Operational notes Regulation

NIS2, October 2026: what must be in the binder when ACN comes knocking

5 min read

A hand signing a document with a pen, close-up, in black and white
The signature at the bottom of the page is not enough: what counts is the trail of how you got there.

On 4 September 2024 Italy transposed NIS2 with Legislative Decree 138/2024. Since then, many companies have read the directive as a bureaucratic exercise: register, wait for instructions, breathe out. Whoever read it that way got the calendar wrong. For the first wave of entities — those registered between December 2024 and February 2025, with the list consolidated by the National Cybersecurity Agency (ACN) in April 2025 — article 24 of the decree sets 18 months from that point to adopt baseline security measures: the deadline lands in October 2026. ACN’s own official FAQs confirm this timeline; for entities registered for the first time in the 2026 window, the equivalent deadline — again according to ACN’s official guidance — is 31 July 2027. Two different calendars, the same requirement: proof.

The burning consequence: compliance is not declared, it is demonstrated

NIS2 does not ask for a promise. It asks for a verification. The directive (articles 32-33 of Directive (EU) 2022/2555, transposed into ACN’s supervisory powers) authorises on-site inspections, off-site checks and targeted security audits of essential and important entities. When that request lands, what matters is not what you did: it is what you can show. A policy that exists only in the head of the IT manager, a risk analysis that was never written down, a critical supplier with no security clauses in the contract: in front of an inspector, these count as if they did not exist. The fines under article 38 of the decree are calibrated to this reality: up to €10 million or 2% of worldwide turnover for essential entities, up to €7 million or 1.4% for important entities — and they apply even for formal breaches, at reduced thresholds of 0.1% and 0.07%. The same principle that applies to incidents — you only notice what you measure — applies to compliance: you can only demonstrate what you have written down.

What has to be in the binder, literally

ACN’s technical FAQs list what a NIS entity must be able to produce. It is not an abstract list:

  1. Board minutes (article 23): approval of risk-management measures, oversight of their implementation, evidence of the specific training received by senior management. Responsibility can no longer be delegated wholesale to IT — and without a minute, it cannot be demonstrated.
  2. An up-to-date risk analysis, referring to the company’s actual systems, not a template downloaded from the internet.
  3. Inventories of systems, configurations, known vulnerabilities and personnel with access — the foundation that makes everything else possible.
  4. A register of critical suppliers and contracts with security clauses — the same exercise DORA imposes on the financial sector, here extended to all NIS entities: contracts already in force do not need immediate amendment, but every new contract, renewal or extension must incorporate requirements consistent with the risk analysis. A company that renews an IT contract in October without touching the clauses turns up to the inspection with a hole in its file.
  5. Business continuity and disaster recovery plans, tested, not merely written.
  6. A record of staff training, in addition to that of senior management.
  7. Incident notification procedures that have actually been exercised: early warning to CSIRT Italia within 24 hours, full notification within 72, final report within a month.
  8. Evidence of access control, encryption and network segmentation — not the policy that prescribes it, the proof that it is active.

What to do now, before the calendar does the work for you

Between now and October there are only a few useful working weeks left, holidays and closures included. The sensible order:

  1. An honest gap analysis between what article 24 requires and what you have in writing — not what you do, but what you can prove you do.
  2. Assign responsibility at board level through a formal resolution: that is article 23, and it is the first thing missing almost everywhere.
  3. Review supplier contracts due for renewal or expiry in the coming months: that is where the security clause belongs, not afterwards.
  4. Put in writing what you already do well: often the substance is there, and what is missing is the documentary trail that makes it enforceable in front of an inspector.

How we solve it

The real bottleneck is not working out what is missing: it is the time the legal and technical office needs to compare dozens of policies, contracts and registers against the required measures, item by item. And those documents — security architectures, supplier contracts, continuity plans — are themselves industrial secrets: they cannot be handed to a generic cloud assistant that sends them elsewhere for processing. This is the work we hand to dedicated AI agents: a documentary gap analysis that compares the real binder against the article 24 measures, flags what is missing and proposes the fix, without a single document leaving the company’s perimeter. We do this in two ways, never just one as the sole option: on-premises, inside the client’s own infrastructure, or on CSIDIA’s dedicated cloud — an environment reserved for a single client, accessible only via a dedicated VPN, with a data centre resident in Italy and premises staffed directly by us. The same principle guides our dual-use compliance approach: the regulatory constraint is part of the project, not an obstacle to work around.

Want to know what is really missing from your NIS2 binder before October? A 30-minute session with one of our experts is the fastest way to find out.

Sources