + legal Medium
October 2026 Full security measure compliance across all Article 24 / NIS2 Article 21(2)(a)–(j) measures CISO / IT security lead High
December 31, annually CSIRT referent designation or renewal via ACN portal “Data Update” section CISO / security lead Low
Ongoing from January 2026 Incident notification to CSIRT Italia: 24-hour early warning, 72-hour notification, 30-day final report CISO / incident response team Per-incident (Medium)

For CISOs: The October 2026 security measure deadline is the most resource-intensive item on this table. A gap analysis against all ten Article 21(2) measures should be complete by June at the latest — risk policies, incident procedures, business continuity documentation, supply chain security, MFA deployment, and access control frameworks each require meaningful lead time. For incident notification procedures specifically, see our guide on NIS2 Article 23 incident notification requirements.

For compliance officers: The June 30 categorisation submission requires coordinated input from operations, IT, and legal. The categorisation becomes final after June 30 — an inaccurate submission cannot be quietly corrected, and ACN’s 90-day review period means a modification request may arrive months later. Build the internal documentation now, before submission, so your reasoning is on record regardless of what ACN’s review finds.

For boards: Italy’s personal management accountability provisions mean that governance sign-off on NIS2 risk management is not optional and cannot be fully delegated. The requirement is for management bodies to approve cybersecurity measures and oversight — documented approval, not passive awareness. Board minutes demonstrating that NIS2 compliance was on the agenda and actively reviewed are a foundational piece of evidence in any ACN inspection.

Frequently Asked Questions

Does the contact point need SPID to access the ACN portal?

SPID and CIE are the standard authentication methods. Non-Italian residents who cannot obtain either credential under applicable regulations can request personal portal credentials directly from ACN through the support portal at portale.acn.gov.it. This is an exception route — most Italian entities designate a contact point who holds Italian fiscal residency and can obtain SPID. If you are a non-Italian company with Italian operations and your designated contact point is non-resident, request alternative credentials well before the February registration window opens.

What happens if we miss the June 30 categorisation deadline?

Missing the June 30 deadline constitutes non-compliance with Determination 127437/2026, exposing the entity to administrative fines under Italy’s NIS2 framework — potentially up to €10 million or 2% of annual worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities. Documented technical failures not attributable to the entity are an exception under the determination, but the burden of documentation sits with the entity and must be established before the deadline, not as a retrospective explanation.

We are subject to DORA. Are we also subject to ACN’s NIS2 requirements?

DORA-regulated financial entities remain within Italy’s NIS2 scope but receive specific carve-outs in ACN’s April 2026 determinations: they are exempt from the CSIRT referent appointment obligation and from administrative body member reporting requirements. The broader NIS2 framework — including the categorisation exercise and incident reporting — still applies unless DORA’s own obligations are deemed equivalent. Italian legal counsel is advisable on how the lex specialis principle applies to your specific entity type and supervisory context.

How does Italy’s NIS2 scope compare to other EU member states?

Italy is one of the more expansive EU implementations. Through Annexes III and IV of D.Lgs 138/2024, Italy extended NIS2 scope to cover local government entities, local public transport operators, universities, research institutions, and publicly-controlled companies — categories that many other member states left out of scope or handled through separate frameworks. If your organisation would be out of scope under a generic EU NIS2 reading but operates in Italy in one of these categories, Italian NIS2 obligations still apply.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Agenzia per la Cybersicurezza Nazionale — NIS Registration page: https://www.acn.gov.it/portale/en/nis/registrazione (cited inline)
  2. ACN — NIS: Next Steps in Implementation
  3. ADVANT Nctm — NIS2: ACN Determinations on Relevant Suppliers, Categorisation, and Deadlines for New Entities
  4. Gaming Tech Law — NIS2 Categorisation in Italy: ACN Operational Guidance
  5. NIS2certification.eu — NIS2 in Italy: Scope, Obligations, Compliance Requirements and Authorities
  6. OpenKRITIS — EU NIS2 in Italy
  7. Morri Rossetti & Franzosi — NIS2: New ACN Determinations on Deadlines, Relevant Suppliers, and Categorization
  8. AtWorkStudio — NIS2 Categorisation: How to File Activities on ACN Platform by 30 June 2026
  9. NIS-2-Directive.com — Article 8: National Competent Authorities and Single Points of Contact: https://nis-2-directive.com/NIS_2_Directive_Article_8.html (cited inline)
  10. NIS-2-Directive.com — Article 10: Computer Security Incident Response Teams
  11. NIS-2-Directive.com — Article 21: Cybersecurity Risk-Management Measures
  12. NIS-2-Directive.com — Article 23: Reporting Obligations for Essential and Important Entities
  13. AtWorkStudio — NIS2: ACN Clarifications from the Clusit Event of 29 April 2026
  14. NIS-2-Directive.com — NIS2 Directive Transposition: Italy
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: