Guides · Updated July 2026
The deadlines that ask for documents, not statements.
Ten dates, from June 2026 to December 2027, plus the two AI Act dates that rest on the same documents. For each one: the rule, what you need to have in hand when someone knocks, the note that tells the story and the solution that covers it.
One difference decides the outcome of an inspection: between what an organisation does and what it can show it has done. The deadlines collected here all belong to the second kind — they ask for a dated document, not a statement of intent.
Many of them ask different parties for the same material. The Cyber Resilience Act requires a single technical documentation for products also covered by other Union acts (art. 31(3)): anyone rewriting manuals for January 2027 is already working on the binder that December will need.
-
ACN cloud rules: the transitional tolerance is over
- Rule
- ACN regulation on digital infrastructure and cloud services for public administration, art. 11(10)
- Who it concerns
- Public administrations and bodies handling critical or strategic data.
What you need to have
- The classification of data and digital services into ordinary, critical and strategic, with the reasoning written next to it (art. 3). Where data falls inside the National Cybersecurity Perimeter or the NIS duties, the class is set by law.
- A check of the supplier’s qualification level in the ACN catalogue, not in the brochure: at least QC2 for critical data, QC3 or QC4 for strategic data (art. 17).
- A remediation plan for whatever is out of place: what moves, where, by when, who signs.
For strategic data, Annex 2 adds a jurisdictional constraint: any access request by a non-EU entity must be reported to ACN and granted only after explicit authorisation by the administration.
-
Cyber Resilience Act: the reporting duty
- Rule
- Regulation (EU) 2024/2847, art. 14
- Who it concerns
- Manufacturers of products with digital elements — connected or connectable hardware and software — including products already on the market.
What you need to have
- A channel for receiving vulnerability reports and a coordinated disclosure policy, with a named owner and a triage that works.
- The software bill of materials for your products: without knowing what is inside, no report can be made in time.
- The notification path rehearsed at least once: early warning within 24 hours, full notification within 72, final report within 14 days of the corrective measure for vulnerabilities or within one month for severe incidents.
The clock starts when the manufacturer “becomes aware” of the problem: the real constraint is the ability to notice, not the notification itself. On 27 July 2026 the Commission published its guidance on applying the regulation (communication C(2026) 5252 and annex): it clarifies the scope — remote data processing solutions and free and open source software included —, what counts as a substantial modification, how the support period is determined and how the reporting and risk assessment obligations are met. It is not binding and it does not move 11 September: it is what you write your choices against. Two points in the annex change the scope of the work. First: the duty also covers products placed on the market before 11 December 2027 (art. 69(3)) and stays in force after the support period ends, while the vulnerability handling duties in Annex I, Part II, do not apply in those cases. Second: there is no retroactive reporting — a vulnerability whose active exploitation you already knew about before 11 September 2026 need not be notified, but if the exploitation happens, or you become aware of it, after that date the duty applies.
-
ICT census: public bodies declare what is in the machine room
- Rule
- Article 33-septies(1-ter) of Decree-Law 179/2012; AgID survey opened on 22 July 2026
- Who it concerns
- Public administrations required to answer the questionnaire on their ICT estate.
What you need to have
- A real inventory of systems, applications and services in operation, stating where they run and who manages them: it is the basis for every answer, and almost nobody has it ready.
- The classification of data and services under the ACN cloud regulation, which uses the same framework and the same categories.
- The final declaration of completeness and accuracy, signed by the legal representative or the digital transition officer: you sign for figures that must be verifiable.
Anyone who has never taken the inventory signs for figures they do not know. And that inventory is the same map security needs: your exposed surface is the part you can list.
-
NIS2: the baseline security measures, evidenced
- Rule
- Italian Legislative Decree 138 of 4 September 2024, arts. 23, 24 and 29, with the deadline set by art. 42(1)(c) and by ACN determination 379907/2025
- Who it concerns
- Essential and important entities in the first wave: registered between December 2024 and February 2025, they received their listing notification from 12 April 2025 onwards.
What you need to have
- Board minutes: approval of the risk management measures, supervision of their implementation, evidence of the training received by senior management (art. 23).
- An up-to-date risk analysis on the organisation’s real systems, plus inventories of systems, configurations, known vulnerabilities and staff with access.
