NIS: what changes for regulated entities — updated register, reinforced security measures and the 2027 registration window

22 Sep , 2026 - News

NIS: what changes for regulated entities — updated register, reinforced security measures and the 2027 registration window

On 18 September 2026 the Italian National Cybersecurity Agency (ACN) announced important news for NIS entities: the update of the register of regulated organisations, the launch of the consultation on the new reinforced security measures, and the date of the next registration window. At the same time, the Agency published the Vademecum NIS, which gathers the calendar of obligations into a single document. For companies included among essential and important entities, it is time to take stock and get compliant.

The September 2026 news

The NIS Implementation Board — bringing together ACN, the sector Authorities and regional representatives — ordered the update of the register of NIS entities, covering more than 2,000 late registrations and about 2,000 review proceedings, analysed by ACN between May and July.

The most significant development looking ahead is the launch of the consultation on reinforced security measures: designed around the principles of proportionality and gradualness, they will integrate and replace the basic security measures adopted in the first phase of the decree. It is the third consultation through which the Agency involves the interested sectors via the sector tables.

Finally, a date for the diary: from 1 January to 28 February 2027 a new registration window opens — or update — for the public and private entities to which NIS applies.

The six obligations for NIS entities

The Vademecum recalls that the NIS decree (Legislative Decree 138/2024) sets six main obligations for the organisations on the register:

  • Registration and its update (art. 7, para. 1)
  • Transmission and update of information (art. 7, para. 4)
  • Obligations for administrative and management bodies (art. 23)
  • Cybersecurity risk-management measures (art. 24)
  • Incident notification (art. 25)
  • Listing and categorisation of activities and services (art. 30)
NIS — the 6 obligations of the decree, FinGreenTech card

The calendar of obligations

The Vademecum sets precise time windows, recurring every year:

  • 1 January – 28 February: registration or its update on the ACN services portal. The outcome — inclusion, permanence or removal from the register — arrives by 14 April.
  • 15 April – 31 May: transmission or update of information. In case of changes, the update must in any case be made within 14 days.
  • 1 May – 30 June: categorisation of activities and services.

Added to these are the deadlines tied to the year of inclusion in the register:

  • Entities included in 2025: notification of significant baseline incidents to CSIRT Italia from January 2026, and adoption of basic security measures by October 2026.
  • Entities included in 2026: notification from January 2027, and basic security measures by July 2027.
NIS — calendar of obligations, FinGreenTech card

What it means in practice, and how to get ready

Being a NIS entity is not just a formal box to tick: it means adopting verifiable technical and organisational measures, being able to notify an incident within the required timeframe, and involving top management, who are personally accountable. Turning obligations into concrete projects takes expertise and method.

FinGreenTech is an ACN-qualified supplier (QC2) and certified to ISO/IEC 27001, 27017, 27018, 22301 and 20000. We support organisations in preparing for risk-management measures (art. 24), in setting up incident-notification processes (art. 25), and in the registration and categorisation obligations on the ACN portal. The goal is to reach the deadlines ready, not chasing them.

Are you a NIS entity, or think you might be? Book a call with us to review your position and your compliance path. Write to info@fingreentech.com.

Sources: Italian National Cybersecurity Agency (ACN) — “News for NIS entities” (18 September 2026) and “Vademecum NIS” (September 2026).


Transparency note. This article was drafted with the support of artificial intelligence tools and reviewed by the FinGreenTech team, which holds editorial responsibility for it.


, , , , , ,

Leave a Reply

Your email address will not be published. Required fields are marked *