Applies to: organizations that filed late or requested a review, entities already included in the Italian NIS list, and entities that must register or update their data in 2027.
On 18 September 2026, Italy's National Cybersecurity Agency (ACN) announced an update to the NIS entity list, after examining more than 2,000 late registrations and around 2,000 review proceedings, and confirmed the next registration or update window, from 1 January to 28 February 2027 (ACN announcement). The same announcement opened the consultation on reinforced security measures, covered in a separate article.
In Brief
- The list update concerns more than 2,000 late registrations and approximately 2,000 review proceedings examined by ACN between May and July 2026.
- Those aggregate figures do not mean that roughly 4,000 entities were automatically added to the list: ACN does not disclose that outcome in the announcement.
- The next annual registration or data-update window runs from 1 January through 28 February 2027.
- The 2027 window does not postpone earlier obligations: ACN's Vademecum notice identifies October 2026 as the baseline-measures deadline for entities included in the NIS list in 2025.
- Organizations should prepare evidence, portal roles, corporate data and governance decisions before the window opens rather than treating registration as a last-minute filing.
The NIS Entity List Is Being Updated
The announcement followed a plenary meeting of ACN's NIS Implementation Table with sector authorities and regional representatives. ACN states that the update concerns more than 2,000 late registrations and around 2,000 review proceedings analyzed from May to July 2026. This indicates a material administrative review after the ordinary registration cycle, but the announcement does not provide a breakdown of accepted, rejected or still-pending cases (ACN announcement).
What the numbers do not establish
The two case volumes should not be added together and presented as a confirmed number of new NIS entities. The official notice does not state:
- that every late registration resulted in inclusion;
- that every review changed the previous classification;
- whether any cases overlap;
- the distribution between essential and important entities;
- the sector-by-sector result of the update.
For an individual organization, the authoritative evidence remains its formal status and the information made available through the ACN process. Press-release totals are useful for understanding scale, not for determining whether a specific entity is in scope.
Practical checks for affected organizations
Organizations that submitted late or requested a review should preserve a traceable file containing:
- the registration or review submission and its receipt;
- ACN communications and portal notifications;
- the legal-entity and sector data used for the assessment;
- the internal rationale supporting the classification position;
- the decision trail for management and governing bodies.
This creates a defensible baseline if the status changes or if the organization must align data, contacts and compliance workstreams quickly.
The 2027 Registration and Update Window
ACN confirms that the next registration or update window opens on 1 January 2027 and closes on 28 February 2027 for public and private entities to which the NIS framework applies. ACN's September 2026 Vademecum notice also presents this as the recurring annual cycle through the ACN services portal (ACN announcement, ACN NIS Vademecum notice).
The action depends on the entity's position:
| Organization profile | Expected preparation |
|---|---|
| Potentially in scope and not yet registered | Revalidate legal entity, sector, size and service-scope assumptions; prepare the registration evidence. |
| Already included in the NIS list | Reconcile the data that must be updated or confirmed for the 2027 cycle. |
| Late registrant or review applicant | Confirm the outcome of the ACN process before relying on the previous classification. |
| Group with several legal entities | Assess each entity separately and maintain a documented group-level coordination model. |
Registration is not merely a calendar event. The data submitted to ACN must remain coherent with corporate records, operational services, relevant suppliers, public digital assets, designated contacts and the organization's actual governance structure.
Do not combine the registration and security timelines
The 2027 portal window is separate from the implementation timetable for security measures. In its 11 September 2026 Vademecum notice, ACN identifies October 2026 as the first deadline for implementing baseline security measures for entities included in the NIS list in 2025. Organizations must therefore verify the timetable attached to their own inclusion cohort rather than treating 28 February 2027 as a general extension (ACN NIS Vademecum notice).
Governance: What Management Bodies Should Control
In its 14 July 2026 update, ACN states that approval of the documents required by Article 23 of the NIS decree is an exclusive responsibility of the collegiate body, or the monocratic body where applicable, and cannot be delegated. Operational implementation may instead be delegated to the competent functions (ACN update on governing-body FAQs).
Before the 2027 window, management should be able to answer four questions:
- Is the entity's NIS status confirmed and supported by current evidence?
- Are the point of contact, substitute and CSIRT roles current and formally assigned?
- Do portal data, corporate records and the actual service perimeter agree?
- Are baseline measures progressing against the deadline applicable to the entity's cohort?
A Practical Preparation Plan for the 2027 Cycle
Phase 1: Confirm status and ownership
- Verify the result of any late registration or review proceeding.
- Identify the accountable legal entity and executive sponsor.
- Confirm portal users and escalation paths.
Phase 2: Reconcile data and scope
- Compare corporate data with the information already held in the ACN workflow.
- Recheck activities, services, public domains and IP resources.
- Validate relevant suppliers and cross-functional data owners.
Phase 3: Approve and submit
- Escalate strategic decisions to the appropriate governing body.
- Perform a factual and document consistency review before submission.
- Retain approvals, evidence and portal receipts after the filing.
This workflow reduces a recurring risk: filing correct-looking data that does not match the operating reality.
Frequently Asked Questions
Were about 4,000 organizations added to the NIS list?
ACN reports more than 2,000 late registrations and around 2,000 review proceedings, but does not say that every case resulted in inclusion or that the two populations can be summed without overlap.
When is the next NIS registration or update window?
It runs from 1 January to 28 February 2027, according to the ACN announcement.
Does an existing NIS entity need to wait until January to prepare?
No. Status evidence, portal roles, legal-entity data, service scope, relevant suppliers and governance approvals can be reconciled before the filing window opens.
Can the governing body delegate approval of the strategic NIS documents?
ACN's updated FAQs state that approval of the Article 23 documents cannot be delegated. Operational implementation activities can be assigned to the competent organizational functions (ACN FAQ update).
Conclusion
The list update closes a significant administrative phase, but for an individual entity only its own formal status counts. The priority is to confirm it, meet the baseline deadline applicable to its cohort and reach the 1 January-28 February 2027 window with data and governance evidence already reconciled.
We can help you prepare the 2027 cycle: scope verification, documentation review, responsibility mapping and evidence management before ACN submissions, through NIS 2 consulting and the NIS 2 documentation audit.
Related Reading
- NIS Reinforced Security Measures: ACN Opens the Consultation
- ACN NIS Vademecum 2026: Compliance Calendar and Operational Checklist
- ACN NIS Platform: Registration, Annual Update, and Continuous Update
- NIS Activity and Service Categorization: ACN Publishes the 2026 Model