ACN NIS Vademecum 2026: Compliance Calendar and Operational Checklist

ACN's NIS Vademecum 1.0 (September 2026) puts the NIS obligations on one calendar: six obligation families, three recurring annual windows and different timelines for the 2025 and 2026 cohorts. A period-by-period checklist.

September 27, 2026 12 min read

Two people in front of a wall planner pointing at a deadline Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. The Six Main NIS Obligation Families
  4. NIS Compliance Calendar at a Glance
  5. Different Timelines for the 2025 and 2026 Cohorts
  6. 1. Registration Is a Recurring Scope Declaration
  7. 2. Information Must Be Continuously Maintained
  8. 3. Categorization Connects Services to Proportionate Measures
  9. A Governance Model for the Annual Cycle
  10. Operational Checklist
  11. Common Interpretation Errors
  12. Frequently Asked Questions
  13. Conclusion
  14. Related Reading
  15. Official Sources

Applies to: organizations that have received formal notice of inclusion or continued inclusion in Italy's list of essential and important NIS entities.

The ACN NIS Vademecum, version 1.0 of September 2026, consolidates the main NIS obligations into one operating calendar. It identifies six obligation families, three recurring annual windows and different implementation milestones for entities listed in 2025 and 2026. The immediate priority is the October 2026 baseline-security milestone for the 2025 cohort; the next recurring cycle then opens with registration or registration updates from 1 January to 28 February 2027 (ACN announcement, ACN NIS Vademecum 2026 PDF).

In Brief

  • The Vademecum is an official general guide, not a substitute for Legislative Decree 138/2024, ACN determinations or entity-specific communications.
  • The six main obligation families cover registration, information updates, governing-body duties, cybersecurity risk-management measures, incident notification, and activity/service categorization.
  • Recurring annual windows are 1 January-28 February, 15 April-31 May, and 1 May-30 June.
  • Changes to information already shared with ACN must be updated promptly and no later than 14 days after the change.
  • Entities listed in 2025 and those listed in 2026 follow different initial implementation calendars.
  • All formal communications must use the NIS services available through the ACN services portal after authentication, user registration and association with the organization.

Scope and Source Boundary

This article translates the Vademecum into an operational calendar and explains the information, roles and evidence that organizations should prepare.

It does not:

  • determine whether a specific organization falls within NIS scope;
  • calculate an entity's exact individual deadline without its ACN inclusion notice;
  • replace sector-specific provisions or the official ACN determinations;
  • extend the Vademecum beyond what ACN published in version 1.0.

The PDF states that its intended recipients are organizations notified by certified email of their inclusion or continued inclusion in the NIS list. The authoritative evidence for an individual entity is therefore its formal ACN communication together with the applicable legal and implementing acts (ACN NIS Vademecum 2026 PDF, ACN NIS legislation area).

The Six Main NIS Obligation Families

The Vademecum groups the framework around six principal obligations. They should be managed as connected workstreams rather than isolated filings.

Legal reference Obligation family Operational question
Article 7(1) Registration and registration update Is the entity's NIS declaration complete, current and supported by its scope assessment?
Article 7(4) Transmission and update of information Are corporate, contact, service, infrastructure and supplier data current?
Article 23 Governing and management body obligations Have the competent bodies exercised the required oversight and approval responsibilities?
Article 24 Cybersecurity risk-management measures Are the applicable security measures implemented and supported by maintained evidence?
Article 25 Incident notification Can the organization identify, assess and notify significant incidents through the required process?
Article 30 Listing and categorization of activities and services Has the entity completed the harmonized impact assessment for its activities and services?

This high-level map needs an applicability check. The Vademecum notes additional duties for top-level domain name registry and domain registration service providers. It also notes that financial entities subject to Regulation (EU) 2022/2554 (DORA) are exempt from some requirements under the NIS decree and implementing determinations, while voluntary implementation remains possible (ACN NIS Vademecum 2026 PDF).

NIS Compliance Calendar at a Glance

The calendar combines recurring annual duties with one-time implementation milestones linked to the year in which the entity entered the NIS list.

Period Required activity Main output
1 January-28 February, every year Register or update registration by submitting a new NIS declaration Current scope declaration and registration data
By 14 April, every year ACN communicates inclusion, continued inclusion or removal for entities that registered within the ordinary window Formal status communication
15 April-31 May, every year Transmit or update the information required by Article 7(4) and (5) and the implementing determination Verified information package
Within 14 days of a change Update information previously shared with ACN Timely change record and portal update
1 May-30 June, every year Perform or update activity and service categorization Harmonized impact assessment and categorization outcome
By 31 December of the inclusion year, where the option is used Complete designation of the CSIRT contact and substitutes Confirmed incident-notification roles

The deadlines are not interchangeable. Completing annual registration does not satisfy the information-update or categorization obligations, and an annual update does not remove the duty to report relevant changes within 14 days (ACN NIS Vademecum 2026 PDF).

