Description

Implemented Second Decree implementing the National Cybersecurity Perimeter (Incident Notification)

On 1 January 2022, the grace period for the implementation of prime ministerial decree 81/2021 ended, defining incident notification procedures as part of the implementation of the National Cybersecurity Perimeter. The decree categorises entities and systems based on their criticality, depending on which different time limits are set out for both implementation of the appropriate security measures and notification of any incidents to the Italian CSIRT and competent authorities. In particular, the decree contains tables outlining what entities are required to notify the CSIRT of incidents within six hours or within one hour of becoming aware of it. Entities that are part of the Perimeter shall follow these notification procedures starting 1 January 2022.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
infrastructure provider: internet and telecom services
Implementation Level
national
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2021-04-14
adopted

On 14 April 2021, Prime Ministerial Decree 81/2021 was adopted, defining incident notification proc…

2021-06-11
adopted

On 11 June 2021, the prime ministerial decree 81/2021 was published, defining incident notification…

2021-06-26
in grace period

On 26 June 2021, the prime ministerial decreee 81/2021 entered into force with a grace period, defi…

2022-01-01
in force

On 1 January 2022, the grace period for the implementation of prime ministerial decree 81/2021 ende…