---
title: ACN Incident Taxonomy Under Law 90/2024
description: ACN adopted the incident taxonomy under Law 90/2024. Learn what obligated entities must do now to comply with the new classification framework.
canonical: https://www.aegister.com/en/cms/insights/acn-incident-taxonomy-law-90-2024/
url: /en/cms/insights/acn-incident-taxonomy-law-90-2024/
lang: en
---

![](/static/images/header-contact.webp)

# ACN Adopts Incident Taxonomy Under Law 90/2024: What Obligated Entities Must Do Now

---

![ACN Adopts Incident Taxonomy Under Law 90/2024: What Obligated Entities Must Do Now](/static/images/cms/acn-tassonomia-incidenti-legge-90.webp)

## ACN Adopts Incident Taxonomy Under Law 90/2024: What Obligated Entities Must Do Now

February 20, 2026

[ACN](/en/cms/keyword/acn/)
[compliance](/en/cms/keyword/compliance/)
[notification](/en/cms/keyword/notification/)
[cybersecurity](/en/cms/keyword/cybersecurity/)
+6

Italy has now formalized the incident taxonomy that triggers mandatory reporting and notification under Article 1 of Law 90/2024. ACN adopted it through the **Determina of 9 February 2026**, published in the Official Gazette on **17 February 2026 (No. 39, code 26A00713)**, and the measure applies from its publication date.

Sources: [ACN page](https://www.acn.gov.it/portale/w/legge-90/2024-adottata-la-tassonomia-degli-incidenti-che-fanno-scattare-l-obbligo-di-notifica), [GU - Determina 9 febbraio 2026](https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?atto.codiceRedazionale=26A00713&atto.dataPubblicazioneGazzetta=2026-02-17&elenco30giorni=false), [Art. 2 - application date](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=2&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Key takeaways

- The taxonomy is now legally anchored for Article 1, paragraph 1, Law 90/2024 obligations.
- Obligated entities must report and notify incidents included in **Allegato A** of the ACN determina.
- Article 1, paragraph 2, of Law 90/2024 sets the timing model: report within **24 hours** and complete notification within **72 hours** from knowledge of the incident.
- ACN explicitly states coherence with NIS incident categories and allows simplification where pre-notification/notification under Article 25 of Legislative Decree 138/2024 is performed.

Sources: [Law 90/2024 - Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=24G00108&art.dataPubblicazioneGazzetta=2024-07-02&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=1&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1), [Determina - Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1), [D.Lgs. 138/2024](https://www.gazzettaufficiale.it/eli/id/2024/10/01/24G00155/SG)

## What changed in practice

The new determina does not create a separate conceptual framework disconnected from existing NIS obligations. Instead, ACN links Law 90/2024 incident obligations to a taxonomy coherent with the "incidenti significativi di base" framework already used in the NIS context.

For compliance teams, this means that notification governance should be designed as a **single operational process** across overlapping legal regimes, not parallel fragmented workflows.

Source: [Determina - Art. 1, paragraphs 1-2 and recitals](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Taxonomy at a glance (Allegato A)

The published Allegato A includes incident codes such as:

- **IS-1**: evidence of external confidentiality loss of digital data.
- **IS-2**: evidence of integrity loss with external impact on data.
- **IS-3**: evidence of service-level violations affecting services/activities against expected service levels.

Source: [Allegato A](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=1&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Who is in scope under Law 90/2024

Article 1 of Law 90/2024 lists a broad set of public-sector and related entities, including central public administrations, regions/provinces, metropolitan cities, large municipalities/capital municipalities, specified transport operators, local health authorities, and relevant in-house companies.

Details are defined in the official legal text and should be mapped against the entity perimeter with legal counsel and governance owners.

Source: [Law 90/2024 - Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=24G00108&art.dataPubblicazioneGazzetta=2024-07-02&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=1&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Notification timing model to operationalize

Under Article 1, paragraph 2, Law 90/2024:

1. Initial reporting without delay and no later than 24 hours from awareness.
2. Complete notification within 72 hours from the same moment.
3. Reporting/notification is performed through ACN institutional procedures.

Source: [Law 90/2024 - Art. 1, paragraph 2](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=24G00108&art.dataPubblicazioneGazzetta=2024-07-02&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=1&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Operational checklist for cyber, GRC, and legal teams

1. Update your incident classification matrix to include Allegato A codes (IS-1, IS-2, IS-3 and full taxonomy entries).
2. Align triage and escalation playbooks to 24h/72h legal timings.
3. Harmonize Law 90/2024 and NIS reporting workflows to avoid duplicate or inconsistent submissions.
4. Review accountability and evidence capture for regulatory defensibility.
5. Test the end-to-end reporting process with table-top exercises.

