Resources

NIS2

Checklist

Det. ACN 379907/2025, Annexes 1 and 2

Updated 23 September 2026

by Alessandro Monego

NIS2 checklist of the ACN basic measures

The 43 measures of ACN Determination 379907/2025, with the requirements for essential and important entities, the evidence to prepare and the documents to have approved.

The basic measures are the official list of what ACN (Agenzia per la Cybersicurezza Nazionale, Italy's National Cybersecurity Agency) requires of NIS2 entities: 43 measures with 116 requirements for essential entities, 37 measures with 87 requirements for important entities (ACN Determination 379907/2025). Here you will find every measure with what it requires in one line, the letter of Article 24 of Legislative Decree 138/2024 (D.Lgs. 138/2024) that it covers and the documents to have approved by the management bodies. Download the full version to work through it requirement by requirement.

  • Code: the subcategory of the Italian National Framework for Cybersecurity and Data Protection (GV Govern, ID Identify, PR Protect, DE Detect, RS Respond, RC Recover).
  • Requirements E / I: how many requirements the measure has for essential and for important entities. A dash means the measure does not apply to important entities.
  • Art. 24: the letter of paragraph 2 that the measure covers, according to Appendix A of the ACN Reading Guide.

GV · Govern

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
GV.OC-04An up-to-date list of the relevant information and network systems1 / 1aList of relevant systems
GV.RM-03A risk management plan to identify, analyse, assess, treat and monitor risks1 / 1aRisk management plan
GV.RR-02The cybersecurity organisation, with roles, list of staff, point of contact, deputy and CSIRT liaison; reviewed at least every two years4 / 4aOrganisational document, list of rolesYes
GV.RR-04Reliable screening of those who access relevant systems and of system administrators; confidentiality obligations that continue after the relationship ends5 / 3iHR security procedures, contract clauses
GV.PO-01Security policies for 16 areas, from risk management to incident response3 / 3aSecurity policiesYes
GV.PO-02Review of the policies at least once a year and after significant events, with a register of the outcomes3 / 2aRegister of reviews
GV.SC-01Cybersecurity involved in procurement, and security requirements for supplies2 / 1dProcurement procedure with security requirements
GV.SC-02Security roles of third-party staff defined and known2 / 2dList of roles, third parties included
GV.SC-04Inventory of suppliers with a security impact, with contact person and type of supply1 / 1dSupplier inventory
GV.SC-05Security requirements included in requests for quotation, tenders and contracts1 / 1d, eContract clauses
GV.SC-07Risk assessment of every supply and periodic verification of the requirements2 / 2dSupplier risk assessment, outcomes of checks

ID · Identify

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
ID.AM-01Hardware inventory, including IoT, OT and mobile devices1 / 1iHardware inventory
ID.AM-02Inventory of services, systems and software, including those used via API1 / 1iSoftware and services inventory
ID.AM-03Inventory of network flows between your systems and the outside1 / –iNetwork flow inventory
ID.AM-04Inventory of suppliers' IT services, cloud included1 / 1iInventory of suppliers' services
ID.RA-01Identification of vulnerabilities, with periodic vulnerability assessments or penetration tests and reports3 / 1eVA/PT reports
ID.RA-05Documented risk assessment, at least every two years and after significant events4 / 3aRisk assessmentYes
ID.RA-06Risk treatment plan, with any compensating measures and the residual risks accepted3 / 3aRisk treatment planYes
ID.RA-08Monitoring of CSIRT Italia and CERT channels, fixing of vulnerabilities, vulnerability management plan5 / 4eVulnerability management planYes
ID.IM-01Compliance plan, periodic reports to the management bodies, plan for assessing the effectiveness of the measures4 / 2fCompliance plan, reportsYes
ID.IM-04Business continuity, disaster recovery and crisis management plans5 / 5cThe three plans3 documents

