Mandatory CSIRT Contact Person Designation for NIS Entities – NIS2 FAQ

Direttiva NIS2

A client of ours requested clarification regarding the obligation to communicate the CSIRT contact person, asking whether this requirement applies only to public entities identified by Art. 1, paragraph 1, of Law no. 90/2024, or if it concerns the entire pool of NIS entities. The answer provides a precise regulatory framework, based on ACN Determination no. 333017/2025 and Legislative Decree 138/2024, which implements the NIS2 directive.

Is the communication of the CSIRT contact person required for all NIS entities or only for those referred to in Art. 1, paragraph 1, of Law 90/2024?

Below is the response from Francesco Ongaro, founder of ISGroup:

The designation of the CSIRT contact person is required for all NIS entities, regardless of whether they are included among those identified in Art. 1, paragraph 1, of Law no. 90/2024.

This obligation is provided for in Art. 7, paragraph 1 of ACN Determination no. 333017/2025, which establishes that the CSIRT contact person is a natural person designated by the point of contact via an electronic procedure on the ACN Portal starting from November 20 and no later than December 31, 2025.

There is no reference that limits this obligation solely to the entities mentioned in Law 90/2024, which primarily concerns the fulfillment of appointing a cybersecurity contact person in the public sector. The designation of the CSIRT contact person is, instead, a requirement provided for by the NIS2 regulations (Legislative Decree 138/2024), applicable to all registered NIS entities.

The sentence:

The designation of the point of contact by the entities referred to in Article 1, paragraph 1, of Law no. 90 of June 28, 2024, which fall within the scope of the NIS decree, may satisfy the obligation to appoint and communicate the cybersecurity contact person referred to in Article 8, paragraph 2, of the same law.

means that public entities (indicated in Art. 1, paragraph 1 of Law 90/2024) that are also NIS entities can avoid a double appointment, meaning:

  • if they have already designated the NIS point of contact,
  • and this public entity falls within the scope of Law 90/2024,

then the designation of the point of contact also counts as fulfillment of the obligation to appoint a cybersecurity contact person pursuant to Law 90/2024.

To delve deeper into the distinction between the two roles, see also the analysis on the distinction between the point of contact and the CSIRT contact person in ACN Determination no. 333017/2025.

This clarification allows NIS entities to correctly fulfill their obligations to designate the CSIRT contact person, avoiding duplication and ensuring compliance with ACN provisions and NIS2 regulations. For entities that have yet to complete their registration or verify their perimeter, it is useful to also consult the guide on ACN and the NIS2 list: compliance by March 31.

At ISGroup, we support NIS entities in the correct application of the obligations provided for by the NIS2 directive, from perimeter verification to the definition of a structured NIS2 compliance path, with technical and consulting assistance for the designation and communication of the CSIRT contact person.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In