Operational notes Regulation

NIS2, 12 October 2026: the deadline is a document, not a date

8 min read

Two glass hourglasses on a light shelf, with sand at different levels, photographed in black and white
Each hourglass measures its own time from the moment it was turned — not from the date on the calendar.

A typical scenario, not one of our own cases. A group with three companies, all registered as NIS entities, organises itself around the same deadline: 12 October 2026, the date that circulates in webinars and appears in our own compliance calendar. The group’s compliance lead sets a single deadline for all three. Then, while tracking down the notice of inclusion in the list to attach to the file, they discover the three companies received it on three different days — none of them exactly on 12 April 2025. The single plan stops holding up: each company has its own deadline, and none of the three actually falls on 12 October.

The law that delegates, the determination that fixes the term

Legislative Decree No. 138 of 4 September 2024 (the NIS Decree, transposing Directive (EU) 2022/2555) does not set the deadlines itself. Article 31(1) and (2) gives ACN the task of setting them for the duties under articles 23, 24, 25, 27, 28 and 29, “duly taking into account” risk exposure, size and potential severity; article 42(1)(c) authorises the Agency, “in the first-application phase”, to set the base specifications. It is the same mechanism that, through a separate determination, individualises the categorisation of activities and services: the NIS Decree’s principle of proportionality always translates into a judgement on the individual entity, never into one rule identical for everyone.

ACN first exercised this power on 14 April 2025, then through Determination No. 379907 of 19 December 2025, in force since 15 January 2026. Its article 3 states, verbatim: paragraph 1, “the deadline for adopting the base security measures […] is set at eighteen months from the receipt, by the NIS entity, of the notice of inclusion in the list of NIS entities”; paragraph 2, the same count but at nine months for reporting significant base incidents. The same eighteen months, from the same receipt, apply to top-level domain registries and registrars (article 4(1)).

12 October is not written down: we checked

We searched for the string “12 October” in the three official texts downloaded today from ACN’s website: Determination 379907/2025, Determination 127434/2026, and the “Duties” page of the NIS portal. It appears in none of the three. The only “October” that does appear is a different one: 16 October 2024, when the NIS legislation came into force.

So where does the date in circulation come from? From a calculation worked backwards from a real but partial starting point. ACN’s news item “NIS, the second phase gets under way”, of 15 April 2025, reports that the list identified over 20,000 organisations, more than 5,000 of them essential entities, and that “from 12 April ACN began notifying the entities concerned of their inclusion, or not, in the list of NIS entities”. Eighteen months after 12 April 2025 falls on 12 October 2026: it is the earliest possible date in the cycle, not the only one and not the latest. An entity that received its notice on 20 April has eighteen months from there: its deadline is 20 October, not the 12th.

This is not the first time we have found this gap in a compliance deadline: it applies just as much to the ICT census of Italy’s public bodies, where 30 September is not in the law but in an AgID act. Here the logic is more treacherous: the act that sets the deadline — the ACN determination — exists and is public, but the deadline it sets is not a day on a calendar. It is a count that starts from a private event specific to each entity.

Two texts from the same authority, two ways of counting

The “Duties” page, written for a general audience, describes the same window differently: “the legislative decree establishes an initial, differentiated implementation window: 9 months for notifications and 18 months for security measures, running from the date the list of NIS entities was consolidated (April 2025).” Here the count starts from a single date for the whole list. The determination, which is the act from which the legal duty and the penalty actually flow, instead runs the count from each individual entity’s own receipt of its notice: a different date for each one.

This is not a contradiction to call out, and we found no grounds to say either reading is wrong: they are two different levels of description, one general and one operational, that stay close together as long as the gap between the first and last notice in the wave stays narrow. But “narrow” is not “zero”, and an entity that has to account for a deadline at an inspection does not prove it with the sector average — it proves it with its own certified email.

The consequences, in order of urgency

  1. Your deadline is a document, not a date. Without the notice of inclusion and its date of receipt, you do not know what your deadline is — and you cannot prove it at an inspection. The first thing to do is not to open a compliance plan: it is to track down that certified email in your own registry.

  2. Within a group, the dates diverge. Several companies in the same group, registered separately, may have received their notice on different days: they therefore have different deadlines. A single group-wide plan built around one date is wrong by construction, and the error only shows up at the first check, company by company.

  3. Two regimes coexist. Entities that were on the 2025 list and remain on it follow the individual count (article 3 of Determination 379907/2025, referred to by article 1(3) of Determination No. 127434 of 13 April 2026). Entities entering the list for the first time in 2026 instead have fixed dates, the same for everyone: 31 July 2027 for security measures, 1 January 2027 for reporting. A supplier that joined the list this year and a customer registered last year, in the same supply chain, do not have the same duties on the same date: it weighs on the security clauses in their contracts.

  4. Reporting is already in force. The eighteen months apply to security measures; the nine months for reporting, for the first wave, expired earlier — in January 2026. An entity now planning its measures for October may, without noticing, have already carried the duty to report a significant incident for months.

What to do now

  1. Retrieve, for each entity in the group, the notice of inclusion and its date of receipt: it is that document, not the calendar, that sets the deadline.
  2. Count eighteen and nine months from that date — not from the 12 October that circulates at conferences — and check which regime each entity falls under: individual for 2025, fixed for 2026.
  3. If the notice cannot be found, request it from the entity’s NIS point of contact before building a plan on an assumed date.
  4. For the full list of what needs to be in the file — board minutes, risk assessments, the supplier register, continuity plans — the article-by-article list is here.

How we solve it

That notice, its date of receipt, and the status of each measure under Annexes 1 and 2 are, in a group with several NIS entities, data scattered across different mailboxes, different registries and different people — the fragmentation that turns a shared compliance plan into an illusion. The first step is to turn it into a check that runs continuously over each company’s documents and systems: who received what, when, what was adopted and on what date, with the audit trail ready to show at an inspection — not a spreadsheet someone updates from memory once a year.

The same system, extended beyond this single deadline, holds the group’s data together — ACN notices, supplier registers, system inventories, logs — in a single operational model on which AI agents execute decisions with an operator in command: not just “when is our deadline”, but “which company in the group risks missing it, and with which measure still open”. For large enterprises, defence, public administration and healthcare, in two modes — on-premises, on autonomous machines that need no deep integration into the client’s network, or dedicated CSIDIA cloud, with a dedicated VPN and a data centre in Italy under our direct supervision — and with shared management: an organisation that does not already have staff running AI systems in-house does not need to hire them to use this.

Do you already know, for each company in your group, when the notice of inclusion in the list of NIS entities arrived? Half an hour with one of our experts for a first check against your real dates.

Sources