- A register of critical suppliers and contracts with security clauses: existing contracts need not be amended immediately, but new contracts, renewals and extensions incorporate them. The ACN FAQs updated on 24 July 2026 (MSB.13-MSB.19) clarify that requirements need only be set for supplies with a potential security impact, and that not every baseline measure has to be pushed onto the supplier — but the tailoring has to be justified in writing, and that justification is itself a document to hold.
- Business continuity and disaster recovery plans that have been tested, not only written, and a staff training register.
- Incident notification procedures actually rehearsed: early warning to CSIRT Italia within 24 hours, full notification within 72, final report within one month. For the first wave the art. 25 notification duty has been in force since January 2026: October adds the measures, not the notification.
- Evidence that access control, encryption and network segmentation are active — not the policy that prescribes them.
The deadline is not the same for everyone: it runs eighteen months from the receipt of each entity’s own listing notification (ACN determination 379907/2025, art. 3), and those notifications started going out on 12 April 2025 — so the date has to be worked out entity by entity, within the October 2026 that ACN indicates. For entities listed for the first time in 2026 the deadline is 31 July 2027, with the notification duty running from 1 January 2027 (ACN determination 127434/2026, art. 1).
-
Tracking pixels in email: consent and notice, in writing
- Rule
- Italian Data Protection Authority, measure no. 284 of 17 April 2026 — guidelines on the use of tracking pixels in email communications, published in Official Gazette no. 98 of 29 April 2026
- Who it concerns
- Anyone placing tracking pixels in email: controllers sending marketing and newsletters, email service providers, operators of bulk email platforms.
What you need to have
- A notice stating that the message carries a pixel, what it records and for what purpose: the general notice on your website does not cover email tracking.
- Consent collected before sending, under art. 122 of the Italian Privacy Code and arts. 4(11) and 7 GDPR: it may be encompassed within consent to receiving promotional communications, but only if the request is “framed neutrally and without pressure” and the notice names the pixel.
- Withdrawal made possible in granular form too (art. 7(3) GDPR): someone who wants the newsletter must be able to refuse the tracking without giving up the newsletter.
- The data protection by design and by default measures required by art. 25 GDPR, non-sequential identifiers and separated data layers included.
- A map of who processes this data on your behalf: the pixel belongs to the sending platform, but the roles have to be defined case by case under the accountability principle (art. 5(2) GDPR), weighing art. 26 on joint controllership too — read the contract before the deadline, not after.
The period does not run from the date of the measure. The guidelines set “un termine pari a 6 mesi dal momento della loro pubblicazione in Gazzetta Ufficiale entro il quale i soggetti tenuti dovranno conformarvisi” — six months from publication in the Official Gazette. Publication was on 29 April 2026, so the date is 29 October 2026. The work needed is not technical but a matter of choice: decide which metrics you actually need and drop the rest, because every open recorded without consent is processing without a legal basis.
-
Product liability: documentation as a defence
- Rule
- Directive (EU) 2024/2853
- Who it concerns
- Anyone placing on the market, or integrating, software and AI systems in a product or service under their own brand.
What you need to have
- Technical documentation of the product, producible on a court order: whoever fails to produce it, or produces it incomplete, opens the door to the presumption of defectiveness.
- Decision logs and a trace of human control over critical actions: that is what allows you to show what the system decided and why.
- Contracts with model and platform suppliers stating who provides the evidence in any proceedings, and within what timeframe.
The Italian delegation sits in law 36 of 17 March 2026, Annex A, point 4; the detailed legislative decree has not been published, and as of 28 July 2026 no draft has been transmitted to Parliament. Under art. 31(1) of law 234/2012 the government has until 9 August 2026 — four months before the European deadline — with a three-month extension if the parliamentary opinion lands close to expiry. The European deadline does not move in either case.
-
Machinery Regulation: the manual decides the CE marking
- Rule
- Regulation (EU) 2023/1230, which repeals Machinery Directive 2006/42/EC on the same date
- Who it concerns
- Manufacturers of machinery and partly completed machinery, importers and distributors placing products on the Union market.
What you need to have
- Instructions for use compliant with Annex III, point 1.7.4: manufacturer identification, description, intended use and reasonably foreseeable misuse, assembly, commissioning, use, maintenance, residual risks.
- The language set by the member state of use, easily understood by end users; a free paper copy within one month if the buyer asks for it at the time of purchase; safety information always on paper for non-professional users.
