ACN supervision under NIS 2: inspections, orders and fines

For entities placed on the NIS list in April 2025, ACN gives October 2026 as the deadline for the baseline measures. How ACN supervises after that: monitoring and self-assessments, ex ante inspections for essential entities and ex post for important ones, orders and formal notices, fines up to 2% of turnover. With the deadlines for each cohort, late registrations included, and a checklist for the evidence file.

October 10, 2026 12 min read

An auditor taking notes during an interview with an IT manager Made with AI
Contents
  1. In brief
  2. Deadlines by cohort
  3. How ACN supervision works: the four areas
  4. Essential and important entities: ex ante and ex post inspections
  5. Enforcement measures: warnings, formal notices, orders
  6. Penalties
  7. What to prepare: the evidence file

For entities placed on the NIS list in spring 2025, October 2026 is the month the National Cybersecurity Agency (ACN) gives for completing the baseline security measures. Once that deadline passes, the question for management changes: what can ACN check, what can it ask for, and with what consequences. This guide answers from the official texts: D.Lgs. 138/2024, ACN's determinations and its FAQ on monitoring, supervision and enforcement.

In brief

  • For entities placed on the NIS list in 2025 the deadline is eighteen months from receipt of the communication of inclusion (ACN Determination 379907/2025, art. 3): for those who received it on 12 and 13 April 2025, ACN gives October 2026; those placed on the list later in 2025 count eighteen months from their own communication.
  • Entities listed for the first time in 2026 have their own terms: incident notification from 1 January 2027 and baseline measures by 31 July 2027.
  • ACN's supervision covers four areas: monitoring, analysis and support; checks and inspections; enforcement measures; penalties.
  • Essential entities can be inspected ex ante, including random checks. Important entities only when ACN has evidence suggesting possible violations.
  • Fines reach EUR 10 million or 2% of worldwide annual turnover, whichever is higher, for essential entities, and EUR 7 million or 1.4% for important ones. A missing or late registration raises the most serious penalty up to three times.
  • ACN's first request may be a report, including a self-assessment and an implementation plan: keep an evidence file ready.

Deadlines by cohort

The terms depend on the year of inclusion in the list and on the date you received ACN's communication. Determination 379907/2025, which replaces 164179/2025 from 15 January 2026 (art. 9), sets eighteen months for the baseline measures and nine months for the notification of significant incidents. Both run from receipt of the communication of inclusion (art. 3, paragraphs 1 and 2).

EntitiesNotification of significant incidentsBaseline security measuresSource
Listed with the communications of 12 and 13 April 2025Nine months from the communication: ACN gives January 2026Eighteen months from the communication: ACN gives October 2026ACN Det. 379907/2025, art. 3; ACN page on the baseline specifications; FAQ ELN.1
Listed later in 2025, including after a late registrationNine months from their own communicationEighteen months from their own communicationACN Det. 379907/2025, art. 3; FAQ MSB.3
Listed for the first time in 2026From 1 January 2027By 31 July 2027ACN Det. 127434/2026, art. 1
Late registrations in the September 2026 list updateNo specific term published by ACNNo specific term published by ACNACN news of 18 September 2026

The months in the table are those ACN gives for entities that received the communication on 12 and 13 April 2025. The legal term remains eighteen months from receipt, as ACN's NIS Vademecum of September 2026 also notes. For entities listed in 2025 the same term applies to the obligations of the management bodies (D.Lgs. 138/2024, art. 42). Entities listed in 2025 that stay on the 2026 list keep these terms (ACN Det. 127434/2026, art. 1, paragraph 3).

In 2025 ACN extended the list to take account of hundreds of late registrations (ACN news of 23 December 2025). On 18 September 2026 it announced a further update, covering more than 2,000 late registrations and about 2,000 review requests. ACN had published no specific dates for these organisations as of 8 October 2026. Determination 127434/2026 applies to entities listed for the first time in 2026: notification from 1 January 2027, measures by 31 July 2027. Check the date and content of your communication. We covered the update in our article on the updated NIS list and the 2027 registration window, and the terms for new entities in the one on deadlines for new NIS entities in 2026.

Two deadlines concern every entity. The CSIRT referent must be designated by 31 December of the year of inclusion in the list (ACN Det. 127437/2026, art. 7, paragraph 1). The next registration or update window runs from 1 January to 28 February 2027. The full annual calendar is in our article on the NIS Vademecum 2026 and the compliance calendar.

