Operational notes Regulation

Legislative decree 134/2024: the list of critical entities cannot be read, by law

7 min read

Wooden door reinforced with rows of large iron rivets, with a small hatch at the centre closed by a metal grille behind which only darkness is visible, black and white photograph
The grille lets you look. What lies beyond the door stays where no one outside can know it.

An entity does not find out on its own that it is a critical entity: there is no register to consult, only a letter that may or may not arrive. That is the structure of legislative decree 4 September 2024, no. 134, Italy’s transposition of directive (EU) 2022/2557 on the resilience of critical entities — signed, among others, by the ministers of Defence and the Interior, Crosetto and Piantedosi, in force since 18 October 2024. Every deadline in it runs from an act that almost never coincides with a date knowable in advance.

Who identifies whom, against which thresholds

Article 2 defines a critical entity as a public or private body identified under article 8 among the categories operating in Annex A’s sectors: from energy to transport, healthcare to digital infrastructure. The sectoral competent authorities (ASC) identify the critical entities in their own sector by 17 January 2026 and report them to the single point of contact (PCU), at the Prime Minister’s Office. The thresholds the ASCs apply, though, are set elsewhere: article 9(2) assigns them to a prime ministerial decree, proposed by the Interministerial Committee for Resilience (CIR), due by 17 July 2025, with only an optional thirty-day parliamentary opinion before it can be adopted regardless (paragraph 3).

The list the entity concerned cannot read

Based on the reports it receives, the PCU compiles the list of critical entities (article 8(3)); here the law changes register. Paragraph 4 sets its adoption by prime ministerial decree, after hearing the CIR, by 17 July 2026, and adds: «Il decreto di cui al primo periodo non è soggetto a pubblicazione ed è escluso dall’accesso» (The decree referred to in the first sentence is not subject to publication and is excluded from access). Not a delay, not de facto secrecy: an exclusion written into the very provision creating the list. An entity on it learns of it only through the notice the PCU must send within thirty days, naming the responsible ASC (paragraph 5). Within the same thirty days the PCU also reports every critical entity’s identity to the National Cybersecurity Agency (paragraph 6); the full list also goes to Italy’s intelligence bodies — DIS, AISE, AISI, under articles 4, 6 and 7 of law no. 124/2007 (paragraph 7). The single entity gets a notice about itself alone; intelligence and the cyber agency see the whole perimeter.

Nine months inside ten

The notice also starts the clocks. Duties under chapters III and IV take effect ten months after notification (paragraph 5), subject to exceptions the same paragraph carves out — article 13(1) among them. That is where the second clock sits: «Fermo restando il termine di dieci mesi […], i soggetti critici […] effettuano una valutazione del rischio entro nove mesi dal ricevimento della notifica […], e, successivamente, […] almeno ogni quattro anni» (Without prejudice to the ten-month period […], critical entities […] carry out a risk assessment within nine months of receiving the notification […], and, subsequently, […] at least every four years). Nine months inside ten, not as an alternative: the shorter deadline bites first, closing the risk assessment before the chapter III duties generally apply.

The dates, had the calendar held

Today, 4 September 2026, the 17 July 2026 deadline for the list expired forty-nine days ago. Had the decree been adopted on time, the notice would have arrived by 16 August 2026, the risk assessment would fall around 16 May 2027, and the chapter III and IV duties would take effect around 16 June 2027 — conditional hypotheses, pure arithmetic: the actual adoption date is not public, by design. An indirect clue comes from the other decree, on thresholds, due a year earlier, on 17 July 2025: trade press reports that on that same 17 July 2026 the Council of State gave a favourable opinion, with numerous observations, on its draft — still a draft, a year past deadline.

Silence that denies

Article 15 introduces checks on people: a critical entity may request the European criminal record certificate under article 28-bis of presidential decree 313/2002, for sensitive roles, for staff authorised remote or on-site system access, and for candidates to such roles (paragraph 1), via a reasoned request to the ASC (paragraph 2). Here the law inverts the best-known rule of Italian administrative procedure: «Nel caso in cui la ASC non fornisca risposta entro dieci giorni […] l’autorizzazione […] si intende negata» (If the ASC does not respond within ten days […] authorisation […] is deemed denied). Not silence-as-consent: silence-as-refusal. A third decree, after hearing the data protection authority, will set retention periods for the certificates (paragraph 3): the authority already gave a favourable opinion on the draft on 29 January 2026 — at that date, still a draft.

Twenty-four hours, thresholds elsewhere

On incidents, article 16 requires notification «entro ventiquattro ore» (within twenty-four hours) of becoming aware of it, barring operational impossibility (paragraph 2). What makes an incident significant — beyond the general parameters of users affected, duration and geographic area (paragraph 3) — is decided by sector-by-sector thresholds under that same article 9(2) decree (paragraph 4): still stuck at draft stage. The twenty-four hours already exist; the yardstick for whether they apply, for now, does not. Resilience here is not only digital: article 14 covers physical protection too — fencing, barriers, perimeter and access-control systems (paragraph 2(b)) — with fines up to €125,000 for failing to assess risk, adopt measures, or notify incidents (article 21).

What we have not verified

Whether the list was adopted by 17 July 2026 cannot be verified from public sources, nor could it be by design: the provision excludes that decree from publication and access. We record this as a fact of the law, not a suspicion of non-compliance, without speculating on a list we have not read and could not read. On the thresholds decree, direct searches turned up nothing: the Official Gazette’s internal search engine returns no useful results, senato.it responds with an anti-bot challenge, and the Chamber of Deputies’ documenti.camera.it endpoint returns a 404. We found the Council of State’s 17 July 2026 opinion only through trade press (Staffetta Quotidiana and Staffetta Acqua): no official text of the opinion, and no confirmation that the decree has since been published.

The two axes, applied to a list you cannot read

Comply. Knowing in advance whether it falls among the critical entities is not within an organisation’s power: the decree’s structure says so. What stays possible is arriving ready for the notice: article 13(4) lets the risk assessment draw on documents already built for other regimes, if they cover the risks and dependencies of paragraph 3 — the bridge for anyone with a map already built for NIS2 or the DORA register. Arrive with dependencies mapped and the nine months go to refining; arrive without, and they go to gathering the basics from scratch.

Decide. The same system holds together the infrastructure map, dependencies, personnel checks and incident-notification thresholds in a single operating model, on which AI agents run the checks and one operator signs off the decision. It applies in both modes of the offer — on-premise, on autonomous machines with no deep integration into the client’s network, or dedicated cloud with a data centre in Italy — always with managed operation: an organisation should not need in-house staff on hand before a notice ever arrives. It is the principle behind how we build the platform.

Not sure whether your organisation falls among the critical entities, but want to be ready if the notice arrives? Half an hour with one of our experts to build the first dependency map.

See the service

Sources