Cyber Resilience Act: Italian decree, ACN and penalties

On 2 October the Italian Council of Ministers gave preliminary approval to the legislative decree adapting national law to Regulation (EU) 2024/2847. ACN is the notifying authority and the market surveillance authority and may rely on the Guardia di finanza; the AI authorities, Banca d'Italia, CONSOB, IVASS and the data protection authority supervise in their own areas. Consumer complaints go to CSIRT Italia, with an SME channel, proportionate fees and a regulatory sandbox, the Sandbox-CRA.

ComplianceCybersecurityGovernanceCybersecurityComplianceCRAEU RegulationACNSMEsSandbox

Article

Four figures on the Italian decree adapting national law to the Cyber Resilience Act
Data from the Council of Ministers press release and Regulation (EU) 2024/2847. Sources at the end.

On 2 October the Italian Council of Ministers gave preliminary approval to the legislative decree adapting national law to Regulation (EU) 2024/2847, the Cyber Resilience Act. The text was proposed by the Prime Minister and the Minister for European Affairs, the NRRP and Cohesion Policies. The delegation is in Article 15 of Law no. 36 of 17 March 2026, the 2025 European Delegation Law.

The regulation applies directly. The decree sets out who supervises in Italy, how penalties are applied and which tools the smallest companies get.

Who supervises

The National Cybersecurity Agency (ACN) has two roles:

  • notifying authority for conformity assessment bodies, which are assessed and monitored by the national accreditation body;
  • market surveillance authority, with the option of relying on the Guardia di finanza.

Other authorities supervise in their own areas:

  • for products that are also high-risk AI systems, the authorities competent under the national AI rules;
  • for supervised financial institutions, Banca d’Italia, CONSOB and IVASS;
  • for matters within its remit, the Italian data protection authority (Garante per la protezione dei dati personali).

The authorities work in coordination, including through information-sharing agreements.

Penalties and complaints

Each authority applies the regulation’s administrative penalties under its own procedures. The maximum amounts are set by Article 64 of the regulation:

  • up to €15 million or 2.5% of worldwide annual turnover, if higher, for the essential requirements of Annex I and the obligations of Articles 13 and 14;
  • up to €10 million or 2% for the other obligations listed in paragraph 3, including those of importers and distributors;
  • up to €5 million or 1% for incorrect, incomplete or misleading information supplied to notified bodies and market surveillance authorities.

Consumers can report vulnerabilities, incidents and cyber threats directly to CSIRT Italia. Breaches of the regulation are also added to the matters for which representative actions can be brought to protect consumers’ collective interests.

SMEs and the Sandbox-CRA

For the smallest companies the decree provides:

  • a dedicated advisory channel for micro, small and medium-sized enterprises and start-ups, defined by ACN and the Ministry of Enterprises and Made in Italy;
  • proportionate fees for conformity assessment;
  • a regulatory sandbox, the Sandbox-CRA, supervised by ACN.

The dedicated channel and regulatory sandboxes are provided for in Article 33 of the regulation. The Sandbox-CRA offers controlled testing environments to develop and verify innovative products before they are placed on the market. Micro and small enterprises get priority access. The sandbox is coordinated with those for financial services and for artificial intelligence.

The timeline

Article 71 of the regulation sets three dates:

As of 3 October the first two dates have already passed. After the preliminary approval the draft goes through the required opinions, including those of the parliamentary committees, and then back to the Council of Ministers for final approval before publication in the Official Gazette.

What we think

The draft confirms ACN as the main point of reference for the cybersecurity of digital products, with the sector authorities for finance, personal data and AI. For a manufacturer it means knowing whom to answer to and with which tools, starting from the SME channel and the Sandbox-CRA. The operational details (penalty procedures, fee amounts, sandbox access rules) will require the text of the draft, which the press release does not include.

What to watch

  • The publication of the draft as a government act and the opinions of the parliamentary committees.
  • Final approval and publication in the Official Gazette.
  • The penalty procedures of each authority and how they coordinate.
  • The conformity assessment fees and the rules of the Sandbox-CRA.

Sources

Need support?Under attack?Service Status
Need support?Under attack?Service Status