## FAQ

### From when does this taxonomy apply?

From the publication date of the determina in the Official Gazette, i.e., 17 February 2026. Source: [Art. 2 - Pubblicazione](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=2&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

### Does this replace NIS notification obligations?

The determina states coherence with NIS incident categories and provides a simplification approach where pre-notification/notification under Article 25 NIS is made. Compliance teams should still ensure all legal requirements are met in practice. Source: [Determina - Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

### Which incident types trigger obligations?

Those included in Allegato A of the ACN determina. Source: [Allegato A](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=1&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)

## Official sources

- [ACN page - Legge 90/2024: tassonomia incidenti](https://www.acn.gov.it/portale/w/legge-90/2024-adottata-la-tassonomia-degli-incidenti-che-fanno-scattare-l-obbligo-di-notifica)
- [GU - Determina 9 febbraio 2026 (26A00713)](https://www.gazzettaufficiale.it/atto/serie_generale/caricaDettaglioAtto/originario?atto.codiceRedazionale=26A00713&atto.dataPubblicazioneGazzetta=2026-02-17&elenco30giorni=false)
- [GU - Determina Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)
- [GU - Determina Art. 2](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=0&art.idArticolo=2&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)
- [GU - Determina Allegato A](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=26A00713&art.dataPubblicazioneGazzetta=2026-02-17&art.flagTipoArticolo=1&art.idArticolo=1&art.idGruppo=0&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)
- [GU - Law 90/2024 Art. 1](https://www.gazzettaufficiale.it/atto/serie_generale/caricaArticolo?art.codiceRedazionale=24G00108&art.dataPubblicazioneGazzetta=2024-07-02&art.flagTipoArticolo=0&art.idArticolo=1&art.idGruppo=1&art.idSottoArticolo=1&art.idSottoArticolo1=10&art.progressivo=0&art.versione=1)
- [GU - Legislative Decree 138/2024 (NIS)](https://www.gazzettaufficiale.it/eli/id/2024/10/01/24G00155/SG)

Share this post

## Related News

[![ACN NIS 2026 Platform Rules and New Deadlines: Master Overview](/static/images/cms/nis2-basic-measures-acn.webp)](/en/cms/insights/nis-acn-platform-2026-new-deadlines-overview/)

[ACN NIS 2026 Platform Rules and New Deadlines: Master Overview](/en/cms/insights/nis-acn-platform-2026-new-deadlines-overview/)

[ACN's April 2026 package sets new NIS deadlines for subjects listed for the first time in 2026 (incident notification from 1 January 2027, baseline measures by 31 July 2027) and updates the platform operating rules for registration, annual and continuous updates, relevant suppliers, and categorization.](/en/cms/insights/nis-acn-platform-2026-new-deadlines-overview/)

[NIS2](/en/cms/keyword/nis2/)
[ACN](/en/cms/keyword/acn/)
+8

[![UNI/PdR 174:2025 for NIS Organizations Certified to ISO 27001: What It Changes Operationally](/static/images/cms/uni-pdr-174-2025-nis-iso-27001.webp)](/en/cms/insights/uni-pdr-174-2025-nis-iso-27001/)

[UNI/PdR 174:2025 for NIS Organizations Certified to ISO 27001: What It Changes Operationally](/en/cms/insights/uni-pdr-174-2025-nis-iso-27001/)

[ACN published UNI/PdR 174:2025 as an operational bridge between ISO/IEC 27001 and NIST CSF 2.0 for NIS-scoped organizations. It helps ISO-certified entities align existing controls with NIS baseline security measures.](/en/cms/insights/uni-pdr-174-2025-nis-iso-27001/)

[ACN](/en/cms/keyword/acn/)
[compliance](/en/cms/keyword/compliance/)
+7

[![NIS 2026 Reminder: 8 Days Left Before the 28 February Registration Deadline](/static/images/cms/nis-registrazione-2026-scadenza.webp)](/en/cms/insights/nis-2026-registration-deadline-february/)

[NIS 2026 Reminder: 8 Days Left Before the 28 February Registration Deadline](/en/cms/insights/nis-2026-registration-deadline-february/)

[Organizations in scope of Italy's NIS regime have until 28 February 2026 to complete annual registration via the ACN Services Portal. Both new and previously registered entities must submit a 2026 declaration.](/en/cms/insights/nis-2026-registration-deadline-february/)

[NIS2](/en/cms/keyword/nis2/)
[ACN](/en/cms/keyword/acn/)
+8

### NIS 2 Compliance with Aegister

Complete solutions for NIS 2 Directive compliance: expert consulting, implementation and ongoing support.

[Discover](/en/solutions/compliance/nis2/)
