ACN security measures and implementation guidelines
NIS2 says what you must achieve, never how you demonstrate it. Italy answers with ACN measures. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
There is no ACN label to hold and no certification to obtain: compliance is demonstrated to the authority, not certified by a third party. Because the measures live in determinations rather than in the decree itself, they can be updated without a change in the law — check the current determination, not a summary.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is widely used in Italy as the underlying management system, but it does not replace the ACN determinations.
2 routes, chosen by scope and depth
The floor set by ACN determination, expected in place before ACN inspections begin.
All entities in scope
Additional measures layered on the basic set according to the entity's classification as essential or important.
Entities whose classification or sector requires more
What it is built on
ACN measures does not invent its own taxonomy. It sits on Article 21 of the directive as transposed by D.Lgs. 138/2024, detailed by binding ACN determinations.
Italy did not publish a standalone certifiable framework. ACN issues binding determinations that set the security measures, graduated between a basic set and specialist sets, together with guidelines on the incident management process. The obligations are organisational and evidentiary: governance, risk management and accountability, with binding safeguards on the supply chain and notification to CSIRT Italia.
Why there is no unit-level mapping
The measures are set by binding ACN determinations, graduated between a basic set and specialist sets according to the entity classification. All ten article 21(2) measures are addressed by the regime; the determination allocates them.
No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.
No stable public identifiers to map against
This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.
What you already have, for the same measure
Nobody in scope starts from nothing. ACN measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|
| (a) Risk analysis | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | 8.24 | SC |
| (i) HR, access, assets | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
- https://www.acn.gov.it/portale/en/nis/la-normativa
- https://www.acn.gov.it/portale/en/w/nis2-linee-guida-sul-processo-di-gestione-degli-incidenti-di-sicurezza-informatica
We are not affiliated with Agenzia per la Cybersicurezza Nazionale (ACN). ACN measures and related marks belong to their owners.