Cybersecurity 2026

ITALY Law and Practice Contributed by: Paolo Balboni, Luca Bolognini, Francesco Capparelli and Giulia Finocchiaro, ICT Legal Consulting

5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Cybersecurity certification in Italy operates primarily within the EU framework established by Regulation (EU) 2019/881, commonly referred to as the Cyber - security Act. This framework provides for Euro - pean cybersecurity certification schemes covering ICT products, services and processes, and defines assurance levels reflecting the degree of confidence in security properties. Certification schemes function as instruments of risk communication and assurance rather than as substitutes for substantive security obli - gations. Certification under the EU framework is, in principle, voluntary, but it acquires practical relevance through regulatory expectations, procurement requirements and market practice. In critical sectors and public procurement, certification increasingly operates as a benchmark for acceptable security standards and may influence supplier selection and contractual allocation of risk. In this sense, certification functions as a gov - ernance tool that complements statutory obligations by providing standardised evidence of compliance. In the Italian legal environment, cybersecurity certifi - cation interacts with sector-specific regimes and with broader regulatory frameworks governing outsourc - ing and supply-chain security. Certified products and services may benefit from facilitated assessment in regulated environments, but certification does not dis - place the responsibility of regulated entities to ensure that cybersecurity requirements are met in practice. The role of certification is therefore to support, rather than replace, comprehensive risk management and oversight. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Cybersecurity obligations in the context of personal data processing derive from the security principle enshrined in data protection law and from the associ - ated breach notification regime. Controllers and pro -

tion, information sharing and incident management across the product life cycle. In regulated and critical environments, cyber-resilience requirements also interact with procurement pro - cesses. Contracting authorities and regulated opera - tors increasingly consider compliance with product security obligations as an element of risk assessment and vendor selection. This interaction reinforces the preventative function of cyber-resilience legislation by incentivising higher security standards at market entry and by reducing the propagation of vulnerabilities in operational environments. 4.2 Key Obligations Under Legislation Key obligations under cyber-resilience legislation focus on secure design, vulnerability handling and life cycle management. Economic operators are required to identify and address cybersecurity risks during the design and development phases and to implement processes that enable timely detection, remediation and communication of vulnerabilities. These obliga - tions are structured to ensure that security considera - tions are embedded within product governance and are not relegated to post-market responses. Post-market surveillance constitutes a central element of compliance. Operators are expected to monitor products in use, to assess emerging threats and to provide security updates and patches within appropri - ate timeframes. Transparency obligations require that vulnerabilities and incidents be documented and com - municated to competent authorities where thresholds are met. These mechanisms support regulatory over - sight and contribute to collective situational aware - ness. Enforcement operates through market surveillance authorities empowered to assess conformity, require corrective actions and impose sanctions. In serious cases, measures may include restrictions on mar - ket availability. Cyber-resilience obligations therefore extend beyond compliance formalities and operate as enforceable conditions for continued market partici - pation.

220 CHAMBERS.COM

Powered by