Resources

NIS2

Guide

D.Lgs. 138/2024, artt. 35-38

Updated 23 September 2026

by Alessandro Truffo

ACN inspections under NIS2: how they work and what evidence to keep ready

What the ACN can ask you for, what differs between essential and important entities, and what proof to keep, area by area, according to the basic measures.

In brief

The ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) checks compliance with NIS2 in four ways: monitoring, checks and inspections, enforcement measures and sanctions. Essential entities can be inspected even without a specific reason, important entities only if the ACN has information that points to a violation. In both cases, what counts is what you can demonstrate: approved policies and plans, up-to-date inventories, registers and proof that the technical measures work.

How the ACN supervises

The ACN's FAQ MVE.1 divides supervisory activity into four areas, which correspond to the articles of Chapter V of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition:

  • Monitoring, analysis and support (Article 35). It is continuous and starts from the information you have already submitted, beginning with registration. The ACN can ask you for reporting, including periodic reporting, with self-assessments and implementation plans, or for security audits and scans.
  • Checks and inspections (Article 36). Checks of the documentation submitted, on-site and remote inspections, including random checks, and requests for access to data and documents, with the stated purpose.
  • Enforcement measures (Article 37). Orders and formal warnings (diffide) setting out how and by when to remedy. Before adopting them, the ACN notifies you of its preliminary findings and gives you at least fifteen days to submit observations, except in urgent cases.
  • Sanctions (Article 38). For violations concerning measures and notifications, up to €10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher, and up to €7 million or 1.4% for important entities.

The ACN states that it takes a gradual, risk-based approach. In deciding, it takes into account, among other things, the seriousness and duration of the violation, the measures you have adopted to limit the damage and the degree of cooperation (FAQ MVE.1, which refers to Article 34(6)). Failure to cooperate with the ACN is itself punishable (Article 38(10)).

Essential and important entities: what differs

The main difference is when a check can take place (FAQ MVE.3):

  • Essential entities: inspections, on-site and remote, including random checks, can also be ordered preventively, without any suspicion.
  • Important entities: checks and inspections are triggered only if the ACN obtains or receives evidence, indications or information suggesting a possible violation. The law speaks of elements that the ACN “obtains or receives”: they can therefore also come from outside.

In addition, the ACN cannot impose periodic security audits on important entities, while it can do so for essential ones (Article 37(3)). For both, it can ask for the data that demonstrate the implementation of security policies, such as audit results and the related proof (Article 37(2)).

From when the evidence counts

The basic security measures must be adopted within eighteen months of the notice of inclusion in the list for entities that joined in 2025, and by 31 July 2027 for those that joined in 2026 (FAQ MSB.3). We explain how to calculate your date in the guide to the October 2026 deadline; for the overall picture of entities and obligations, see the NIS2 guide.

Incident notification, on the other hand, is already mandatory for the 2025 cohort, from nine months after the notice. Proof of how you handle and notify incidents is therefore needed right now.

How to organise the evidence

FAQ MSB.11 lists the documents the ACN expects: lists, inventories, plans, policies, procedures and registers. You can organise them however you like, even in a single document, on paper or in digital form, as long as they reflect the current situation and are easy to consult.

A few practical rules that make a check simpler:

  • An index per measure. For each code (for example GV.PO-01), state which documents and which proof cover it, and where they are.
  • Version, date and approval on every document. For those that require approval by the management bodies, keep the minutes or the resolution. The list is in Appendix C of the ACN Reading Guide (Guida alla lettura).
  • Proof of execution, not just of intent. Next to the backup procedure, the backup results; next to the training plan, the register of who attended it.
  • Exceptions in writing. If you do not apply a requirement for “justified and documented regulatory or technical reasons”, the justification and the compensating measures must be in the risk treatment plan (measure ID.RA-06).

The evidence, area by area

The measures in Annex 1 to ACN Determination 379907/2025, for important entities, follow the six functions of the National Framework (Framework nazionale). Below you will find, for each one, the proof that the requirements explicitly ask for. Annex 2, for essential entities, adds further measures: among the additional evidence are the inventory of network flows, reference configurations and a plan to assess the effectiveness of the measures (FAQ MSB.11).

  • Govern (GV): security organisation approved by the management bodies and a list of personnel with their roles, including the point of contact and the CSIRT liaison (GV.RR-02); procedures for choosing who accesses the relevant systems and the system administrators (GV.RR-04); approved policies for the sixteen areas (GV.PO-01), and the results of the review carried out at least annually (GV.PO-02); risk management plan (GV.RM-03).
  • Suppliers (GV.SC): supplier inventory with contact person and type of supply (GV.SC-04); risk assessment of supplies (GV.SC-07); security requirements in contracts (GV.SC-05); results of periodic checks on supplies (GV.SC-07).
  • Identify (ID): list of relevant systems (GV.OC-04); inventories of hardware, software and services, and of supplier services, including cloud (ID.AM-01, ID.AM-02, ID.AM-04); risk assessment, approved and repeated at least every two years (ID.RA-05); treatment plan with the accepted residual risks (ID.RA-06); vulnerability management plan and proof that you follow the channels of CSIRT Italia (Italy's national CSIRT) (ID.RA-08); compliance plan and periodic reports to the management bodies (ID.IM-01); approved business continuity, disaster recovery and crisis management plans (ID.IM-04).
  • Protect (PR): register of user accounts and periodic reviews of authorisations (PR.AA-01); multi-factor authentication on relevant systems (PR.AA-03); separate administrative accounts (PR.AA-05); protection of physical access (PR.AA-06); approved training plan and register of participants (PR.AT-01); encryption of laptops and removable media and of data in transit (PR.DS-01, PR.DS-02); periodic backups with offline copies (PR.DS-11); security updates (PR.PS-02); logs of remote and administrative access, with retention periods (PR.PS-04); secure development practices, if you develop software (PR.PS-06); list of remotely accessible systems and firewalls (PR.IR-01).
  • Detect (DE): tools to detect significant incidents and documented expected service levels (DE.CM-01); anti-malware protection on endpoints (DE.CM-09).
  • Respond and recover (RS, RC): incident management plan and plan for notification to CSIRT Italia, approved and reviewed at least every two years (RS.MA-01); procedures for informing the recipients of your services (RS.CO-02); recovery procedures (RC.RP-01).

The expected service levels in measure DE.CM-01 deserve attention: they are used to recognise one of the incidents that must be notified, the one concerning service availability. We cover this in the guide to incident notification.

If a request arrives

  1. Read the purpose. Requests for access to data and documents must state it and specify what is needed (Article 36(1), letter (c)): answer that, completely.
  2. Involve the right people straight away. The point of contact, the security manager and, for important decisions, the management bodies, which by law oversee the obligations (Article 23).
  3. Meet the deadlines. The ACN sets out how and by when to comply and to report back.
  4. Do not reconstruct at the last minute. A document dated yesterday with yesterday's approval says a lot about how prepared you are. If something is missing, it is better to say so and show the compliance plan with its dates.
  5. Keep track of what you handed over, to whom and when.

How Epic Assess helps you

In Epic Assess each requirement of the ACN measures has its own linked policies and evidence, with renewal deadlines and an approval history. The Inspection Ready Pack gathers into a single package documents in DOCX, evidence with its metadata, incident notifications, the categorised list of activities and services, and ACN registration data. It is not a certificate of compliance and has no recognition from the ACN: it is an orderly way to show what you have done.

Sources

The sources are official texts, published in Italian.