CRA Compliance in Italy
National competent authority, Article 14 CSIRT contacts, and enforcement guidance for Italy manufacturers.
Italy established the Agenzia per la Cybersicurezza Nazionale (ACN) in 2021, creating a dedicated national cybersecurity authority that serves as the country's CRA national competent authority and hosts CSIRT Italia. Italian manufacturers — particularly in the industrial automation, aerospace, and fashion-tech sectors — must navigate CRA requirements alongside Italy's Perimetro di Sicurezza Nazionale Cibernetica, which imposes overlapping security obligations on supply chains for critical national infrastructure. Italy has one of the EU's largest manufacturing sectors, making CRA compliance a significant national economic issue.
National Competent Authority (CRA)
ACN
Agenzia per la Cybersicurezza Nazionale
ACN was established in 2021 as Italy's national cybersecurity agency, taking over functions previously dispersed across DIS, CNAIPIC, and other bodies. ACN serves as Italy's CRA national competent authority and hosts CSIRT Italia as its operational incident response arm.
https://www.acn.gov.it →National CSIRT (Article 14 Reports)
CSIRT Italia
CSIRT Italia
https://www.csirt.gov.it/segnalazione
https://www.csirt.gov.it →CRA Enforcement in Italy
ACN serves as Italy's national competent authority for the CRA, with market surveillance functions coordinated with MIMIT (Ministero delle Imprese e del Made in Italy) for consumer and industrial products. Italy's complex regulatory landscape — including the Perimetro di Sicurezza Nazionale Cibernetica and NIS2 transposition through the D.Lgs. 138/2024 — creates overlapping obligations that manufacturers must carefully map. ACN has moved quickly to build domestic capacity, publishing cybersecurity guidelines and establishing Italy's national cybersecurity certification scheme. ACN participates actively in ENISA working groups and coordinates with EU peer authorities on CRA technical requirements.
Article 14 Incident Reporting for Italian Manufacturers
Italian manufacturers must submit Article 14 notifications to CSIRT Italia through the secure reporting portal at csirt.gov.it. CSIRT Italia operates 24/7 incident response capability and accepts reports in Italian and English. The Article 14 obligation requires an early warning within 24 hours of detecting active exploitation and a full notification within 72 hours. Italy's Perimetro framework already requires incident notification for critical infrastructure supply chains through ACN, and manufacturers subject to both frameworks should coordinate their notification procedures to satisfy both obligations efficiently. CSIRT Italia participates in the EU CSIRTs network and relays reports to ENISA.
Market Surveillance & Penalties
Market surveillance for CRA products in Italy is coordinated between ACN and MIMIT, with USMAF (port health authorities) and the Guardia di Finanza involved in border-level surveillance of imported products. Italy will implement the full CRA penalty regime: up to €15 million or 2.5% of global annual turnover for violations of essential cybersecurity requirements. Italy's enforcement tradition in product safety has historically been variable, but ACN's creation signals a more centralised and capable enforcement approach for cybersecurity. Manufacturers should expect documentation-based surveillance first, with technical testing reserved for higher-risk product categories.
Support for Italian Manufacturers
ACN publishes Italian-language cybersecurity guidelines and implementation guidance for manufacturers, including sector-specific frameworks for industrial and critical infrastructure supply chains. The agency operates a free Sportello Unico (single contact point) for cybersecurity regulatory enquiries from businesses. Confindustria and its sector federations (including Federmeccanica and Confindustria Digitale) provide CRA implementation guidance for Italian industrial manufacturers. ENEA and CNR research institutes provide technical expertise for conformity assessment activities. Italy's national cybersecurity certification body operates under ACN for products requiring third-party evaluation.
CVD Portal automates your Article 14 notification obligations.
Pre-built notification workflows for CSIRT Italia, deadline tracking, CSAF advisory generation, and a public CVD submission portal. Free forever.
Start your free portalFrequently asked
How do I contact ACN as a manufacturer with a CRA compliance question?+
ACN can be contacted through acn.gov.it, where a manufacturer enquiry form is available. For CRA-specific queries, ACN's regulatory affairs division handles industry communications. CSIRT Italia at csirt.gov.it handles incident notifications and vulnerability reports. ACN engages manufacturers through its annual Cybertech Europe events and sector-specific working groups conducted through Confindustria's cybersecurity committee.
Does Italy have national-level CRA implementing legislation?+
Italy has transposed NIS2 through D.Lgs. 138/2024, and CRA implementing measures are expected through delegated legislation under the same enabling framework. MIMIT is leading the product safety aspects of CRA implementation, while ACN leads the cybersecurity enforcement aspects. National implementing decrees are expected ahead of the CRA's December 2027 application date. The Perimetro di Sicurezza Nazionale Cibernetica legislation (L. 133/2019 and implementing decrees) will be coordinated with CRA requirements for manufacturers in the critical infrastructure supply chain.
How does the CRA interact with Italy's Perimetro di Sicurezza Nazionale Cibernetica?+
Italy's Perimetro di Sicurezza Nazionale Cibernetica imposes security requirements on ICT assets used by operators of critical national functions, including supply chain security obligations that affect manufacturers. The Perimetro framework is administered by ACN and requires technology providers to pass security assessments (CVCN evaluations) for certain high-risk products. The CRA's essential requirements for all products with digital elements complement rather than replace Perimetro obligations. Manufacturers supplying both the general market and critical infrastructure should conduct a combined Perimetro and CRA compliance analysis.
Need a CRA compliance checklist for your product?
Browse free niche-specific checklists covering classification, Annex I obligations, and CVD requirements.