Resources

NIS2

Guide

D.Lgs. 138/2024, art. 25

Updated 23 September 2026

by Alessandro Monego

NIS2 incident notification in Italy: 24 hours, 72 hours and one month

Which incidents must be notified to CSIRT Italia, when the clock starts, what to write at each stage, and a practical workflow to prepare before you need it.

In brief

If a significant incident hits your company, you must send CSIRT Italia (Italy's national CSIRT) a pre-notification (pre-notifica, the early warning) within 24 hours of having evidence of it, a notification within 72 hours and a final report within one month of the notification (Article 25 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition). Which incidents are significant is set by ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) through four precise cases, IS-1, IS-2, IS-3 and IS-4, the last one for essential entities only. Notifications are sent through the segnalazioni.acn.gov.it portal.

When the obligation applies

The obligation depends on the year you were added to the list of NIS entities (FAQ ISB.G.3):

  • Added in 2025: nine months from receiving the notice of inclusion in the list. For those who received it in April 2025, ACN indicates January 2026: the obligation already applies.
  • Added for the first time in 2026: the obligation applies from 1 January 2027.

The security measures have a longer deadline instead: you will find it in the guide to the October 2026 deadline.

Which incidents are significant

The decree gives a general definition: an incident is significant if it has caused or can cause severe operational disruption of services or financial losses, or if it has affected or can affect other people by causing considerable losses (Article 25(4)). To make it workable, ACN Determination 379907/2025 turns it into four cases (Annex 3 for important entities, Annex 4 for essential entities). You have an incident to notify when you have evidence of:

  • IS-1: a loss of confidentiality, towards the outside, of digital data that you own or control, even partial.
  • IS-2: a loss of integrity, with an impact towards the outside, of the same data.
  • IS-3: a breach of the expected service levels of your services or activities, as you defined them under measure DE.CM-01.
  • IS-4, for essential entities only: unauthorised access to that data, or access that abuses the privileges granted.

Two clarifications from ACN remove many doubts. The cause does not matter: a flood, a failure or a human error are incidents to notify just as much as an attack, if they produce one of these effects (FAQ ISB.G.2). And IS-3 only works if the expected service levels are written down beforehand: if you have not defined what “degraded service” means, you cannot recognise the moment when you must notify.

Non-significant incidents, near misses and threats can be notified on a voluntary basis (Article 26). Notification, mandatory or voluntary, does not expose you to greater liability than the incident itself entails (Article 25(3)).

When the clock starts

The 24 and 72 hours do not run from the moment the incident happens, but from when you have evidence of it: when, after an analysis that may be only preliminary, you have objective elements showing that one of the cases has occurred (FAQ ISB.G.4). The evidence usually comes from:

  • external reports, for example from CSIRT Italia;
  • internal reports, such as a user calling the help desk about a malfunction;
  • events detected by monitoring systems.

It pays to record straight away the date and time of the evidence and who detected it: it is the reference point from which every deadline is counted.

The deadlines, stage by stage

Article 25(5) sets the timing and the content:

  1. Pre-notification, within 24 hours. Without undue delay. It states, where possible, whether the incident may result from unlawful or malicious acts and whether it may have a cross-border impact. You send it with the information you have: the ACN guidelines on incident management acknowledge that at the start much of the data is not yet available.
  2. Notification, within 72 hours. It updates the pre-notification and adds an initial assessment of severity and impact and, if you have them, the indicators of compromise.
  3. Interim report, if requested. Only at the request of CSIRT Italia, with the relevant updates.
  4. Final report, within one month of the notification. A detailed description with severity and impact, the type of threat or root cause, the mitigation measures applied and ongoing, and the cross-border impact if known.
  5. If the incident is still ongoing when the final report is due: a monthly progress report, and the final report within one month of the end of the incident handling.

For its part, CSIRT Italia responds without undue delay and, where possible, within 24 hours of the pre-notification, with initial feedback and, if you ask for it, guidance on mitigation (Article 25(7)).

Who notifies, and where

Notifications are sent by the CSIRT liaison, the person the NIS entity designates to deal with CSIRT Italia, or by a deputy. The channel is the segnalazioni.acn.gov.it portal, and ACN has published a notification guide.

If the incident involves a supplier, ACN separates the cases in FAQs ISB.F.1, F.2 and F.3. If the incident occurs on your systems, even if they are managed by a supplier, the notification is your responsibility. If it occurs on the systems of a supplier that is itself a NIS entity, the supplier notifies, and so do you if it is significant for you. If the supplier that is a NIS entity provides you with cloud services and the incident affects your systems, as a rule you both notify, except for IaaS and hosting of your infrastructure, where only you notify.

If the incident involves a personal data breach there is a separate obligation: notification to the Garante (Italy's data protection authority), without undue delay and, where possible, within 72 hours, unless a risk to individuals is unlikely (Garante per la protezione dei dati personali (Italian Data Protection Authority)). One notification does not replace the other.

A practical workflow to prepare now

Measure RS.MA-01 requires a plan for incident management and notification to CSIRT Italia, approved by the management bodies (Annex 1). In practice it must let you do the following without improvising:

  1. Detect. Whoever receives a report knows whom to pass it to, at any hour.
  2. Record the evidence. Date, time, source, first description.
  3. Classify. A person with the mandate decides whether the event falls under IS-1, IS-2, IS-3 or IS-4. If the answer is no, they write it down and explain why.
  4. Pre-notify within 24 hours with what you know, without waiting to know everything.
  5. Inform senior management. The management bodies must be informed of incidents and notifications (Article 23(3)); the plan states who takes the decisions that the CSIRT liaison cannot take alone.
  6. Investigate and notify within 72 hours, with an assessment of severity and impact.
  7. Communicate externally when needed: to the recipients of your services, if the incident may affect them, after consulting CSIRT Italia (measure RS.CO-02); to the Garante, if personal data is involved.
  8. Close with the final report within one month of the notification and update the plan with the lessons learned.

Keep ready the contacts, the login credentials for the portal, a pre-notification template and an incident register. They are also the evidence ACN may ask you for: the guide to ACN inspections and evidence covers them. For the overall picture of the obligations, there is the NIS2 guide.

How Epic Assess helps

In Epic Assess you log the incident, state whether it must be notified and which case it falls under, from IS-1 to IS-4, and the platform calculates the pre-notification and notification deadlines from the moment of evidence. It prepares pre-filled drafts of the pre-notification and the notification: you review them, complete them and send them yourself from the ACN portal, because the platform does not transmit anything to CSIRT Italia. The notification history stays linked to the evidence and goes into the inspection pack.

Sources

The sources are official texts, published in Italian.