With the Determination of February 9, 2026, published in the Official Gazette, the National Cybersecurity Agency (ACN) has defined the taxonomy of incidents that subjects identified in art. 1, paragraph 1, of the Law of June 28, 2024, no. 90 must report or notify. This classification standardizes the methods of communication for security events and integrates with the obligations provided for by the NIS2 directive.
The three categories of the ACN taxonomy
The taxonomy identifies three types of incidents that require formal reporting or notification:
- IS-1 โ Loss of confidentiality to the outside: concerns the compromise of digital data owned by the subject or over which it exercises control, even partial. It includes violations of personal data, confidential information, or intellectual property.
- IS-2 โ Loss of integrity with external impact: covers unauthorized alterations of data owned by the subject or under its control, even partial, that produce effects on third parties or on external operations.
- IS-3 โ Violation of expected service levels: refers to interruptions or degradation of services and activities compared to the service levels (SL) established by the subject itself, with an impact on business continuity.
Integration with the NIS2 discipline
The ACN Determination explicitly calls for consistency with the NIS2 discipline, already the subject of a previous determination by the Agency. An operationally relevant aspect is that the pre-notification and notification carried out pursuant to the NIS decree also fulfills the obligation provided for by Law 90/2024, avoiding procedural duplications.
This integration simplifies the management of notification obligations for subjects that fall within both regulatory perimeters, reducing the administrative burden and favoring a unified approach to security incident management. For organizations that still need to structure their compliance path, ISGroup’s NIS2 compliance program covers both notification obligations and the overall governance required by the directive.
How to apply the taxonomy in practice
Adopting the taxonomy requires a structured process for classifying security events. Organizations must:
- Define internal procedures to identify and classify incidents according to the three categories IS-1, IS-2, and IS-3
- Establish clear thresholds to determine when an event requires formal reporting or notification
- Integrate the taxonomy into incident response processes and crisis management plans
- Train technical staff and security managers on how to apply the classification
- Document classification decisions to ensure traceability and consistency over time
A Virtual CISO can support the organization in implementing these processes, ensuring that incident classification is aligned with both regulatory requirements and the company’s specific operations. For authorized economic operators, integration with AEO governance and security requirements represents an additional layer of complexity that requires specialized expertise.
Impact on risk management
The ACN taxonomy does not limit itself to defining incident categories but directly influences risk assessment activities. Organizations must consider:
- The probability of events occurring that can be classified into the three categories
- The potential impact of each type of incident on operations and reputation
- Prevention and mitigation measures specific to each category
- Detection and response times needed to contain the effects of the incidents
Integrating the taxonomy into risk assessment processes allows for aligning security priorities with regulatory obligations, optimizing investments in prevention and incident response. An effective SOC monitoring and incident response system allows for the timely detection of events classifiable according to the ACN taxonomy and for activating notification procedures within the expected times.
Entry into force and obligations
The taxonomy entered into force from the date of publication in the Official Gazette. The concerned parties must immediately adjust their incident management procedures to ensure compliance with the reporting and notification obligations provided for by Law 90/2024. To verify whether your organization falls within the perimeter and to know the operational deadlines, it is useful to consult the guide on who is included in the ACN list of NIS2 subjects and the relative deadlines.
- Which subjects must apply the ACN taxonomy?
- The taxonomy applies to subjects identified in art. 1, paragraph 1, of the Law of June 28, 2024, no. 90. These include essential service operators, digital service providers, and other critical entities identified by the legislation. It is necessary to verify your inclusion in the regulatory perimeter through a specific analysis of your activity and sector of belonging.
- Does the notification according to NIS2 also cover the obligations of Law 90/2024?
- Yes, the ACN Determination explicitly clarifies that the pre-notification and notification carried out pursuant to the NIS decree also fulfills the obligation provided for by Law 90/2024. This avoids procedural duplications for subjects that fall within both regulatory perimeters, simplifying the management of obligations.
- How is it determined whether an incident falls into category IS-1, IS-2, or IS-3?
- The classification depends on the nature of the impact: IS-1 concerns the compromise of data confidentiality to the outside, IS-2 covers alterations to integrity with external effects, IS-3 refers to violations of expected service levels. It is necessary to evaluate the event against these criteria and document the classification decision to ensure consistency and traceability.
- What are the timelines for incident reporting?
- The reporting timelines follow the provisions of Law 90/2024 and, for NIS2 subjects, the related discipline. In general, a timely pre-notification followed by a full notification within defined terms is required. It is fundamental to define internal procedures that guarantee compliance with these terms, considering the time needed for classification and gathering relevant information.
- How can the taxonomy be integrated into existing incident response processes?
- Integration requires updating incident management procedures to include the classification phase according to the three ACN categories. It is necessary to train the incident response team, define clear decision-making criteria, and integrate the taxonomy into ticketing and documentation tools. A structured approach also involves periodic tests to verify the effectiveness of the classification in realistic scenarios.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
