MACHINERY REGULATION

(EU) 2023/1230

Is your documentation really ready for January 20, 2027?

Ready for the new Machinery Regulation?

From 2027 you can deliver machinery documentation digitally. QRcube® supports the management and retention of this documentation, with version traceability and the paper version always available when needed.

Contact us

SDS – Safety Data Sheets

Delivering the sheet to the customer isn't enough: every revision under Article 31(9) must be sent without delay to recipients supplied in the previous 12 months. Missing an update: administrative fines up to €60,000.

Distribute SDS with no risk

With SDS Manager you send sheets to your customers, propagate updates to those who received them and keep proof of every transmission. Fully tracked, supporting compliance.

Contact us
All industries →
PlansCertiblogSecurityAboutPartnerContact
Start free

NIS2, October 2026: demonstrable security measures

· by Loris Angeloni

Share:
NIS2, October 2026: demonstrable security measures

For entities included in the NIS list in 2025, the deadline to adopt basic security measures falls in October 2026, 18 months after receiving the ACN communication. There is no single deadline of October 31: each entity must verify the date of its own communication. Having a risk analysis, an incident management policy, and a business continuity plan is not enough if the planned measures are not adopted. The measures must be adopted in practice: policies and documents help, but alone are not sufficient to demonstrate their implementation.

Legislative Decree 138/2024 transposes the NIS2 directive in Italy. The basic specifications published by ACN indicate the measures to be adopted, with deadlines linked to the inclusion communication. A company might have written a perfect access management plan and continue to share credentials on a company chat. In an audit, policies and evidence of their implementation can be examined together: logs and records help reconstruct the activities performed.

What changes in October 2026

For entities included in the list in 2025, the obligation to report basic significant incidents is operational from January 2026. Basic security measures, however, must be adopted within 18 months of the inclusion communication: for many, the deadline falls in October 2026, but the specific day depends on the communication received. For entities included for the first time in 2026, ACN indicates different deadlines, including July 2027 for basic measures. Consult the ACN communication on new entities.

The annexes of ACN determination 379907/2025 distinguish basic measures for essential and important entities. They concern risk management, supply chain security, incident management, and access control. But beneath every measure there is the same question: if an inspector asked for proof, would you be able to retrieve it from emails, shared folders, and files on different computers?

Measures, audits, and penalties

Penalties are regulated by article 38 of Legislative Decree 138/2024. The application of penalties depends on the violation ascertained, the category of the entity, and the circumstances provided for by the decree. A document platform does not replace the assessment of obligations nor does it prevent penalties.

During an audit, documents and evidence pertinent to the adopted measures may be requested. Access logs and version history can help reconstruct document management. If the answer is to search through different people's mailboxes, the problem is not abstract cybersecurity: it is that the documents demonstrating the work done are scattered, without a consistent record of who touched them.

Why the document archive is a hole almost no one looks at

NIS2 measures also concern risk and incident management. Document traceability can provide useful evidence: where are the previous versions of a security plan updated three times in a year, who shared that report with an external supplier, when was a certain register last opened.

For a company that manages these documents in generic shared folders, reconstructing that history in October, under inspection, is a manual, slow, and often incomplete task. An archive that automatically tracks versions, accesses, and shares makes it easier to consult the available history. It does not replace risk analysis or the policies that a company must still write: it can provide useful evidence to support the verification of adopted measures, without by itself demonstrating compliance with NIS2 obligations.

schermata.png

Certiblok®, with the DRM® & Archive module, maintains the history of every document version with date, time, and who modified it, and a log of every access. The Audit Room allows an inspector to access a document room limited to only pertinent files, without handing over company credentials. These elements help produce the required evidence: compliance with NIS2 obligations remains a company's responsibility, not something a document platform alone can guarantee.

What to do before your deadline

Those who fall into the first NIS group must verify the date of their ACN communication and whether basic measures have been adopted. Documentary evidence aids verification but does not replace security measures. It is worth asking, for each of the areas required by Legislative Decree 138/2024: if an inspector asked today, who in the company would be able to quickly retrieve the proof, and from where.

For the general overview on NIS2 and GDPR, read what you truly risk in case of a cyber attack. Learn more about Certiblok®'s UNI CEI EN ISO/IEC 27001:2024 certified information security management system and the DORA framework for the financial sector: these are distinct topics, not shortcuts to comply with NIS2.

Key takeaways

  • The NIS2 deadline for basic security measures is October 2026 for many entities, but it depends on the individual ACN communication date.
  • Companies must demonstrate actual implementation of security measures, not just documented policies, to comply with NIS2.
  • Penalties for non-compliance are severe and determined by the violation, entity category, and specific circumstances.
  • Effective document management, including version history and access logs, is crucial for providing auditable evidence of NIS2 compliance.
  • Certiblok®'s DRM® & Archive and Audit Room features can help manage and present documentary evidence, but compliance remains the company's responsibility.
  • It is essential to identify who can quickly retrieve proof of adopted measures within your company before an audit.

FAQ

What is the NIS2 deadline for security measures?
For entities included in the NIS list in 2025, the deadline to adopt basic security measures is 18 months from their ACN communication, which for many falls in October 2026. The exact date varies per entity.
What kind of evidence is required for NIS2 compliance?
NIS2 compliance requires demonstrable evidence of adopted measures, not just documented policies. This includes logs, records, version histories, and other proof of practical implementation.
How can document management help with NIS2?
A robust document management system helps track versions, access, and shares, providing clear traceability. This simplifies the process of retrieving evidence for auditors and demonstrating effective security practices.
Are there penalties for NIS2 non-compliance?
Yes, Legislative Decree 138/2024 outlines significant penalties for NIS2 violations, the application of which depends on the severity of the breach and the entity's classification.
Does a document platform guarantee NIS2 compliance?
No, a document platform aids in providing evidence and managing records, but it does not independently guarantee NIS2 compliance. Compliance is the responsibility of the company, involving a comprehensive approach to risk management and policy implementation.

Text generated with AI assistance and reviewed by a human.