In December 2025 we published a guide to NIS2 deadlines on this blog. That article has aged — and aged the right way, because the 2025 deadlines were about census-taking: register, declare, be listed.
The 2026 ones are about substance. And the most important falls in a little over three months.
1. The 2026 calendar, in order
| Deadline | Requirement |
|---|---|
| April 15 - May 31, 2026 | Update of each NIS entity's information |
| May 1 - June 30, 2026 | Categorization of activities and services performed |
| October 31, 2026 | Implementation of the baseline security measures defined by ACN |
| From 2027 | Significant incident notification for entities that became NIS in 2026 |
The first two windows are closed. If you missed them, silence does not cure the failure: the continuous update obligation remains, requiring any relevant change to be communicated within fourteen days.
The deadline that really counts is October 31, 2026: by that date entities inside the NIS2 perimeter must have implemented the baseline security measures defined by the National Cybersecurity Agency. Not "started a journey": implemented.
2. The two determinations that change the game
In 2026 ACN issued two acts that shift NIS2's centre of gravity from the individual organization to the supply chain.
Determination no. 155238 of April 20, 2026 — categorization of activities and services. Every NIS2 entity must classify what it does. The purpose is stated: to allow the Authority to determine, at a later stage, which information systems will be subject to stricter security measures according to their relevance.
Translated: the classification you filed in spring is the basis on which your future obligations will be calibrated. Anyone who filled that form in loosely has written their own compliance perimeter for years to come.
Determination no. 127437/2026 — register of relevant suppliers. All NIS entities must list on the ACN platform the suppliers in their supply chain, identifying those to be classified as important or essential entities.
This is the year's most significant development, and it is worth pausing on.
3. The supply chain is no longer a contract clause
Until 2025, supply-chain security was a contractual clause: a declaration, an annex, at most an annual questionnaire. Since 2026 it is a register filed with a national authority.
Anyone supplying infrastructure — data center, cloud, connectivity, managed services, software — therefore finds themselves in a new position: their name sits in a register, associated with a NIS client and a relevance classification. Three very practical consequences follow.
First: a supplier who cannot answer becomes a compliance risk for the client, not merely an operational one. And a compliance risk, unlike an outage, is solved by changing supplier.
Second: the questions become standardized. Anyone who has faced an ACN questionnaire knows the recurring items are always the same — access management, segregation, logging and retention, business continuity, incident notification with contractual timings, subcontracting and its location.
Third: geography comes back in through the window. Knowing where the data physically sits, under which jurisdiction and with which subcontracting chain is no longer an architectural preference: it is a box to fill in.
4. What being "NIS-ready" means for infrastructure
There is no NIS2 certification, and anyone selling one is selling a badge that does not exist. There are five capabilities a supplier must be able to document, and the client must be able to carry into their own file:
- Inventory and classification of assets and services delivered to the client, consistent with the filed categorization
- Access control with role separation, vetting of personnel holding physical and logical access, and traceability of interventions
- Logging and retention with guaranteed integrity and declared timeframes — also the point where NIS2 overlaps with the AI Act for anyone hosting AI systems
- Business continuity with recovery objectives measured and tested, not estimated
- Incident notification with contractual timings aligned to those the client owes ACN: if the supplier reports in seventy-two hours, the client is already late
5. The July checklist
A little over three months remain until October 31. In order of urgency:
- Confirm you are in the perimeter and under which status: essential or important entity changes the intensity of obligations
- Re-read the categorization filed in spring and correct it if it describes what you do badly: continuous update exists precisely for this
- Close the register of relevant suppliers, verifying each one knows they are on it
- Run a gap assessment on ACN baseline measures and sequence the work by feasibility before October, not by architectural elegance
- Align notification timings across all live contracts, upstream and downstream
6. Three rulebooks, one question
2026 lined up three sets of rules that appear to be about different things. The AI Act requires conformity of AI systems and, for high risk, traceability and logs. NIS2 requires supply-chain security and a filed register of who is in it. The Cloud and AI Development Act, once it becomes law, will ask which sovereignty level the supplier sits at.
Three independent regulatory tracks converging on a single operational question: where does your workload run, who controls it, and with what documentable guarantees. It is the same question, asked by three different authorities.
A year ago NIS2 was a registration exercise. On October 31 it becomes a verifiable technical requirement, and its most interesting part is not about you: it is about who supplies you. Better to ask them before ACN does.
Note: this article is for informational purposes only and does not constitute legal advice. The scope of application and specific obligations must be verified with your advisors and against official ACN documentation.