How ACN supervision works: the four areas

Chapter V of D.Lgs. 138/2024 gives ACN, as the national competent NIS authority, four supervision tools (art. 34, paragraph 1). ACN's FAQ present them as four areas (FAQ MVE.1):

  1. Monitoring, analysis and support (art. 35). A systematic, continuous activity. It starts from the information submitted with the registration; where that is not enough, ACN can ask for a report, periodic if needed, "including self-assessments and implementation plans" (paragraph 3, letter a)). It can also ask for security audits and security scans, and issue recommendations and warnings on alleged violations (letters b), c) and d)).
  2. Checks and inspections (art. 36). Review of the documents submitted, on-site and remote inspections, including random checks, and requests for access to data, documents and information.
  3. Enforcement measures (art. 37). Orders and formal notices to comply, remedy shortcomings or stop a violation.
  4. Administrative fines and ancillary sanctions (art. 38).

According to ACN, support acts "before and independently of" the inspection and enforcement powers (FAQ MVE.2). The Agency says it works "with a gradual, risk-based approach" (FAQ MVE.1), and the decree allows it to prioritise its activities by risk (art. 34, paragraph 2). The FAQ mention no grace period after the deadline.

Security audits and scans requested or ordered by ACN are carried out by independent bodies. Their cost is borne by the audited entity, except in duly justified cases (art. 34, paragraph 7). Communications with ACN go primarily through the digital platform (art. 34, paragraph 9).

In every case ACN takes into account at least the following (art. 34, paragraph 6):

  • the seriousness of the violation: repeated violations, failure to notify significant incidents, failure to remedy after binding instructions, obstruction of supervision and false or grossly inaccurate information count as serious in particular;
  • the duration of the violation and any previous violations;
  • the material or non-material damage caused;
  • intentional conduct or negligence;
  • the measures taken to prevent or mitigate the damage;
  • adherence to approved codes of conduct or certification mechanisms;
  • the level of cooperation with ACN.

Some of these can be documented before any check: the measures in place, notifications sent on time, prompt answers to requests.

Essential and important entities: ex ante and ex post inspections

The tools are the same; the threshold for using them is not (FAQ MVE.3).

AspectEssential entitiesImportant entities
Checks and on-site or remote inspectionsAlso ex ante, including random checksOnly ex post: when ACN obtains or receives evidence, indications or information suggesting possible violations (art. 36, paragraph 2)
Security audits ordered by ACNPeriodic or targetedTargeted only: ACN cannot require periodic audits (art. 37, paragraph 3, letter a))
Maximum fine for the obligations of articles 23, 24 and 25EUR 10 million or 2% of worldwide annual turnoverEUR 7 million or 1.4% of worldwide annual turnover
Suspension of certificates or authorisations after an unheeded formal noticePossible (art. 38, paragraph 4)Not provided for
Temporary incapacity to hold management functions after an unheeded formal noticePossible (art. 38, paragraph 6)Possible (art. 38, paragraph 6)

For an important entity, then, an inspection follows something that points to a violation. Monitoring under article 35, with its requests for reports and self-assessments, applies to every NIS entity. The other differences between the two categories, starting with the number of baseline measures, are in our guide on essential and important entities in the baseline specifications.

Enforcement measures: warnings, formal notices, orders

Warnings belong to the monitoring phase: ACN can issue recommendations and warnings on alleged violations (art. 35, paragraph 3, letter d)). The enforcement measures proper are in article 37 and take into account the results of monitoring and inspections (paragraph 1). With these powers ACN can:

  • ask for the data that show security policies are implemented, such as audit results and the underlying evidence (paragraph 2);
  • order the entity to carry out security audits or scans, implement the recommendations of an audit, meet its obligations, stop conduct that breaches the decree, follow binding instructions or remedy shortcomings (paragraph 3);
  • order the entity to inform the recipients of its services of significant incidents, inform the public or make violations public (paragraph 3, letters g), h), i) and l));
  • order compliance with binding instructions to prevent an incident or remedy it (paragraph 4);
  • appoint one of its officials to support the entity for a set period, including on-site and remote visits (paragraph 5).

If the entity does not comply, ACN issues a formal notice (diffida) (paragraph 6), setting reasonable and proportionate methods and terms (paragraph 7). Before an order or a formal notice it notifies its preliminary conclusions and allows at least fifteen days for observations (paragraph 8). The exception is when immediate action is needed to prevent or respond to an incident (paragraph 9).

Enforcement measures do not rule out penalties. ACN writes that using enforcement powers "does not preclude the exercise of sanctioning powers" (FAQ MVE.4), and the decree says the same (art. 38, paragraph 3). Fifteen days for documented observations is short if the evidence has to be found after the notification.

Penalties

The violations are the same for everyone; the amounts and ancillary sanctions change depending on whether the entity is essential, important or a public administration (FAQ MVE.5). Article 38 sets two groups of violations.

