Glossary

NIS2

Glossary

art. 30 D.Lgs. 138/2024; Det. ACN 155238/2026

Updated 23 September 2026

by Victor Mita

Categorisation of activities and services (categorizzazione)

The categorisation of activities and services is the list that every essential and important entity sends each year to ACN (Italy's National Cybersecurity Agency), from 1 May to 30 June, assigning each activity or service a category of relevance.

How it works

Article 30 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, sets the obligation; the model is defined by ACN Determination 155238/2026 (20 April 2026). Activities and services are organised into ten macro-areas and each one is assigned one of four categories: minimal, low, medium or high impact, according to what would happen if it were compromised.

The obligation applies from 1 January 2026 (Article 42(2)): the first window was May to June 2026.

In practice

  • It is filled in on the ACN platform, in web forms: there is no official file to upload.
  • Silence means consent: ACN has 90 days to respond, which can be extended once by another 60; if it does not respond, compliance is deemed validated (Article 30(3) and (4)).
  • Why it matters: ACN uses the categories of relevance to scale the obligations (Article 31). A poorly done categorisation today can turn into the wrong obligations tomorrow.
  • Fine: failing to submit or update the list is among the breaches of Article 38(10).

Not to be confused with the list of relevant suppliers, which goes into the annual update from 15 April to 31 May.

Legal reference

Articles 30, 31, 38(10)(c) and 42(2) of D.Lgs. 138/2024; ACN Determination 155238/2026.

Related terms

Further reading

Sources

The sources are official texts, published in Italian.