Directive NIS2 European Union
Determinazioni ACN under D.Lgs. 138/2024

ACN security measures and implementation guidelines

NIS2 says what you must achieve, never how you demonstrate it. Italy answers with ACN measures. If you operate there, this is what your regulator reads.

Implementation routes
2
Member states using it
1

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

There is no ACN label to hold and no certification to obtain: compliance is demonstrated to the authority, not certified by a third party. Because the measures live in determinations rather than in the decree itself, they can be updated without a change in the law — check the current determination, not a summary.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is widely used in Italy as the underlying management system, but it does not replace the ACN determinations.

Implementation routes

2 routes, chosen by scope and depth


Basic measures

The floor set by ACN determination, expected in place before ACN inspections begin.

All entities in scope

Specialist measures

Additional measures layered on the basic set according to the entity's classification as essential or important.

Entities whose classification or sector requires more

What it is built on

ACN measures does not invent its own taxonomy. It sits on Article 21 of the directive as transposed by D.Lgs. 138/2024, detailed by binding ACN determinations.

Italy did not publish a standalone certifiable framework. ACN issues binding determinations that set the security measures, graduated between a basic set and specialist sets, together with guidelines on the incident management process. The obligations are organisational and evidentiary: governance, risk management and accountability, with binding safeguards on the supply chain and notification to CSIRT Italia.

Mapping

Why there is no unit-level mapping


Basis

The measures are set by binding ACN determinations, graduated between a basic set and specialist sets according to the entity classification. All ten article 21(2) measures are addressed by the regime; the determination allocates them.

Limit of this mapping

No stable public identifier set to map against, and the determinations can be revised without amending D.Lgs. 138/2024. Read the determination in force — a mapping published here would be a snapshot of a moving target.

No stable public identifiers to map against

This is a fact about the framework, not a gap in our research. Publishing invented identifiers here would give false precision on the most binding document in the country. The level this framework does publish is recorded above.

The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. ACN measures is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to ACN measures and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training 5.37 6.3 8.7 AT SI CM
(h) Cryptography 8.24 SC
(i) HR, access, assets 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Sources

We are not affiliated with Agenzia per la Cybersicurezza Nazionale (ACN). ACN measures and related marks belong to their owners.

Cart 0