Resources
NIS2 · AI Act
Updated 23 September 2026
NIS2 and AI Act glossary
The words of Legislative Decree 138/2024 (Italy’s NIS2 transposition), of the ACN determinations and of the AI Act, each with its definition, legal reference and sources.

- ACN (Agenzia per la Cybersicurezza Nazionale)
- ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) is the public authority that applies NIS2 in Italy: it registers entities, sets out how to meet the obligations, receives incident notifications and supervises, up to imposing fines.
- Article 24: risk management measures
- Article 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, requires essential and important entities to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems, and sets ten elements that these measures must cover as a minimum.
- Basic security measures (misure di sicurezza di base)
- The basic security measures are the list of technical and organisational measures that ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) requires of NIS2 entities to meet Articles 23 and 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition: 43 measures with 116 requirements for essential entities, 37 measures with 87 requirements for important entities.
- Categorisation of activities and services (categorizzazione)
- The categorisation of activities and services is the list that every essential and important entity sends each year to ACN (Italy's National Cybersecurity Agency), from 1 May to 30 June, assigning each activity or service a category of relevance.
- CSIRT Italia
- CSIRT Italia is Italy's national computer security incident response team: it operates within ACN (Italy's National Cybersecurity Agency) and receives the incident notifications that NIS2 requires of essential and important entities.
- Deployer (AI Act)
- Under the AI Act, a deployer is the person or organisation that uses an artificial intelligence system under its own authority, except where it does so in the course of a personal, non-professional activity: in practice, the company that adopts and uses an AI tool developed by someone else.
- Essential entity (soggetto essenziale)
- An essential entity (soggetto essenziale) is an organisation that falls under Italy's NIS2 law in the most demanding category: it must adopt 43 basic security measures and faces fines of up to €10 million or 2% of worldwide turnover.
- Important entity (soggetto importante)
- An important entity (soggetto importante) is an organisation that falls within the scope of Italy's NIS2 law but is not classified as essential: it has the same kinds of obligations, with 37 basic measures instead of 43 and lower fines.
- Management bodies (organi di amministrazione e direttivi, Article 23)
- The management bodies (organi di amministrazione e direttivi; for an SME, usually the board of directors or the sole director) are, under Article 23 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, the people responsible for the cybersecurity of the NIS2 entity: they approve the measures, oversee their implementation and are liable for infringements.
- NIS2 scope (perimetro NIS2)
- The NIS2 scope (perimetro NIS2) is the set of organisations to which Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, applies: as a rule, medium-sized and large enterprises in the sectors listed in Annexes I and II, plus some categories included regardless of size.
- Point of contact (punto di contatto)
- The point of contact (punto di contatto) is the individual the NIS2 entity designates to handle the implementation of the decree: they access the ACN portal, carry out the annual registration and deal with ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) on behalf of the organisation.
- Pre-notification (pre-notifica)
- The pre-notification (pre-notifica) is the first alert that a NIS2 entity sends to CSIRT Italia (Italy's national CSIRT) when it has evidence of a significant incident: it must be sent without undue delay and in any case within 24 hours.
- Relevant supplier (fornitore rilevante NIS)
- A relevant supplier (fornitore rilevante NIS) is a supplier of services or products to a NIS2 entity that meets at least one of two criteria: the supply is ICT, or its interruption would have a significant impact because it cannot easily be replaced.
- Significant incident (incidente significativo)
- A significant incident is a cyber incident that has caused, or can cause, severe disruption of services or financial losses for the entity, or considerable losses for other people or companies: it is the incident that NIS2 requires you to notify.
- Significant incident notification (notifica di incidente significativo)
- Significant incident notification is the obligation on essential and important entities to report to CSIRT Italia (Italy's national CSIRT) every incident with a significant impact, in several stages with fixed deadlines: 24 hours, 72 hours, one month.