What the basic security measures are
Italy's Legislative Decree 138/2024 (D.Lgs. 138/2024, "the NIS decree"), which transposes Directive (EU) 2022/2555 (NIS2), requires essential and important entities to take cybersecurity risk management measures (Articles 23 and 24) and to notify significant incidents (Article 25). The decree leaves it to the ACN (Agenzia per la cybersicurezza nazionale) to set proportionate obligations, deadlines and procedures through its own determinations (Article 31 and Article 40(5)). For the initial phase, the ACN adopted the so-called basic specifications (Article 42(1)(c)).
The determination currently in force is No 379907/2025, signed on 18 December and registered on 19 December 2025, applicable from 15 January 2026. It has four technical annexes:
- Annex 1: basic security measures for important entities;
- Annex 2: basic security measures for essential entities;
- Annexes 3 and 4: basic significant incidents to be notified to CSIRT Italia (IS-1, IS-2, IS-3 for everyone; IS-4 for essential entities only).
The measures follow the Italian National Framework for Cybersecurity and Data Protection, 2025 edition, which mirrors the structure of the NIST Cybersecurity Framework 2.0: functions, categories, subcategories (for example GV.RR-02) and, for each measure, one or more numbered requirements. The code and the description of the measure come from the framework; the requirements say what is concretely needed for the measure to count as implemented.
How many measures per function
The count below is taken from the official files published by the ACN (xlsx version of Annexes 1 and 2) and matches the stated totals.
| Function | Important: measures | Important: requirements | Essential: measures | Essential: requirements |
|---|---|---|---|---|
| GV · Govern | 11 | 21 | 11 | 25 |
| ID · Identify | 9 | 21 | 10 | 28 |
| PR · Protect | 12 | 34 | 16 | 47 |
| DE · Detect | 2 | 5 | 2 | 9 |
| RS · Respond | 2 | 5 | 2 | 5 |
| RC · Recover | 1 | 1 | 2 | 2 |
| Total | 37 | 87 | 43 | 116 |
Deadlines: why the date differs for each entity
Article 3 of Determination 379907/2025 does not set a calendar date: the deadline for adopting the basic measures is eighteen months from receipt of the notice of inclusion in the list of NIS entities; the deadline for notifying basic significant incidents is nine months from the same notice.
The ACN started sending the first notices of inclusion in April 2025, via the NIS platform and the entity's certified digital address. That is why the Agency refers to "October 2026" for the measures and "January 2026" for notifications. But the exact day depends on when your notice was received: check your PEC (certified email) and the NIS area of the ACN portal.
In the checklist below you can enter the date of your notice: the tool calculates the 18 and 9 months and lets you download the deadline as a calendar file (.ics).
What differs between important and essential entities
Annex 2 contains all of Annex 1 plus six measures and 29 additional requirements. The measures that apply to essential entities only are:
ID.AM-03: an up-to-date inventory of network flows between the entity's systems and the outside world;PR.AT-02: dedicated training for specialised roles, including system administrators, with a register;PR.PS-01: documented secure reference configurations (hardening) for the relevant systems;PR.PS-03: procedures for the secure transfer and disposal of media, and a register of hardware maintenance;PR.IR-03: secured emergency communication systems;RC.CO-03: procedures for communicating recovery activities internally after an incident.
Several common measures also have extra requirements for essential entities: periodic vulnerability testing and testing before go-live with documented reports (ID.RA-01), backup restore tests and backup encryption (PR.DS-11), verification of critical software updates in a test environment (PR.PS-02), inbound traffic analysis and monitoring of remote and administrative access (DE.CM-01), a plan for assessing the effectiveness of the measures (ID.IM-01) and a register of policy reviews (GV.PO-02).
Decisions for the management bodies
A distinctive feature of the basic specifications is the number of documents that must be approved by the management and executive bodies, in line with Article 23 of the decree. It pays to plan them into the board calendar:
- the cybersecurity organisation, with roles and responsibilities (
GV.RR-02); - the security policies for the 16 listed areas (
GV.PO-01); - the risk assessment (
ID.RA-05) and the treatment plan, including acceptance of residual risks (ID.RA-06); - the vulnerability management plan (
ID.RA-08) and the remediation plan (ID.IM-01); - the business continuity, disaster recovery and cyber crisis management plans (
ID.IM-04); - the training plan (
PR.AT-01) and the incident management plan with notification to CSIRT Italia (RS.MA-01).
Recurring deadlines not to miss
Adopting the measures is not enough: many have a minimum frequency. The main ones:
| Activity | Minimum frequency | Measure |
|---|---|---|
| Review of security policies | At least annually, and after significant incidents or regulatory and organisational changes | GV.PO-02 |
| Review of roles and responsibilities | At least every two years | GV.RR-02 |
| Risk assessment | At planned intervals, at least every two years | ID.RA-05 |
| Review of continuity, DR and crisis plans | At least every two years | ID.IM-04 |
| Review of the incident management plan | At least every two years, incorporating lessons learned | RS.MA-01 |
| Review of user accounts and authorisations | Periodic (frequency set by you) | PR.AA-01 |
| Verification of supplier compliance | Periodic and documented | GV.SC-07 |
Mapping to ISO/IEC 27001:2022
The ACN does not publish an official mapping to ISO/IEC 27001. In the checklist we have indicated, for each measure, the Annex A controls (and management system clauses) that usually produce the same evidence: for example PR.DS-11 (backup) with A.8.13, PR.PS-04 (logs) with A.8.15, GV.SC-04/GV.SC-05 (suppliers) with A.5.19 and A.5.20, ID.RA-05 with clause 6.1.2. It is an indicative mapping: organisations already certified to ISO 27001 have a head start, but still need to check the specific Italian requirements, such as the list of relevant network and information systems, the CSIRT contact in the security organisation or monitoring the channels of CSIRT Italia (ID.RA-08).
Interactive checklist of the basic measures
The measures and requirements are our unofficial English translation of Annexes 1 and 2 of ACN Determination 379907/2025 (official xlsx files). The status you set is saved in this browser only; you can export it to CSV.
Loading the measures…
The ISO/IEC 27001:2022 references are our own indicative mapping, not an ACN document. The authoritative text is the Italian text published on the ACN website, including table 1 of the policies in the appendix to the annexes.
How to use the checklist in practice
- Define the perimeter. Many requirements apply "to at least the relevant network and information systems": first of all you need that list (
GV.OC-04), together with the inventories of hardware, software and supplier services (ID.AM). - Assign an owner to every requirement. The cybersecurity organisation (
GV.RR-02) must include the point of contact, a deputy and the CSIRT contact. - Collect the evidence. Almost every measure ends with "procedures are adopted and documented": for an inspection, what counts is the approved, dated and versioned document.
- Justify exceptions. If a requirement does not apply for regulatory or technical reasons, write it down and link the compensating measures to the risk treatment plan (
ID.RA-06). - Export and share. The CSV opens in Excel and can become the basis of the remediation plan you take to the board.
Sources
- ACN, Modalità e specifiche di base: Determination 379907/2025, Annexes 1-4 (PDF and xlsx), "Guida alla lettura" guidelines (in Italian).
- ACN, text of Determination 379907/2025 (Arts. 2-3 and 9, in Italian).
- ACN, news item of 13 April 2026 on Determinations 127434/2026 and 127437/2026.
- Legislative Decree No 138 of 4 September 2024, Gazzetta Ufficiale General Series No 230 of 1 October 2024 (current text on Normattiva).
ACN determinations provide for a notice to be published in the Gazzetta Ufficiale; for publication references, the ACN website is authoritative. Content checked as of 1 October 2026.