The plenary meeting of the National Cybersecurity Agency’s [NIS](https://www.acn.gov.it/portale/nis) Implementation Working Group, attended by the sectoral authorities and regional representatives, examined in greater detail the determinations adopted by the Director General of ACN. An **update of the list of NIS entities** was ordered, covering more than 2,000 late registrations and approximately 2,000 review proceedings examined by ACN between May and July. This activity forms part of the collaborative implementation process pursued by ACN in its capacity as the national NIS authority, with a view to ensuring effective oversight of the country’s productive system.
A **consultation on strengthened security measures** has also been launched. The measures have been developed in accordance with the principles of proportionality and gradual implementation underpinning the NIS framework. The consultation process, conducted **through the sectoral working groups**, is intended to supplement and replace the baseline security measures adopted during the initial implementation phase of the NIS Decree.
This is the third consultation through which the Agency, together with the sectoral authorities, has invited constructive engagement with the sectors concerned regarding the implementing measures under the NIS Decree. Contributions received will be taken into account during the Authority’s review process, in accordance with the principle of participatory regulation that characterises ACN’s approach.
The Working Group also recalled that the **new registration or update window** for public and private entities falling within the scope of the NIS framework will open on 1 January 2027. Registration will close on 28 February 2027.
Since mid-September, the [NIS Handbook](https://www.acn.gov.it/portale/nis) has also been available, providing general guidance on the main compliance obligations and related deadlines, as well as specific guidance on selected topics.
The first upcoming deadline, in October, concerns the implementation of the baseline security measures by entities included in the NIS list in 2025.
The next deadline concerns registration for 2027. As in each year, from 1 January to 28 February all NIS entities are required to complete or update their online registration by accessing ACN’s services portal.
The specific guidance also addresses the updating of information and the categorisation of activities and services.
Registration, in addition to being a mandatory compliance requirement, is the first step towards becoming part of the community of NIS entities and gaining access to the support activities provided by ACN and CSIRT Italia within a framework of participatory regulation and cooperative compliance.
By updating its information, a NIS entity shares with the competent national NIS authority (ACN) the information required under the NIS Decree, thereby enhancing the protection of the entity’s networks and information systems, as well as those of the country as a whole, including through strengthened analyses aimed at safeguarding the systemic relevance of the supply chain.
Through the categorisation of activities and services, the [NIS](https://www.acn.gov.it/portale/nis) entity also carries out a simplified impact assessment based on a harmonised model and shares the outcome with ACN, in order to determine proportionate obligations concerning security measures.
Further information is available in the section dedicated to the NIS framework and in the frequently asked questions published on the institutional website of the National Cybersecurity Agency (ACN).