Different Timelines for the 2025 and 2026 Cohorts

The Vademecum separates the initial implementation timetable according to the year of inclusion.

Inclusion cohort Significant-incident notification Baseline security measures
Included in the NIS list in 2025 From January 2026 Complete by October 2026
Included in the NIS list in 2026 From January 2027 Complete by July 2027

Why the individual inclusion notice still matters

The month-level summary is not a universal single-day deadline. For entities that registered by 28 February 2025, the Vademecum's footnotes state that the precise deadlines under Article 42 of the NIS decree are calculated from receipt of the inclusion communication:

  • 9 months for baseline significant-incident notification;
  • 18 months for adoption of baseline security measures.

An organization should therefore retain the certified-email inclusion notice and calculate its exact date from that formal evidence. For entities included in 2026, the Vademecum refers to the dedicated ACN determination issued after the first-application period (ACN NIS Vademecum 2026 PDF, ACN baseline specifications area).

1. Registration Is a Recurring Scope Declaration

ACN defines registration as the process through which an entity presents itself to the national competent NIS authority and supplies the information needed to determine whether it falls within the entity types in Annexes I, II, III and IV of the NIS decree and whether it is an important or essential entity.

Ordinary registration runs from 1 January to 28 February every year. The Vademecum is explicit that all NIS entities must register or update their registration by filing a new declaration through Servizio NIS/Registrazione on the ACN services portal. Entities that complete the process within the ordinary window receive their inclusion, continued-inclusion or removal communication by 14 April (ACN registration FAQs).

The first registration is also when the organization designates its point of contact. This natural person handles implementation of the NIS decree on behalf of the entity, accesses NIS services, performs registration and interacts with ACN.

Registration preparation file

Before the window opens, maintain a controlled file containing:

  • legal-entity identification and group structure;
  • applicable sector, subsector and entity type;
  • size and scope assessment inputs;
  • services that support the NIS classification;
  • point-of-contact appointment and authority;
  • evidence supporting changes from the previous declaration;
  • submission receipt and subsequent ACN status communication.

Registration should be treated as a documented assessment, not as a form copied from the previous year.

2. Information Must Be Continuously Maintained

The information-update process gives ACN and CSIRT Italia the data needed to support entities and protect networks and information systems. It has two components:

  1. continuous maintenance, with updates made promptly and no later than 14 days after a change;
  2. an annual verification window from 15 April to 31 May.

The first information transmission is also when the entity designates the substitute point of contact, the CSIRT contact and any CSIRT substitutes. The Vademecum notes that designation of the CSIRT contact and substitutes may be deferred until 31 December of the year in which the entity is included (ACN NIS Vademecum 2026 PDF, ACN roles and procedures FAQs).

Information that must be governed

The Vademecum lists the following information categories:

  • entity identification and contact data, including tax code, company name, registered office, legal representative, general attorneys, telephone number, digital domicile and a functional ordinary email address;
  • point-of-contact and substitute details;
  • CSIRT contact and substitute details;
  • details of natural persons serving on governing and management bodies;
  • secretariat details, where present;
  • applicable services offered in the European Union and the relevant Member States;
  • public static IP addresses and domain names used or available to the entity;
  • information-sharing agreements;
  • relevant suppliers;
  • for certain entity types, main establishment and other EU establishments or representative details.

This is a cross-functional dataset. Legal, corporate affairs, HR, IT infrastructure, security operations, procurement and compliance may each own part of it. A single accountable data register is safer than collecting the fields from scratch during the filing window (ACN information-update FAQs).

3. Categorization Connects Services to Proportionate Measures

Activity and service categorization is the process through which a NIS entity performs a simplified impact analysis using a harmonized model and shares the outcome with ACN. Its purpose is to support proportionate security-measure obligations.

The recurring window runs from 1 May to 30 June through Servizio NIS/Categorizzazione. The exercise should not be treated as a purely technical inventory. It requires a defensible mapping between the legal entity, the activities and services within NIS scope, their operational dependencies and the impact assumptions used in the model (ACN categorization area, ACN categorization FAQs).

An effective preparation set includes:

  • a stable catalogue of in-scope activities and services;
  • service owners and accountable business functions;
  • supporting systems, suppliers and operational dependencies;
  • impact-analysis inputs and approval evidence;
  • reconciliation with relevant-supplier and public-asset data;
  • a change log showing why a category changed from the previous cycle.

