NIS2 October 2026: Countdown to ACN Inspections

5 ottobre 2026

For many organisations in the first cohort, the deadline for implementing baseline security measures is approaching. Here is the evidence that may be subject to verification.

31 October 2026 is not just another deadline: it marks ACN’s transition from the guidance and implementation-support phase to actual inspection and enforcement activities within the NIS2 framework.


What exactly is due.
For entities included in the national NIS list in 2025, the deadline for implementing baseline security measures is set at eighteen months from receipt of the notification confirming their inclusion, a deadline that, for the first cohort of entities, falls largely in October 2026.


The measures are structured into functions, categories and requirements under ACN Determination No. 379907/2025: 87 requirements for important entities and 116 for essential entities.


What changes from 31 October.
From that date, the Agency may begin verification activities. The supervisory regime is not the same for all entities: essential entities are subject to
ex ante supervision, meaning proactive controls, while important entities are primarily subject to ex post supervision, typically triggered by an unreported incident or a report from a third party.


The penalties are significant.
Fines can reach
€10 million for essential entities and €7 million for important entities, with an unprecedented element in the European cybersecurity framework: responsible executives may be temporarily suspended from their duties in cases of serious and repeated infringements.

What to do, the minimum checklist:
→ Conduct a gap analysis against Annexes 3 and 4 of the ACN Determination, covering the security measures applicable to your organisation’s profile.

→ Verify mandatory roles: Point of Contact and CSIRT Contact Person, including their respective deputies.

→ Test the incident notification process (24-hour early warning, 72-hour incident notification, final report within 30 days), this obligation has already been in force since 15 January 2026.

→ Map the supply chain: review supply-chain risk management, with particular attention to direct suppliers and critical services.


Two months may sound like plenty of time. For a thorough gap analysis, it often isn’t.


Sources: Legislative Decree No. 138/2024; ACN Determination No. 379907/2025; ACN portal - “Modalità e specifiche di base” section


#NIS2 #CyberSecurity #ACN #Compliance #GRC #CyberRisk #RiskManagement #MagisPartners

Ispezioni ACN NIS2, misure di sicurezza di base NIS2, sanzioni NIS2
5 ottobre 2026
Entro ottobre 2026 scadono i termini NIS2 per le misure di sicurezza di base. Requisiti ACN, controlli e priorità per soggetti essenziali e importanti.
AI Act 2 agosto 2026: cosa รจ cambiato per le imprese
17 settembre 2026
Dal 2 agosto 2026 si applicano nuovi obblighi AI Act su trasparenza e governance, mentre l'alto rischio è slittato. Cosa devono fare le imprese.
17 luglio 2026
Per le organizzazioni nel perimetro Part-IS, la conformità entra nella fase delle evidenze operative.
7 luglio 2026
NIS2 operativa: obblighi di notifica, tempistiche e impatti sull’Incident Response. Scopri come adeguare processi, governance e framework GRC.
1 luglio 2026
Per CISO e Risk Manager, inventario e classificazione dei sistemi AI diventano priorità di governance.
10 giugno 2026
Le sfide legate a ๐˜ค๐˜บ๐˜ฃ๐˜ฆ๐˜ณ๐˜ด๐˜ฆ๐˜ค๐˜ถ๐˜ณ๐˜ช๐˜ต๐˜บ, ๐˜ค๐˜ฐ๐˜ฎ๐˜ฑ๐˜ญ๐˜ช๐˜ข๐˜ฏ๐˜ค๐˜ฆ ๐˜ฆ ๐˜ณ๐˜ฆ๐˜ด๐˜ช๐˜ญ๐˜ช๐˜ฆ๐˜ฏ๐˜ป๐˜ข ๐˜ฐ๐˜ฑ๐˜ฆ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ท๐˜ข stanno cambiando rapidamente il settore aviation e il mondo delle infrastrutture critiche.
10 giugno 2026
๐Ÿ‡ช๐Ÿ‡บ EU AI Act: cos’è e cosa prevede.
10 giugno 2026
๐Ÿ‡ช๐Ÿ‡บ Direttiva NIS2: UE e la Sicurezza Informatica
10 giugno 2026
Quanto può costarti ignorare il rischio cyber? ๏ปฟ