The inspection does not ask whether you comply: it asks for the data that proves it
7 min read
A typical scenario, not our own case. A manager at a public healthcare body, an NIS entity classed as important, receives a reporting request from Italy’s National Cybersecurity Agency. It is not an inspection: for an important entity it could not be, without a lead. This is monitoring, which the FAQ calls «a carattere sistematico e continuativo» and the Agency carries out «prima e indipendentemente dall’esercizio dei poteri ispettivi e di esecuzione» — systematic and continuous, and before and independently of any inspection power. The first instinct is almost always to pull out the security policies the board has already approved: the most common response, and from today the most fragile one.
Today, 11 August 2026, the National Cybersecurity Agency published five new FAQs on the NIS regime — numbered MVE.1 to MVE.5 — on monitoring, supervision and enforcement. The first sums up the scope: four areas — monitoring, analysis and support; checks and inspections; enforcement measures; administrative fines and accessory penalties — governed by three principles: «effettività, proporzionalità e dissuasività», effectiveness, proportionality and dissuasiveness.
Compliance is not the point; proving it is
FAQs interpret; the decree rules. Legislative Decree No. 138 of 4 September 2024 — the NIS Decree — settles the point that actually matters in a single paragraph. Article 37(2) authorises the Authority, in exercising its enforcement powers, to require entities, stating the purpose, to provide:
«i dati che dimostrino l’attuazione di politiche di sicurezza informatica, quali i risultati di audit sulla sicurezza e i relativi elementi di prova, nonché le informazioni necessarie per lo svolgimento dei propri compiti istituzionali».
In our rendering: data proving cybersecurity policies have been implemented — security-audit results and their evidence — plus the information the Authority needs for its tasks.
It does not ask for the policy. It asks for the data proving the policy was implemented: the audit result, its piece of evidence, dated. A policy signed off by the board is not that data — it states an intention, not a verified outcome. An audit result, with its evidence, is. The same lesson applies to another NIS deadline: the deadline is a document, not a date — implementation, in the same way, is not a statement, it is a data point.
Two speeds, not one
The second thing to understand is who risks an unannounced inspection. FAQ MVE.3 is unambiguous: for essential entities, on-site and remote inspections, including random checks, may be ordered even ex ante; for important entities, they may not — they require, first, evidence, indications or information suggesting a possible breach of the decree. It is the same rule set out in Article 36(2): for an essential entity, an inspection can arrive with nothing to foreshadow it; for an important one, a concrete lead is needed first.
There is a second asymmetry, absent from the FAQ and found only in the decree. Article 37(3)(a) authorises the Authority to order periodic or targeted security audits, particularly after a significant incident or breach — but the same provision closes with a firm limit: «l’Autorità nazionale competente NIS non può prescrivere l’esecuzione periodica di audit di sicurezza ai soggetti importanti» — the competent NIS Authority may not require important entities to run periodic security audits. For an important entity, a recurring audit stays its own choice, not an obligation imposed from above — a margin worth knowing before an inquiry, not during one.
Not cooperating costs more than the breach
The decree does not treat supervision as a one-off check. Article 34(6) requires that powers be exercised while respecting the rights of defence, and lists factors that aggravate a breach: among them, on the same footing, obstructing supervisory activity and providing false or seriously inaccurate information — failing to cooperate, or cooperating by lying, weighs as heavily as the breach that triggered the check. That respect is not rhetorical: Article 37(8) requires the Authority to notify entities of its preliminary findings before issuing orders, allowing no fewer than fifteen days for observations.
When the Authority orders an audit, it does not let the entity mark its own work: Article 34(7) requires independent bodies, and is explicit on who pays — the entity being audited, save in duly justified cases. Which bodies qualify, and on what basis, is still an open chapter in Italy under the European definition of managed security services. If shortcomings persist, Article 37(3)(l) lets the Authority order the breaches made public: the fine stays between the parties; publication does not.
The public-sector angle: two liabilities that stack
For today’s angle, the heaviest point sits not in the FAQs but in Article 38 of the decree. Public administrations under Annex III sit inside the NIS perimeter with their own band of fines: if essential, Article 38(9) sets the fine at between €25,000 and €125,000; if important, those amounts are reduced by a third. For essential undertakings (public bodies excluded), the ceiling is €10 million, or 2% of worldwide turnover if higher, «il cui minimo è fissato nella misura di un ventesimo del massimo edittale» — the minimum fixed at one-twentieth of the statutory maximum: a twentieth of ten million, our own sum on the fixed ceiling, is €500,000 — the minimum, not the maximum. For important undertakings the ceiling is €7 million or 1.4%, with the minimum at one-thirtieth: over €233,000 on the fixed threshold alone, rising if 1.4% of turnover exceeds it.
On personal liability, the decree layers two regimes, and this is where the government angle bites hardest. Article 38(6) lets the accessory penalty of incapacity to hold managerial functions within the same entity be applied to whoever runs or directs an essential or important entity — management bodies, the managing director, the legal representative — until the breach is remedied. For public employees, Article 38(7) adds the ordinary regime of public service: the breach «può costituire causa di responsabilità dirigenziale, disciplinare e amministrativo-contabile» — may give rise to managerial, disciplinary and administrative-accounting liability. A manager in public administration or in defence does not answer only for the entity: they answer personally, on two fronts that stack.
See the service · Talk to an engineer
Where we stop
The Agency’s FAQs are not a source of law and add no obligations: they are the Authority’s own interpretation, applied when it exercises those powers — which is why they matter in practice — but the duty and the penalty sit in the decree, not the FAQ. We have no news of inspections already ordered on the strength of these FAQs, and we do not claim there are any. We do not know by what criteria the Agency will prioritise checks, beyond what MVE.1 states in general terms — «un approccio graduale basato sul rischio» — a gradual, risk-based approach, with no thresholds spelled out. This is a reading of primary sources, not legal advice.
The two axes, applied
Complying. In our system, Article 37(2) becomes a control running on the client’s documents and systems: for each NIS duty, which data proves it, where it sits, who produces it, with what date and what evidence — not supplier registers that never say what they supply, but a file that exports itself, dated, on the day of the request, instead of being rebuilt from memory. The same principle holds on another front of national security, that of accreditations replacing company clearances: what counts is the verifiable system, not the word given.
Deciding. The same system holds documents, management software, archives, systems and sensors together in a single operating model — the organisation’s data lake becoming one thing — on which AI agents execute decisions with a human operator in command, for large enterprises, defence, public administration and healthcare. Compliance with Article 37 is the door in; the decision-making system that holds the same sources together to decide, not only to answer an inspection, is what we sell. Always in two delivery modes — on-premises, on autonomous machines needing no deep integration into the client’s network, or dedicated cloud with a data centre in Italy — always with shared management: no in-house AI staff need be hired.
From the first session, at no cost, comes the dated list of which data prove which of your NIS duties, and where it sits — blank boxes included. It stays yours even if we do not go on together. Talk to one of our engineers.