NOSI: an Italian company’s industrial security clearance is six documents, not a stamp
7 min read
A typical scenario, not a case of ours. A company that builds security systems wins a RISERVATISSIMO tender. It already holds the Preliminary Authorisation, obtained months earlier to bid. On award, the request that actually matters arrives: the file for the Nulla Osta di Sicurezza Industriale — the NOSI, not a discretionary stamp but the measure that, says Article 1(ff) of Italy’s DPCM of 6 November 2015, no. 5, “authorises the economic operator to handle and manage classified information” and lets the contract be executed. Whoever pulls the file together finds out within a week that the Security Officer named at bid stage left eight months ago, the beneficial-owner list does not reflect the latest change in shareholding, the anti-mafia certificate has expired, and the secure area set up for the bid was never checked for execution. Four different offices, none of which knew it had to answer to the UCSe — Italy’s central office for secrecy — within six months.
Two measures, one common mix-up
DPCM 5/2015 — Official Gazette no. 284 of 5 December 2015, in force on Normattiva as of 19 August 2026 — draws a careful line between two measures everyday language blurs together. The Preliminary Authorisation (AP), Article 1(ee), “allows the economic operator to take part in tenders” for RISERVATISSIMO and SEGRETO contracts: it lets a company compete, lasts six months from issue (Article 43(5)), and is what most companies obtain first. The NOSI, letter ff), is something else: it authorises handling and managing the information itself, and is required to bid for contracts above SEGRETO and — the point the scenario above makes — to carry out works, supplies or services above RISERVATO once awarded. Holding the AP does not mean holding the NOSI: they are two separate files, and the second opens exactly when the first seems to have closed the matter. This is not the same ground as the clearances for EU classified information, where at RESTREINT UE the facility clearance is not required at all: here we are on the national track, where it is required, of more than one person at once.
Who needs the personal clearance — not just the company
Article 44(2) sets the precondition in one line that maps to an entire org chart: “A precondition for issuing the NOSI is that the legal representative, the Security Officer and, where necessary, the technical director and other personnel hold a NOS [personal security clearance].” It is not enough for the company, as a legal entity, to be trustworthy: personal clearances are needed for whoever represents it and whoever actually handles the information, lasting as long as Law 124/2007 sets out — five years for SEGRETISSIMO, ten for SEGRETO and RISERVATISSIMO. It is a turnover question that runs through HR, and it has to cross-reference a register that almost never lives in the same system: whoever leaves the Security Officer role, or loses their NOS, must be reported — and the NOSI hangs on that report being made, not on someone remembering to make it.
The secure area has to be proven, not declared
Article 44(3) requires the operator to set up “a secure area with the characteristics set out in Chapter VIII, suited to the needs of the contract’s execution”; paragraph 5 adds that, where RISERVATISSIMO information or higher is handled through COMSEC and CIS systems, the corresponding accreditations are also required. So far this looks like a facilities task. Paragraph 4 shifts the centre of gravity: the UCSe verifies “the existence and suitability” of those areas, assigning the checks “to the security bodies within the Armed Forces” — not a form to sign, an actual site inspection. The paperwork sits in IT and facilities management, almost never in the same file as the personnel record that holds the NOS.
Beneficial owners and anti-mafia checks: two different “231” decrees, two different offices
Article 45(2) lists the documentation required for issue: at letter e), “documentation attesting the identity of the economic operator’s beneficial owners pursuant to legislative decree no. 231 of 21 November 2007” — Italy’s anti-money-laundering law. Paragraph 5 does not treat this as a one-off attachment: the operator “must promptly report any change relating to its beneficial owners”, even for a NOSI already issued. Paragraph 4 refers back to the documentation under Article 43(3) — including, at letter c), the anti-mafia documentation under Article 84 of legislative decree 159/2011. Do not confuse the two “231” decrees: the 2007 one concerns beneficial owners, while Article 47(1)(a) — a ground for denying or revoking the NOSI — cites a different decree, legislative decree no. 231 of 8 June 2001, on corporate administrative liability: disqualification sanctions recorded under decree 313/2002 are enough on their own to bring the NOSI down. Same number, two laws, and — at most companies — two offices that rarely talk to each other: whoever keeps the beneficial-owner register is almost never the person running the 231/2001 compliance model.
The calendar no single office keeps on its own
Article 45(7) sets the issuing deadline: six months from receipt, suspended if the UCSe needs further information. Article 46 sets its duration once granted: five years for SEGRETISSIMO, ten for SEGRETO and RISERVATISSIMO. But the calendar date is not the only risk: Article 47(3) allows denial, revocation or limitation even of a NOSI already issued, when the security organisation shows “signs of ongoing inadequacy” in physical measures, cleared personnel, or technical CIS and COMSEC measures — and Article 48(1)(d) adds that “security checks” alone are enough to reveal them. The NOSI is not a milestone reached once: it is a condition proven continuously, with documents someone else, in another office, may have let lapse without telling whoever holds the file.
What a supplier must be able to show, and who holds it today
- NOS of the legal representative, Security Officer and, where required, technical director and “other personnel” — HR, five- or ten-year expiry.
- Secure area certified for the level required, with COMSEC/CIS accreditations — IT and facilities.
- Beneficial-owner register, updated at every change — anti-money-laundering compliance.
- Anti-mafia documentation in date — legal or procurement office.
- No disqualification sanctions under decree 231/2001 — the supervisory body, yet another office.
- Traceability of security checks, to answer if the UCSe asks about ongoing adequacy, not just the original file.
See the service · Talk to an engineer
What we do not know
We do not offer legal advice, and we do not handle or disclose classified information: we work from public sources, here the text of DPCM 5/2015 as shown in force on Normattiva at the time of writing. We do not know whether the UCSe is preparing updates to the regulation’s implementing provisions, nor the internal review practices the Agency or contracting authorities follow case by case: that remains ground a company checks with its own UCSe contacts, not with an article.
The two axes, applied to the NOSI
Compliance. In our set-up, the NOSI file becomes a control that runs across the client’s documents and systems: for each of the six requirements — personnel NOS, secure area, beneficial owners, anti-mafia checks, no 231/2001 sanctions, security-check history — which data proves it, where it sits, who updates it, on what date. Not a file rebuilt from memory when the UCSe comes knocking, but a record kept ready, as with ICT procurement inside the national cyber perimeter: what counts is a verifiable system, not a promise made once.
Decisions. The same set-up holds personnel files, secure-area floor plans, the beneficial-owner register, CIS certifications and contracts together in a single operating model, on which AI agents execute decisions with an operator in command — for large enterprises, defence, public administration and healthcare. Always on-premise, on self-contained machines needing no deep network integration, or on a dedicated cloud, with a dedicated VPN and a data centre resident in Italy, always with shared management: a supplier of classified-information systems should not also have to staff its own AI administrator in-house. This is the method behind our platform, not an added line item.
From the first session, at no cost, you get a dated list of what stands for your NOSI: clearances due to expire, the system they sit in, who updates them — including the blanks. It stays yours even if we do not go on to work together. Talk to one of our engineers.
Sources
- DPCM of 6 November 2015, no. 5 — provisions on the administrative protection of state secrets and classified and restricted-distribution information, Arts. 1, 42–48 (Normattiva, text in force)
- Law of 3 August 2007, no. 124, Art. 9 — duration of the NOS by classification level (Normattiva)
- DIS — Department of Information for Security, DPCM 5/2015 text coordinated with the 2017 amendments