Skip to content

ACN, AgID, PSN...: who does what in Italian cybersecurity

ACN, AgID, PSN, CSIRT Italia, CVCN, Garante: the operational map of Italian cybersecurity. Who you notify, in how many hours, and who does what.

Italian cybersecurity governance is an alphabet soup: ACN, AgID, CSIRT, CVCN, PSN, plus the Garante and the postal police orbiting nearby. If you run IT or compliance in a company that just entered the NIS2 perimeter, or that supplies someone who did, you do not need the constitutional history of each acronym. You need to know exactly one thing per situation: who do I call, through which channel, within how many hours. This article is that map. I built it while doing compliance work for clients in Italy, and every deadline in it comes from the primary sources: Legislative Decree 138/2024 (the Italian NIS2 transposition, in force since 16 October 2024), the ACN implementing determinations, and the founding acts of each body. Skip to the table and the decision list at the end if you are in a hurry; the sections in between explain why the map looks the way…