NIS2
Checklist
Det. ACN 379907/2025
Updated 23 September 2026
by Victor Mita
NIS2 deadline of October 2026: what you need to have ready
For companies that joined the NIS list in 2025: how to work out your date, what ACN requires, a practical checklist and what happens next.

In brief
If in 2025 your company received the notice of inclusion in the list of NIS entities kept by ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency), you have 18 months from that date to adopt all the basic security measures: if you received it in April 2025, the deadline falls in October 2026. Adopting the measures means having implemented every requirement of ACN Determination 379907/2025 that applies to you and being able to prove it with up-to-date, approved documents. If you joined the list for the first time in 2026, you have until 31 July 2027.
What your exact date is
31 October 2026 is the date you will read most often, but no official text sets it. Article 3 of ACN Determination 379907/2025 sets a period of eighteen months “from receipt, by the NIS entity, of the notice of inclusion in the list”. ACN began sending those notices from 12 April 2025, which is why its own website speaks of “18 months (October 2026)”.
In practice:
- You received the notice in April 2025: your deadline falls in October 2026, eighteen months after the day you received it. If you received it in mid-April, do not count on 31 October.
- You received it later in 2025: the period is still eighteen months from receipt, as ACN's FAQ MSB.3 confirms. Your date therefore falls after October 2026.
- You joined the list for the first time in 2026: the same FAQ sets the deadline at 31 July 2027.
Check on the NIS platform the day you received the notice, work out the eighteen months and mark the date in your calendar with a few weeks' margin.
Who it applies to and what it requires
The deadline concerns all entities that have received the notice of inclusion in the list (FAQ MSB.1). What changes is the catalogue: important entities follow Annex 1 of the determination, with 37 measures and 87 requirements; essential entities follow Annex 2, with 43 measures and 116 requirements (ACN Reading Guide (Guida alla lettura)).
There is also an obligation that is already in force for the 2025 cohort: the notification of significant incidents, with a period of nine months from the same notice. If you have not organised it yet, start there: you will find the full flow in the guide to incident notification in 24 and 72 hours.
What “adopting” the measures means
For ACN, adopting the measures means implementing all the requirements set for your type of entity (FAQ MSB.6). Requirements are of two kinds: administrative, such as policies, plans and procedures, and technical, such as encryption, updates or multi-factor authentication (FAQ MSB.10). A written policy without the technical measure it describes is not enough, and the reverse is also true.
Three points that are often missed:
- Approval is the job of the management bodies. Article 23 of Legislative Decree 138/2024 (D.Lgs. 138/2024), Italy's NIS2 transposition, says that they approve how the measures are to be implemented and are liable for violations. The ACN Reading Guide (Guida alla lettura) (Appendix C) lists the documents to have approved.
- Documents must describe the situation as it is today and be updated when things change. They can be on paper or digital, as long as the people who need to consult them can find them easily (FAQ MSB.11).
- Exceptions must be justified in writing. Many requirements allow “justified and documented regulatory or technical reasons” for not applying them: in that case you need compensating measures and a description of the residual risk in the risk treatment plan (measure ID.RA-06 of Annex 1).
The checklist
The list follows the documentary evidence indicated by ACN in FAQ MSB.11 and the measures of Annex 1. If you are an essential entity, Annex 2 adds further items, for example the inventory of network flows and the reference configurations.
- Cybersecurity organisation approved by the management bodies, with the list of the people involved, the point of contact, the deputy point of contact and the CSIRT liaison (GV.RR-02).
- Security policies for the sixteen areas listed in measure GV.PO-01, from risk management to incident response, approved by the management bodies and reviewed at least once a year (GV.PO-02).
- Up-to-date inventories: physical devices, services, software systems and applications, suppliers' IT services (cloud included) and suppliers (ID.AM-01, ID.AM-02, ID.AM-04, GV.SC-04).
- Lists: the relevant information and network systems (GV.OC-04) and the systems accessible remotely, with the access methods (PR.IR-01).
- Risk assessment and risk treatment plan, both approved by the management bodies; the assessment must be repeated at least every two years (ID.RA-05, ID.RA-06).
- The plans: risk management, vulnerability management, compliance plan, business continuity, disaster recovery, crisis management, training and incident management.
- The records: outcomes of the policy reviews, employee training, maintenance carried out.
- The technical measures in operation: multi-factor authentication on relevant systems according to the risk assessment (PR.AA-03), backups with offline copies (PR.DS-11), security updates installed (PR.PS-02), logs of remote and administrative access (PR.PS-04), anti-malware protection on endpoints (DE.CM-09), configured firewalls (PR.IR-01).
- Suppliers: supply chain risk assessed and documented (GV.SC-07) and security requirements to be included in contracts (GV.SC-05).
If something is missing, Article 24(4) of D.Lgs. 138/2024 requires you to adopt corrective measures without undue delay. The compliance plan required by measure ID.IM-01 is the document in which you state what is missing, who is dealing with it and by when.
What happens after the deadline
The deadline does not close the work: from then on ACN can also check that the measures are actually in place. Its tools are in Chapter V of the decree:
- Monitoring (Article 35): it can ask you for reporting, including periodic reporting, with self-assessments and implementation plans, or for audits and security scans.
- Checks and inspections (Article 36): on essential entities they can also be preventive and random; on important entities only if ACN has evidence suggesting a violation (FAQ MVE.3).
- Formal warnings (diffide) and fines (Articles 37 and 38): for violations concerning the measures and notification, up to €10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher, and up to €7 million or 1.4% for important entities. If the company does not comply with a formal warning, the people who run it can be declared temporarily unfit to perform management functions.
Contracts change too. According to FAQ MSB.12, security requirements must be included in supply contracts concluded, renewed or extended from the deadline for adopting the measures onwards; existing contracts do not have to be rewritten. And some activities become recurring: the annual review of policies, the risk assessment at least every two years, training.
You will find how to prepare for a check, measure by measure, in the guide to ACN inspections and evidence. For the overall picture of entities, obligations and fines, start from the NIS2 guide.
What changes if you joined in 2026
For entities included in the list for the first time in 2026, the dates are fixed and the same for everyone: basic measures by 31 July 2027 (FAQ MSB.3) and the obligation to notify significant incidents from 1 January 2027 (FAQ ISB.G.3). The catalogue of measures is the same.
Ten months seems a long time, but there are many documents to have approved and management bodies meet on their own schedule. A sensible order: first incident notification, which comes due first; then organisation, inventories and risk assessment, because almost all the other measures depend on them; finally policies, plans and technical measures.
How Epic Assess helps you
Epic Assess turns the ACN measures for your profile into a register of requirements, each with an owner, a deadline and linked evidence. It calculates deadlines from the date of your notice and prepares draft policies for you to complete and have approved, with a history of approvals. It does not certify compliance and does not replace ACN's checks: it helps you know what is missing and prove what you have done.
Sources
The sources are official texts, published in Italian.
- Legislative Decree no. 138 of 4 September 2024 (Normattiva): Articles 23, 24, 35, 36, 37, 38.
- D.Lgs. 138/2024 in the Gazzetta Ufficiale (Official Journal) no. 230 of 1 October 2024
- ACN Determination 379907/2025, signed text
- ACN, “Modalità e specifiche di base” (basic procedures and specifications)
- Annex 1, basic measures for important entities
- Annex 2, basic measures for essential entities
- ACN Reading Guide to the basic specifications (Guida alla lettura)
- ACN, NIS FAQ: security measures and incident notification
- ACN, NIS FAQ: monitoring, supervision and enforcement
- ACN, “NIS, avviata la seconda fase” (NIS, second phase launched) (15 April 2025)