Home › Guides › NIS2 › Italy: relevant suppliers

Italy's NIS2 relevant suppliers and CPV codes: how to complete the list for the ACN

Since 2026, every NIS entity in Italy must report its relevant suppliers to the National Cybersecurity Agency (ACN), with tax code, country and the CPV codes of the supply. Here is who goes on the list, which data you need, how to find the right CPV code and the most common mistakes.

Updated 1 October 2026

  • Rule: Article 18 of ACN Determination No 127437 of 13 April 2026 (applicable from 15 April 2026), which replaces Determination 379887 of 19 December 2025.
  • Who: all NIS entities in Italy, essential and important, in the annual information update.
  • When: every year from 15 April to 31 May; the next window is in 2027.
  • What: company name, tax code, country of registered office, CPV codes of the supplies received, relevance criterion.

Why the ACN asks for a supplier list

Article 3(9)(f) of Legislative Decree 138/2024 (D.Lgs. 138/2024, the Italian NIS2 decree) allows the decree to be applied, regardless of size, to an entity considered critical "as a systemic element of the supply chain, including the digital supply chain" of one or more essential or important entities. To identify these entities, the Agency needs to know who NIS operators depend on: hence the obligation to list relevant NIS suppliers, introduced with the determination on the digital platform.

The list is submitted in the NIS Service/Annual information update on the ACN portal, together with the other data under Article 16 (management bodies, IP address space and domain names, CSIRT contact, information-sharing arrangements). The point of contact confirms the information with a declaration made under Presidential Decree (D.P.R.) 445/2000.

Who counts as a relevant supplier

Article 1(1)(ll) of Determination 127437/2026 defines a relevant NIS supplier as an entity that provides services or products to a NIS entity and meets at least one of two criteria:

1. ICT supplyThe supply relates to the activities or services in Annex I, points 8 and 9, of the NIS decree: digital infrastructure (IXPs, DNS, TLD registries, cloud, data centres, CDNs, trust services, electronic communications networks and services) and B2B ICT service management (managed services and managed security services).
2. Non-fungible supplyA disruption or compromise of the supply would have a significant impact on the entity's ability to deliver its NIS activities and services, including because no alternative suppliers exist.

The criteria can apply separately or together, so a supply can be ICT, non-fungible or non-fungible ICT (ACN FAQ FRN.2). According to the ACN, this covers all of the entity's digital dependencies and also non-digital ones that cannot be replaced without a significant impact: the example the Agency gives is electricity.

The data to report for each supplier

Field (Art. 18)What to enter
a) Company nameThe registered name of the supplier that delivers the supply (see below for resellers and subcontractors).
b) Tax codeThe supplier's Italian tax code (codice fiscale) (for foreign suppliers see the note below the table).
c) Country of registered officeThe country where the supplier has its registered office, including outside the EU.
d) CPV codesThe Common Procurement Vocabulary codes (Reg. (EC) 2195/2002, amended by Reg. (EC) 213/2008) for the supplies you use. One row per code.
e) Relevance criterionICT, non-fungible, or both.

For foreign suppliers without an Italian tax code, check in the portal how the field should be completed: the ACN FAQs do not clarify this.

How to find the right CPV code

CPV is a tree classification: eight digits plus a check digit after the hyphen (for example 72400000-4). The first two digits indicate the division, the third the group, the fourth the class and the fifth the category; further digits refine it further. A few practical rules:

