Country Overview Updated: August 2026

Cyber Resilience Act Enforcement in Italy

Learn how the EU Cyber Resilience Act applies to companies in Italy, including local market surveillance and enforcement by ACN.

Core Definition

The Cyber Resilience Act is an EU Regulation, meaning it applies directly in Italy without the need for national transposition. However, enforcement and market surveillance activities will be conducted by national authorities like ACN. Any product with digital elements sold or made available in Italy must comply with CRA standards by December 2027.

Key Compliance Steps for Italy

  1. Identify Local Representatives: If you are based outside the EU but selling into Italy, appoint an Authorized Representative in the Union.
  2. Monitor ACN Guidelines: Follow any localized guidance or translation of standards provided by ACN.
  3. Prepare ENISA Reporting: Ensure your vulnerability reporting pipelines are connected to the central ENISA platform and your national CSIRT.
  4. Localize Documentation: Ensure that the required EU Declaration of Conformity and user instructions are available in the languages required by Italy.

How This Plays Out in Practice

ACN (Agenzia per la Cybersicurezza Nazionale), only established in 2021, is still building out the institutional capacity to run full CRA market surveillance alongside its national cybersecurity perimeter duties.

What to Watch For

Italy's industrial machinery and manufacturing base overlaps heavily with CRA's higher-risk ICS and robotics categories.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Italy.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.