Mandatory CSIRT Representative for NIS2 and Legislative Decree 138/2024

Referente CSIRT obbligatorio per NIS2 e Decreto 138 2024

Identifying the CSIRT Point of Contact affects an organization’s ability to respond to cyber crises and comply with Legislative Decree 138/2024. With ACN Determination no. 333017/2025, essential and important entities must designate this role between November 20 and December 31, 2025. Choosing between an internal or external resource requires an analysis of technical skills, business processes, and the legal responsibilities established by the national regulatory framework.

Mandatory minimum requirements for the CSIRT Point of Contact

Article 7 of Determination 333017/2025 establishes that the CSIRT Point of Contact and any substitutes must possess multidisciplinary requirements essential for operating and interacting with CSIRT Italia. These criteria are substantive and cannot be overlooked.

  • Cybersecurity skills: At least basic competence is required to understand the nature of threats and to engage technically with the national authority. The ability to analyze logs and communicate with those managing monitoring (SOC) is necessary.
  • Incident management: Practical experience in handling digital crises is required. The Point of Contact must distinguish between routine anomalies and “significant incidents” according to Article 25 of the NIS2 Decree and ACN Determination no. 164179/2025.
  • Knowledge of networks and systems: Mastery of the NIS entity’s IT/OT architecture is needed to manage timely and complete notifications within the 24 and 72-hour time windows.

This role aligns with the profile of a “Cyber Incident Responder” according to ENISA, involving technical reporting tasks and collaboration with legal and technical functions.

Internal option: CISO and IT manager

Many organizations select the CSIRT Point of Contact internally. The most suitable roles are CISO, IT Manager, CTO, or Cybersecurity Manager.

Advantages of the internal role

  • Integration into processes: an internal resource understands decision-making dynamics, information systems, and key figures (legal, communications, management).
  • Authority preference: ACN FAQs highlight a preference for an internal Point of Contact.
  • Direct control: allows for immediate response without the need for contractual escalation.

Disadvantages and risks

  • Operational overload: in medium-sized contexts, the CISO or IT Manager might not have sufficient time to oversee 24/7 notifications, especially during complex incidents.
  • Single Point of Failure: without substitutes, the internal Point of Contact can become a bottleneck during absences.

Outsourcing option: external professionals and SOCs

The ACN Determination provides that the CSIRT Point of Contact can be external: a SOC manager, an outsourced CERT, or an outsourced IT manager.

Advantages of outsourcing

  • H24/7 coverage: specialized partners guarantee continuous coverage, which is fundamental for complying with the 24-hour pre-notification requirement.
  • Vertical skills: access to certified experts updated on the latest threats.
  • Reduction of fixed costs: for SMEs or entities without an internal cyber team, it avoids the direct hiring of specialists.

Mandatory contractual constraints

  • Operational responsibilities and confidentiality obligations.
  • Methods of access to corporate IT systems for log collection and evidence gathering.
  • Guaranteed response times (SLAs) in the event of an incident.
  • Ownership of communications toward CSIRT Italia and privacy roles (GDPR).

Companies such as Infor (BeeCyber), Argo Cyber, Axitea, and Axera offer “CSIRT Point of Contact as a Service,” which includes a mandatory preliminary assessment and gap analysis.

Strategic criteria for selection

  • Large/essential organizations: have an internal CISO, supported by an internal or external SOC for detection.
  • Medium/important organizations: often use a mixed model with an internal Point of Contact and support from external consultants.
  • SMEs and small entities: rely more on outsourcing or unify the Point of Contact (PdC) and CSIRT Point of Contact, which is only possible if the role remains internal.

Substitutes: operational continuity

Article 7, paragraph 3, of Determination 333017/2025 allows for the appointment of one or more substitutes for the CSIRT Point of Contact. This choice is an essential best practice.

  • They must possess the same technical and system knowledge requirements as the primary Point of Contact.
  • They can operate on the ACN Portal and send notifications in the absence of the primary holder.
  • Each substitute must authenticate individually on the portal via SPID or CIE.

The absence of substitutes can prevent pre-notification within 24 hours and lead to violations of Article 25 of the NIS2 Decree.

Operational delegations and legal responsibility

  • The CSIRT Point of Contact acts through technical-operational delegation.
  • Final responsibility for NIS2 obligations and security measures remains with the administrative and management bodies, according to Article 23 of Legislative Decree 138/2024.
  • Company leadership must approve the incident management plan and ensure adequate resources.

Basic NIS2 organizational chart

  1. Management bodies: sanctioning responsibility and policy approval.
  2. Point of Contact (PdC): institutional representative toward ACN for administrative compliance.
  3. CSIRT Point of Contact: technical interface toward CSIRT Italia.
  4. Support functions: IT, legal, DPO, communications.

The selection of the CSIRT Point of Contact should be viewed as the creation of a vital hub between the technological and decision-making components. Effectiveness depends on the ability to operate under pressure and integration with the organization’s incident response plan.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!