NIS2
Checklist
Det. ACN 379907/2025, Annexes 1 and 2
Updated 23 September 2026
by Alessandro Monego
NIS2 checklist of the ACN basic measures
The 43 measures of ACN Determination 379907/2025, with the requirements for essential and important entities, the evidence to prepare and the documents to have approved.
The basic measures are the official list of what ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) requires of NIS2 entities: 43 measures with 116 requirements for essential entities, 37 measures with 87 requirements for important entities (ACN Determination 379907/2025). Here you will find every measure with what it requires in one line, the letter of Article 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024) that it covers and the documents to have approved by the management bodies. Download the full version to work through it requirement by requirement.
- Code: the subcategory of the Italian National Framework for Cybersecurity and Data Protection (GV Govern, ID Identify, PR Protect, DE Detect, RS Respond, RC Recover).
- Requirements E / I: how many requirements the measure has for essential and for important entities. A dash means the measure does not apply to important entities.
- Art. 24: the letter of paragraph 2 that the measure covers, according to Appendix A of the ACN Reading Guide.
GV · Govern
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| GV.OC-04 | An up-to-date list of the relevant information and network systems | 1 / 1 | a | List of relevant systems | |
| GV.RM-03 | A risk management plan to identify, analyse, assess, treat and monitor risks | 1 / 1 | a | Risk management plan | |
| GV.RR-02 | The cybersecurity organisation, with roles, list of staff, point of contact, deputy and CSIRT liaison; reviewed at least every two years | 4 / 4 | a | Organisational document, list of roles | Yes |
| GV.RR-04 | Reliable screening of those who access relevant systems and of system administrators; confidentiality obligations that continue after the relationship ends | 5 / 3 | i | HR security procedures, contract clauses | |
| GV.PO-01 | Security policies for 16 areas, from risk management to incident response | 3 / 3 | a | Security policies | Yes |
| GV.PO-02 | Review of the policies at least once a year and after significant events, with a register of the outcomes | 3 / 2 | a | Register of reviews | |
| GV.SC-01 | Cybersecurity involved in procurement, and security requirements for supplies | 2 / 1 | d | Procurement procedure with security requirements | |
| GV.SC-02 | Security roles of third-party staff defined and known | 2 / 2 | d | List of roles, third parties included | |
| GV.SC-04 | Inventory of suppliers with a security impact, with contact person and type of supply | 1 / 1 | d | Supplier inventory | |
| GV.SC-05 | Security requirements included in requests for quotation, tenders and contracts | 1 / 1 | d, e | Contract clauses | |
| GV.SC-07 | Risk assessment of every supply and periodic verification of the requirements | 2 / 2 | d | Supplier risk assessment, outcomes of checks |
ID · Identify
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| ID.AM-01 | Hardware inventory, including IoT, OT and mobile devices | 1 / 1 | i | Hardware inventory | |
| ID.AM-02 | Inventory of services, systems and software, including those used via API | 1 / 1 | i | Software and services inventory | |
| ID.AM-03 | Inventory of network flows between your systems and the outside | 1 / – | i | Network flow inventory | |
| ID.AM-04 | Inventory of suppliers' IT services, cloud included | 1 / 1 | i | Inventory of suppliers' services | |
| ID.RA-01 | Identification of vulnerabilities, with periodic vulnerability assessments or penetration tests and reports | 3 / 1 | e | VA/PT reports | |
| ID.RA-05 | Documented risk assessment, at least every two years and after significant events | 4 / 3 | a | Risk assessment | Yes |
| ID.RA-06 | Risk treatment plan, with any compensating measures and the residual risks accepted | 3 / 3 | a | Risk treatment plan | Yes |
| ID.RA-08 | Monitoring of CSIRT Italia and CERT channels, fixing of vulnerabilities, vulnerability management plan | 5 / 4 | e | Vulnerability management plan | Yes |
| ID.IM-01 | Compliance plan, periodic reports to the management bodies, plan for assessing the effectiveness of the measures | 4 / 2 | f | Compliance plan, reports | Yes |
| ID.IM-04 | Business continuity, disaster recovery and crisis management plans | 5 / 5 | c | The three plans | 3 documents |
PR · Protect
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| PR.AA-01 | Recorded, individual user accounts, strong credentials, periodic review of authorisations | 4 / 4 | i | Account management procedure, review outcomes | |
| PR.AA-03 | Authentication proportionate to risk and multi-factor authentication on relevant systems | 3 / 3 | i, l | Authentication procedure, MFA configuration | |
| PR.AA-05 | Least privilege, separation of duties, separate administrative accounts | 3 / 3 | i | Permission management procedure | |
| PR.AA-06 | Protected physical access to relevant systems | 2 / 2 | i | Physical security procedure | |
