NIS Entity List Update: Late Registrations, Reviews and the 2027 Window

On 18 September 2026 ACN announced an update of the NIS entity list after more than 2,000 late registrations and about 2,000 reviews, and confirmed the 1 January to 28 February 2027 registration window. What the figures do and do not say, and how to prepare.

September 27, 2026 6 min read

Compliance officer completing an online registration on a laptop Made with AI
Contents
  1. In Brief
  2. The NIS Entity List Is Being Updated
  3. The 2027 Registration and Update Window
  4. Governance: What Management Bodies Should Control
  5. A Practical Preparation Plan for the 2027 Cycle
  6. Frequently Asked Questions
  7. Conclusion
  8. Related Reading
  9. Official Sources

Applies to: organizations that filed late or requested a review, entities already included in the Italian NIS list, and entities that must register or update their data in 2027.

On 18 September 2026, Italy's National Cybersecurity Agency (ACN) announced an update to the NIS entity list, after examining more than 2,000 late registrations and around 2,000 review proceedings, and confirmed the next registration or update window, from 1 January to 28 February 2027 (ACN announcement). The same announcement opened the consultation on reinforced security measures, covered in a separate article.

In Brief

  • The list update concerns more than 2,000 late registrations and approximately 2,000 review proceedings examined by ACN between May and July 2026.
  • Those aggregate figures do not mean that roughly 4,000 entities were automatically added to the list: ACN does not disclose that outcome in the announcement.
  • The next annual registration or data-update window runs from 1 January through 28 February 2027.
  • The 2027 window does not postpone earlier obligations: ACN's Vademecum notice identifies October 2026 as the baseline-measures deadline for entities included in the NIS list in 2025.
  • Organizations should prepare evidence, portal roles, corporate data and governance decisions before the window opens rather than treating registration as a last-minute filing.

The NIS Entity List Is Being Updated

The announcement followed a plenary meeting of ACN's NIS Implementation Table with sector authorities and regional representatives. ACN states that the update concerns more than 2,000 late registrations and around 2,000 review proceedings analyzed from May to July 2026. This indicates a material administrative review after the ordinary registration cycle, but the announcement does not provide a breakdown of accepted, rejected or still-pending cases (ACN announcement).

What the numbers do not establish

The two case volumes should not be added together and presented as a confirmed number of new NIS entities. The official notice does not state:

  • that every late registration resulted in inclusion;
  • that every review changed the previous classification;
  • whether any cases overlap;
  • the distribution between essential and important entities;
  • the sector-by-sector result of the update.

For an individual organization, the authoritative evidence remains its formal status and the information made available through the ACN process. Press-release totals are useful for understanding scale, not for determining whether a specific entity is in scope.

Practical checks for affected organizations

Organizations that submitted late or requested a review should preserve a traceable file containing:

  1. the registration or review submission and its receipt;
  2. ACN communications and portal notifications;
  3. the legal-entity and sector data used for the assessment;
  4. the internal rationale supporting the classification position;
  5. the decision trail for management and governing bodies.

This creates a defensible baseline if the status changes or if the organization must align data, contacts and compliance workstreams quickly.

The 2027 Registration and Update Window

ACN confirms that the next registration or update window opens on 1 January 2027 and closes on 28 February 2027 for public and private entities to which the NIS framework applies. ACN's September 2026 Vademecum notice also presents this as the recurring annual cycle through the ACN services portal (ACN announcement, ACN NIS Vademecum notice).

The action depends on the entity's position:

Organization profile Expected preparation
Potentially in scope and not yet registered Revalidate legal entity, sector, size and service-scope assumptions; prepare the registration evidence.
Already included in the NIS list Reconcile the data that must be updated or confirmed for the 2027 cycle.
Late registrant or review applicant Confirm the outcome of the ACN process before relying on the previous classification.
Group with several legal entities Assess each entity separately and maintain a documented group-level coordination model.

Registration is not merely a calendar event. The data submitted to ACN must remain coherent with corporate records, operational services, relevant suppliers, public digital assets, designated contacts and the organization's actual governance structure.

Do not combine the registration and security timelines

The 2027 portal window is separate from the implementation timetable for security measures. In its 11 September 2026 Vademecum notice, ACN identifies October 2026 as the first deadline for implementing baseline security measures for entities included in the NIS list in 2025. Organizations must therefore verify the timetable attached to their own inclusion cohort rather than treating 28 February 2027 as a general extension (ACN NIS Vademecum notice).

Governance: What Management Bodies Should Control

In its 14 July 2026 update, ACN states that approval of the documents required by Article 23 of the NIS decree is an exclusive responsibility of the collegiate body, or the monocratic body where applicable, and cannot be delegated. Operational implementation may instead be delegated to the competent functions (ACN update on governing-body FAQs).

Before the 2027 window, management should be able to answer four questions:

  1. Is the entity's NIS status confirmed and supported by current evidence?
  2. Are the point of contact, substitute and CSIRT roles current and formally assigned?
  3. Do portal data, corporate records and the actual service perimeter agree?
  4. Are baseline measures progressing against the deadline applicable to the entity's cohort?

A Practical Preparation Plan for the 2027 Cycle

Phase 1: Confirm status and ownership

  • Verify the result of any late registration or review proceeding.
  • Identify the accountable legal entity and executive sponsor.
  • Confirm portal users and escalation paths.

Phase 2: Reconcile data and scope

  • Compare corporate data with the information already held in the ACN workflow.
  • Recheck activities, services, public domains and IP resources.
  • Validate relevant suppliers and cross-functional data owners.

Phase 3: Approve and submit

  • Escalate strategic decisions to the appropriate governing body.
  • Perform a factual and document consistency review before submission.
  • Retain approvals, evidence and portal receipts after the filing.

This workflow reduces a recurring risk: filing correct-looking data that does not match the operating reality.

Frequently Asked Questions

Were about 4,000 organizations added to the NIS list?

ACN reports more than 2,000 late registrations and around 2,000 review proceedings, but does not say that every case resulted in inclusion or that the two populations can be summed without overlap.

When is the next NIS registration or update window?

It runs from 1 January to 28 February 2027, according to the ACN announcement.

Does an existing NIS entity need to wait until January to prepare?

No. Status evidence, portal roles, legal-entity data, service scope, relevant suppliers and governance approvals can be reconciled before the filing window opens.

Can the governing body delegate approval of the strategic NIS documents?

ACN's updated FAQs state that approval of the Article 23 documents cannot be delegated. Operational implementation activities can be assigned to the competent organizational functions (ACN FAQ update).

Conclusion

The list update closes a significant administrative phase, but for an individual entity only its own formal status counts. The priority is to confirm it, meet the baseline deadline applicable to its cohort and reach the 1 January-28 February 2027 window with data and governance evidence already reconciled.

We can help you prepare the 2027 cycle: scope verification, documentation review, responsibility mapping and evidence management before ACN submissions, through NIS 2 consulting and the NIS 2 documentation audit.

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 27, 2026

ACN NIS Vademecum 2026: Compliance Calendar and Operational Checklist

ACN's NIS Vademecum 1.0 (September 2026) puts the NIS obligations on one calendar: six obligation families, three recurring annual windows and differ…

February 12, 2026

NIS 2 baseline deadline October 2026: 8-month implementation roadmap

With the NIS 2 baseline adoption deadline set for October 2026, organizations have roughly 8 months left. This guide provides a compressed, phased ro…

February 11, 2026

NIS 2 KPIs and continuous improvement: operational metrics for resilient compliance

ACN guidance frames improvement as a continuous phase across the full incident lifecycle. This guide provides a practical KPI framework, governance r…