- If the instructions are digital only: availability online for the whole expected lifetime of the machine and in any case for at least ten years from placing on the market, even if the manufacturer ceases trading in the meantime.
- The requirements on protection against corruption and on the safety of control systems (Annex III, points 1.1.9 and 1.2.1), with additional requirements for machinery with self-evolving behaviour or logic.
Without compliant instructions there is no valid declaration of conformity; without the declaration there is no CE marking. It is not a penalty that arrives after an inspection: it blocks you on the day you place the machine on the market.
-
Data centres: the annual sustainability report
- Rule
- Directive (EU) 2023/1791, art. 12, and Delegated Regulation (EU) 2024/1364, art. 3(1)
- Who it concerns
- Owners and operators of data centres in the Union with an installed information technology power demand of at least 500 kW: enterprise, colocation and co-hosting.
What you need to have
- The 2026 calendar-year figures, measured and not estimated: total energy consumption and the consumption of the IT equipment alone, water and potable water input, reused waste heat and its temperature, renewable energy split between guarantees of origin, power purchase agreements and on-site generation (Annex II, point 1).
- The register of measurement points and measuring devices, which Annex II requires you to keep for at least ten years: it is what shows where the reported numbers come from.
- The ICT capacity of servers and storage equipment at the end of the reporting year (Annex II, point 2). For colocation data centres the allowance in art. 3(3) only covered the first two reporting periods: it is gone by now.
- The public-facing part: art. 12 of the directive requires the Annex VII information to be made public, except what is covered by trade secrecy — and which part that is has to be decided and written down beforehand, not in front of an inspection.
The duty is annual, and reporting goes through the national system where the member state hosting the data centre has set one up, otherwise straight to the European database. The threshold is measured on installed IT power, not on floor area: a single equipment room can cross it. If you keep your systems at a provider you are not the obliged party, but those same figures are worth writing into the contract.
-
Pay transparency: the first report on the gap
- Rule
- Italian Legislative Decree 96 of 7 May 2026, arts. 9, 10 and 11
- Who it concerns
- Companies with at least 250 employees, reporting annually, and companies between 150 and 249, with the same first deadline and then every three years. Between 100 and 149 the start is 7 June 2031.
What you need to have
- The categories of workers doing equal work or work of equal value, defined by the company with criteria set down in writing.
- The calculation of mean and median pay, quartile composition and variable component, for each category.
- Objective and gender-neutral criteria for grading and progression, written before a gap has to be justified: above 5% in a category, if the gap is not justified on those criteria and is not corrected within six months of the pay report, a joint assessment with workers’ representatives is triggered (art. 10).
- The processing register and access restricted to pay-equality purposes only (art. 11).
One duty has been active since 7 June 2026, with no size threshold: art. 7 gives every worker the right to ask in writing for average pay levels by gender, with an answer due within two months, and bans clauses preventing workers from disclosing their own pay.
-
Cyber Resilience Act: technical file and software bill of materials
- Rule
- Regulation (EU) 2024/2847, arts. 13, 28, 30, 31 and 32, Annexes I and VII
- Who it concerns
- Manufacturers of products with digital elements placed on the Union market.
What you need to have
- The technical documentation of art. 31 with the minimum content of Annex VII, per product family and updated version by version: general description, architecture, vulnerability handling, risk assessment, standards applied, test reports.
- The software bill of materials in a commonly used, machine-readable format, covering at least the top-level dependencies (Annex I, part II, point 1).
- A support period determined and justified: at least five years (art. 13(8)), with the information used to set it inside the file.
- Conformity assessment, EU declaration of conformity and CE marking, in that order. The file and the declaration stay available to the authorities for at least ten years from placing on the market, or for the support period if longer.
- The bill of materials classified as a confidential document before the first reasoned request: who sees it, through which channel you transmit it, where it is stored.
For the “important” products of Annex III and the “critical” ones of Annex IV, the file leaves the company and lands on the desk of a notified body.
Two dates that ask for no new documents, but presuppose them.
On 2 December 2027 the obligations on Annex III high-risk AI systems apply; on 2 August 2028 those on systems embedded in already regulated products, the Machinery Regulation included. The full calendar, with the Italian dates attached to it, sits in the other guide.
AI Act: every deadline, in order
The first step
Operational from week one.
A real use case, on your data, in production. Then it grows, week after week.
It starts with a session with our engagement expert. Your data stays yours, always.