YOUR
Search

    24.04.2026

    What changes under the new ACN determination on categorisation?


    Practical guidance on the new NIS compliance requirements to be fulfilled by 30 June 2026.

    Italy’s National Cybersecurity Agency (“ACN”) has today published Determination No. 155238/2026 (“the Determination”), which sets out the relevance categories, as well as the process, procedures and criteria for the listing, characterisation and categorisation of activities and services. 

    The Determination introduces two categorisation models, set out in its Annexes 1 and 2 respectively. Both are structured around ten macro-areas, each with a name, description and pre-assigned relevance category. The four relevance categories established by the Determination are: high impact, medium impact, low impact and minimal impact. 

    Essentially, the two annexes identify the same macro-areas, which differ only in the relevance category assigned to them.

    As regards the scope of application, Annex 1 applies to (i) NIS entities operating in the following sectors: energy; transport; healthcare; drinking water; wastewater; space; postal and courier services; waste management; manufacturing, production and distribution of chemicals; production, processing and distribution of food; manufacturing; and (ii) entities providing local public transport services. Annex 2 applies to all other NIS entities not falling within those sectors.

    In practice, the Determination requires NIS entities, through the ACN Portal, to list and categorise all internal and external activities and services and assign them to the relevant macro-areas of the model set out in the applicable annex. For each activity or service, entities must specify three elements: the corresponding macro-area, the name and description, and the relevance category.

    The Determination also allows entities a degree of discretion. NIS entities may assign a specific activity or service to a different category from that pre-assigned to the macro-area, based on their assessment of the impact that a potential compromise could have on their ability to properly carry out NIS-related activities and services. In such case, the entity must retain the documentation supporting that assessment. By contrast, where the entity does not carry out activities or provide services attributable to one or more macro-areas, it is not required to report them.

    The Determination also lays down two coordination provisions. The first concerns entities that have already classified data and services for the Public Administration in accordance with ACN Directorial Decree No. 21007/24: for such entities, that model continues to apply, rather than the model introduced by the Determination. The second concerns activities and services subject to the national cyber security framework, for which the relevance category is predetermined as “high impact”, without applying the standard procedure.

    For matters not expressly governed by the Determination, the provisions of the NIS Decree shall apply. The Determination shall apply from 1 May 2026.

    Raffaele Giarda joins ADVANT Nctm as new Partner
    ADVANT Nctm announces that Raffaele Giarda has joined the Firm as…
    Read more
    2025 annual report of the Italian Data Protection Authority: AI is accelerating, digital compliance must keep pace
    On 2 July 2026, at the Sala della Regina of Palazzo Montecitorio, the Italian…
    Read more
    AI Enters Trade Secret Protection
    On 10 June 2026, the Italian Council of Ministers approved two draft legislative…
    Read more
    Space Economy and Data Economy: the National Space Policy Strategic Document (DSPSN)
    The context and purpose of the National Space Policy Strategic Document…
    Read more
    Personal data governance in football clubs: data use as a strategic lever at the intersection of GDPR, security and value creation
    The football club as a data ecosystem (and as a media company) From a personal…
    Read more
    Tracking pixels in e-mails: the Data Protection Authority's new rules
    1. Introduction By Order No. 284 of 17 April 2026, published in the Official…
    Read more
    THE COMMISSION’S NEW GUIDELINES ON THE CLASSIFICATION OF HIGH-RISK AI SYSTEMS
    The context and structure of the Guidelines Regulation (EU) 2024/1689 (“AI…
    Read more
    WHY DID THE COURT OF ROME ANNUL THE DATA PROTECTION AUTHORITY’S ORDER ON OPENAI?
    Summary of the judgement On 18 March 2026, the Court of Rome annulled in its…
    Read more
    Cyber Resilience Act: the countdown has started
    With Regulation (EU) 2024/2847 (“Cyber Resilience Act” or “CRA”), the European…
    Read more