Operational notes Regulation

Law 90/2024: who classifies the incident in the first twenty-four hours?

7 min read

Crank handle and gear of a hand-operated striped boom barrier, with the arm lowered in the background, black and white photograph
The barrier comes down by hand: whoever has to turn the crank knows it beforehand, not while it is needed.

At eight on a Friday evening, in an Italian municipality or health authority, whoever notices that something is wrong has two decisions to make: whether the event is a reportable incident, and which channel of the National Cybersecurity Agency it should go to. If nobody settled them beforehand, in writing and with a role attached, that person settles them alone. And the clock on the first one is already running.

The twenty-four hours set by law 28 June 2024, no. 90 are not there to fix the incident: they are there to classify it and communicate it. Article 1(2) requires a report «senza ritardo e comunque entro il termine massimo di ventiquattro ore dal momento in cui ne sono venuti a conoscenza a seguito delle evidenze comunque ottenute» (within twenty-four hours of becoming aware, on whatever evidence obtained), and then, «entro settantadue ore a decorrere dal medesimo momento, la notifica completa» (within seventy-two hours from the same instant, full notification). The two deadlines do not stack: they run from the same instant. Counting seventy-two hours from the report has already cost you a day.

The instant that starts the clock can come from outside

The phrase «a seguito delle evidenze comunque ottenute» is deliberately wide: awareness may come from an Agency alert, a supplier’s phone call, a citizen who can no longer reach a service. Yet the body learns of it through one specific person, at the hour that person reads the message — and the first thing the portal asks for is the date and time of detection. It is the body itself that declares when its own clock started. The duty has applied since 17 July 2024 and, for municipalities above 100,000 residents, regional capitals, health authorities, transport operators and their in-house companies, since 13 January 2025.

Three codes, and a fourth that may not be on your list

The taxonomy was adopted by determination of the ACN director general no. 28900 of 9 February 2026, in Official Gazette no. 39 of 17 February 2026 and applicable from that day — we told that story when the taxonomy was missing, and someone finally wrote it. Annex A lists three codes: IS-1, loss of confidentiality of digital data towards the outside; IS-2, loss of integrity with outward impact; IS-3, breach of expected service levels «stabiliti dal soggetto» (set by the entity itself).

This is where public bodies get it wrong: anyone who is also a NIS entity has two lists, not one. Annex 3 to ACN determination no. 379907 of 19 December 2025, the one for important entities, carries the same three codes. Annex 4, for essential entities, carries four: it adds IS-4, evidence of «accesso, non autorizzato o con abuso dei privilegi concessi, a dati digitali» (access, unauthorised or abusing granted privileges, to digital data). Privilege abuse by an internal user, with no exfiltration and no service disruption, must be notified by an essential entity; it is not on the law 90 list.

One single notification, but in one direction only

The Agency simplified the overlap one way round. The recitals of the February determination treat the duty as discharged «in caso di prenotifica e notifica effettuata ai sensi dell’art. 25 del decreto NIS» (where early warning and notification are made under article 25 of the NIS decree); the operative text adds that the taxonomy «rileva anche ai fini dell’adempimento dell’obbligo di cui all’art. 25» (is also relevant for discharging the article 25 duty). Neither states the converse: that a report filed as a law 90 entity also closes article 25 of legislative decree 138/2024. And article 25 asks for more: early warning within 24 hours, notification within 72, a final report within one month, and monthly reports for as long as the incident stays open.

One detail makes the choice irreversible that same evening. The public reporting portal asks you to identify yourself by picking one of four regimes — NIS, Perimeter, law 90, other entities — but warns that NIS notifications require logging in to the ACN Services Portal and filling in a dedicated form: one route is open to anyone, the other sits behind credentials. If those credentials are not already live and held by someone reachable, they cannot be obtained on a Friday night. And the NIS deadline for notifications, nine months from the communication received, expired in January 2026 for almost everyone.

The plan the inspection looks for

The first omission costs no money: article 1(5) provides that the Agency warns the body and may order inspections within the twelve months following the finding of delay or omission. The second, within five years, costs between 25,000 and 125,000 euro, and «può costituire causa di responsabilità disciplinare e amministrativo-contabile per i funzionari e i dirigenti responsabili» (disciplinary and accounting liability for the officials and managers responsible).

The inspection does not arrive empty-handed: it also checks the measures in the Agency’s guidelines, adopted by decree of the director general no. 37032 of 13 November 2024 and now at version 1.1, January 2025. Measure RS.RP-1 requires an up-to-date response plan defining at least «le articolazioni preposte all’attuazione del piano, definendone le competenze decisionali, finanziarie e tecniche» (the units responsible for the plan, with their decision-making, financial and technical powers) and the procedures for notifying incidents under article 1 of law 90/2024. The name of whoever classifies is already a line in a document the Agency can ask for: the inspection asks for the data proving implementation.

Why a closed system

The raw material of a notification is always the same: time of detection, affected assets, attack vectors, recovery measures taken and planned, indicators of compromise, relevant evidence. Translated: logs, tickets, configurations, the last few hours of internal correspondence. It has two natures, both incompatible with a generic external service. IS-1 and IS-2 concern, by definition, data the body has lost control of, which in a municipality or a health authority means personal data of citizens and patients. And the list of affected assets and vectors is an up-to-date map of your own weakness, written while the intrusion may still be open: uploading it to an external service for help drafting the text means exporting it at the worst possible moment, with credentials that may be among the compromised ones, and leaving a copy outside the perimeter that nobody will inventory.

That is why the machine reading the logs and drafting the text has to sit inside. The taxonomy becomes a control running over the body’s logs and tickets, proposing a code, a time of detection and a channel, with a record of who decided and when: compliance turns into evidence you can produce, rather than an opinion. The same set-up then holds monitoring, asset registers, service contracts and archives together in a single operational model, on which AI agents run the checks with an operator in command. On-premise on self-contained machines that need no deep integration into your network, or on a dedicated cloud with data centre in Italy and premises we staff ourselves, with shared management: no public body should have to hire people to administer models.

Want to know which list applies to your organisation, and who would have the power to classify tonight? Half an hour with one of our experts.

What we do not know

We do not provide legal advice: we work from public sources, here the texts in force on Normattiva today, the Official Gazette and the Agency’s published documents. Article 1(7)(a) exempts operators of essential services and digital service providers under article 3(1)(g) and (i) of legislative decree 18 May 2018, no. 65: an article repealed since 18 October 2024 and, unlike paragraph 1, never rewritten. We do not know whether the exemption still covers those identified as such before that date — determination 379907 still defines them that way — or whether it has lost its object. We did not find the determination on inspection procedures required by paragraph 5, neither in the Gazette nor among the Agency’s acts: we cannot rule out that it exists.

Sources