On 11 August 2026 the Italian National Cybersecurity Agency added to its NIS frequently asked questions a section on monitoring, supervision and enforcement, made up of answers MVE.1 to MVE.5 and announced by the Agency on the same day. This is not new legislation and it adds no further obligations: it is the soft law explanation of how the national competent authority under NIS intends to exercise the powers conferred on it by Chapter V of Legislative Decree No 138 of 4 September 2024. The timing matters, though: for entities added to the NIS register during 2025, the eighteen month deadline for adopting the basic security measures is now falling due, and supervision stops being a theoretical chapter of the decree.
Four areas, one assessment
FAQ MVE.1 breaks the Agency’s activity down into four areas: monitoring, analysis and support under Article 35; verification and inspection under Article 36; enforcement measures under Article 37; and administrative fines and accessory sanctions under Article 38. They are distinct areas, but not watertight compartments, because the decree links them expressly: Article 38(1) requires the authority, when exercising its sanctioning powers, to take account of the outcome of monitoring, of the findings of inspections and of the exercise of enforcement powers.
The Agency states that it will proceed with a gradual, risk based approach and according to the principles of effectiveness, proportionality and dissuasiveness, taking account of the elements listed in Article 34(6): the gravity of the breach and the importance of the provisions breached, its duration, any relevant previous breaches, material or immaterial damage caused, intent or negligence, measures taken to prevent or mitigate the damage, adherence to approved codes of conduct or certification mechanisms, and the level of cooperation with the authority. In practice, that list turns conduct held before and during the control into a factor in quantifying the fine.
Monitoring is not an inspection, but it feeds the file
FAQ MVE.2 describes the Article 35 activity as systematic and continuous, aimed at knowing the NIS entities and accompanying them in implementing their obligations. It relies on the information entities transmit under the decree, starting with the information provided for registration; where that is not sufficient, the authority may acquire more, requesting among other things reporting, including on a periodic basis, or self assessments. Support, which includes recommendations, FAQs, guidelines and outreach through the sector round tables, operates before and independently of any inspection or enforcement power.
The distinction has a practical weight worth noting. A request for reporting or self assessment is not an inspection and does not trigger the procedural safeguards that an inspection brings with it, yet what an entity declares in that setting feeds the overall assessment the Agency makes when setting priorities, planning support and, where appropriate, moving to the following areas. Inaccurate self declarations cost more than prudent silence.
Essential and important entities: the difference lies in the trigger
This is the sharpest point in the whole section. FAQ MVE.3 confirms that verification and inspection activities are differentiated: for essential entities, on site and remote inspections, including random checks, may also be ordered ex ante; for important entities they may not. For the latter, an inspection may be ordered only where the authority has obtained or received evidence, indications or information suggesting possible breaches of the decree, under Article 36(2). The powers themselves are the same: verification of the documentation transmitted, on site and remote inspections, and requests for access to data, documents and other information, with an obligation to state the purpose of the request.
For an essential entity, therefore, a control may arrive with no suspicion of any breach, and the classification as essential or important, which many organisations treated as a formality of the registration stage, decides whether the organisation must consider itself permanently open to inspection. On how that classification came about, and what it means in terms of notifications and measures, the earlier account in NIS 2 put to the test: notifications, categorisation and security measures in the 2026 roll out remains useful.
Formal notices and fines are not alternatives
The enforcement measures under Article 37, FAQ MVE.4 explains, are the acts by which the authority requires an entity to bring its conduct into line with its obligations, to remedy identified shortcomings or to cease conduct in breach of the decree, and they are exercised through orders and formal notices setting reasonable and proportionate arrangements and deadlines. The Agency makes one point that is worth reading twice: resorting to enforcement powers does not preclude the exercise of sanctioning powers, because the two functions are different and complementary. Complying with a formal notice, in other words, does not erase the breach already committed.
On the sanctioning side, FAQ MVE.5 clarifies that the offences under Article 38(8) are the same for everyone, while the amounts and the scope of accessory measures differ. For essential entities other than public administrations the fine may reach ten million euro or two per cent of total worldwide annual turnover for the preceding financial year, whichever is higher, with a minimum set at one twentieth of the statutory maximum; for important entities the ceiling falls to seven million euro or one point four per cent, with a minimum of one thirtieth. For the public administrations listed in Annex III and for the publicly held or publicly controlled entities identified by the provision, the range runs from twenty five thousand to one hundred and twenty five thousand euro, reduced by one third where the entity is an important one.
There is also the accessory sanction under Article 38(6), which reaches natural persons: if the entity fails to comply within the deadline set by the formal notice, the authority may impose on management and governing bodies, and on those acting as chief executive or legal representative, a temporary disqualification from managerial functions within that same entity, lasting until the necessary remedial measures are adopted. It is the Italian translation of the accountability of senior management already discussed in Cyber accountability reaches the board, but the standards to demonstrate it have not been written yet.
The calendar that makes supervision current
The supervision FAQs arrive once the framework of obligations has settled. The section on security measures and incident notification recalls that determination 379907/2025 of 19 December 2025, applicable from 15 January 2026, updated determination 164179 of 14 April, recording the completion of the notification of the technical rules to the Commission under Directive 2015/1535, whose standstill period ended on 11 November. From 15 January 2026, once the transitional provisions for operators of essential services and telecommunications operators lapsed, the general notification regime applies.
As for the basic measures, FAQ MSB.3 draws a distinction: for entities entered in the register during 2025 the deadline is eighteen months from receipt of the notice of inclusion, while for those entered for the first time in 2026 it expires on 31 July 2027. Since registration on the Agency’s platform runs from 1 January to 28 February each year, for the first cohort those eighteen months fall due between the second half of 2026 and the early months of 2027, depending on when each entity received its notice. That is the window in which Article 35 monitoring finally has something to measure.
What remains on the entities
The five answers do not move substantive law by a millimetre, but they say plainly that NIS compliance is not exhausted by adopting the measures before the deadline: it has to be documented well enough to survive a reporting request, a self assessment or an inspection which, for essential entities, may be ordered with no trigger of suspicion. Anyone classified as essential has reason to put the evidence of the basic measures in order now, because the timing of the control is not theirs to choose; important entities have more room, but only until something emerges that suggests a breach. In both cases, adherence to codes of conduct and approved certifications and cooperation with the Agency are not a shield, yet they weigh on the size of the fine. For manufacturers of products with digital elements it is worth recalling that a second reporting duty runs in parallel from 11 September 2026, the one under the Cyber Resilience Act, with its own channels and deadlines.




