CVCN: the rule says what to hand over, is silent on who sees it next
8 min read
A typical scenario, not a case of ours. A company building a software system for an organisation inside Italy’s national cyber security perimeter is asked to trigger a CVCN evaluation. The specification says what has to be handed over: architecture, security functions, results of tests already run, a test environment that faithfully reproduces real operating conditions. Someone in the legal department asks the question the specification skips: once handed over, who sees that material, for how long, and what is left of it when the outcome arrives? The answer should sit in the implementing regulation. And the regulation, read article by article, does not answer it there either.
What the supplier has to hand over
The implementing regulation is presidential decree 5 February 2021, no. 54, adopted under article 1(6) of decree-law 21 September 2019, no. 105 (converted by law 18 November 2019, no. 133). Neither text has an official English version; verbatim passages below are quoted from the Italian original, with a translation in italics alongside. Article 5(5) lists what it calls the «propedeutiche e indispensabili» — preparatory and indispensable — activities the supplier must carry out once the CVCN or a CV impose tests: providing evidence that the security functions are fit for purpose; «provvedere all’allestimento di un ambiente di test adeguatamente rappresentativo della realtà di esercizio presso il laboratorio o, se necessario, presso il fornitore o presso il soggetto del perimetro» — setting up a test environment representative of real operating conditions, at the laboratory, at the supplier itself, or at the organisation inside the perimeter; providing a general description of the object’s architecture and functions, and of the security functions implemented; the results of tests already run by the supplier, the manufacturer or a third party. Upstream, article 3(4) adds a risk-assessment document mapping the components the object interacts with. It is a precise list of what leaves the company’s boundary: not an interface to demo, but architecture, behaviour and, for the test environment, potentially the working product itself.
Two locations, not one
The already-quoted letter b) leaves the location of the test environment open: the laboratory, or — as just seen — the supplier itself or the organisation inside the perimeter. Article 7(3) confirms this for running the tests: ordinarily at the laboratories of the CVCN, the CVs and the LAPs, but, «se necessario, possono essere eseguiti da personale del CVCN, dei CV e dei LAP presso il fornitore o il soggetto incluso nel perimetro» — if necessary, CVCN, CV or LAP staff may carry them out at the supplier’s premises or at the organisation inside the perimeter. The material need not leave the company: it can stay there, with evaluation staff accessing it on site. But if the environment is set up at a laboratory, the rule draws no further line on who, inside the CVCN, the CV or the LAP, may actually see it, nor on where it ends up once the procedure closes.
The confidentiality the regulation does write, and for whom
The decree does not ignore confidentiality — it just always writes it to protect someone else. Article 4(8) charges the CVCN, the CVs and the LAPs with the «riservatezza» — confidentiality — of the test methodologies the CVCN shares with them; article 7(4) binds them, in near-identical terms, to «non divulgare» — not disclose — the same methodologies: two almost identical clauses, protecting a single object — the State’s technical know-how on how to test a system, not what the supplier has just handed over to be tested. The word’s other occurrences point the same way: article 3(4)(b) uses «riservatezza» for a security property of the finished product, not a rule on the evaluation file; article 5(8) uses it for the tender document’s confidentiality, not the material handed over after the award. Nowhere does the regulation use the word for the technical material a supplier hands to the CVCN, the CVs or the LAPs.
