INDUSTRIES, TECHNOLOGY | ACN releases new FAQs on NIS2 obligations

On 14 July 2026, the Italian Cybersecurity Authority (ACN) announced the release new updates to the FAQs on NIS2 obligations applicable to the management bodies of essential and important entities under Article 23 of Legislative Decree No. 138/2024 (the NIS 2 Decree) implementing the NIS2 Directive. The FAQs represent an important interpretative tool, providing practical guidance on the governance obligations introduced by the NIS2 framework.

In particular, ACN updated FAQs ODA.8 and ODA.9, clarifying the extent to which management bodies may delegate the performance of their duties under Art. 23 of NIS2 Decree. ACN confirms that operational activities may be delegated, while the management body retains overall responsibility for the actions of its delegates. The approval of the cybersecurity measures required under the NIS2 framework, however, remains a non-delegable responsibility of the management body acting collectively.

ACN also introduced new FAQs ODA.10, ODA.11 and ODA.12. FAQ ODA.10 clarifies that the documents requiring approval by the management body (identified in the relevant ACN guidelines) need to contain the information necessary for the management body to exercise its management, strategic planning and oversight functions. Those documents may subsequently be supplemented by delegates with additional technical and operational details.

Finally, FAQs ODA.11 and ODA.12 specify that these supplementary technical documents, and any subsequent updates to them, do not require approval by the management body. ACN also confirms that entities remain free to organise their internal documentation system in the manner they consider most effective.

Newsletter n. 120 – July 2026