Practical guidance on the new NIS compliance requirements to be fulfilled by 30 June 2026.
Italy’s National Cybersecurity Agency (“ACN”) has today published Determination No. 155238/2026 (“the Determination”), which sets out the relevance categories, as well as the process, procedures and criteria for the listing, characterisation and categorisation of activities and services.
The Determination introduces two categorisation models, set out in its Annexes 1 and 2 respectively. Both are structured around ten macro-areas, each with a name, description and pre-assigned relevance category. The four relevance categories established by the Determination are: high impact, medium impact, low impact and minimal impact.
Essentially, the two annexes identify the same macro-areas, which differ only in the relevance category assigned to them.
As regards the scope of application, Annex 1 applies to (i) NIS entities operating in the following sectors: energy; transport; healthcare; drinking water; wastewater; space; postal and courier services; waste management; manufacturing, production and distribution of chemicals; production, processing and distribution of food; manufacturing; and (ii) entities providing local public transport services. Annex 2 applies to all other NIS entities not falling within those sectors.
In practice, the Determination requires NIS entities, through the ACN Portal, to list and categorise all internal and external activities and services and assign them to the relevant macro-areas of the model set out in the applicable annex. For each activity or service, entities must specify three elements: the corresponding macro-area, the name and description, and the relevance category.
The Determination also allows entities a degree of discretion. NIS entities may assign a specific activity or service to a different category from that pre-assigned to the macro-area, based on their assessment of the impact that a potential compromise could have on their ability to properly carry out NIS-related activities and services. In such case, the entity must retain the documentation supporting that assessment. By contrast, where the entity does not carry out activities or provide services attributable to one or more macro-areas, it is not required to report them.
The Determination also lays down two coordination provisions. The first concerns entities that have already classified data and services for the Public Administration in accordance with ACN Directorial Decree No. 21007/24: for such entities, that model continues to apply, rather than the model introduced by the Determination. The second concerns activities and services subject to the national cyber security framework, for which the relevance category is predetermined as “high impact”, without applying the standard procedure.
For matters not expressly governed by the Determination, the provisions of the NIS Decree shall apply. The Determination shall apply from 1 May 2026.