The new decision of 13 April 2026
On 13 April 2026, ACN published two new Directives from the Director-General
The first, No. 127437/2026, updates and replaces the previous one, No. 379887 of 19 December 2025, and introduces the obligation to carry out the process of listing and categorising activities and services, as well as to identify relevant NIS suppliers in the annual update of information.
The second, No. 127434/2026, sets out the deadlines by which entities newly included in the NIS register in 2026 must comply with their obligations to report incidents and implement security measures.
This is not merely a bureaucratic update. The publication marks the transition from theory to practice. ACN non si limita più a identificare i soggetti, ma impone un modello strutturato di gestione, affinché la cybersicurezza diventi governance, responsabilità e capacità dimostrabile.
The application period: 1 May – 30 June 2026
This obligation, as set out in Article 30 of the NIS2 Decree and applicable from 2026, must be fulfilled annually between 1 May and 30 June via the ACN platform, following notification of inclusion on the list of NIS entities.
The deadline cannot be extended. Once the deadline of 30 June has passed, the categorised list of activities and services shall be deemed definitively finalised and no longer subject to amendment, except in cases of delay due to documented technical or operational difficulties not attributable to the party concerned.
What exactly should organisations do?
The process requires each NIS entity to access the ACN Portal via the Point of Contact and carry out the following tasks:
- List all activities and services carried out – both internal and those provided to third parties.
- Classify them under one of the 10 macro-areas set out in the ACN model – including a residual category ‘Other services and activities’ to cover cases not falling within the main categories.
- Assign a relevance category to each service or activity, choosing from four levels: Minimal, Low, Medium, High.
Subsequently, between 1 May and 30 June, the Contact Point may upload the list of services to the Portal, assigning a relevance category to each one using the ACN template and a simplified BIA.
The severity category reflects the impact that a breach of that service or system would have on the entity’s ability to perform its NIS functions. An inaccurate or undocumented assessment would not stand up to scrutiny by ACN.
What is the real purpose of categorisation:
Categorisation is not just a box to tick on a checklist. It is the foundation upon which the entire long-term NIS2 compliance process rests.
This step will pave the way for a more granular differentiation of the security levels required in the phase following October 2026.
In the ‘long-term’ phase, potentially more ambitious obligations – including sector-specific ones – will come into play, proportionate to the categorisation of activities and services.
The link with the supply chain
The new guidelines also introduce a parallel obligation of equal importance: NIS entities are required to identify and report relevant third-party suppliers whose unavailability or compromise could have a significant impact on the services provided. This list includes ICT suppliers and non-fungible suppliers, i.e. those that cannot be replaced within a reasonable timeframe.
This reminds us that the nature of these relationships is a genuine ecosystem.
What to do now
The time between now and 1 May is not a time for waiting. It is a time to:
- Please check that you are included in the NIS 2026 list and the relevant annex (1 or 2).
- Map out all activities and services in full, including those provided to third parties, which are often overlooked.
- Develop a simplified BIA that supports the assignment of relevance categories.
- Document the decisions so that they stand up to any checks or requests for changes from ACN.
- Please check that the relevant suppliers section on the portal has been updated, as the deadline for this is 31 May.
It will be necessary to manage detailed lists, supply chain maps and service classifications that must stand up to any inspections.
Rexilience is ready to support you now that NIS2 has entered its most practical phase!