YOUR
Search

    06.10.2025

    NIS: The CSIRT Contact Person must be appointed by 31 December


    On 19 September, the ACN (National Cybersecurity Agency) adopted Determination ACN No. 250916, which updates and replaces the previous Determination ACN No. 333017 of 22 July 2025.

    The most significant change is the introduction of the CSIRT Contact Person.

    Who is the CSIRT Contact Person?

    The CSIRT Contact Person is the individual responsible for managing communications with CSIRT Italia (the national Computer Security Incident Response Team) and for transmitting notifications of significant incidents (as defined in Determination ACN No. 164179) as well as voluntary reports of relevant cybersecurity information.

    To ensure prompt and continuous communication with the CSIRT, the regulation allows the appointment of one or more deputies to the CSIRT Contact Person. These deputies support the Contact Person in their duties and can act on their behalf in cases of absence or impediment.

    Unlike the Point of Contact and the Deputy Point of Contact, the CSIRT Contact Person (and their deputy) may also be an external individual (for example, a consultant).

    In any case, designated persons must possess basic skills in cybersecurity and incident management, along with an in-depth knowledge of the information systems and networks of the NIS entity for which they operate.

    The designation must be carried out by the Point of Contact through a dedicated procedure. This procedure will be active from 20 November 2025 and must be completed by 31 December 2025 via the service portal accessible through the ACN website.

    At first glance, the introduction of the CSIRT Contact Person represents an important support tool for NIS entities, as it allows them to delegate the management of incident notifications to external individuals. This relieves NIS entities from particularly burdensome and time-consuming activities for which it may be preferable to rely on external consultants with specific expertise.

    This is particularly useful for:

    • NIS entities that lack adequate internal structures or resources to manage the requirements related to incident notification;
    • foreign organizations under national jurisdiction (for example, providers of public electronic communications networks and publicly available electronic communications services) that may face challenges due to language barriers or time zone differences.

    If you need assistance and support in fulfilling the obligations under the NIS framework, click here

    Raffaele Giarda joins ADVANT Nctm as new Partner
    ADVANT Nctm announces that Raffaele Giarda has joined the Firm as…
    Read more
    2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace
    On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian…
    Read more
    AI Enters Trade Secret Protection
    On 10 June 2026, the Italian Council of Ministers approved two draft legislative…
    Read more
    Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)
    The context and purpose of the National Space Policy Strategic Document…
    Read more
    Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation
    The football club as a data ecosystem (and as a media company) From a personal…
    Read more
    Tracking pixels in e-mails: the Data Protection Authority's new rules
    1. Introduction By Order No. 284 of 17 April 2026, published in the Official…
    Read more
    THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS
    The context and structure of the Guidelines Regulation (EU) 2024/1689 (“AI…
    Read more
    WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?
    Summary of the judgement On 18 March 2026, the Court of Rome annulled in its…
    Read more
    Cyber Resilience Act: the countdown has started
    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European…
    Read more