ViolationsEssential entitiesImportant entitiesPublic administrations
Obligations of the management bodies (art. 23), risk management measures (art. 24), incident notification (art. 25); failure to comply with orders and formal notices (paragraph 8)Up to EUR 10,000,000 or 2% of worldwide annual turnover in the previous financial year, whichever is higher; minimum one twentieth of the maximumUp to EUR 7,000,000 or 1.4% of worldwide annual turnover, whichever is higher; minimum one thirtieth of the maximumEssential: EUR 25,000 to 125,000; important: amounts reduced by one third
Registration, communication or update of information (art. 7); list and categorisation of activities and services (art. 30); certification, domain names and sector rules (arts. 27, 29 and 32); failure to cooperate with ACN or CSIRT Italia (paragraph 10)Up to 0.1% of worldwide annual turnoverUp to 0.07% of worldwide annual turnoverEssential: EUR 10,000 to 50,000; important: amounts reduced by one third

For the second group, paragraph 11 keeps the minimum amounts of paragraph 9. Turnover is calculated under Recommendation 2003/361/EC; the public administrations column covers those in Annex III and some types in Annex IV. Three rules increase or accompany the fine:

  • Missing or late registration. All violations in both groups are charged and the penalty for the most serious one applies, increased up to three times (paragraph 13).
  • Repeat violations. If the same provision is breached again, the penalty increases up to double; for different violations the most serious one applies, increased up to three times (paragraph 12, with article 8-bis of Law 689/1981).
  • Ancillary sanctions. If a formal notice is not met within its terms, ACN can suspend, or ask for the suspension of, a certificate or authorisation of the essential entity (paragraph 4, not applicable to public administrations). It can also impose a temporary incapacity to hold management functions on the management bodies, the chief executive or the legal representative of essential and important entities (paragraph 6).

The natural persons responsible for an essential entity, or who represent it, ensure compliance with the decree and can be held liable for failures (paragraph 5). In every NIS entity the management bodies are responsible for violations (art. 23, paragraph 1). We cover this in our guide on the obligations of management bodies under article 23.

Finally, the decree provides two tools to settle cases (paragraph 15). The first is the invitation to comply: if the offender complies within the term set, the procedure stops; it does not apply to repeat violations or to entities that have already received a formal notice. The second is payment of a reduced amount within sixty days of notification of the charge: one third of the maximum or, where more favourable and where set, twice the minimum. How these tools apply is left to a decree of the President of the Council of Ministers (art. 40, paragraph 1, letter c)).

What to prepare: the evidence file

Almost every ACN tool starts with a request for documents: a report or self-assessment (art. 35), a review of the documents submitted (art. 36), the data that show policies are implemented (art. 37). Keep a single, current, dated file you can answer from within the terms set. This checklist follows the obligations of the decree and the baseline measures:

  • Position on the list. Communication of inclusion with its date of receipt, category of essential or important entity, receipts of the registration and of the annual updates (art. 7), list and categorisation of activities and services (art. 30).
  • Roles. Point of contact and substitute, CSIRT referent and any substitutes, with the designation records.
  • Management bodies. Resolutions approving how the measures are implemented, records of the training attended, minutes showing the bodies are informed of incidents and notifications (art. 23).
  • Baseline measures. For each requirement in the annex for your category (Annex 1 for important entities, Annex 2 for essential ones): the reference document, who approved it and when, evidence of implementation. The measures are described in our guide to the baseline obligations set by ACN.
  • Self-assessment and plan. A current self-assessment and an implementation plan with priorities, owners and dates: these are the documents article 35 names. You can start from our NIS 2 self-assessment checklist.
  • Incidents. Incident register, the criteria used to assess significance, the early warnings, notifications and final reports sent to CSIRT Italia, with their sending times (art. 25).
  • Audits and tests. Results of audits, scans and tests, with the corrective actions and their status.
  • Suppliers. Inventory of suppliers with potential security impact and security requirements written into contracts (measures GV.SC-04 and GV.SC-05).
  • Dealings with ACN. Log of requests received, answers sent and terms set.

If some measures are not complete yet, the plan records the state of implementation and the expected dates: that is the information ACN can ask for in a report. The steps to get there are in our roadmap to the baseline measures deadline. For a first picture of your posture, the Cyber Check-up returns your company's cyber profile and priorities; to build or complete the programme, we support you through NIS 2 compliance.

If you want to know how your file would hold up to an ACN request, we review it with you in a NIS 2 documentation audit, with the findings and a remediation plan.

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 16, 2026

NIS 2 Compliance Documentation Audit: How the Scoring Methodology Works

Aegister’s scoring methodology evaluates NIS 2 documents at requirement-point level across 5 dimensions on a 0-4 scale. This guide covers the scoring…

February 14, 2026

NIS 2 Documentary Evidence and Audit Readiness: How to Structure Compliance Proof

ACN baseline guidance requires documentary evidence as a core compliance element. Practical guide to evidence families, obligation-to-evidence mappin…

February 13, 2026

Compliance Documentation Audit for NIS 2 Baseline Obligations: Method Overview

A Compliance Documentation Audit maps NIS 2 documents to baseline requirements, scores maturity on a 0-4 scale, verifies evidence traceability, and c…