PR · Protect

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
PR.AA-01Recorded, individual user accounts, strong credentials, periodic review of authorisations4 / 4iAccount management procedure, review outcomes
PR.AA-03Authentication proportionate to risk and multi-factor authentication on relevant systems3 / 3i, lAuthentication procedure, MFA configuration
PR.AA-05Least privilege, separation of duties, separate administrative accounts3 / 3iPermission management procedure
PR.AA-06Protected physical access to relevant systems2 / 2iPhysical security procedure
PR.AT-01Training plan for staff and management bodies, with a register3 / 3gTraining plan, training registerYes
PR.AT-02Dedicated training for specialised roles and system administrators2 / –gSpecialist training register
PR.DS-01Encryption of laptops and removable media; no autorun, scanning of media3 / 3hProcedure, encryption configurations
PR.DS-02Encryption of data sent outside, voice and video communications included2 / 2h, lProcedure, configurations
PR.DS-11Periodic backups, offline copies, protection of backups, restore tests5 / 2cBackup procedure, restore test outcomes
PR.PS-01Secure reference configurations (hardening) of relevant systems2 / –eList of reference configurations
PR.PS-02Only software that receives security updates, timely patches, testing of critical software5 / 3eUpdate procedure
PR.PS-03Secure disposal of storage devices, register of hardware maintenance2 / –eDisposal procedure, maintenance register
PR.PS-04Logs of remote and administrative access, kept securely for defined periods4 / 4bLogging procedure, retention periods
PR.PS-06Secure software development practices1 / 1eSecure development guidelines
PR.IR-01Remote access defined and protected, list of remotely accessible systems, firewalls4 / 4iList of remote access, procedure
PR.IR-03Protected emergency communication systems2 / –lEmergency communication procedure

DE · Detect

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
DE.CM-01Tools to detect significant incidents, expected service levels, traffic and email filtering, access monitoring7 / 3bExpected service levels, monitoring procedure
DE.CM-09Endpoint protection against malicious code2 / 2bProcedure, anti-malware coverage

RS · Respond

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
RS.MA-01Plan for incident management and notification to CSIRT Italia, reviewed at least every two years3 / 3bIncident management planYes
RS.CO-02Procedures to inform service recipients about incidents and threats, and the public if ACN requires it2 / 2bCommunication procedures

RC · Recover

CodeWhat it requires, in one lineRequirements E / IArt. 24Typical evidenceTo approve
RC.RP-01Procedures to restore systems affected by incidents, within the incident plan1 / 1bRecovery procedures
RC.CO-03Internal communication of recovery activities1 / –bRecovery communication procedure

Totals: 43 measures and 116 requirements for essential entities; 37 measures and 87 requirements for important entities. The 6 measures for essential entities only: ID.AM-03, PR.AT-02, PR.PS-01, PR.PS-03, PR.IR-03, RC.CO-03.

Download the full checklist, requirement by requirement

The official text of every ACN requirement, with columns to work on it: status, owner, evidence, review date. It also flags the requirements with the risk-based clauses (Appendix B) and those that call for approval by the management bodies (Appendix C). CSV file, opens in Excel, Numbers or Google Sheets. Free, no sign-up.

The file is in Italian: the requirement texts are quoted verbatim from the ACN annexes, which ACN publishes in Italian, and the column headings match them. We do not translate the requirements, so that the file stays the official wording you are assessed against. The one-line English summaries on this page help you find your way around it.

The eleven documents to have approved

Appendix C of the ACN Reading Guide (Guida alla lettura) lists the documents that the administrative and executive bodies must approve, with the requirement that asks for it.

  • Cybersecurity organisation: GV.RR-02, point 1
  • Cybersecurity policies: GV.PO-01, point 3
  • Risk assessment: ID.RA-05, point 3
  • Risk treatment plan: ID.RA-06, point 3
  • Vulnerability management plan: ID.RA-08, point 4
  • Compliance plan: ID.IM-01, point 1
  • Business continuity plan: ID.IM-04, point 4
  • Disaster recovery plan: ID.IM-04, point 4
  • Crisis management plan: ID.IM-04, point 4
  • Training plan: PR.AT-01, point 2
  • Incident management plan: RS.MA-01, point 2

Before you use it

An informative checklist based on Annexes 1 and 2 of ACN Determination 379907/2025 and on the ACN Reading Guide (v2.1, April 2026). The one-line summaries are ours, translated from our Italian page; they do not replace the official text, published by ACN in Italian, which prevails. Ticking every row is not the same as being compliant: compliance is assessed on your own context, and it is ACN that assesses it.

Sources

The sources are official texts, published in Italian.

Updated 23 September 2026. If a source changes, we update the page.