| PR.AT-01 | Training plan for staff and management bodies, with a register | 3 / 3 | g | Training plan, training register | Yes |
| PR.AT-02 | Dedicated training for specialised roles and system administrators | 2 / – | g | Specialist training register | |
| PR.DS-01 | Encryption of laptops and removable media; no autorun, scanning of media | 3 / 3 | h | Procedure, encryption configurations | |
| PR.DS-02 | Encryption of data sent outside, voice and video communications included | 2 / 2 | h, l | Procedure, configurations | |
| PR.DS-11 | Periodic backups, offline copies, protection of backups, restore tests | 5 / 2 | c | Backup procedure, restore test outcomes | |
| PR.PS-01 | Secure reference configurations (hardening) of relevant systems | 2 / – | e | List of reference configurations | |
| PR.PS-02 | Only software that receives security updates, timely patches, testing of critical software | 5 / 3 | e | Update procedure | |
| PR.PS-03 | Secure disposal of storage devices, register of hardware maintenance | 2 / – | e | Disposal procedure, maintenance register | |
| PR.PS-04 | Logs of remote and administrative access, kept securely for defined periods | 4 / 4 | b | Logging procedure, retention periods | |
| PR.PS-06 | Secure software development practices | 1 / 1 | e | Secure development guidelines | |
| PR.IR-01 | Remote access defined and protected, list of remotely accessible systems, firewalls | 4 / 4 | i | List of remote access, procedure | |
| PR.IR-03 | Protected emergency communication systems | 2 / – | l | Emergency communication procedure |
DE · Detect
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| DE.CM-01 | Tools to detect significant incidents, expected service levels, traffic and email filtering, access monitoring | 7 / 3 | b | Expected service levels, monitoring procedure | |
| DE.CM-09 | Endpoint protection against malicious code | 2 / 2 | b | Procedure, anti-malware coverage |
RS · Respond
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| RS.MA-01 | Plan for incident management and notification to CSIRT Italia, reviewed at least every two years | 3 / 3 | b | Incident management plan | Yes |
| RS.CO-02 | Procedures to inform service recipients about incidents and threats, and the public if ACN requires it | 2 / 2 | b | Communication procedures |
RC · Recover
| Code | What it requires, in one line | Requirements E / I | Art. 24 | Typical evidence | To approve |
|---|---|---|---|---|---|
| RC.RP-01 | Procedures to restore systems affected by incidents, within the incident plan | 1 / 1 | b | Recovery procedures | |
| RC.CO-03 | Internal communication of recovery activities | 1 / – | b | Recovery communication procedure |
Totals: 43 measures and 116 requirements for essential entities; 37 measures and 87 requirements for important entities. The 6 measures for essential entities only: ID.AM-03, PR.AT-02, PR.PS-01, PR.PS-03, PR.IR-03, RC.CO-03.
Download the full checklist, requirement by requirement
The official text of every ACN requirement, with columns to work on it: status, owner, evidence, review date. It also flags the requirements with the risk-based clauses (Appendix B) and those that call for approval by the management bodies (Appendix C). CSV file, opens in Excel, Numbers or Google Sheets. Free, no sign-up.
The file is in Italian: the requirement texts are quoted verbatim from the ACN annexes, which ACN publishes in Italian, and the column headings match them. We do not translate the requirements, so that the file stays the official wording you are assessed against. The one-line English summaries on this page help you find your way around it.
The eleven documents to have approved
Appendix C of the ACN Reading Guide (Guida alla lettura) lists the documents that the administrative and executive bodies must approve, with the requirement that asks for it.
- Cybersecurity organisation: GV.RR-02, point 1
- Cybersecurity policies: GV.PO-01, point 3
- Risk assessment: ID.RA-05, point 3
- Risk treatment plan: ID.RA-06, point 3
- Vulnerability management plan: ID.RA-08, point 4
- Compliance plan: ID.IM-01, point 1
- Business continuity plan: ID.IM-04, point 4
- Disaster recovery plan: ID.IM-04, point 4
- Crisis management plan: ID.IM-04, point 4
- Training plan: PR.AT-01, point 2
- Incident management plan: RS.MA-01, point 2
Before you use it
An informative checklist based on Annexes 1 and 2 of ACN Determination 379907/2025 and on the ACN Reading Guide (v2.1, April 2026). The one-line summaries are ours, translated from our Italian page; they do not replace the official text, published by ACN in Italian, which prevails. Ticking every row is not the same as being compliant: compliance is assessed on your own context, and it is ACN that assesses it.
Sources
The sources are official texts, published in Italian.
- ACN, page “Modalità e specifiche di base” (Annexes 1 and 2, PDF and xlsx)
- ACN, Reading Guide (Guida alla lettura) to the basic specifications, v2.1 (Appendices A, B, C)
- D.Lgs. 138/2024, Articles 23 and 24 (Normattiva)
Updated 23 September 2026. If a source changes, we update the page.