Cybersecurity & Data Protection Blog | CyberGrant

NIS2 deadline October 31, 2026: what must be operational

Written by CyberGrant Team | October 2, 2026

The NIS2 deadline of October 31, 2026: what must be operational, and what stays exposed

Four weeks left. October 31, 2026 is the date by which NIS entities added to Italy's national register during 2025 must have base security measures adopted and working. From November 1 the National Cybersecurity Agency (ACN) stops accompanying and starts inspecting.

Most compliance programs will reach the date with signed policies. Few will reach it with evidence. And almost none will have closed the gap that inspections do not ask about today but incidents surface tomorrow: what happens to a document after it leaves the systems where those measures were implemented.

Key takeaways

  • The October 31, 2026 deadline comes from art. 4 of ACN Determination 379907/2025 and applies to entities registered in 2025, 18 months from their notification. Entities registered in 2026 follow the terms set by Determination 127434/2026.
  • Essential entities: 43 measures and 116 requirements (Annex 2). Important entities: 37 measures and 87 requirements (Annex 1).
  • ACN asks for measures implemented and working, not documented. That difference shows up as evidence produced over time, not as a date.
  • Base measures on data (PR.DS-01, PR.DS-02) cover data at rest and in transit inside systems you control. The notifiable incident, IS-1, is loss of confidentiality toward the outside.
  • Third parties are involved in 48% of breaches, up 60% in a year (Verizon DBIR 2026). That is where data leaves the reach of your measures while staying yours for notification purposes.

 

What actually falls due on October 31, 2026?

ACN Determination 379907/2025 uses a two-word phrase that changes how the deadline should be read: measures must be implemented and working. The weight falls on the second word.

It is not enough to say MFA is switched on, log collection is configured, the access policy is approved. Implemented and working are proven in different ways.

An example. You enable MFA on October 28 and set up log collection. By October 31 everything is running. But if the only evidence you can produce is dated the 28th, that evidence proves the measure was introduced. Not that it has become part of how the organization works.

This is the question of evidence continuity. An access log is worth the period it documents. A backup counts as a real control when it runs and gets restore-tested on a regular basis. Permissions have to be reviewed periodically, not once. Awareness training is a recurring program, not a course completed with the deadline in mind.

Compliance is not a snapshot. It is a record built over time.

For anyone still behind, that makes the priority twofold: switch on the measures that start producing evidence immediately and, for those started late, put in writing the start date, the work already done and the plan for keeping it running. In a review, a young control that genuinely operates and is documented holds up better than a control that looks complete on paper because it was reconstructed after the fact.

 

Which base measures hit business documents directly?

The measures follow the Italian National Framework for Cybersecurity and Data Protection (2025 edition). Four areas bear directly on how files are protected, shared and traced.

ACN area Reference measures What you must be able to show
Cryptography PR.DS-01, PR.DS-02 Documented usage policies, data at rest and in transit protected on relevant systems
Identity and access PR.AA-01, PR.AA-03, PR.AA-05 Credentials managed, strong authentication, least privilege applied and reviewed
Supply chain GV.SC-01, GV.SC-02, GV.SC-04, GV.SC-05, GV.SC-07 Suppliers mapped, risk assessed, security requirements in contracts
Training PR.AT-01, PR.AT-02 Staff awareness and specialized roles, with proof of delivery

For essential entities, Annex 2 adds 6 measures and 29 requirements on top of Annex 1, including vulnerability assessment and penetration testing, encrypted backups with restore testing, and access monitoring with parameters to detect privilege abuse.

Anyone who knows GDPR will recognize the list. Encryption, MFA and logging already counted as appropriate measures under art. 32. NIS2 makes them prescriptive and verifiable, which moves the relationship between the two frameworks out of the legal department.

Why paper compliance will not survive an inspection

Because the decree moved the center of gravity from declaration to proof. Art. 23 of Legislative Decree 138/2024 assigns management bodies direct, non-delegable responsibility for approving and supervising the measures, with mandatory training for senior leadership. Penalties under art. 38 reach 10 million euros or 2% of annual worldwide turnover for essential entities, 7 million or 1.4% for important entities, whichever is higher. Individuals at the top can face additional interdictory measures.

Incident notification has been in force since January 2026, in three non-negotiable stages: pre-notification to CSIRT Italia within 24 hours, full notification within 72 hours, final report within 30 days.

Annexes 3 and 4 define what counts as a significant incident. IS-1 is loss of confidentiality, toward the outside, of digital data owned by the entity or under its control, even partial. IS-2 is loss of integrity with external impact. IS-3 is breach of expected service levels. For essential entities only, IS-4 adds unauthorized access or abuse of granted privileges on digital data.

IS-1 rewards a close reading. The obligation attaches to data you control even partially. Not to data sitting on your servers.

Where base measures leave data exposed

This is where the deadline shows a structural limit, and it belongs to the typical technical solution, not to the regulation.

PR.DS-01 protects data at rest. PR.DS-02 protects data in transit. Both work where the infrastructure is yours. A document shared with a supplier travels over an encrypted channel and, on arrival, becomes readable again once the transport layer is decrypted. From that moment neither measure reaches it. It remains data you control partially, so it remains inside the scope of IS-1.

The numbers say this is the likely path, not the edge case. Verizon DBIR 2026 puts breaches involving third parties at 48% of the total, up from 30% the previous year, a 60% increase. The same report notes that only 23% of third-party organizations fully remediated missing or improperly configured MFA on their cloud accounts, and that weak passwords and permission misconfigurations took close to eight months to resolve half of the findings. IBM's Cost of a Data Breach 2025 puts third-party and supply chain compromise at USD 4.91 million average cost, second only to malicious insiders at USD 4.92 million.

