Operational notes Regulation

NIS categorisation: the one duty you judge, not fill in

6 min read

A series of pale wooden rings nested one inside the other, photographed from above, in black and white
Each ring holds the next one inside it, but deciding how deep to go remains a judgement made by whoever looks in.

A typical scenario, not a case of ours. A NIS entity — on the register for a year, perhaps without ever having reported an incident — reaches May 2026 and discovers it must fill in, through the ACN portal, a list of every activity it carries out and every service it provides, each tagged with a relevance category: high, medium, low, minimal impact. Whoever is handling it opens the model, sees that every macro-area already carries a pre-assigned category, leaves it as it is to save time, and submits by 30 June. Nobody in security has checked whether that category actually describes the organisation. The trouble is that it is this number, not the name of the activity, that will decide how far next year’s security measures have to reach.

The rule, with its precise terms

The duty sits in Article 30(1) of Legislative Decree no. 138 of 4 September 2024 (the NIS decree): “for the purposes of Article 24(1), from 1 May to 30 June each year, starting from receipt of the first communication under Article 7(3)(a), essential and important entities communicate and update, through the digital platform under Article 7(1), a list of their activities and services, including all the elements necessary to characterise them and the assignment of a relevance category.” Paragraph 2 hands ACN the task of setting the relevance categories and the criteria for listing, characterising and categorising; Article 42(2) fixes when: “the obligation under Article 30(1) applies from 1 January 2026” — in practice, the first usable window was the one that has just closed, from 1 May to 30 June 2026. The next one opens on 1 May and closes on 30 June 2027, and does not reopen.

ACN exercised that power through a Director General’s determination (no. 155238/2026), digitally signed by Bruno Frattasi on 13 April 2026, after consulting the Table for the implementation of the NIS framework at its meeting of 9 April. The resulting model (Article 2) lists ten macro-areas, each with a pre-assigned relevance category, and sets out four levels: high, medium, low, minimal impact. The determination applies from 1 May 2026 (Article 8(2)).

The judgement the platform will not make for you

Up to this point it is a filing exercise: listing, macro-area by macro-area, the name and description of every activity and service (Article 3(2) of the determination). What changes the nature of the duty is paragraph 3: “NIS entities may assign a relevance category […] different from the one pre-assigned to the macro-area […] on the basis of their own assessment of the impact a possible compromise would have […] on the entity’s ability to properly carry out its NIS activities and services. In that case, NIS entities keep the documentation recording that assessment.” This is not a default to accept: it is a case to be made, with the paperwork ready for when someone asks for it.

And someone does ask: Article 30(3) of the decree gives ACN 90 days from the communication to check the conformity of what has been submitted, extendable once by a further 60 in complex cases. But paragraph 4 adds the part almost nobody reads to the end: “in the absence of feedback […] within the deadlines […] conformity […] is deemed validated.” Silence from the Agency, category validated. Anyone who underrates an activity out of budgetary caution — a lower category means, in theory, cheaper measures — and is not caught in time spends a full year with a calmer self-portrait than the real one, backed by a stamp nobody actually applied.

Two penalties, two different targets

The decree does not treat failing to submit the list the same way as submitting it wrongly. Article 38(10)(c) punishes, with an administrative penalty, “failure to communicate or update the list of activities and services, or their categorisation, under Article 30(1)”: up to 0.1% of worldwide turnover for essential entities, 0.07% for important ones (paragraph 11), or fixed amounts — from €10,000 to €50,000 — for public bodies. That is the penalty for not handing in the assignment. But a wrong categorisation is rarely challenged on its own: it surfaces when the security measures calibrated on that category are assessed under Article 24, and there the penalty is the far heavier one under paragraph 8(a) of the same Article 38 — up to €10 million or 2% of worldwide turnover for essential entities, up to €7 million or 1.4% for important ones. The small fine is for the missing form. The large one comes later, for measures built on the wrong number.

One document, three regimes

The categorised list does not stand alone. Article 4 of the determination says that any entity that has already classified its data and services as ordinary, critical or strategic under Article 3 of ACN’s cloud regulation applies that model instead of this one: whoever has already done the work for the 30 June 2026 migration does not do it twice, they reuse it. Article 5 closes the other side: activities and services subject to the national cybersecurity perimeter are automatically assigned the “high impact” category, and fall outside the self-assessment of Article 3 — they are not judged, because they have already been judged. Anyone inside all three regimes — NIS, public-sector cloud, the Perimeter — ends up with a single document that makes them talk to each other; anyone who has already done the work for either of the other two arrives in May with half the job done.

What to do now

  1. Reopen the list you have just submitted (or the one you should have submitted) and check, macro-area by macro-area, whether the pre-assigned category actually matches the impact of a compromise — not the convenience of leaving it as it is.
  2. Write down the assessment, not just the category: paragraph 3 asks for the documentation behind every departure from the default, and it needs to be kept from day one, not reconstructed if a review arrives.
  3. Cross-check against cloud and Perimeter: if you already have an ACN cloud classification or activities inside the Perimeter, make sure the NIS list is not rebuilding them from scratch.
  4. Put 30 June 2027 in the compliance deadlines calendar, not in the personal diary of whoever handled it this year: the duty is annual, and the person changes more often than the deadline does.

How we solve it

Done properly, that list is the most sensitive document an organisation writes about itself: it says what it does, through which services, and how much each one weighs if it breaks. If an AI assistant helps build it — cross-checking real activities against macro-areas, keeping the assessment consistent from one year to the next, flagging a departure that has not yet been documented — that assistant is handling exactly the map an adversary would want to read. It cannot be a generic service hooked up to the open web. We work in two modes, never just one: on-premise, inside the client’s own infrastructure, or on CSIDIA’s dedicated cloud, an environment reserved for the single client, accessed via a dedicated VPN, with the data centre resident in Italy, in premises we directly guard.

Do you need to know whether your categorisation would survive a review, or whether you have inherited a category nobody has ever checked? Half an hour with one of our experts for the first read of the list.

Sources