Operational notes Regulation

ICT census of Italy’s public bodies by 30 September 2026: AgID set the date, not the law

8 min read

A row of computer servers in a rack, shot from the side in black and white
The census asks you to count exactly this: not whether the rack exists, but what runs on it, where it sits, and who can reach it.

The provision of law that requires the ICT census of Italy’s public administration does not contain the date of 30 September 2026. Anyone who goes and reads it — article 33-septies(1-ter) of Decree-Law 179 of 18 October 2012 (converted into Law 221 of 17 December 2012) — finds a duty that recurs “every three years”, not a day on a calendar. The deadline that now appears in every announcement, on the platform where the questionnaire is filled in, and in our own compliance calendar, is an administrative act of the Agency for Digital Italy (AgID), not a rule of primary legislation. That distinction changes the nature of the duty, and it is worth starting there.

The clause that fixes no date

The text, in the version in force since 1 January 2022, reads as follows: “The Agency for Digital Italy (AgID) carries out, every three years, with the support of the National Institute of Statistics where needed, the census of the Data Processing Centres (CED) of public administration referred to in paragraph 2 and, in agreement with the competent structure of the Presidency of the Council of Ministers, […] defines in the Three-Year Plan for IT in public administration the strategy for developing public bodies’ digital infrastructure […] and the strategy for adopting the cloud model for public administration, to which public bodies must adhere.” Paragraph 2, referenced to define the object, clarifies what a CED is: “the site hosting one or more IT systems […] which as a minimum comprises computing resources, network equipment for connectivity, and mass storage systems.” Neither sentence contains a day, a month or a year: the frequency is triennial in the literal sense, but the law does not say in which window of the year the survey must open or close. That decision, every time, falls to AgID.

The act that sets 30 September, and what it actually asks for

On 22 July 2026 AgID published a news item titled “The census of the ICT estate of public administration is under way”, with a standfirst that doubles as the operational deadline: “Public bodies have until 30 September 2026 to respond to the questionnaire.” The same text anchors it explicitly to the law: “The census is provided for by law (paragraph 1-ter of article 33-septies of decree-law no. 179/2012) and falls within the framework of the Digital Administration Code (CAD, legislative decree no. 82 of 7 March 2005).” AgID’s dedicated page repeats the deadline in a section titled, precisely, “Deadline”: “Central and local public bodies must complete the questionnaire by 30 September 2026. For schools and universities the deadline will be announced later.” For the latter, the questionnaire “will be available to complete from September” — a second window, still without a closing date.

The questionnaire can only be filled in on the PA digitale 2026 platform, in the reserved area, under “Compliance duties and questionnaires”, and is split into three parts. The first, ICT organisation, records the structure of the IT department, whether a digital transformation plan exists, the formal presence of a Digital Transition Officer (RTD), and the use of artificial intelligence technologies in internal processes. The second, Mapping of infrastructure and services, splits in turn into data centres — location, storage capacity, computing power, connectivity, energy sustainability — and classified data and services, where each service must state “the level of migration to the cloud or to qualified infrastructure (under ACN regulation no. 21007/24)”: the same regulation and the same determination number we already covered when writing about the 30 June 2026 cloud deadline. The third, Optimisation of ICT spending, asks for operating costs, software licence spend and the use of Digital Procurement Platforms under article 25 of legislative decree 36/2023. At the end, the legal representative or the RTD signs a “compilation attestation” certifying the completeness and accuracy of the data entered: not an anonymous checklist, but a declaration with a name on it.

Why the distinction is not a lawyer’s quibble

The 30 September deadline is therefore an administrative choice within a legislative framework that only imposes the three-year periodicity. Neither the launch announcement nor the compilation guide we consulted mentions any specific penalty for missing that date — unlike the monetary fines spelled out in the Perimeter decree for failing to notify CVCN. The 2017-2018 precedent, when AgID circular no. 5/2017 tied non-participation to losing eligibility as a National Strategic Hub, does not appear to have been reproduced in these terms for the 2026 edition.

That does not make the exercise optional. Paragraph 1-ter says public bodies “must adhere” to the strategy that the Three-Year Plan will define on the basis of these same data: a legal duty that matures downstream, not at the moment of filling in the form. And the part that truly exposes whoever signs is not a missing answer, but a wrong one: a completeness-and-accuracy attestation signed over estimated figures, or over an inventory nobody has ever verified, is a formal declaration that can later be set against what the body actually has running — in a NIS2 inspection, a CVCN assessment, or an ACN check on the cloud migration.

The inventory everything else rests on

Here the theme connects to the rest of what we cover. A body inside the National Cybersecurity Perimeter must notify CVCN before awarding ICT supplies: it cannot do that without knowing what systems it has. A first-wave NIS2 entity must produce, by October, “inventories of systems, configurations, known vulnerabilities and personnel with access” — almost word for word the “Mapping of infrastructure and services” section of this census. A body that missed the 30 June cloud-migration window now has to put in a signed document exactly how far it has actually got. The ICT census is not a fourth, parallel duty: it is the base inventory the other three rest on, because none of them can be demonstrated without knowing, precisely, what is running in the machine room, where, and under what qualification level. A body discovering only now that it lacks this data is not discovering a census problem: it is discovering a gap it should already have closed for everything else.

What to do now

  1. Assign the signatory immediately — legal representative or RTD — and treat the final attestation for what it is: a declaration, not a formality.
  2. Convene the people who actually hold the data before opening the questionnaire: infrastructure, services, security, the DPO, external suppliers where needed.
  3. Retrieve the real state of your cloud migration — ACN classification, QC level reached — before writing it into the classified-data section: if the 30 June migration is not complete, the census is where that delay becomes a signed, written fact.
  4. Reuse what you already have for NIS2: if you have built the systems inventory article 24 requires, most of the “Mapping of infrastructure and services” section is already written.
  5. Schools and universities: the window opens in September with a deadline still to be announced, but organisational data can be prepared now.

How we solve it

The underlying problem is not filling in a questionnaire every three years: it is that, between one census and the next, almost no public body keeps the inventory that questionnaire asks for up to date — and rediscovers it from scratch, under deadline, every time. The right fix is to turn that inventory into a control that runs continuously against the body’s own systems — data centres, applications, classification level, migration status — with a trail of who verified what and when, ready to show both at the next census and at any NIS2 or CVCN inspection in between, instead of a form filled in once and already stale the next day.

The same inventory, held together in a single operational model with the rest of the body’s data — contracts, suppliers, incidents, ICT spend — is also the basis on which AI agents execute decisions with an operator in command: not just “the census is ready”, but “these three data centres are below the required QC level, here is the sequence of action”. For large enterprises, defence, public administration and healthcare we offer both delivery modes, never one as the only option: on-premises, on self-contained machines that do not require deep integration into the client’s network, or CSIDIA’s dedicated cloud, with data centres in Italy and premises we staff directly. And we manage it: a public body that does not already have in-house staff running AI systems does not need to hire any to use this.

Want to know whether your body already has, today, the data to answer the census without estimating it? Half an hour with one of our experts for the first check.

Sources