ACN Adopts Incident Taxonomy Under Law 90/2024: What Obligated Entities Must Do Now

ACN adopted the incident taxonomy under Law 90/2024 via the Determina of 9 February 2026. Obligated entities must now report incidents within 24 hours and notify within 72 hours based on Allegato A classifications.

February 20, 2026 3 min read

A hand filling in a printed form to classify an incident Made with AI
Contents
  1. Key takeaways
  2. What changed in practice
  3. Taxonomy at a glance (Allegato A)
  4. Who is in scope under Law 90/2024
  5. Notification timing model to operationalize
  6. Operational checklist for cyber, GRC, and legal teams
  7. FAQ
  8. Official sources

Italy has now formalized the incident taxonomy that triggers mandatory reporting and notification under Article 1 of Law 90/2024. ACN adopted it through the Determina of 9 February 2026, published in the Official Gazette on 17 February 2026 (No. 39, code 26A00713), and the measure applies from its publication date.

Sources: ACN page, GU - Determina 9 febbraio 2026, Art. 2 - application date

Key takeaways

  • The taxonomy is now legally anchored for Article 1, paragraph 1, Law 90/2024 obligations.
  • Obligated entities must report and notify incidents included in Allegato A of the ACN determina.
  • Article 1, paragraph 2, of Law 90/2024 sets the timing model: report within 24 hours and complete notification within 72 hours from knowledge of the incident.
  • ACN explicitly states coherence with NIS incident categories and allows simplification where pre-notification/notification under Article 25 of Legislative Decree 138/2024 is performed.

Sources: Law 90/2024 - Art. 1, Determina - Art. 1, D.Lgs. 138/2024

What changed in practice

The new determina does not create a separate conceptual framework disconnected from existing NIS obligations. Instead, ACN links Law 90/2024 incident obligations to a taxonomy coherent with the "incidenti significativi di base" framework already used in the NIS context.

For compliance teams, this means that notification governance should be designed as a single operational process across overlapping legal regimes, not parallel fragmented workflows.

Source: Determina - Art. 1, paragraphs 1-2 and recitals

Taxonomy at a glance (Allegato A)

The published Allegato A includes incident codes such as:

  • IS-1: evidence of external confidentiality loss of digital data.
  • IS-2: evidence of integrity loss with external impact on data.
  • IS-3: evidence of service-level violations affecting services/activities against expected service levels.

Source: Allegato A

Who is in scope under Law 90/2024

Article 1 of Law 90/2024 lists a broad set of public-sector and related entities, including central public administrations, regions/provinces, metropolitan cities, large municipalities/capital municipalities, specified transport operators, local health authorities, and relevant in-house companies.

Details are defined in the official legal text and should be mapped against the entity perimeter with legal counsel and governance owners.

Source: Law 90/2024 - Art. 1

Notification timing model to operationalize

Under Article 1, paragraph 2, Law 90/2024:

  1. Initial reporting without delay and no later than 24 hours from awareness.
  2. Complete notification within 72 hours from the same moment.
  3. Reporting/notification is performed through ACN institutional procedures.

Source: Law 90/2024 - Art. 1, paragraph 2

  1. Update your incident classification matrix to include Allegato A codes (IS-1, IS-2, IS-3 and full taxonomy entries).
  2. Align triage and escalation playbooks to 24h/72h legal timings.
  3. Harmonize Law 90/2024 and NIS reporting workflows to avoid duplicate or inconsistent submissions.
  4. Review accountability and evidence capture for regulatory defensibility.
  5. Test the end-to-end reporting process with table-top exercises.

FAQ

From when does this taxonomy apply?

From the publication date of the determina in the Official Gazette, i.e., 17 February 2026. Source: Art. 2 - Pubblicazione

Does this replace NIS notification obligations?

The determina states coherence with NIS incident categories and provides a simplification approach where pre-notification/notification under Article 25 NIS is made. Compliance teams should still ensure all legal requirements are met in practice. Source: Determina - Art. 1

Which incident types trigger obligations?

Those included in Allegato A of the ACN determina. Source: Allegato A

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

April 14, 2026

New NIS Subjects in 2026: Incident-Notification and Baseline-Measure Deadlines

The ACN 2026 timing determination sets a distinct implementation path for entities first listed in the Italian NIS perimeter during 2026: significant…

April 14, 2026

ACN NIS 2026 Platform Rules and New Deadlines: Master Overview

ACN's April 2026 package sets new NIS deadlines for subjects listed for the first time in 2026 (incident notification from 1 January 2027, baseline m…

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…