The Italian National Cybersecurity Agency (Agenzia per la cybersicurezza nazionale – ACN) has updated its FAQs on the NIS framework, introducing new FAQs MVE.1, MVE.2, MVE.3, MVE.4 and MVE.5 concerning monitoring, supervision and enforcement activities.
FAQ MVE.1 clarifies that supervision and enforcement activities are structured around four areas: monitoring, analysis and support; audits and inspections; enforcement measures; and administrative pecuniary and ancillary sanctions. Through these activities, the Agency monitors and assesses compliance by NIS entities with their applicable obligations. The same FAQ confirms that such activities are carried out through a gradual, risk-based approach, in accordance with the principles of effectiveness, proportionality and deterrence, while taking into account the specific circumstances of each case.
With regard to monitoring, analysis and support, FAQ MVE.2 highlights their systematic and ongoing nature and their purpose of supporting NIS entities in the implementation of their obligations. More specifically, the FAQ explains that, through monitoring, the Agency gathers the information necessary to assess the status of implementation of the applicable obligations; through analysis, it evaluates the resulting findings; and through support activities, it assists NIS entities, including by means of recommendations, guidelines and awareness-raising initiatives.
As regards audits and inspections, FAQ MVE.3 clarifies that ex ante inspection activities may be carried out only in respect of essential entities.
FAQ MVE.4 further specifies that, through enforcement measures, the Agency may require NIS entities to bring their conduct into compliance with the applicable obligations, remedy identified deficiencies or cease conduct carried out in breach of such obligations, including through formal orders and notices to comply.
Finally, FAQ MVE.5 clarifies that the amount of pecuniary sanctions and the scope of ancillary measures vary depending on whether the entity concerned qualifies as an essential entity, an important entity or a Public Administration.