Applies to: essential and important NIS entities already implementing the baseline measures, and the governance, risk and compliance functions planning how their controls will evolve.
On 18 September 2026, Italy's National Cybersecurity Agency (ACN) opened a consultation with sector tables on reinforced security measures. ACN says they are intended to supplement and replace the baseline measures adopted for the first implementation phase of the NIS decree, but the announcement publishes neither a final catalogue nor an effective date: the reinforced measures are not yet an obligation (ACN announcement).
In Brief
- The consultation is underway with sector tables; it is ACN's third consultation on NIS implementing measures.
- The measures are developed under the NIS principles of proportionality and graduality.
- Once adopted, they will supplement and replace the baseline measures of the first implementation phase.
- Until an official act says otherwise, the baseline framework remains the reference, with the deadlines already assigned to each cohort of entities.
- For entities included in the NIS list in 2025, the baseline-measures deadline remains October 2026.
What ACN Announced
The announcement followed a plenary meeting of ACN's NIS Implementation Table with sector authorities and regional representatives. Besides the consultation, it announced the update of the NIS entity list and the 2027 registration window, covered in a separate article.
On the reinforced measures, ACN states three things (ACN announcement):
- the consultation has started with the sector tables;
- the measures were developed using the NIS principles of proportionality and graduality;
- they are intended to supplement and replace the baseline measures adopted in the first implementation phase.
Baseline and Reinforced Measures: Where Things Stand
| Baseline measures | Reinforced measures |
|---|---|
| Existing first-application framework remains the current reference until officially superseded. | Sector consultation has started, but the announcement does not publish a final control catalogue or an effective date. |
| Current implementation and evidence work should continue. | Organizations can perform readiness analysis, but should label assumptions and avoid declaring future controls mandatory. |
| Deadlines already assigned to specific cohorts remain relevant. | Final scope, transition rules and timing must come from subsequent official acts. |
The October 2026 Deadline Still Stands
The consultation does not move the baseline-measures timetable. In its 11 September 2026 Vademecum notice, ACN identifies October 2026 as the deadline for implementing baseline security measures for entities included in the NIS list in 2025 (ACN NIS Vademecum notice). Each organization must verify the timetable attached to its own inclusion cohort.
Pausing the baseline program while waiting for the reinforced measures would therefore be the wrong response. A better approach is to continue closing current gaps while designing documentation, risk management and evidence collection so that stronger requirements can be incorporated without rebuilding the compliance model.
How to Prepare Without Anticipating Obligations
- Continue implementing the applicable baseline measures and collect evidence over time, not only close to the deadline.
- Keep consistent strategic documents, procedures, registers and evidence, so that a new requirement attaches to controls that are already traced.
- Create a controlled mapping area for reinforced measures, to be completed only once ACN publishes the final requirements.
- Label assumptions: in a work plan, a control expected from the reinforced measures should be marked as such, not as a current obligation.
- Bring the topic to the governing body with a precise question: can future reinforced measures be mapped into the existing risk and control model without losing traceability?
Frequently Asked Questions
Are the reinforced security measures already in force?
No. The September 2026 announcement says the measures are under consultation with sector tables and does not announce a final catalogue or effective date. The applicable baseline framework should continue to be implemented until an official act changes it.
Should work on the baseline measures be paused?
No. The reinforced measures will replace the baseline ones only once adopted, and the deadlines already assigned to each cohort remain valid, starting with October 2026 for entities included in 2025.
When will the final measures be published?
The 18 September 2026 announcement gives no date. Final scope, transition rules and timing will come from the official acts ACN adopts at the end of the consultation.
Conclusion
The consultation shows where the NIS framework is heading; it is not a new immediate obligation. The priority remains closing the baseline measures by the deadline of each entity's cohort, with documentation and evidence built to absorb more mature requirements once ACN publishes the final acts.
We can help you close the baseline measures and prepare the move to the reinforced ones, through NIS 2 consulting and Cyber Console, the compliance platform for NIS 2 and ISO/IEC 27001.
Related Reading
- NIS Entity List Update: Late Registrations, Reviews and the 2027 Window
- ACN NIS Vademecum 2026: Compliance Calendar and Operational Checklist
- NIS 2 baseline obligations in practice: master overview for governance, controls, and incident operations
- NIS 2 Article 24 in Practice: How to Implement Cybersecurity Risk-Management Measures