ACN publishes NIS Vademecum: what changes for registration and security measures

ACN has published the Vademecum for NIS subjects: not an informational note, but the document the Italian authority will use from now on to read registration, security measures and incident notifications from essential and important entities. It contains two precise deadlines worth putting on the calendar right away.
On September 11, 2026, Italy's National Cybersecurity Agency (ACN) made the Vademecum for NIS (Network and Information Security) subjects available online — the operational document through which the national authority competent for NIS2 obligations clarifies how it intends to read registration, security measures and incident notifications from essential and important entities in Italy.
Two deadlines to note right away
The Vademecum is not a statement of principles: it sets operational deadlines.
October 2026. By this month, entities added to the NIS roster during 2025 must have implemented the required basic security measures. This is not a soft deadline: it is the first concrete compliance check for the cohort of entities registered last year.
January 1 – February 28, 2027.The window for annual registration and updates through ACN's service portal. This applies to all NIS subjects, not just new registrants: it's when previously submitted information must be reviewed and confirmed.
The mechanism worth noting: proportionality through categorization
The most useful point in the Vademecum, from a compliance standpoint, isn't the deadline itself but the mechanism attached to it: updating information is tied to the categorization of the entity's activities and services. In practice, ACN uses this classification to enable a simplified impact analysisand to calibrate security obligations proportionally to the organization's actual profile — not an identical set of requirements for every NIS subject regardless of size or the criticality of the services it provides.
For an organization already within the NIS2 perimeter, this means that describing one's activities and services on the ACN portal isn't an isolated bureaucratic task: it's the input that determines, in practice, what the authority will expect in terms of security measures.
Why it pays to act now, not in February 2027
Anyone already running a NIS2 gap analysis — or mapping existing ISO/IEC 27001 controls — has a concrete reason to revisit that work in light of this document, before the 2027 registration window opens:
- The activity/service categorization reported to ACN must be consistent with what the internal gap analysis has found — a mismatch here translates into a poorly calibrated security obligation, not just a formal issue.
- Entities registered in 2025 have an October 2026 deadline on baseline measures: that's a near-term deadline, not a 2027 horizon.
- Existing ISO/IEC 27001 controls need to be mapped, one by one, to the risk profiles implied by the new ACN classification — that's the alignment work that turns the document into an operational starting point, not just something to read.
The Vademecum, in other words, is the reference to use to speak the same language as the competent authority — not a document to file away until the deadline arrives.
Sources
- ACN — Agenzia per la Cybersicurezza Nazionale, "Online il Vademecum per i soggetti NIS" (NIS Vademecum published), September 11, 2026.
Does your NIS2 categorization hold up under ACN's reading?
We support essential and important entities with NIS2 gap analysis and ISO/IEC 27001 control mapping, to reach the registration window with a consistent classification and security measures already aligned.
Talk to us →