Skip to content
11 days until the Art. 14 reporting obligation (11 September 2026).
Documentation Support Risk class
00Cyber Resilience Act · Practical guide · 5 August 2026 · 10 min read

How to report to CSIRT Italia (ACN) under the CRA

The Cyber Resilience Act obliges the manufacturer to report an actively exploited vulnerability within 24 hours to the designated national CSIRT and to ENISA. For companies with an Italian point of contact, the designated national CSIRT is CSIRT Italia, hosted by the Agenzia per la Cybersicurezza Nazionale. This is the operational route: who receives the report, where it is filed, and what to arrange before the emergency.

1. Who receives your notification: ACN and CSIRT Italia

The Agenzia per la Cybersicurezza Nazionale (ACN) is the national authority, and CSIRT Italia is the team that operates inside it. ACN is based in Rome and coordinates the national cybersecurity strategy as well as hosting the response team.

The chain is exactly this: ACN as the institution, CSIRT Italia as the operational team that reads your notification and, together with ENISA, forms the pair of recipients envisaged by the regulation. It is not a mailbox that answers when convenient: it is a designated national reference point, with its own procedures for accreditation and access.

ACN was set up in 2021 as the national cybersecurity authority, pulling into one body powers that were previously spread out. CSIRT Italia is its operational team: it receives reports, correlates them and issues advisories to industry. For a manufacturer it is a single counterpart, which simplifies something that elsewhere is split across several desks.

Art. 14 · designated CSIRTEach Member State designates one of its CSIRTs as the coordinator that receives the notifications from manufacturers under the regulation. In Italy that role is held by CSIRT Italia, within ACN.
Analysts in an emergency operations centre

2. The national channel, in practice

The language of the notification is Italian. ACN publishes advisories and security bulletins in Italian and runs a reporting channel for operators in regulated sectors — the same administrative door through which the designation of your company contact point passes.

If you already report as a NIS entity you know that route. The CRA does not replace it and is not absorbed into it: they are two separate duties, with different triggers, that can arise together from the same event and must both be discharged.

CSIRT Italia · official website

3. The landscape around it

Italy transposed NIS2 through legislative decree 138/2024 and concentrated the role of national competent authority in ACN. The result is an ecosystem where CSIRT Italia is the operational point of contact for most cyber reporting duties.

For the CRA that is not an automatic answer: designating the CSIRT that receives manufacturers' notifications follows the national implementation of the Regulation. Check the designation in force before you file, and do not infer it from NIS2.

One last practical point: ACN also handles national cybersecurity certification and the coordination with ENISA on European schemes. If your product lands in the critical class and needs certification, the institutional counterpart is the same one your notification goes to. That is not a small advantage: it cuts the number of doors to knock on when the two things intersect.

4. How filing works, in short

Filing is not an email to the authority: it goes through the single reporting platform established by Art. 16, and access requires EU Login credentials validated beforehand.

The chain of deadlines — 24 hours, 72 hours, final report — is the same across the Union and is set out in full on the Art. 14 page. For the article’s other trigger the final deadline changes: it is on the severe incident page.

EU Login is not something you improvise. Register at least one person, confirm the account and enrol the second factor now, while there is no pressure — then keep the credentials retrievable by more than one hand. EU Login · Commission authentication

5. What to prepare before an incident

Five things, arranged calmly, make the difference between a report filed in time and one filed too late. First, the designation and validation of the company's contact point to CSIRT Italia: the reporting relationship is between named parties, and identifying yourself for the first time under pressure costs hours you do not have. Second, the EU Login credentials described above, held by at least two people.

In Italy it pays to check early whether your company is already registered with ACN for other duties: the contact point and the credentials may partly overlap, and finding that out calmly is worth more than finding it out on the day of the case.

And a note on time: Italy runs on CEST in summer and CET in winter, and Art. 14's twenty-four hours are counted in real hours, not office hours. If the moment of awareness falls on the Friday evening of a long weekend, the deadline falls inside the long weekend. Whoever runs a rota already knows this; whoever does not has the reason here.

This guide describes our reading of the regulatory text and the public procedures; it does not constitute legal advice, and the platform's operational details may evolve.

National authorities

Who receives your notification, country by country

Art. 14 sends the notification to two recipients: the CSIRT designated by your Member State, and ENISA. The CSIRT changes with the country. Pick yours and read who staffs it, how filing works and what to prepare in advance.

Nine countries. Designation for CRA purposes follows national implementation: check the one in force before you file.