started · updated
ACN prepares for 2026 enforcement of EU cybersecurity regulations
The Italian National Cybersecurity Agency (ACN) is preparing for the enforcement of major European cybersecurity regulations. Under the Cyber Resilience Act, starting September 11, 2026, manufacturers with products in the European market will be legally required to report serious cyber vulnerabilities and incidents.
To assist with this transition, the European Commission has released non-binding guidelines covering topics such as open-source software, risk assessment, and vulnerability management. These guidelines aim to provide clarity for developers and businesses regarding the technical and operational requirements of the regulation.
Simultaneously, the ACN is moving into a new phase of enforcement regarding the NIS2 Directive. Following a period of guidance for small and medium-sized enterprises (SMEs), the agency is expected to begin systematic monitoring, inspections, and potential sanctions by October 2026. The oversight will target approximately 20,000 entities, including 5,000 essential subjects, focusing on whether actual daily practices align with documented security plans.
Entities
Agenzia per la Cybersicurezza Nazionale · Cyber Resilience Act · European Commission · NIS2 Directive