< Back to all clusters
[TECHNOLOGY] · Italy · 3 sources

started · updated

Italy's ACN implements new NIS2 cybersecurity compliance measures

The Italian National Cybersecurity Agency (ACN) is implementing new operational measures to enforce the NIS2 Directive, shifting focus from individual organizational security to systemic ecosystem resilience. A key component of this strategy is the management of supply chain risks, as vulnerabilities in marginal suppliers can cascade to critical infrastructure and public administrations.

Under ACN Determination n. 127437/2026, organizations within the NIS2 perimeter are now required to provide a structured list of their ‘relevant NIS suppliers’. This measure serves as a defensive intelligence tool, allowing the ACN to map interdependencies and identify critical nodes in the national supply chain that may require regulatory inclusion.

Additionally, the ACN has released new guidance via updated FAQs focused on monitoring, supervision, and enforcement (MVE). These guidelines clarify how compliance will be verified, what information must be provided to the Authority, and the consequences of non-compliance. This transition moves the focus from mere formal adoption of security measures to the practical demonstration of compliance during regulatory oversight.

Entities

Agenzia per la Cybersicurezza Nazionale · NIS2 Directive