Practical guide
How to draft the NIS2 incident notification to ACN with AI
3 min read · Updated July 2026 · Editorial oversight: Avv. Federico Papa
The notification of a significant incident is a core obligation introduced by Directive (EU) 2022/2555 (NIS2), transposed in Italy by Legislative Decree 138/2024. Essential and important entities must fulfill this duty toward the National Cybersecurity Agency (ACN) whenever an event compromises network and information system security. The procedure aims to ensure a coordinated response to cyber threats and mitigate risks to the internal market. Failure to notify or delays expose entities to severe administrative sanctions under the national framework.
In brief
Legislative Decree 138/2024, transposing Directive (EU) 2022/2555 (NIS2), mandates essential and important entities to notify the National Cybersecurity Agency (ACN) of significant incidents. The process requires an early warning within 24 hours, a detailed notification within 72 hours, and a final report within one month. Significance is determined by operational disruptions and third-party damages under Article 23. AI tools assist in drafting reports detailing indicators of compromise (IoC) and root causes. Non-compliance with these statutory deadlines triggers administrative fines and inspections.
The steps
- 1.
Assessment of incident significance
The practitioner must determine whether the incident is significant under Article 23 of the NIS2 Directive and Legislative Decree 138/2024. An incident is deemed significant if it causes a severe operational disruption of services or inflicts material or non-material damage on third parties. It is also necessary to evaluate whether the event entails a cross-border impact or compromises the continuity of a service critical to society or the economy. This preliminary phase is crucial for correctly initiating communication flows with the national authority.
- 2.
Submission of early warning within 24 hours
Upon detecting the incident, the entity must submit an early warning to the ACN within the strict deadline of 24 hours. This document must be concise, specifying whether the incident is suspected to stem from unlawful acts or if it could have a cross-border impact. Prompt submission enables the Computer Security Incident Response Team (CSIRT) Italy to monitor the situation in real time. At this stage, an exhaustive technical analysis is not required, but rather an immediate notification of the critical issue.
- 3.
Incident notification within 72 hours
Within 72 hours of becoming aware of the incident, the entity must transmit a more detailed notification supplementing the early warning. The document must update the initial assessment, specifying the severity and impact of the incident as well as available indicators of compromise (IoC). It is essential to describe the nature of the threat and any exploited vulnerabilities, if known at the time of drafting. This notification serves as the foundation for any technical assistance provided by competent authorities.
- 4.
Analysis of impact and involved services
The notification content must detail precisely which information assets and critical services have been compromised. The estimated number of affected users and expected duration of service downtime must be specified, along with the affected geographical area, distinguishing between local, national, or supranational impact. These details enable the ACN to classify the incident and coordinate response measures at the European level.
- 5.
Drafting the final report within one month
The procedure concludes with the submission of a final report to the ACN within one month of the incident notification. This document must contain a detailed description of the incident, including its root cause and the mitigation measures adopted. The final impact must be specified, quantifying damages and long-term consequences for the organization. If the incident is still ongoing at that time, a progress report must be submitted in temporary lieu of the final report.
Legal basis: Dir. UE 2022/2555 (NIS2)D.Lgs. 138/2024 (attuazione NIS2)Art. 23 Dir. UE 2022/2555 (NIS2)
The template structure
The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.
Notifying entity and ACN
Identification data of the reporting entity and institutional references of the National Cybersecurity Agency.
Entity identification
Details regarding the entity's classification as essential or important, along with relevant cyber points of contact.
Description of the incident
Presentation of facts, indication of detection date and time, and identification of the involved information systems or digital services.
Impact and severity
Technical assessment of the event's significance, focusing on affected users, service downtime, and geographical scope.
Measures adopted
List of actions taken to contain the threat and planned interventions to restore full operational continuity.
Classification and follow-up
Specification of the submission type, such as early warning or intermediate notification, and indication of aspects still under investigation.
Place, date, signature
Digital signature of the legal representative or designated cybersecurity officer.
Mistakes to avoid
- Failure to comply with the strict 24-hour deadline for the early warning, constituting a formal breach of cooperation obligations.
- Omission of cross-border impact details, impeding coordination among Member State authorities.
- Misclassification of the entity as essential or important, leading to the application of incorrect supervisory regimes.
- Failure to submit the mandatory final report within one month following the initial notification.
Frequently asked questions
What happens if notification deadlines are not met?
Failure to meet the 24 or 72-hour deadlines leads to administrative fines under Legislative Decree 138/2024. Furthermore, the ACN may initiate direct inspections to verify the entity's cybersecurity posture.
Must the notification be sent even if the incident is not yet resolved?
Yes, the notification obligation arises as soon as the entity becomes aware of the event's significance, regardless of whether it has been resolved. Periodic updates and a final report must follow once system security is fully restored.
Which channels must be used for submission to ACN?
Communications must be sent through official channels established by the Agency, typically a dedicated digital platform or certified email (PEC), ensuring legal proof of dispatch. Entities must strictly adhere to the technical instructions published on the CSIRT Italy portal.

What edit.legal automates
- —Automated verification of incident classification based on Legislative Decree 138/2024 criteria.
- —Monitoring of statutory deadlines for early warning, notification, and final reporting via integrated alerts.
- —Assisted drafting of technical descriptions using structured templates aligned with ACN guidelines.
Put edit.legal to the test on actual cases
Try edit.legal for free on an active case. No credit card required.
Try edit.legal for freeThis guide is for informational purposes only and does not constitute legal advice for your specific case.