Home › Guides › NIS2 › Italy's ACN basic measures

Italy's ACN basic measures: the complete NIS2 requirements checklist

The basic specifications of Italy's National Cybersecurity Agency (ACN) translate the NIS2 obligations into verifiable requirements: 37 measures and 87 requirements for important entities, 43 measures and 116 requirements for essential ones. Here you'll find what they ask, by when, and a checklist to fill in and export.

Updated 1 October 2026

At a glance

  • Source: ACN Determination No 379907 of 19 December 2025, Annexes 1 and 2, applicable from 15 January 2026. It replaces Determination 164179 of 14 April 2025.
  • How many: important entities 37 measures / 87 requirements; essential entities 43 measures / 116 requirements.
  • By when: 18 months from receipt of the notice of inclusion in the NIS list. For those who received it in April 2025 that means October 2026; for those added to the list in 2026, 31 July 2027.
  • Who is accountable: the management and executive bodies approve policies, plans and the risk assessment, and are accountable for them.

On this page

  1. What the basic security measures are
  2. How many measures per function
  3. Deadlines: why the date differs for each entity
  4. What differs between important and essential entities
  5. Decisions for the management bodies
  6. Recurring deadlines not to miss
  7. Mapping to ISO/IEC 27001:2022
  8. Interactive checklist of the basic measures
  9. How to use the checklist in practice
  10. Sources

What the basic security measures are

Italy's Legislative Decree 138/2024 (D.Lgs. 138/2024, "the NIS decree"), which transposes Directive (EU) 2022/2555 (NIS2), requires essential and important entities to take cybersecurity risk management measures (Articles 23 and 24) and to notify significant incidents (Article 25). The decree leaves it to the ACN (Agenzia per la cybersicurezza nazionale) to set proportionate obligations, deadlines and procedures through its own determinations (Article 31 and Article 40(5)). For the initial phase, the ACN adopted the so-called basic specifications (Article 42(1)(c)).

The determination currently in force is No 379907/2025, signed on 18 December and registered on 19 December 2025, applicable from 15 January 2026. It has four technical annexes:

  • Annex 1: basic security measures for important entities;
  • Annex 2: basic security measures for essential entities;
  • Annexes 3 and 4: basic significant incidents to be notified to CSIRT Italia (IS-1, IS-2, IS-3 for everyone; IS-4 for essential entities only).

The measures follow the Italian National Framework for Cybersecurity and Data Protection, 2025 edition, which mirrors the structure of the NIST Cybersecurity Framework 2.0: functions, categories, subcategories (for example GV.RR-02) and, for each measure, one or more numbered requirements. The code and the description of the measure come from the framework; the requirements say what is concretely needed for the measure to count as implemented.

How many measures per function

The count below is taken from the official files published by the ACN (xlsx version of Annexes 1 and 2) and matches the stated totals.

Measures and requirements per function of the National Framework
FunctionImportant: measuresImportant: requirementsEssential: measuresEssential: requirements
GV · Govern11211125
ID · Identify9211028
PR · Protect12341647
DE · Detect2529
RS · Respond2525
RC · Recover1122
Total378743116

Deadlines: why the date differs for each entity

Article 3 of Determination 379907/2025 does not set a calendar date: the deadline for adopting the basic measures is eighteen months from receipt of the notice of inclusion in the list of NIS entities; the deadline for notifying basic significant incidents is nine months from the same notice.

The ACN started sending the first notices of inclusion in April 2025, via the NIS platform and the entity's certified digital address. That is why the Agency refers to "October 2026" for the measures and "January 2026" for notifications. But the exact day depends on when your notice was received: check your PEC (certified email) and the NIS area of the ACN portal.

Added to the list in 2025Basic measures: 18 months from the notice (for those who received it in April 2025, October 2026). Incident notification: 9 months (January 2026). Deadlines confirmed for those who remain on the 2026 list.
Added to the list in 2026Basic measures by 31 July 2027; obligation to notify basic significant incidents from 1 January 2027 (ACN Determination 127434 of 13 April 2026, applicable from 30 April 2026).

In the checklist below you can enter the date of your notice: the tool calculates the 18 and 9 months and lets you download the deadline as a calendar file (.ics).

What differs between important and essential entities

Annex 2 contains all of Annex 1 plus six measures and 29 additional requirements. The measures that apply to essential entities only are:

  • ID.AM-03: an up-to-date inventory of network flows between the entity's systems and the outside world;
  • PR.AT-02: dedicated training for specialised roles, including system administrators, with a register;
  • PR.PS-01: documented secure reference configurations (hardening) for the relevant systems;
  • PR.PS-03: procedures for the secure transfer and disposal of media, and a register of hardware maintenance;
  • PR.IR-03: secured emergency communication systems;
  • RC.CO-03: procedures for communicating recovery activities internally after an incident.

Several common measures also have extra requirements for essential entities: periodic vulnerability testing and testing before go-live with documented reports (ID.RA-01), backup restore tests and backup encryption (PR.DS-11), verification of critical software updates in a test environment (PR.PS-02), inbound traffic analysis and monitoring of remote and administrative access (DE.CM-01), a plan for assessing the effectiveness of the measures (ID.IM-01) and a register of policy reviews (GV.PO-02).