In practice: the most common route to an IS-1 notification runs through a file sitting in someone else's infrastructure, under controls you did not implement and that the DBIR finds slower than your own.

The Italian context does not help. Clusit's 2026 report counts 507 serious incidents against Italian organizations in 2025, up 42% from 357 in 2024, and 9.6% of the global sample.

What to do in the weeks that remain

There is no time left for a remediation program. What remains is good for three things: closing evidence gaps, closing the gap on data that leaves, and putting in writing what will not be ready.

If you run security (CISO). For each applicable measure, reconstruct the evidence chain: who performs it, how often, what artifact it produces, where that artifact lives. Where the time series does not exist, do not manufacture it. Document when it started and how it continues. Then check something teams routinely skip: the ability to revoke access in real time to a document already delivered to a supplier. It is the only control that reduces IS-1 exposure on data no longer in your systems.

If you run architecture (CIO, CTO). Map outbound document flows before mapping systems. Which documents leave, to whom, through which channel, with what access expiry. Most organizations discover at this point that real channels outnumber governed ones, and that SharePoint, OneDrive and email cover sharing but not protection after delivery. We have written on why traditional DLP does not produce compliance.

For both. The notification process has to be rehearsed, not described. Twenty-four hours goes fast when nobody knows who decides that an event qualifies as significant.

How file-centric protection maps to ACN requirements

The logic is simple. If protection lives in the file rather than in the perimeter, it survives the moment the file leaves the perimeter.

FileGrant encrypts the document at creation and keeps encryption active wherever the file goes, including after download onto a third-party system. Lock&Go encrypted download uses CRYSTALS-Kyber, standardized by NIST as FIPS 203 (ML-KEM) in August 2024, which also addresses harvest-now-decrypt-later exposure on documents with multi-year value. RBAC and automatic classification cover the least-privilege requirement. The audit trail produces the granular evidence an inspection asks for and a policy alone does not generate. Post-share revocation acts on the gap left by PR.DS-01 and PR.DS-02: a file already delivered becomes unreadable again.

Stated precisely: it does not replace the collaboration platform. It sits alongside Microsoft 365, SharePoint and OneDrive and adds the control those tools do not exercise after delivery. For the full mapping of controls to regulatory requirements, see secure file sharing solutions and the NIS2 white paper.

October 31 is not the end of the path. ACN will publish long-term measures by the end of 2026, scaled to the relevance assigned to each entity. Organizations arriving at the deadline with real evidence face that next phase from a different position than those arriving with a folder of signed PDFs.

 

Frequently asked questions about the October 31, 2026 NIS2 deadline

 

Who has to meet the October 31, 2026 deadline?

Essential and important entities added to Italy's national NIS register during 2025, for whom the 18 months set by art. 4 of ACN Determination 379907/2025 expire on that date. Entities registered for the first time in 2026 follow the terms set by ACN Determination 127434/2026 of April 13, 2026. The clock starts from receipt of the registration notice, not from a single date shared by everyone.

How many security measures must be adopted by the deadline?

Essential entities must adopt the 43 measures and 116 requirements in Annex 2 of ACN Determination 379907/2025. Important entities must adopt the 37 measures and 87 requirements in Annex 1. The gap is 6 measures and 29 requirements, concentrated on vulnerability assessment and penetration testing, encrypted backups with restore testing, privilege abuse monitoring, and hardened configurations.

What happens on November 1, 2026?

The accompaniment phase ends and ACN can begin inspections on whether measures were actually adopted. Supervision is ex ante for essential entities and ex post for important ones. Penalties under art. 38 of Legislative Decree 138/2024 reach 10 million euros or 2% of annual worldwide turnover for essential entities and 7 million or 1.4% for important ones, whichever is higher, with possible interdictory measures for directors.

What encryption does NIS2 require for business documents?

No regulation mandates a specific algorithm. Measures PR.DS-01 and PR.DS-02 require that confidentiality, integrity and availability of data at rest and in transit be protected with measures appropriate to risk, backed by documented usage policies. In practice that means at least AES-256 at rest and TLS 1.3 in transit. For documents with multi-year value, quantum-safe encryption such as CRYSTALS-Kyber, standardized as NIST FIPS 203, addresses the harvest-now-decrypt-later threat.

Does a file shared with a supplier fall under notification obligations?

Yes, if loss of confidentiality toward the outside occurs. The IS-1 category in Annex 3 covers digital data owned by the entity or under its control, even partial, which includes documents physically held by a supplier. That is why supply chain security and the ability to revoke access to an already shared document bear directly on notification risk.

Are written policies enough to pass an ACN inspection?

No. The determination refers to measures implemented and working. An approved policy proves a decision, not an operating process. The evidence that holds up in a review consists of access logs, permission review records, restore test results and training records: artifacts produced continuously over time.

What is the difference between Determination 379907/2025 and the April 2026 ones?

379907/2025 defines base security measures and base significant incidents, and replaced 164179/2025. The April 2026 determinations address other matters: 127434/2026 sets deadlines for entities registered in 2026, 127437/2026 governs the digital platform and introduces the register of relevant NIS suppliers, and 155238/2026 adopts the categorization model for activities and services under art. 30. Base measures remain those in 379907/2025.