NIS2
Guide
Det. ACN 379907/2025
Updated 23 September 2026
by Alessandro Truffo
ACN basic measures for NIS2: what they are and how to tackle them
The 43 measures for essential entities and the 37 for important entities, explained in plain English, with a method to get started.

In brief
The basic measures are the list of security requirements that ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) asks NIS entities to meet in order to comply with Articles 23 and 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition. They are currently set by ACN Determination 379907 of 19 December 2025: 43 measures with 116 requirements for essential entities and 37 measures with 87 requirements for important entities. Most of the requirements are organisational: policies, plans, inventories and registers, plus some technical requirements such as multi-factor authentication.
Here you will find what the determination contains, how it links to Article 24 and a sensible order of work for an SME.
Which determination applies today
The determination in force is 379907/2025. Its Article 9 states that it “updates and replaces” the previous ACN Determination 164179 of 14 April 2025 and that it applies from 15 January 2026. If you have material built on 164179, do not throw it away: the ACN FAQs (DSB.1) explain that the changes are mostly refinements of wording. Some examples:
- GV.RR-02: the CSIRT liaison and their deputies are now part of the cybersecurity organisation.
- ID.RA-06: it now explicitly refers to a “cybersecurity risk treatment plan”.
- PR.DS-11 point 4 and PR.PS-02 point 1: backup verification and the installation of security updates must be carried out “in accordance with the outcome of the risk assessment”.
- Policies must be made known to the relevant units, taking into account the “need to know” principle.
It is still worth rereading the documents you have already written with the new text alongside.
How the measures are structured
The determination has four annexes. The measures for important entities are in Annex 1, those for essential entities in Annex 2. Annexes 3 and 4, by contrast, describe the significant incidents to be notified.
Each measure has a code such as GV.PO-01 taken from the Italian National Framework for Cybersecurity and Data Protection (Framework nazionale per la Cybersecurity e la Data Protection, 2025 edition), a description and one or more numbered requirements. The code indicates the function (GV Govern, ID Identify, PR Protect, DE Detect, RS Respond, RC Recover), the category and the subcategory.
The ACN Reading Guide (Guida alla lettura) explains the difference between the two versions:
- 27 measures have the same requirements for essential and important entities;
- 10 measures have additional requirements for essential entities;
- 6 measures apply only to essential entities: ID.AM-03, PR.AT-02, PR.PS-01, PR.PS-03, PR.IR-03 and RC.CO-03.
So if you are an important entity, you are working on a subset of the version for essential entities, not on a different document.
How they link to Article 24
Article 24(2) lists ten minimum elements, from letter a) to letter l). Appendix A of the ACN guide links each element to the measures. Some examples:
- a) Risk analysis and information system security: GV.OC-04, GV.RM-03, GV.RR-02, GV.PO-01, GV.PO-02, ID.RA-05, ID.RA-06.
- b) Incident handling and notifications: PR.PS-04, DE.CM-01, DE.CM-09, RS.MA-01, RS.CO-02, RC.RP-01, RC.CO-03.
- c) Business continuity and backup: ID.IM-04, PR.DS-11.
- d) Supply chain: GV.SC-01, GV.SC-02, GV.SC-04, GV.SC-05, GV.SC-07.
- g) Basic cyber hygiene and training: PR.AT-01, PR.AT-02.
- l) Multi-factor authentication and secured communications: PR.AA-03, PR.DS-02, PR.IR-03.
This table is also useful for whoever has to report to the board of directors. The management bodies approve how the measures are implemented and are liable for infringements (Article 23): talking in terms of the letters of Article 24 is simpler than talking in codes.
What you need to produce, in practice
According to the ACN guide and FAQ MSB.11, six types of document are needed to implement the measures and demonstrate it:
- Lists: staff in the security organisation, remotely accessible systems, reference configurations (the last for essential entities only).
- Inventories: physical devices, services, systems and software, suppliers and the services they provide, network flows (for essential entities only).
- Plans: risk assessment and treatment, business continuity and disaster recovery, vulnerability management, training, incident response, compliance plan.
- Policies: at least those listed in table 1 in the appendix to the annex that applies to you. Measure GV.PO-01 lists 16 areas, from risk management to incident response.
- Procedures: where the individual requirement calls for them.
- Registers: policy reviews, staff training, maintenance.
You can organise the content as you prefer, in a single document or in several. It must, however, describe the real situation and be updated when something changes. For the risk assessment (ID.RA-05) ACN does not impose a model: you can use the one you already have (FAQ MSB.9).
The clauses that narrow the scope
Many requirements contain clauses that let you focus your effort where it is needed. The ACN guide identifies four:
- “for at least the relevant network and information systems”: you can limit the requirement to the systems whose compromise would have a significant impact on the activities for which you are a NIS entity. This is why measure GV.OC-04 requires you to keep an up-to-date list of those systems.
- “in accordance with the outcome of the risk assessment”: how and where you apply the requirement depends on your ID.RA-05 assessment.
- “save for justified and documented regulatory or technical reasons”: you can derogate, but you must write down the reason and state the compensating measures in the risk treatment plan.
- “supplies with potential security impacts”: the supplier requirements apply only to supplies that can affect the security of your systems.
These clauses only lighten the work if you have first drawn up the list of relevant systems and carried out the risk assessment. That is why they are the first steps of the method that follows.
An order of work for an SME
- Check your category and deadline. Whether you are essential or important is set by the decree according to sector and size. For those added to the list in 2025, the deadline is 18 months from the notice of inclusion in the list; for those added in 2026 it is 31 July 2027 (ACN Determination 127434/2026). Check the date of ACN's PEC (Italy's certified email): for most 2025 companies the deadline falls in October 2026 (see the guide to the October deadline).
- Build the governance. Appoint the security organisation (GV.RR-02) and have the policies approved by the management bodies (GV.PO-01).
- Draw up the inventories and choose the relevant systems. Without this step you cannot use the clauses described above.
- Assess the risks and write the treatment plan (ID.RA-05, ID.RA-06). Many technical choices depend on this.
- Close off the most common technical requirements: multi-factor authentication, verified backups, updates, endpoint protection.
- Prepare incident response. The 24- and 72-hour windows leave no time for improvising (see the notification guide).
- Keep your evidence in order. In a check, what counts is what you can show (see the guide to evidence for ACN inspections).
If you do not yet know whether NIS2 applies to you, start from the NIS2 guide.
Where Epic Assess can help
Epic Assess contains the catalogue of ACN measures, with the text of the determination requirement by requirement and the link to the letters of Article 24. Each requirement links to policies and evidence, and from there you can prepare a pack to show in the event of an inspection. Draft policies are proposals to review and approve: compliance remains your responsibility and that of your management bodies.
Sources
The sources are official texts, published in Italian.
- ACN Determination 379907/2025 (signed text)
- Annex 1, measures for important entities
- Annex 2, measures for essential entities
- ACN, NIS Guidelines (Linee guida NIS), basic specifications: Reading Guide (Guida alla lettura) (v2.1, April 2026)
- ACN, page “Modalità e specifiche di base” (basic procedures and specifications)
- ACN, FAQ “Misure di sicurezza e notifica di incidenti” (security measures and incident notification)
- ACN, news item on determinations 127434/2026 and 127437/2026 (13 April 2026)
- D.Lgs. 138/2024 on Normattiva