Glossary

NIS2

Glossary

artt. 1 e 10 D.Lgs. 138/2024

Updated 23 September 2026

by Alessandro Monego

ACN (Agenzia per la Cybersicurezza Nazionale)

ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) is the public authority that applies NIS2 in Italy: it registers entities, sets out how to meet the obligations, receives incident notifications and supervises, up to imposing fines.

What it does for NIS2

Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, gives it three roles at once:

  • NIS national competent authority: every year it draws up the list of essential and important entities (by 31 March), adopts the implementing determinations, supervises and imposes fines;
  • NIS single point of contact: it handles relations with the other Member States and with the Union;
  • CSIRT Italia: the incident response team, which operates within it and receives the notifications.

Alongside ACN work the sector authorities (Article 11): for example the Ministry of the Environment and Energy Security for energy, water and waste, the Ministry of Health for healthcare, and the Ministry of Enterprises and Made in Italy (MIMIT) for digital infrastructure and much of manufacturing.

In practice

You deal with ACN mainly through its digital platform (the ACN portal, NIS Services): there the point of contact registers the organisation, updates its data every year and submits the categorisation. The operating rules are not all in the decree: they are in ACN's determinations, such as 379907/2025 on the basic measures and 127437/2026 on the platform and on suppliers.

Not to be confused: a platform or a private consultant cannot "certify" compliance on ACN's behalf. The only assessment with legal value is the Agency's.

Legal reference

Article 1(2)(c), Article 7 and Article 10 of D.Lgs. 138/2024; Decree-Law 82/2021 (which established the Agency).

Related terms

Further reading

Sources

The sources are official texts, published in Italian.