NIS2
Guide
Det. ACN 127437/2026
Updated 23 September 2026
by Alessandro Monego
NIS2 relevant suppliers: how to compile the list for ACN
Who must submit it, which suppliers to include, the five data points required and how to choose CPV codes, under ACN Determination 127437/2026.

In brief
If you have received from ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) the notice of inclusion in the list of NIS entities, every year you must also submit the list of your relevant suppliers. This is required by Article 18 of ACN Determination 127437 of 13 April 2026. The list is part of the annual update of information, which is done on the ACN digital platform from 15 April to 31 May. For each supplier, five data points are needed: company name, tax code (codice fiscale), country of the registered office, CPV codes of the supplies and relevance criterion.
The first window closed on 31 May 2026, and the next one opens on 15 April 2027. It pays to prepare now: it is also a chance to put in order the supplier inventory that the security measures require anyway.
Where the obligation comes from
Article 7 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition requires NIS entities to update their information on the ACN platform every year, between 15 April and 31 May. Paragraph 6 gives ACN the task of defining the procedures and the additional information. It did so with Determination 127437/2026, which replaced the previous determination 379887/2025 and introduced Article 18 on relevant suppliers.
The purpose is explained in ACN FAQ FRN.1. Regardless of size, the decree can apply to anyone who is a “systemic element” of the supply chain of other NIS entities (Article 3(9)(f)). Through the lists, ACN collects the data to identify these suppliers, in agreement with the sector authorities.
Who must submit the list
All NIS entities, essential and important, that are required to carry out the annual update (FAQ AGA.4). The “NIS/Aggiornamento annuale” (annual update) service on the ACN Services Portal is visible only to users associated with organisations that have received the notice of inclusion in the list (FAQ AGA.5).
If instead you are the supplier of a NIS entity, you do not become a NIS entity for that reason. According to FAQ AMB.GE.6, there is no “direct propagation” of the decree along the supply chain. Your client will, however, have to ask you for contractual security obligations. We cover this in the guide “Your client asks you for NIS2”.
Which suppliers are “relevant”
Under the definition in Article 1(1)(ll) of the determination, a supplier is relevant if it provides you with products or services and meets at least one of two criteria (FAQ FRN.2):
- ICT supply: the supply falls within the activities in Annex I, points 8 and 9, of the decree, that is digital infrastructure and business-to-business ICT service management (cloud, data centres, managed services and managed security services, DNS and similar).
- Non-fungible supply: if the supply is interrupted or compromised, your ability to carry out the activities for which you are a NIS entity is significantly affected, partly because you have no alternatives.
The criteria can be used alone or together, so a supply can be ICT, non-fungible or non-fungible ICT. FAQ FRN.4 gives some examples:
- Non-redundant connectivity (ICT and non-fungible): Internet services 72400000-4, Internet service providers 72411000-4, data transmission 72318000-7.
- Electricity (non-fungible): electricity distribution 65310000-9.
- Cloud computing (ICT): Internet services 72400000-4, data processing 72300000-8, IT services 72500000-0.
- Managed services and managed security services (ICT): IT services 72500000-0, system maintenance and support 72250000-2, IT consultancy and support 72600000-6.
Electricity shows that the list is not only about IT. What counts is every dependency you cannot replace without a significant impact.
Grey areas
The ACN FAQs clarify some common situations:
- Foreign suppliers, including those outside the EU: they must be listed (FRN.5), including those serving your sites abroad (FRN.6).
- Subcontracting: if you contract with A and A uses B, as a rule you list A. B goes on the list only if its contribution to the supply is evident (FRN.7).
- Supply delivered by someone else: if you contract with A but the service is delivered by B, as a rule you list B and also assess A (FRN.8). Example: a SaaS product from B managed by A makes both relevant. If A only sells you the licences and then plays no further part, A does not appear to be relevant.
- Companies in your group: they must be assessed like any other supplier (FRN.9).
The five data points and CPV codes
Article 18 of the determination requires, for each supplier (FAQ FRN.3):
- the company name;
- the tax code;
- the country where it has its registered office;
- the CPV codes of the supplies you use;
- the relevance criterion applied.
CPV codes are the Common Procurement Vocabulary for public contracts under Regulation (EC) 2195/2002, as amended by Regulation (EC) 213/2008. Choose the most precise code that describes the supply. ACN also points to a correspondence table between CPV codes and ATECO codes (Italy's classification of economic activities) in the Public Contracts Code (Codice dei contratti pubblici, Annex II.2 bis, Table D.1), but only as guidance: the final choice of codes is yours.
A practical detail: if a supplier has more than one CPV code, in the file you must enter one row for each code, repeating the same supplier (FRN.10). A supplier with three CPV codes therefore takes up three rows.
How to prepare for the 2027 window
- Start from the supplier inventory. The basic measures already require an inventory of suppliers and the services they provide (see the ACN basic measures). Do not start from scratch.
- Filter with the two criteria. For each supplier, ask yourself whether the supply is ICT and whether you could replace it within a timeframe compatible with your services. Write the answer down: you will need it to justify your choices.
- Collect the company details. The tax code of foreign suppliers is often missing from your records: ask for it in good time.
- Assign the CPV codes and check them again on separate rows.
- Appoint an owner and keep the list up to date during the year. Changes to information already submitted must be notified within 14 days (FAQ AGA.1).
The annual update also covers other data, such as the deputy point of contact, the management bodies, IP addresses and domains. You will find them in the guide to registration on the ACN portal.
What you risk if you do not do it
The list is part of the Article 7 information. Article 38(10) penalises failure to submit or update this information, as well as failure to follow the procedures set by ACN. For these infringements, paragraph 11 provides for fines of up to 0.1% of total worldwide annual turnover for essential entities and up to 0.07% for important entities, without prejudice to the minimums in paragraph 9. For the full picture, read NIS2 fines.
Where Epic Assess can help
In Epic Assess you keep a supplier register with CPV codes and relevance criterion, check the VAT number on the European VIES system and send a security questionnaire to critical suppliers. From there you export a file matching the ACN template: the five Article 18 fields, in the order of the determination, with one row per CPV code. It is not an official ACN template, and you upload it to the portal yourself.
Sources
The sources are official texts, published in Italian.
- ACN, FAQ “Aggiornamento delle informazioni” (information update) (AGA, FRN)
- ACN, “Aggiornamento delle informazioni” (information update) page
- ACN, news item on determinations 127434/2026 and 127437/2026 (13 April 2026)
- ACN, FAQ “Ambito di applicazione” (scope) (AMB.GE.6)
- D.Lgs. 138/2024, Article 7
- D.Lgs. 138/2024, Article 38
- Regulation (EC) 213/2008 amending Regulation (EC) 2195/2002 (CPV)