Decisions for the management bodies

A distinctive feature of the basic specifications is the number of documents that must be approved by the management and executive bodies, in line with Article 23 of the decree. It pays to plan them into the board calendar:

  • the cybersecurity organisation, with roles and responsibilities (GV.RR-02);
  • the security policies for the 16 listed areas (GV.PO-01);
  • the risk assessment (ID.RA-05) and the treatment plan, including acceptance of residual risks (ID.RA-06);
  • the vulnerability management plan (ID.RA-08) and the remediation plan (ID.IM-01);
  • the business continuity, disaster recovery and cyber crisis management plans (ID.IM-04);
  • the training plan (PR.AT-01) and the incident management plan with notification to CSIRT Italia (RS.MA-01).

Recurring deadlines not to miss

Adopting the measures is not enough: many have a minimum frequency. The main ones:

ActivityMinimum frequencyMeasure
Review of security policiesAt least annually, and after significant incidents or regulatory and organisational changesGV.PO-02
Review of roles and responsibilitiesAt least every two yearsGV.RR-02
Risk assessmentAt planned intervals, at least every two yearsID.RA-05
Review of continuity, DR and crisis plansAt least every two yearsID.IM-04
Review of the incident management planAt least every two years, incorporating lessons learnedRS.MA-01
Review of user accounts and authorisationsPeriodic (frequency set by you)PR.AA-01
Verification of supplier compliancePeriodic and documentedGV.SC-07

Mapping to ISO/IEC 27001:2022

The ACN does not publish an official mapping to ISO/IEC 27001. In the checklist we have indicated, for each measure, the Annex A controls (and management system clauses) that usually produce the same evidence: for example PR.DS-11 (backup) with A.8.13, PR.PS-04 (logs) with A.8.15, GV.SC-04/GV.SC-05 (suppliers) with A.5.19 and A.5.20, ID.RA-05 with clause 6.1.2. It is an indicative mapping: organisations already certified to ISO 27001 have a head start, but still need to check the specific Italian requirements, such as the list of relevant network and information systems, the CSIRT contact in the security organisation or monitoring the channels of CSIRT Italia (ID.RA-08).

Interactive checklist of the basic measures

The measures and requirements are our unofficial English translation of Annexes 1 and 2 of ACN Determination 379907/2025 (official xlsx files). The status you set is saved in this browser only; you can export it to CSV.

Entity type
Deadline

Loading the measures…

The ISO/IEC 27001:2022 references are our own indicative mapping, not an ACN document. The authoritative text is the Italian text published on the ACN website, including table 1 of the policies in the appendix to the annexes.

How to use the checklist in practice

  1. Define the perimeter. Many requirements apply "to at least the relevant network and information systems": first of all you need that list (GV.OC-04), together with the inventories of hardware, software and supplier services (ID.AM).
  2. Assign an owner to every requirement. The cybersecurity organisation (GV.RR-02) must include the point of contact, a deputy and the CSIRT contact.
  3. Collect the evidence. Almost every measure ends with "procedures are adopted and documented": for an inspection, what counts is the approved, dated and versioned document.
  4. Justify exceptions. If a requirement does not apply for regulatory or technical reasons, write it down and link the compensating measures to the risk treatment plan (ID.RA-06).
  5. Export and share. The CSV opens in Excel and can become the basis of the remediation plan you take to the board.
From checklist to recurring controls A checklist tells you where you are today; an ACN inspection asks you to show that reviews, checks and training actually happen at the required frequency. In Dazr Compliance every requirement becomes a recurring control with attached evidence, a due date and reminders, and policies have versions and staff acknowledgement.

Sources

ACN determinations provide for a notice to be published in the Gazzetta Ufficiale; for publication references, the ACN website is authoritative. Content checked as of 1 October 2026.

Frequently asked questions

By when must the ACN basic security measures be adopted?

Within 18 months of receiving the notice of inclusion in the list of NIS entities (Art. 3 of ACN Determination 379907/2025). For entities that received it in April 2025 the deadline falls in October 2026; the exact date depends on the notice received. For entities added to the list in 2026 the deadline is 31 July 2027 (ACN Determination 127434/2026).

How many basic measures are there for important and essential entities?

Annex 1 (important entities) contains 37 measures and 87 requirements; Annex 2 (essential entities) contains 43 measures and 116 requirements. The measures are organised in the six functions of the Italian National Framework: Govern, Identify, Protect, Detect, Respond and Recover.

Is an ISO/IEC 27001 certification enough to meet the basic measures?

No, not automatically. Many requirements overlap with Annex A controls, but the basic measures contain specific obligations (for example approval of plans by the management bodies, monitoring the channels of CSIRT Italia, the list of relevant network and information systems) that have to be checked one by one. The mapping on this page is indicative.

What if a requirement cannot be applied for technical reasons?

Several requirements allow exceptions for justified and documented regulatory or technical reasons. For the requirements listed in table 2 of the appendix to the annexes, measure ID.RA-06 requires compensating measures to be adopted where applicable and recorded in the risk treatment plan approved by the management and executive bodies.

Turn the measures into recurring controls

Dazr Compliance imports the NIS2 set as recurring activities with evidence, due dates and reminders, with a risk register, a supplier register and a read-only view for the auditor. Hosted in the EU. Free for one user; Basic at €29/month, Pro at €99/month.

This page is for information only and does not constitute legal advice.