Italy’s Law 90/2024 Connects Public-Sector Deadlines to Cybercrime Enforcement

Italy’s Law 90/2024 combines operational cybersecurity duties with stronger cybercrime provisions. For covered public organisations, the message is immediate: detect quickly, report in stages and put accountable security leadership in place.

Law No. 90 of 28 June 2024 was published on 2 July and entered into force on 17 July 2024. It strengthens national cybersecurity, resilience in public administration and the criminal-law response to computer offences.

The statute arrived shortly before Italy’s NIS2 decree, but it is not simply a duplicate. It targets national institutions and specified public and strategic organisations while also changing the enforcement environment around attacks and extortion.

The clock starts before the full story exists

For covered public administrations and other listed entities, the law introduced a staged incident-notification structure using procedures made available by the National Cybersecurity Agency, ACN. An initial report is required within 24 hours after learning of an incident falling within the relevant taxonomy, followed by a fuller notification within 72 hours.

The architecture resembles a good incident process: an early signal for situational awareness, then a more complete account after initial investigation. It does not require the first message to contain a finished forensic narrative.

Organisations should define what evidence is needed to determine that an event matches the reportable taxonomy, who has authority to notify and how the 24-hour clock is recorded. If those decisions begin only after a crisis call reaches senior management, the usable investigation window will be much shorter.

Local detection must reach a national channel

Many public services are delivered through regional offices, outsourced providers and shared platforms. The person who first sees an alert may not know that it affects a covered entity. Contracts and operating procedures must therefore create a fast route from technical observation to the organisation’s reporting decision.

A supplier’s promise to notify “without undue delay” is not precise enough where the customer has a 24-hour external milestone. Agreements should specify immediate triggers, contact methods, minimum facts, evidence preservation and continued updates. They should also address incidents detected by another customer or shared infrastructure that may change the assessment.

Cybersecurity gains an organisational owner

The law requires affected public administrations to establish a cybersecurity structure and appoint a cybersecurity contact with professional and integrity requirements. That role should not become a ceremonial address for ACN correspondence.

The contact needs access to service inventories, incident records, risk decisions and executive escalation. They also need a relationship with procurement, because architecture and supplier terms determine whether the entity can meet its notification and resilience duties.

Leadership should document who can act when the designated contact is unavailable. A statutory role without deputies, authority or access can become a single point of failure.

Procurement is part of the security perimeter

Law 90 also supports stronger attention to cybersecurity in procurement of technology used in contexts connected with strategic national interests. Subsequent implementing measures identify essential cybersecurity elements for specified technology categories and circumstances in which security-related award criteria apply.

That direction encourages buyers to evaluate maintainability, vulnerability handling, secure configuration and supply-chain origin rather than relying on a generic security certificate. Procurement files should show how technical requirements relate to the service’s risk, how supplier claims will be tested and how security will be maintained after award.

Criminal-law changes affect incident strategy

The statute strengthens provisions concerning computer crimes and aggravating circumstances. That does not turn every cyber incident into a criminal case, but it increases the importance of preserving evidence and coordinating regulatory, operational and law-enforcement decisions.

Incident playbooks should identify who can authorise contact with law enforcement, how volatile evidence is captured and how investigators are given information without undermining recovery or confidentiality. Payment and communication decisions in extortion events should not be separated from legal assessment.

What covered entities should test

  • Can every operating unit reach the central incident function at any hour?
  • Does the supplier process leave enough time for a 24-hour preliminary report?
  • Can the organisation distinguish the initial notification from the 72-hour update?
  • Is the cybersecurity contact empowered to obtain facts across departments?
  • Do procurement records connect security requirements to national and service risk?
  • Can evidence be preserved while systems are restored?

Law 90/2024 links three layers that organisations often manage separately: operational reporting, institutional responsibility and the criminal response. A compliance document cannot bridge those layers on its own. The incident process, governance model and technical estate must do it together.

Official sources

Continue the series

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *