In the update published on 14th of July 2026, the National Cybersecurity Agency (ACN) supplemented its FAQs addressing the obligations of the management and governing bodies of the entities falling within the scope of the NIS 2 rules. The intervention - which supplements the existing FAQs ODA.8 and ODA.9 and introduces the new FAQs ODA.10, ODA.11 and ODA.12 - resolves doubts on certain interpretive points that, in practical application, had given rise to uncertainty both among businesses and within the public administrations subject to Legislative Decree No. 138 of 4 September 2024.
The starting point is Article 23 of Legislative Decree 138/2024, by which the national legislature implemented Directive (EU) 2022/2555 (NIS 2). The provision places on the management and governing bodies of essential and important entities a series of direct and personal obligations: approval of cyber-risk management measures, supervision of their implementation, adequate training in information security, and personal liability in the event of a breach. As is well known, the provision does not expressly clarify the boundary between what must be approved by the collegiate or single-member body and what may instead be handled by the internal technical structures. The FAQs discussed here fill this gap.
FAQs ODA.8 and ODA.9 confirm that "the approval of the documents provided for by Article 23 of the NIS decree constitutes an exclusive competence of the collegiate body or, where applicable, of the single-member body, and cannot be delegated", whereas "the carrying out of the activities necessary for the operational implementation of the obligations laid down by the rules remains delegable.”
The distinction was not foreign to the text of the decree - it was already implicit in it - but its explicit statement in the FAQs removes the interpretive margin that had allowed some organizations to structure delegations exceeding the permitted limits.
The contribution of greatest practical impact is that of the new FAQ ODA.10. The documents to be submitted for the approval of the management body "must set out the security measures at least at the level of strategic direction and planning", whereas documentation of a technical and operational nature - procedures, operating instructions, manuals - may be "prepared and updated by the competent structures without the need for approval by the governing bodies.”
Before this clarification, an expansive reading of Article 23 risked drawing into the sphere of competence of the management body acts of a purely executive nature, with distorting effects on decision-making processes wholly disproportionate to the purpose of the provision.
FAQs ODA.11 and ODA.12 grant NIS entities broad freedom in shaping their own documentary framework. NIS entities may in fact organize their documentation in the manner they consider most suitable to their organizational structure: in a single instrument or in a coordinated set of separate documents. Moreover, the updating of the technical and organizational safeguards referred to in the strategic documentation does not trigger the need for fresh formal approval of that documentation by the top-level body.
On this point, the most recent interpretive debate deserves emphasis: the flexibility recognized by FAQs ODA.11 and ODA.12 does not translate into documentary informality. Organizational freedom nonetheless presupposes a governed documentary system, in which changes are traceable and responsibilities clearly identifiable. ACN simplifies the processes, not the level of substantive rigor required.
The resulting framework is a system structured on two distinct levels. At the strategic level - the exclusive and non-delegable competence of the management body - sit the direction and planning of the security measures under Article 23. At the operational level - delegable to internal structures - sit procedures, manuals, technical instructions and their subsequent updates. Management bodies thus obtain a clear delimitation of their institutional role, without being involved in the approval of every single technical-operational document. CISOs and IT managers regain managerial autonomy without having to await a formal resolution each time. For the public administrations subject to the NIS rules, the same principle makes it possible to keep the moment of political-administrative direction distinct from that of technical management, avoiding overlaps and procedural redundancies.
The update of 14 July 2026 is not a matter of mere detail. For the essential and important entities that are structuring their compliance with Legislative Decree 138/2024, ACN's clarifications offer an operational map to rely on - and one that would be advisable to adopt before supervisory activities get fully underway.
Lawyer Umberto Mottola and Lawyer Rossella Bucca