Operational notes Regulation

A penetration test is a “managed security service”. Now what?

7 min read

Empty black picture frame hanging on a white wall, black-and-white photograph
The European frame is up on the wall. What belongs inside it, in Italy, has not arrived.

This year you bought a penetration test, a security audit, an incident response retainer, or the services of someone who went into your configurations. Two questions. Could you say which European definition that service falls under? And what do you hold today to show how you chose the supplier — not that you paid them, but on what basis you decided they were fit for it?

If the answer to the second is “the quotation and the invoice”, you are in the ordinary condition. And a European definition, in force without much noise, has made that condition uncomfortable.

The definition, and how wide it is

Regulation (EU) 2025/37 of the European Parliament and of the Council, of 19 December 2024, amends Regulation (EU) 2019/881 — the Cybersecurity Act — “as regards managed security services”. Its Article 1(2) inserts a new point 14a into Article 2 of the 2019 regulation. Verbatim:

“‘managed security service’ means a service provided to a third party consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, such as incident handling, penetration testing, security audits and consulting, including expert advice, related to technical support.”

It is worth reading slowly. It does not only cover the outsourced security operations centre most people picture: it names four categories, and they are the ones every organisation buys. If you have handed one of those activities to someone who is not your employee, you have bought a managed security service within the meaning of Union law.

What actually changes

The regulation does not impose an obligation to certify: it extends the European cybersecurity certification framework to these services. It rewrites the 2019 definitions, adding managed security services throughout — certification scheme, national scheme, European certificate, technical specification, assurance level, conformity self-assessment — and replaces Article 46, which now attests that these services meet given requirements too. ENISA’s tasks are extended accordingly.

Two details are worth pulling out, because they change how you read a commercial offer.

The first is conformity self-assessment, defined as “an action carried out by a manufacturer or provider of ICT products, ICT services, ICT processes or managed security services, which evaluates whether those […] meet the requirements of a specific European cybersecurity certification scheme”. It is a first-party statement, and it is legitimate — but it is a different thing from third-party verification, and in a slide deck the two look much alike.

The second is the assurance level, which the regulation defines as a basis for confidence and then qualifies: it “indicates the level at which an ICT product, ICT service, ICT process or managed security service has been evaluated but as such does not measure the security of the […] managed security service concerned”. A level tells you how deeply someone looked, not how secure the thing they looked at is.

Article 2 closes without slack: the regulation “shall be binding in its entirety and directly applicable in all Member States”.

The Italian side, and the calendar

National adaptation sits with Law No. 36 of 17 March 2026, the European delegation law, in force since 9 April 2026. Article 16(1) delegates the Government to adopt, “within three months of the entry into force of this law”, one or more legislative decrees “to adapt national legislation to Regulation (EU) 2025/37 […] and to coordinate the sectoral rules in force with the European framework”. Three months from 9 April gives 9 July 2026: that is our own calculation on the text, not a date written in the provision.

Paragraph 2 says precisely what it should have produced. Point (a): amend the legislation in force “and in particular Legislative Decree No. 123 of 3 August 2022”. Point (b): amend Decree-Law No. 82 of 14 June 2021 to “specify how the functions assigned to the National Cybersecurity Agency are exercised in respect of the accreditation, authorisation and delegation of bodies”. In other words: who, in Italy, says that a body is fit to assess these services. Article 16 carries no parliamentary opinion clause, so it has no extension of its own.

Where our checking stops

On Normattiva, Legislative Decree No. 123 of 3 August 2022 — the act the delegation names — shows “text in force since 4-9-2022”: never amended since it entered into force. Had the delegation been exercised on that act, the consolidated text would show it. We have also read the summaries of the Official Gazette, General Series, up to No. 184 of 10 August 2026, published yesterday morning, and the most recent legislative decree remains No. 141 of 5 August.

Where we stop, precisely: we have not run an exhaustive search across every legislative vehicle. We can state that the act the delegation names has not been amended, and that the three-month term, by our calculation, ran out on 9 July. This is a reading of primary sources, not legal advice.

It is not an isolated case. Yesterday we wrote about the delegation under Article 15 of the same law, the one on the Cyber Resilience Act, whose Chapter IV has applied since 11 June 2026 while the designation of the National Cybersecurity Agency as notifying authority is still to come. Two delegations in the same law, two pieces of the same European framework, neither of them delivered.

See the service · Talk to an engineer

Why it changes less than you think for the buyer

This is the point. What is missing is the thing that would give you a handle: a national accreditation to cite in a tender, a list to consult. It is not there, and you cannot point to it.

But nothing stops you from writing into the contract what the supplier must demonstrate, and keeping the evidence: which of the four activities they actually provide, which schemes or standards they claim to meet, whether that claim is a self-assessment or third-party verification — and in the latter case, who issued it and when.

Set this up now and the answer is ready when the scheme arrives. Wait, and the selection gets redone from scratch — while an NIS entity gets the same question anyway on supply chain security, where nobody asks whether the scheme existed yet.

The two axes, applied

Complying. Selecting managed security service suppliers stops being a judgement made in the moment and becomes a control running on the client’s contracts and documents: for each one, which activity they provide, on what basis they claim to be fit, whether they self-assess or have been verified, by whom and when, and what evidence is retained. With the dated record to show an inspection or a board. It is the same distinction we isolated reading a sales channel mistaken for an authorisation: being purchasable is not being qualified.

Deciding. The same system holds contracts, supplier registers, test reports, archives and systems together in a single operating model — the organisation’s data lake becoming one thing — on which AI agents execute decisions with a human operator in command, for large enterprises, defence, government and healthcare. When the scheme lands, the answer to “which of our suppliers fall under the definition, and what have they already shown us” arrives in hours rather than weeks — provided the field exists, which is the point already made about register lines that never say what capability is being supplied. Always in two delivery modes: on-premises, on autonomous machines that need no deep integration into the client’s network, or a dedicated cloud with a data centre in Italy, always with shared management.

Back to the opening question. If you were asked tomorrow for the list of suppliers who, under the European definition, provide you with managed security services — and on what basis you judged them fit — could you answer without opening a folder of quotations? In most cases the answer is no.

From the first session, at no cost, comes the dated list of your suppliers falling under the definition in Article 2, point 14a: for each one, which activity they provide, on what basis they claim to be fit, whether it is self-assessment or third-party verification, and what evidence you have kept — blank boxes included. It stays yours even if we do not go on together. Talk to one of our engineers.

Sources