Post 90217

Immagine creata con IAAI-generated image

Cyber accountability reaches the board, but the standards to prove it are still out to tender

On 14 July 2026 the Italian National Cybersecurity Agency (ACN) updated its FAQs on the obligations of the management bodies of NIS entities, clarifying that the approval of cybersecurity risk management measures cannot be delegated and that responsibility for the way that function is exercised stays with those who sit on the board. The day before, ENISA had published a maturity model designed to bring the Cyber Resilience Act into the smallest companies, while warning that no score replaces legal obligations and that no maturity level counts as evidence of compliance. Two weeks earlier, on 30 June, CEN and CENELEC had opened a tender to select the rapporteurs who are to draft the standards supporting that very regulation. Read together, the three documents say one thing: the duty of cybersecurity has already moved up to the top of the organisation and already reached the micro-enterprise, while the technical instrument that should allow compliance to be demonstrated is still being procured.

ACN: approval of the measures cannot be delegated

The update revises FAQs ODA.8 and ODA.9 and adds three new ones, ODA.10, ODA.11 and ODA.12, all devoted to the obligations that Article 23 of the Italian NIS decree places on the management bodies of essential and important entities. The distinction the Agency draws deserves attention. The FAQs allow internal delegation of the activities needed to implement the obligations, but they rule out any delegation of the approval of the arrangements for implementing the risk management measures adopted under ACN Determination 379907/2025. That approval, the Agency states, remains solely and exclusively with the management body acting collectively or, where applicable, with the single-person body, and cannot be transferred either to individual directors or to other internal bodies and functions, whatever the corporate governance model in use.

Alongside approval, three further duties remain non-delegable: overseeing the implementation of the obligations, bearing responsibility for infringements of the decree, and both attending cybersecurity training and promoting equivalent periodic training for employees. In ACN’s characterisation these are duties of strategic direction and planning and, as such, cannot be delegated. What can be delegated is implementation alone, and on this point FAQ ODA.9 adds what matters most to a lawyer: where a delegation exists, for companies Articles 2381 and 2392 of the Italian Civil Code continue to apply. The reference is not decorative, because it brings the matter back inside company law, with the directors’ duty to act on an informed basis and to assess the adequacy of the organisational structure, and with liability for damage caused by failing to observe the duties imposed by law. The Agency’s stated aim is explicit: to raise cybersecurity to the level of a strategic priority for management bodies.

What actually reaches the boardroom

FAQ ODA.10 goes further and lists the documents that must be submitted for approval: the cybersecurity organisation, the cybersecurity policies, the assessment of the risk to the security of network and information systems, the risk treatment plan, the vulnerability management plan, the adaptation plan, the business continuity, disaster recovery and crisis management plans, the training plan and the cybersecurity incident management plan. The list is also set out in table form in Annex C to the reading guide to the baseline specifications. The level of detail required, however, is not technical: the documents must reflect and articulate the security requirements at least at the level of strategic direction and planning, so that the management body can exercise its function in an informed manner. Technical procedures, operating instructions and manuals may be left to the competent internal units.

FAQs ODA.11 and ODA.12 complete the picture in practical terms. A NIS entity may organise its documentation as it sees fit, gathering the content into a single document or spreading it across several coordinated documents, and updating the technical and organisational instruments referenced in the strategic documents does not require those documents to be submitted for approval again. This is a sensible simplification, but it does not soften the central point: what the board approves is not a formality but the informed assumption of a responsibility that the law assigns to it directly. On how the other NIS 2 obligations work in practice, from the categorisation of entities to incident notifications, see NIS 2 put to the test.

The Cyber Resilience Act reaches the micro-enterprise

On 13 July 2026 the European Union Agency for Cybersecurity published the SME Cyber Resilience Maturity Assessment Model, presented as a self-assessment tool aimed primarily at organisations that manufacture and place products with digital elements on the market, and therefore fall directly within the scope of the Cyber Resilience Act, but usable also by integrators and service providers involved in the product life cycle. The model divides the assessment into five domains, running from governance and documentation to risk management and security by design and by default, from vulnerability and patch management to product life cycle management, and finally to awareness, competence and skills. Each domain is measured against five maturity criteria and three maturity profiles, basic, intermediate and advanced, with a downloadable spreadsheet that calculates the scores. The caveat attached to the model is the most interesting part: an advanced maturity level does not replace legal obligations and cannot be regarded as evidence of compliance.

The model comes with the results of a survey carried out between February and March 2026 among 194 organisations from 31 countries, including 25 Member States. Sixty-six per cent of respondents had heard of the regulation, yet the Agency itself acknowledges that understanding of the practical requirements still has room to improve. Company size is the factor that most consistently drives maturity: across all five domains, medium-sized companies score on average about one point higher than microcompanies. Incident response and product life cycle management is the weakest area overall, especially for microcompanies, and the most widespread request is not for more regulation but for tools, since technical documentation templates and secure development templates were each asked for by more than 70 per cent of respondents, while 142 pointed to the need for financial support. The overlap of scopes between NIS 2, DORA and the Cyber Resilience Act translates, for smaller companies, into a problem of resources before it becomes one of legal classification.

The standards meant to make compliance demonstrable are still out to tender

On 30 June 2026 CEN and CENELEC published an open call for tender to select the rapporteurs tasked with developing the vertical standards supporting Regulation (EU) 2024/2847. The work concerns CEN/TC 224, CLC/TC 65X and working group 6 of CEN-CLC/JTC 13, in collaboration with other technical committees within CEN, CENELEC and ETSI, and responds to the standardisation request that the European Commission addressed to the European standardisation organisations in support of the implementation of the regulation. The deadline for applications is 4 August 2026.

This is not a procedural detail. Under the European new legislative framework, harmonised standards are the ordinary route by which a manufacturer may presume the conformity of a product with the essential requirements laid down in the regulation, and therefore document its own diligence without having to rebuild the technical reasoning from scratch. For as long as those standards do not exist, conformity must be demonstrated by other means, more expensive and less predictable, and the cost of that uncertainty falls most heavily on the very companies with the fewest resources to absorb it, that is to say the ones ENISA has just described as the most fragile. It is the same problem that arises whenever a risk has to be measured with instruments that are heterogeneous and not yet settled, as in the comparison between the models of NIST, MIT, CSA and ENISA.

An asymmetry that falls on those who decide

The resulting picture is coherent and uncomfortable. Responsibility moves upwards, because ACN has made clear that approval of the measures belongs to the management body and cannot be placed anywhere else. It moves downwards, because the Cyber Resilience Act reaches the software producer with a handful of employees. And it hardens on the personal level, because the reference to Articles 2381 and 2392 of the Italian Civil Code brings the question back within the liability of directors. Meanwhile, the instruments that should make compliance demonstrable in an ordinary and repeatable way are still the object of a selection of experts that will close in August. The director who today has to approve a risk treatment plan or an adaptation plan does so by assuming full responsibility against a technical benchmark that, for the most part, has not yet been written.

In light of the foregoing, one may ask whether a legal order that brings forward the duty ahead of the instrument that makes its performance provable does not end up turning diligence into a gamble, and whether it is not for those who write the rules to ensure that proof of compliance is available at the moment compliance becomes mandatory.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article