Law 90/2024: the missing taxonomy, and who finally wrote it
8 min read
A typical scenario, not a case of ours. A municipality with more than 100,000 residents discovers an incident on its own information systems. Legal counsel knows law 90/2024 requires reporting within twenty-four hours and full notification within seventy-two. But whoever must write that report faces another question: does this event fall among those to be reported? Answering it requires a taxonomy. Until 17 February this year, no such taxonomy existed in any public, checkable act.
The duty, and who owes it
The population bound by it is wide, and entirely public: law 28 June 2024, no. 90 binds, at article 1(1), central administrations, regions and autonomous provinces, metropolitan cities, municipalities above 100,000 residents and regional capitals, local health authorities and public transport companies above a given size, including their in-house companies for IT, transport, wastewater and waste. Paragraph 2 sets the clock: reporting «senza ritardo e comunque entro il termine massimo di ventiquattro ore» (without delay and in any case within twenty-four hours), full notification within seventy-two, for «qualunque incidente riconducibile a una delle tipologie individuate nella tassonomia di cui al comma 1» (any incident within a category of the paragraph 1 taxonomy). Everything hinges on that taxonomy: without it, a body cannot tell whether the duty applies.
A cross-reference resting on a classified list
The law’s text, as published on 2 July 2024 and in force from 17 July, did not write the taxonomy out: it pointed elsewhere. The incidents to be reported were those «di cui all’articolo 1, comma 3-bis, del decreto-legge 21 settembre 2019, n. 105, convertito, con modificazioni, dalla legge 18 novembre 2019, n. 133, come modificato dall’articolo 3 della presente legge» (referred to in article 1, paragraph 3-bis, of decree-law 105/2019, as amended by article 3 of this law). That paragraph 3-bis, in the perimeter decree, covered «i soggetti di cui al comma 2-bis» (the entities referred to in paragraph 2-bis) — the list of entities inside the perimeter, a list for which the same decree excludes the right of access. The wide, public population of law 90/2024 — municipalities, local health authorities, transport companies — thus found itself assigned the taxonomy written for a different, classified population, itself defined by «determinazioni tecniche del direttore generale, sentito il vice direttore generale, dell’Agenzia per la cybersicurezza nazionale» (technical determinations by the ACN director general, after hearing the deputy director general). A reference to a reference, but one that still held.
The paragraph disappears, the cross-reference stays as written
The link breaks in October 2024. Article 43(2)(a) of legislative decree 4 September 2024, no. 138 — the decree transposing the NIS2 directive, published in the Gazette on 1 October — repeals paragraph 3-bis of article 1 of the perimeter decree: article 43 itself is in force from 16 October, and in Normattiva’s consolidated text paragraph 3-bis disappears from the version in force on 18 October 2024. From that day, the provision law 90/2024 pointed to no longer exists in the statute book. Yet the text of article 1(1) of law 90/2024 stays exactly as written: Normattiva shows it in force from 17 July 2024 to 9 October 2025. For a year, a twenty-four-hour reporting duty resting on thousands of public bodies named as its own source a repealed paragraph. Anyone reading only law 90/2024, without checking it against the NIS decree, would not have noticed.
The fix comes from another law
What closes the gap is not a cybersecurity decree but article 28(2)(a) of law 23 September 2025, no. 132 — «Disposizioni e deleghe al Governo in materia di intelligenza artificiale» (Provisions and delegations on artificial intelligence), Italy’s own AI law, published on 25 September 2025. Inside the article headed «Disposizioni finali» (Final provisions), in force from 10 October 2025, the now-orphaned words are replaced with these: the taxonomy is «adottata con determinazione tecnica del direttore generale dell’Agenzia per la cybersicurezza nazionale» (adopted by technical determination of the director general of the National Cybersecurity Agency). No longer a cross-reference to another law, but a direct delegation to an administrative act of a single office. The fix, though, is only formal: the delegation exists; the act meant to carry it out still does not.