A Governance Model for the Annual Cycle

The Vademecum's dates form one connected governance cycle:

  1. Scope owner: maintains registration assumptions and the entity-level applicability assessment.
  2. Point of contact: coordinates portal submissions and formal interactions with ACN.
  3. Information owners: maintain legal, technical, organizational and supplier data.
  4. CSIRT contact: owns the operational interface for significant-incident notification.
  5. Service owners: validate activity and service categorization inputs.
  6. Governing and management bodies: exercise the oversight and approval responsibilities assigned by the NIS decree.

For each submission, the organization should retain the source data, reviewer, approval, portal receipt and resulting ACN communication. This makes later updates reproducible and reduces contradictions across registration, information updates, incident processes and categorization.

Operational Checklist

Before 1 January

  • Reconfirm legal entities and their NIS status.
  • Review point-of-contact authority and portal access.
  • Collect material changes since the previous declaration.
  • Reconcile services, suppliers, domains and public IP addresses.

During 1 January-28 February

  • Submit a new or updated NIS declaration.
  • Validate that the declaration matches current corporate and operational evidence.
  • Retain the submission receipt and working papers.

By 14 April

  • Record ACN's inclusion, continued-inclusion or removal communication.
  • Confirm which entity cohort and implementation dates apply.
  • Update the compliance plan if status or classification changed.

During 15 April-31 May

  • Verify every information category against its authoritative internal source.
  • Confirm role holders and contact data.
  • Submit updates and preserve evidence of review.

During 1 May-30 June

  • Revalidate the activity and service catalogue.
  • Complete the harmonized impact analysis.
  • Reconcile categorization outcomes with security-measure planning.

Throughout the year

  • Trigger the 14-day update workflow whenever shared information changes.
  • Maintain incident-notification readiness.
  • Track the baseline-measure deadline applicable to the inclusion cohort.
  • Keep documents, registers, technical evidence and portal data consistent.

Common Interpretation Errors

Treating 28 February as the only NIS deadline

It is only the end of the registration window. Information updates, categorization, incident notification and security measures have separate schedules.

Reading October 2026 as one identical day for every 2025 entity

The Vademecum provides a month-level summary, while its footnote ties the exact baseline-measure deadline for timely 2025 registrants to 18 months from the inclusion communication.

Waiting for the annual window to report a change

The annual verification does not replace the obligation to update changed information promptly and within 14 days.

Assigning every field to the cybersecurity team

Many required data points belong to legal, corporate, HR, procurement or infrastructure owners. Cybersecurity can coordinate the process but cannot authoritatively maintain every source record.

Treating categorization as a standalone questionnaire

The result affects proportionate security obligations and should be supported by service ownership, dependencies and documented impact assumptions.

Frequently Asked Questions

Who is the Vademecum addressed to?

It is addressed to organizations formally notified of inclusion or continued inclusion in the list of essential and important NIS entities.

Must an entity already on the NIS list register again in 2027?

The Vademecum states that every year, from 1 January to 28 February, all NIS entities must register or update registration by submitting a new NIS declaration.

When must changed information be updated?

Updates must be made promptly and, in any case, within 14 days of the change.

When does activity and service categorization take place?

The annual window runs from 1 May to 30 June through the ACN NIS categorization service.

Is October 2026 the precise baseline-measure deadline for every entity listed in 2025?

Not necessarily. The Vademecum summarizes the milestone as October 2026, but for entities registered by 28 February 2025 it states that the exact deadline is 18 months after receipt of the inclusion communication.

Where must NIS communications be submitted?

The Vademecum states that communications to the national competent NIS authority must be made through the NIS services on the ACN services portal, after the required authentication, user registration and association with the organization.

Conclusion

The ACN Vademecum turns the NIS framework into a recurring operating calendar. Its main value is not the list of dates alone, but the connection between scope, roles, information quality, incident readiness, security measures and service impact. Organizations should manage the calendar as one evidence-driven process, while calculating cohort-specific deadlines from formal ACN communications and the applicable determinations.

We can help you build that operating model: deadline control, responsibility mapping, information registers, document and evidence review before each ACN portal window. We start from NIS 2 consulting and Cyber Console, the compliance platform for NIS 2 and ISO/IEC 27001.

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 27, 2026

NIS Entity List Update: Late Registrations, Reviews and the 2027 Window

On 18 September 2026 ACN announced an update of the NIS entity list after more than 2,000 late registrations and about 2,000 reviews, and confirmed t…

February 12, 2026

NIS 2 baseline deadline October 2026: 8-month implementation roadmap

With the NIS 2 baseline adoption deadline set for October 2026, organizations have roughly 8 months left. This guide provides a compressed, phased ro…

February 11, 2026

NIS 2 KPIs and continuous improvement: operational metrics for resilient compliance

ACN guidance frames improvement as a continuous phase across the full incident lifecycle. This guide provides a practical KPI framework, governance r…