  • Start from the subject of the contract, not from the supplier's sector: a single company may give you connectivity (72411000-4) and systems support (72250000-2), and that takes two rows.
  • Choose the most specific level that really describes the supply, without forcing it: if no detailed code fits, the higher-level code is acceptable.
  • Always copy the check digit: it is part of the official code.
  • For recent services, use the ACN mappings. The 2008 vocabulary doesn't contain words like "cloud" or "CDN": FAQ FRN.4 indicates which codes to use (table below).
  • Don't confuse CPV and ATECO. Table D.1 of Annex II.2-bis of the Italian Public Contracts Code (D.Lgs. 36/2023) offers a high-level CPV-NACE/ATECO mapping, useful only for orientation: the final choice must be made on the full vocabulary.
Examples given by the ACN (FAQ FRN.4)
SupplyReference CPV codes
Non-redundant data and voice connectivity (non-fungible ICT)72400000-4 Internet services; 72411000-4 Internet service providers ISP; 72318000-7 Data transmission services
Electricity (non-fungible)65300000-6 Electricity distribution and related services; 65310000-9 Electricity distribution
Cloud computing72300000-8 Data services; 72400000-4 Internet services; 72500000-0 Computer-related services; 72510000-3 Computer-related management services
Data centre72000000-5 IT services: consulting, software development, Internet and support
DNS72417000-6 Internet domain names
CDN72400000-4 Internet services
Internet exchange points64221000-1 Interconnection services
Trust services79132100-9 Electronic signature certification services; 48000000-8 Software package and information systems
Electronic communications networks and services64200000-8 Telecommunications services; 64210000-1 Telephone and data transmission services
Managed services and managed security services72500000-0; 72510000-3; 72250000-2 System and support services; 72600000-6 Computer support and consultancy services; 72800000-8 Computer audit and testing services

The most common mistakes

  1. Listing the reseller instead of whoever delivers the service. If the supply is contracted with A but delivered by B, report B; A is relevant only if it contributes to delivery and does not merely facilitate the purchase (FAQ FRN.8). ACN example: a SaaS from B with application management by A, both are relevant; SaaS licences from B bought through A with no other interaction, A does not appear relevant.
  2. Forgetting obvious subcontractors. If A uses B as a subcontractor, you generally report A, but also B when its contribution to the supply is evident (FAQ FRN.7).
  3. Leaving out foreign or intra-group suppliers. Non-EU suppliers, suppliers of foreign branches and suppliers from the same group must be listed too (FAQ FRN.5, FRN.6, FRN.9).
  4. Putting several CPV codes in one cell. One row per code, repeating the supplier (FAQ FRN.10).
  5. Stopping at IT. The non-fungibility criterion also covers energy, connectivity without redundancy and other physical supplies with no alternative.
  6. Using only the division. A code like 72000000-5 is correct for data centres according to the ACN, but for an email service there is 72412000-1: the more precise the code, the more useful the information.
  7. Not updating the list. After the annual update, changes to the information submitted are reported through the continuous update (Art. 19), which the determination requires to be timely and in any case within 14 days of the change (Art. 1(hh)).

The ACN list does not replace the supplier inventory required by the basic security measures: measure GV.SC-04 requires an up-to-date inventory of suppliers of supplies with potential security impact, with a contact person and type of supply; GV.SC-05 and GV.SC-07 require security requirements in contracts, a supply risk assessment and periodic compliance checks. It makes sense to keep a single register from which you derive both the ACN list and the evidence for the basic measures. Details in our checklist of the ACN basic measures.

One supplier register, two obligations In the Dazr Compliance supplier register every supplier has a criticality, services, contracts, review dates and a security assessment; you can note CPV codes and the relevance criterion and export the basis for the annual ACN update.

Sources

Content checked as of 1 October 2026.

Frequently asked questions

By when must relevant NIS suppliers be reported in Italy?

In the annual information update, which runs from 15 April to 31 May each year through the NIS Service/Annual information update on the ACN portal (Art. 16 of ACN Determination 127437/2026). Later changes are reported through the continuous update.

Do foreign or group suppliers have to be listed too?

Yes. According to the ACN FAQs (FRN.5, FRN.6 and FRN.9), foreign suppliers, including non-EU ones, suppliers of foreign branches of Italian NIS entities and suppliers that belong to the same group of companies must also be listed if they meet the relevance criteria.

How do you enter several CPV codes for the same supplier?

According to ACN FAQ FRN.10, you complete one row per CPV code, repeating the supplier's details.

Does a supplier listed as relevant automatically become a NIS entity?

No. The list helps the ACN identify, in agreement with the sector authorities, the systemic elements of the supply chain that may be identified as essential or important entities under Article 3(9)(f) of Legislative Decree 138/2024. Identification requires a formal ACN decision.

Keep your supplier register ready

The Dazr Compliance supplier register holds criticality, services, review dates and security assessments, so the ACN list and the evidence for GV.SC come from the same place. Hosted in the EU, free for one user.

This page is for information only and does not constitute legal advice.