La tua ricerca

    16.04.2025

    NIS: Determinations Defining the Obligations Adopted — Information Update Deadline Set for May 31


    On April 15, 2025, the Italian National Cybersecurity Agency (“ACN”) published on its website three new determinations issued by the Director General of the ACN:

    • Determination ACN No. 136117 of April 10, 2025 — Platform, Point of Contact and Substitute, Information Update and NIS Representative under Article 7 of the NIS Decree (“Determination 136117”);
    • Determination ACN No. 136118 of April 10, 2025 — Notification of Cybersecurity Information Sharing Agreements under Article 17 of the NIS Decree (“Determination 136118”); and
    • Determination ACN No. 164179 of April 10, 2025 — Basic Specifications for Fulfilling Obligations under Articles 23, 24, 25, 29, and 32 of the NIS Decree (“Determination 164179”).

    Determination 136117, which updates and replaces Determination ACN No. 38565 of November 26, 2024, governs access to the services portal and the procedures for registration and information updates, as well as the designation of the point of contact and other persons authorized to operate on the ACN services portal on behalf of NIS entities.

    The main new features introduced by Determination 136117 concern:

    • the substitute point of contact;
    • the secretariat;
    • the operators; and
    • the process for the annual update of information.

    The substitute point of contact is a natural person, different from the main point of contact, designated by the NIS entity pursuant to Article 7(4)(d) of Legislative Decree No. 138/2024, whose role is to support the point of contact in carrying out its functions (except for registration, which remains solely with the point of contact).

    The secretariat, on the other hand, is the natural person who supports the point of contact and the substitute point of contact in interactions with ACN.

    Finally, the operators are those who support the point of contact and the substitute point of contact in operating on the portal.

    As with the point of contact, the functions of the substitute point of contact may only be carried out by the legal representative, a general attorney (registered in the business register), or an employee delegated by the legal representative. However, it is unclear whether this also applies to the secretariat and operators.

    To operate on the portal, the substitute point of contact, the secretariat and the operators must be invited by the point of contact, complete registration and associate their user account with that of the NIS entity. However, the secretariat and operators may not use the portal to send communications to ACN regarding the fulfilment of obligations under Legislative Decree no. 138/2024. The role of secretariat may only be assigned to a single user.

    It should be noted, in any case, that while the designation of the substitute point of contact is mandatory, the involvement of the secretariat and operators is purely optional.

    With regard to the process of updating information, Determination 136117 requires that between April 15 and May 31 of each year, the information required by Article 7(4 and 5) of Legislative Decree no. 138/2024 be submitted via the portal section called "NIS Service/Annual Update".

    In particular, all NIS entities must, as applicable, provide or verify the update of the following information:

    • personal and contact details of the point of contact and, where applicable, data contained in the power of attorney conferred by the legal representative;
    • personal and contact details of the substitute point of contact and, where applicable, data contained in the power of attorney conferred by the legal representative;
    • personal and contact details of the secretariat;
    • personal and contact details of the NIS entity (at a minimum, tax code, company name, registered office address, legal representative, list of general attorneys, telephone number, certified email address and ordinary email address must be provided);
    • list of the members of the administrative and management bodies, to be identified based on Article 38(5) of Legislative Decree no. 138/2024 (at a minimum, name and surname, tax code and certified email address must be provided);
    • list of the services falling within the scope of Legislative Decree no. 138/2024 provided by the NIS entity, indicating the EU Member States in which they are provided;
    • public IP address space in use or available to the NIS entity (i.e. public and static IP addresses used or available to a NIS entity through contracts or agreements with Internet service providers, Regional Internet Registries or other organizations responsible for providing IP addresses based on national, European and international regulations and agreements);
    • domain names in use or available to the NIS entity (i.e. domain names used or available to a NIS entity through contracts or agreements with domain name registration service providers or other organizations responsible for providing domain names based on national, European and international regulations and agreements); and
    • list of information sharing agreements (i.e. voluntary arrangements between NIS entities to exchange relevant cybersecurity information under Article 17 of Legislative Decree no. 138/2024).

    Providers of domain name system services, top-level domain name registry operators, domain name registration service providers, cloud computing service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, online marketplace providers, online search engine providers, and social network platform providers must also, where applicable, provide or verify the update of information relating to their EU establishments. Furthermore, if they are established outside the national territory and have appointed their representative in Italy, they must provide and verify the update of the personal and contact details of the representative in Italy.

    Detailed analyses of Determination 136118 and Determination 164179 will be available shortly.

    If you need assistance and support in fulfilling the obligations set out in the NIS legislation, please contact your professional advisers.

    ALERTE DROIT SOCIAL - Période d’essai : l’employeur peut prévoir une période d’essai s’il n’a pas pu apprécier l’aptitude professionnelle du salarié lors de la précédente relation de travail
    La période d’essai est destinée à évaluer les compétences du salarié (C. trav. Art. L.1221-20). Au cours de cette période, le contrat de travail peut être rompu librement et sans motif (sauf abus). 📢 Dans…
    Approfondisci
    5 Minuten Handelsvertreterrecht für Entscheider: Folge #16 - Kündigt der Handelsvertreter, verliert er seinen Ausgleich. Oder nicht?
    Wenn der Handelsvertreter den Vertrag kündigt, verliert er seinen Ausgleichsansp…
    Approfondisci
    ADVANT Beiten berät CATL als German Legal Counsel bei Börsengang in Hongkong
    Berlin/München, 20. Mai 2025 – Die internationale Wirtschaftskanzlei ADVANT Beit…
    Approfondisci
    Justizstandort-Stärkungsgesetz
    Am 1. April 2025 tritt das Gesetz zur Stärkung des Justizstandortes Deutschland …
    Approfondisci
    Vom Schriftformerfordernis zur Textform bei Gewerberaummietverträgen: (K)eine „Erleichterung“ für Transaktionsparteien?!
    Durch das Inkrafttreten des Vierten Bürokratieentlastungsgesetzes (BEG IV) genüg…
    Approfondisci
    Ersatzanspruch des Errichters eines Gebäudes bei Errichtung auf einem fremden Grundstück und damit einhergehender grundlegender Veränderung des Grundstücks
    Die Bedeutung der Änderung der höchstrichterlichen Rechtsprechung zum Verwendung…
    Approfondisci
    Mitwirkungshandlungen des Auftraggebers im Bauvertrag
    Schon lange hadern die Bauwirtschaft und Teile der Lehre mit einer Besonderheit …
    Approfondisci
    Aggiustare la RIS o rifarla da zero
    Le regole per gli investitori al dettaglio? O cambiano in modo compatibile con l…
    Approfondisci
    Le cripto-attività classificate come quote di organismi di investimento collettivo
    A cura di Lorenzo Macchia per Fondi & Sicav Le cripto-attività, fin dall'inizio…
    Approfondisci