What the text does not say
Here the reading stops at what is there, not at what would seem logical to expect. Presidential decree 54/2021 contains no article, paragraph or cross-reference obliging CVCN, CV or LAP staff not to disclose a supplier’s technical material, no retention period for the test environment or the test reports, no obligation to return or destroy anything once the procedure closes. Article 3(2) states that the data from CVCN communications are collected in electronic archives set up at the administrations where the CVCN and the CVs operate — «archivi informatici istituiti presso le Amministrazioni nelle quali operano il CVCN e i CV» — an archive that exists, with no written retention period. Article 6(1) describes an IT platform that checks whether an object has already been evaluated, precisely to avoid duplicating tests: for that to work, the platform must retain some memory of previously evaluated objects across different procurements, but the regulation does not say what it retains, or for how long. The parent decree-law 105/2019, at article 1(6)(c), limits its one explicit data-protection cross-reference — to Regulation (EU) 2016/679 and the Italian privacy code — to «dati o metadati personali e amministrativi» — personal and administrative data or metadata — accessed during inspections, not to the technical material a supplier hands over to be evaluated. On this material, neither the decree-law nor its implementing regulation says anything. The count can be redone: across the full text of the decree, twenty articles, the words «segreto», «distruzione», «restituzione», «cancellazione», «custodia» and «proprietà intellettuale» — secret, destruction, return, deletion, custody, intellectual property — appear zero times; «riservatezza» five times, «divulgare» once, and none of the six concerns the supplier’s material. That is a silence, not a prohibition or a permission, and it should be flagged as one.
The clearance that does exist, and for whom
A second comparison sharpens the silence. Article 15(2) — in Chapter IV, on inspections and checks, not in the Chapter II evaluation procedure — requires that access to classified information under article 42 of law 124/2007, above «riservato» — restricted — be carried out «esclusivamente da personale in possesso del requisito» — exclusively by staff holding the requirement — of a security clearance. That is a written clearance requirement, but for different staff — the Chapter IV inspectors — and different material: information classified under law 124/2007, not the architecture or source code of a commercial product, which as a rule carries no classification at all. For CVCN, CV and LAP staff actually running the tests, the regulation sets no equivalent requirement: the professionalism-and-rotation criteria and the conflict-of-interest declaration in article 15(4) and (5) apply, textually, to the «personale incaricato» — staff assigned — to inspection activities, not to whoever runs the evaluation tests.
How we solve it
The regulation fixes deadlines with precision — forty-five days plus fifteen, sixty for the tests — and lists with the same precision what the supplier has to put on the table. On custody of that material after it is handed over, it is silent. A supplier cannot fill that silence for the regulator, but it can do the one thing within its own control: log what left, to which laboratory, on which date and for which procedure. It is the same principle behind notifying the CVCN in the first place: a file that withstands scrutiny comes from a check running continuously over systems and contracts, not from the day the request lands. The same setup ties that log to the company’s other scattered data — contracts, suppliers, incidents — into a single operating model on which AI agents execute decisions with an operator in command: complying and deciding off the same file. Always on-premise on standalone machines, or a dedicated cloud with a data centre in Italy and premises we staff ourselves — never one more outside party seeing your code.
Do you need to prepare an ICT supply for a CVCN evaluation and want to know what the rule requires you to hand over, and what it does not? Half an hour with one of our experts for a first reading of the file.
What we don’t know
We do not provide legal advice: we work from public sources, here the text of presidential decree 54/2021 and article 1 of decree-law 105/2019, as in force on Normattiva at the time of writing. We have not verified whether the prime ministerial decree referred to in article 4(8) — the one setting criteria and liaison arrangements between the CVCN and accredited laboratories — contains more specific confidentiality or retention clauses: if a public text of that measure exists, it falls outside this check. Nor do we know what internal practice the CVCN, the CVs and the LAPs follow for custody of the material they receive, or whether non-public protocols fill in what the regulation leaves unwritten: that is ground a supplier checks with its own contacts, not with an article.
Sources
- Presidential decree 5 February 2021, no. 54, art. 5 — activities borne by the supplier for testing (Normattiva, text in force)
- Presidential decree 5 February 2021, no. 54, art. 7 — running the tests and confidentiality of methodologies (Normattiva, text in force)
- Presidential decree 5 February 2021, no. 54, art. 15 — competent authorities and security clearance for inspections (Normattiva, text in force)
- Law 3 August 2007, no. 124, art. 42 — security classifications and the security clearance (Normattiva, Italian)
- Decree-law 21 September 2019, no. 105, art. 1 — perimeter, notification to the CVCN and the GDPR cross-reference for inspections (Normattiva, text in force)