Four months later, a signature
The determination arrives on 9 February 2026, published in Official Gazette no. 39 of 17 February 2026. Its article 1 provides: «I soggetti di cui all’art. 1, comma 1, della legge 28 giugno 2024, n. 90, segnalano e notificano gli incidenti indicati nella tassonomia di cui all’allegato A alla presente determina» (entities under article 1(1) of law 90/2024 report and notify incidents listed in annex A to this determination). Annex A lists exactly three codes: IS-1, the loss of confidentiality, external to the entity, of data it owns or over which it exercises even partial control; IS-2, the same loss, but of integrity; IS-3, a breach of the expected service levels. Paragraph 2 aligns the taxonomy with the «incidenti significativi di base» (basic significant incidents) fixed, for the duties under the NIS decree, by annex 3 to ACN determination no. 379907 of 19 December 2025: an entity caught by both regimes discharges both with one notification. The three codes are the same, almost word for word, with one difference that matters: in the NIS annex the IS-3 service levels are those «stabiliti ai sensi della misura DE.CM-01» (set under measure DE.CM-01), while in February’s annex A they are those «stabiliti dal soggetto» (set by the entity). At the foot the signature, «Il direttore generale: Frattasi», and the formula «sentito il vice direttore generale» (after hearing the deputy director general): the same as the paragraph repealed sixteen months earlier.
Who writes it, who receives it
From 18 October 2024, the day from which the consolidated text no longer carries that paragraph, to 17 February 2026, the day the determination was published, 487 days pass: sixteen months in which the source of the taxonomy was first a paragraph that no longer existed, then — from 10 October 2025 — a delegation not yet exercised. Once closed, one fact stays unchanged across both versions: the body that writes which events count as an incident, for thousands of public entities, is the very Agency those entities must notify, through the portal it runs. For a municipality or a local health authority this means something precise: the criterion by which an event is judged reportable can change through a determination, not a law, with no voice for the reporting entity in its drafting.
How we solve it
Code IS-3 makes the practical problem tighter still: annex A triggers it against expected service levels the entity itself has set — a figure the annex does not define, and which every entity must therefore already hold, in writing, before the incident happens. In most administrations that figure does not live in one system: network monitoring sits with one supplier, application logs with another, internal service agreements — where they exist at all — sit in a contract or a resolution neither ever consults. Telling whether an event crosses IS-1, IS-2 or IS-3 means evidence living in separate systems, plus a parameter no technical system holds unless the entity wrote it down first. It is the principle behind everything else we build: a single, always-current file holding both the technical monitoring and the thresholds the entity has set for itself, with AI agents running the checks and one operator signing off the decision. On-premise on the client’s own infrastructure, or on a dedicated cloud with a data centre in Italy and premises we staff ourselves.
Do you need to work out whether your organisation falls among the entities of article 1, and what the new taxonomy requires you to report? Half an hour with one of our experts.
What we don’t know
We do not provide legal advice: we work from public sources, here the Normattiva texts in force as of today and Official Gazette no. 39 of 17 February 2026. Article 43, which orders the repeal, is in force from 16 October 2024, yet Normattiva’s consolidated text still carries paragraph 3-bis in the version of that day and loses it only in the version of the 18th: two days we cannot explain, counted here in the legislator’s favour. We have not verified whether, before the repeal, the Agency had already adopted a technical determination under the then-current paragraph 3-bis: if one exists, it falls outside this reconstruction. We have not read prime ministerial decree 14 April 2021, no. 81, cited by the repealed paragraph. And we found no act, on the Agency’s site or in the Gazette, that between 10 October 2025 and 9 February 2026 filled the unexercised delegation even provisionally: if any entity had to report an incident in that window, we do not know by what criterion.
Sources
- Law 28 June 2024, no. 90, article 1 — reporting and notification duty, incident taxonomy (Normattiva, text in force)
- Decree-law 21 September 2019, no. 105, article 1 — national cyber security perimeter, paragraph 3-bis repealed (Normattiva, text in force)
- Legislative decree 4 September 2024, no. 138, article 43 — regulatory amendments, repeal of paragraph 3-bis (Normattiva, text in force)
- Law 23 September 2025, no. 132, article 28 — final provisions, delegation of the taxonomy to the ACN director general (Normattiva, text in force)
- ACN, determination 9 February 2026 — taxonomy of incidents under article 1, paragraph 1, of law 28 June 2024, no. 90 (Official Gazette no. 39 of 17-2-2026)
- ACN — Law 90/2024, the incident taxonomy triggering the notification duty has been adopted