Italy’s cyber perimeter and the CVCN: an ICT purchase does not end with a signature
6 min read
A typical scenario, not a case of ours. An organisation inside Italy’s national cyber security perimeter is assessing an AI system to monitor and manage its networks. The specification is written. Then procurement asks the right question: does this supply have to be notified to the CVCN? If so, the project calendar is no longer the supplier’s to set.
The rule, with the references
The perimeter is established by article 1(1) of decree-law 21 September 2019, no. 105, converted with amendments by law 18 November 2019, no. 133. The mechanism that matters to buyers sits in paragraph 6, letter a): organisations inside the perimeter intending to proceed with “the award of supplies of ICT goods, systems and services” for the networks and systems on their own list, where these fall within categories set by prime ministerial decree, “shall notify the National Evaluation and Certification Centre (CVCN)”, attaching the risk assessment for the supply. The obligation has been effective, by express provision, “in any case from 30 June 2022”. The CVCN, placed by the decree at the Ministry of Economic Development, operates within the National Cybersecurity Agency (article 16(6)(a) of decree-law 82/2021); the same letter confirms the evaluation centres of the Ministries of the Interior and of Defence, which use its methodologies. And the list of those inside is not public: it sits in an act for which “the right of access is excluded” and which “is not subject to publication” (paragraph 2-bis). It cannot be inferred: you ask the buyer.
The deadlines, in days
The implementing regulation is presidential decree 5 February 2021, no. 54. Notification must be sent “before the start of the award procedure or, where none is provided for, before the contracts are concluded” (article 3(1)). Then, under article 4:
- 45 days for preliminary checks, extendable once by 15 in cases of particular complexity, including recent technologies “for which no consolidated test methodologies are available”.
- 60 days for the tests, running from the moment the object of the evaluation is made physically available for testing.
- Silence: once the first deadline passes without a decision, the award procedure may continue; once the second passes, so may performance of the contract (paragraph 6). But the deadlines are suspended, once only, if the information supplied is incomplete (article 5(1)).
Where conditions and tests are imposed, tender notices and contracts carry clauses making the contract conditional, suspensively or resolutively, on a favourable test outcome (article 5(6)). A negative outcome produces a reasoned negative decision (article 8(2)); a positive one still allows conditions of use, including on “maintaining the level of security over time in the operating environment” (article 8(3) and (4)).
It covers AI too, and it is written down
The categories are in Annex 1 to the prime ministerial decree of 15 June 2021 (Official Gazette no. 198 of 19 August 2021). In the third — components for data acquisition, monitoring, supervision, control, actuation and automation of networks and industrial and infrastructure systems — it expressly lists “Artificial Intelligence (AI) and Machine Learning (ML) systems for network/system management”, alongside SCADA systems. This is not an expansive reading: it is a line in the annex. The matching technical criterion is article 13 of presidential decree 54/2021, which also covers “the partial or total development of a new software programme” when it is the relevant application layer of an IT service.
What the supplier has to hand over
Article 5(5) of presidential decree 54/2021 lists the “preparatory and indispensable” activities borne by the supplier: evidence that the security functions and their configurations are fit for purpose; a test environment adequately representative of real operating conditions; “a general description of the architecture of the object of evaluation and of its functions”; the tests already carried out together with their results. The tests may cover correct implementation of the security functions and intrusion (paragraph 3). And the costs are the supplier’s: the decree-law, at paragraph 6, letter b), speaks of cooperation “bearing the burden thereof”.
It is not NIS2, and law 90/2024 did not change it
Legislative decree 138/2024 requires risk-management measures and notifications across a wide population — October’s documentary exercise — but it does not require telling the State before awarding an ICT supply, nor does it impose tests on the product. It is also distinct from the ACN cloud qualification, which decides where a dataset may sit: here what is decided is what may enter a system. Law 28 June 2024, no. 90 did not touch it: article 14, on “essential cyber security elements” in ICT procurement, closes at paragraph 4 by stating that “what is laid down in article 1” of the perimeter decree “remains unaffected”. Two tracks, not one.
The penalties, with the figures
Save where the conduct is a criminal offence, failure to notify in time carries an administrative fine of €300,000 to €1,800,000 (paragraph 9, letter d); the same range applies to using products “in breach of the conditions or without having passed the tests” (letter e), plus a three-year disqualification from management, administrative or supervisory office (paragraph 10). A supplier’s failure to cooperate with the tests costs €250,000 to €1,500,000 (letter f). Paragraph 11 punishes with one to three years’ imprisonment anyone supplying untruthful information to obstruct those proceedings: an offence that paragraph 11-bis added to the list triggering corporate liability (legislative decree 231/2001).
The consequence almost nobody writes down
The first is calendar and contract: you choose a supplier knowing the product will be opened, wired up and tested, not merely described in a deck. The second runs deeper. A system able to withstand that scrutiny is necessarily one whose components, dependencies and behaviour are known: the architecture can be described, the operating environment rebuilt in a laboratory, the tests already run exist and have readable results. An opaque service, of which the buyer sees only an interface, has none of this to hand over. It is the requirement the Cyber Resilience Act frames as a software bill of materials; the difference: there you write the verification into the contract, here the State imposes it and a laboratory runs it.
How we solve it
A system that must be capable of being evaluated and tested has to be built so components, dependencies and behaviour stay knowable and reproducible: a software bill of materials, a dependency list, an environment rebuilt on demand, logs available to whoever verifies. That is why we deliver in two modes, never just one: on-premise, inside the client’s own infrastructure, or on a dedicated cloud reserved for the single client, with a dedicated VPN, a data centre resident in Italy and premises we staff ourselves. In both cases the environment can be reproduced and the behaviour measured: the precondition for data and perimeter protection, not an optional extra.
Do you need to work out whether a supply you are about to award goes through the CVCN, and what you must be able to show? Half an hour with one of our experts for a first reading of the procedure.
Sources
- Decree-law 21 September 2019, no. 105, article 1 — perimeter, notification to the CVCN (paragraph 6) and penalties (paragraphs 9-11) (Normattiva)
- Presidential decree 5 February 2021, no. 54 — procedures, arrangements and deadlines for CVCN and CV evaluations (Normattiva)
- Prime ministerial decree of 15 June 2021 — categories of ICT goods, systems and services, Annex 1 (Official Gazette no. 198 of 19 August 2021)
- ACN — Certification: the CVCN and the network of accredited laboratories