What are the ACN baseline measures?
Legislative Decree 138/2024 transposes NIS2 in Italy and lets the National Cybersecurity Agency (ACN) set the baseline obligations. ACN Determination 379907/2025 does so in four annexes: the security measures for important entities (Annex 1) and for essential entities (Annex 2), and the baseline significant incidents for each (Annexes 3 and 4). The measures follow the National Framework for Cybersecurity and Data Protection, 2025 edition, with the functions Govern, Identify, Protect, Detect, Respond and Recover.
Important or essential entity
- Important entities apply Annex 1: 37 measures with 87 requirements.
- Essential entities apply Annex 2: 43 measures with 116 requirements. Six measures are for essential entities only, among them the list of network flows, training for specialist roles, secure configurations and emergency communication.
- Deadlines: the measures apply 18 months, and the duty to notify baseline significant incidents nine months, after ACN’s notice that you are on the list of NIS entities.
- Relevant systems: many requirements apply at least to the network and information systems whose compromise would significantly affect the services that bring you under the decree.
In Dazr you record your category in one control. An important entity marks the measures for essential entities as not applicable in the Statement of Applicability, with the reason.
What you get in Dazr
Each control cites its measure code, such as GV.OC-04, its paragraph in Annex 1 and Annex 2 and the number of requirements for each category.
Incident notification to CSIRT Italia
Under Article 25 of Legislative Decree 138/2024 a significant incident is reported to CSIRT Italia in stages: a pre-notification without undue delay and within 24 hours of becoming aware of it, a notification within 72 hours with a first assessment, an interim report on request, and a final report within one month of the notification. With the ACN framework turned on, the incident register in Dazr counts down each of these deadlines.
One set of evidence for ACN, NIS2 and ISO 27001
Every ACN measure in Dazr names the ISO 27001 controls it maps to and, where there is one, the NIS2 article. Turn on ACN next to NIS2 or ISO 27001 and link the same evidence to each of them.
| Function | NIS2 | ISO 27001:2022 |
|---|---|---|
| Govern | Art. 20; Art. 21(2)(a) and (d) | Clauses 4 to 6 and 9.3; A.5.1 to A.5.4, A.5.19 to A.5.23 |
| Identify | Art. 21(2)(a), (e) and (f) | 6.1, 8.2, 10; A.5.9 to A.5.12, A.8.8 |
| Protect | Art. 21(2)(c), (e), (g), (h), (i) and (j) | A.5.15 to A.5.18, A.6.3, A.8.5, A.8.13, A.8.24 |
| Detect | Art. 21(2)(b) | A.5.25, A.8.15, A.8.16 |
| Respond | Art. 21(2)(b); Art. 23 | A.5.24 to A.5.28 |
| Recover | Art. 21(2)(c) | A.5.29, A.5.30 |
How Dazr helps with the ACN measures
With Dazr Compliance you can:
- Record your category, the date of ACN’s notice and your 18-month and nine-month deadlines
- Run the 43 measures on schedule, with owners, evidence, reminders and a weekly overdue chaser
- Keep the approval of the management bodies on file for policies, plans and risk treatment
- Report significant incidents on time: the incident register counts down the 24-hour, 72-hour and one-month deadlines for CSIRT Italia
- Give your auditor a time-limited, read-only login, or hand over a PDF audit trail

Sources: ACN, baseline arrangements and specifications, ACN Determination 379907/2025, Annex 1, Annex 2, ACN reading guide, ACN, incident handling process, Legislative Decree 138/2024.