Distinction between Point of Contact and CSIRT Representative in ACN Determination no. 333017/2025 – NIS2 FAQ

Direttiva NIS2

A client asked to identify, within the ACN Director’s Determination no. 333017/2025, the point where it is explicitly stated that the CSIRT contact person cannot be the same as the point of contact or their substitute. Regulatory analysis shows that the Determination does not contain an express prohibition, but introduces elements that imply a functional separation between the two roles, consistent with the operational and organizational objectives provided for by the NIS2 regulations.

What is the precise point in the ACN Director’s Determination
333017 where it is explicitly stated that the CSIRT contact person
cannot be the same as the point of contact? Or their
substitute?

Below is the response from Francesco Ongaro, founder of ISGroup:

The Determination does not contain an explicit prohibition in this regard.

However:

Art. 7, paragraph 1, establishes that the CSIRT contact person is designated by the point of contact. This wording implies a functional distinction between the two roles.

The CSIRT contact person must possess at least basic skills in cybersecurity and incident management (Art. 7, paragraph 5), whereas no technical requirement is requested for the point of contact.

By virtue of these elements, although there is no express regulatory incompatibility, it is strongly recommended to separate the roles, especially to ensure operational effectiveness and substantial compliance with the principles of NIS2 governance, particularly regarding the management of significant incidents and the timeliness of notifications (within 24 hours).

This need for separation is particularly evident in small-to-medium-sized entities, where the only internal IT expert has already been appointed as the point of contact: in such cases, the role of CSIRT contact person will likely be entrusted to an external CISO.

This clarification allows NIS entities to correctly fulfill their obligations regarding the designation of the CSIRT contact person, avoiding duplications and ensuring compliance with ACN provisions and NIS2 regulations.

For entities that are structuring their NIS2 compliance path, the correct assignment of these roles is one of the operational steps to be addressed from the early stages, along with the other requirements provided for by registration in the ACN list.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In