Software for sustainable cities
Terranova Logo

TERRANOVA S.r.l. , with registered office in Florence, Via Ferdinando Bartolommei n.ro 4, tax code and registration in the Register of Companies of Florence n.ro 06139270489, as a subject falling within the scope of the Legislative Decree transposing Directive (EU) 2022/2555 (NIS 2), confirms that it has taken the necessary measures to ensure compliance with the obligations provided for by the aforementioned directive and therefore declares that it has carried out the following activities:

Cybersecurity Assessment of your level of compliance:

The Company carried out the Cybersecurity Assessment and communicated the outcome to the Management on 17 October 2024, as required by Article 21 of Legislative Decree 4 September 2024, declaring its compatibility with the provisions of the NIS 2 directive.

Registration with the National Cybersecurity Agency (ACN):

On 17 February 2025, the company completed the registration procedure with ACN through the dedicated digital platform, pursuant to Article 7, paragraph 1 of Legislative Decree 4 September 2024, and received confirmation of registration in the national list of NIS subjects.

Supply chain security management:

The company has adopted a value chain verification system, with particular attention to the assessment of critical suppliers; This process is integrated into the ISO/IEC 27001:2022 certified Information Security Management System and was successfully verified during the audits carried out by Bureau Veritas Italia S.p.A.

NIS Communication and Classification:

On 14 April 2025, as required by Legislative Decree no. 138 of 4 September 2024, the Company received from ACN the Communication pursuant to Article 7, paragraph 3, letter a), of inclusion in the list of NIS entities and its classification identified as an essential entity in relation to the type of "Management of ICT Services – Managed Service Providers".

Adoption of Security Measures:

In compliance with the ACN Determination of 14 April 2025 and in line with Legislative Decree 4 September 2024, the company has adopted the security measures provided for essential subjects.

The measures implemented are consistent with the National Framework for Cybersecurity and Data Protection and include:

-  Definition and implementation of the risk management plan: Assignment of roles and responsibilities in cybersecurity; Adoption of security and access control policies; Continuous monitoring and incident management; Staff training and awareness.

-  Incident Notification: The company has in place procedures for timely notification of significant incidents.

-  Use of certified products and services: The company uses certified ICT products, services and processes within the framework of certification schemes recognized at national and European level, pursuant to Article 27 of Legislative Decree 4 September 2024.

-  Designating a point of contact: A cybersecurity contact point has been designated, as provided for in Article 7, paragraph 1 of Legislative Decree 4 September 2024.


Monitoring and Update:

The company undertakes to maintain continuous monitoring of its IT security measures and to provide annual updates to the ACN, as required by Article 7, paragraph 4 of the Legislative Decree of 4 September 2024.

Obligation to update information annually:

On 27 May 2025, the Company obtained a postponement of the deadline for updating the information from 31 May to 31 July 2025, as permitted by regulatory provisions. This deferral was requested and approved in accordance with the procedures provided for by the competent National Authority NIS. The annual update of the information for the year 2025 was completed on 10 July 2025. 

For the year 2026, the annual update also included the census of NIS relevant suppliers, as required by the new ACN Determination no. 127437/2026, and was completed on 27/05/2026.

Management of Incident Reports to the CSIRT Italia Portal:

On 19/12/2025, the company communicated the technical contact point and his possible replacement as required by the ACN General Manager's Determination of 19 September 2025, no. 333017/2025.

Categorization of Activities and Services

On 29/06/2026 Terranova provided the categorized list of the organization's activities and services on the ACN digital platform, as required by ACN General Manager Determination no. 155238 of 20 April 2026, adopted pursuant to art. 30 of Legislative Decree 138/2024 (NIS Decree).

Stakeholder communication channel

Terranova has established the following channel dedicated to cybersecurity communications with suppliers, customers, partners and other stakeholders, in implementation of the NIST CSF 2.0 GV audit. SC-02:

-  nis2.contact@terranovasoftware.eu

Terranova S.r.l. adopts the timing provided for by Art. 25 of EU Directive 2022/2555 as part of the timing of incident reporting.

In conclusion, as described in this document, TERRANOVA S.r.l. declares that it complies with the provisions of the Legislative Decree transposing the NIS 2 Directive and that it operates as an essential NIS subject.

*The document is to be considered subject to upgrades that will be defined according to the succession of regulatory and/or interpretative changes of the standard.

Document validity date: 22/09/2026


Contact us

Contact

Want to know more?

We’d be happy to talk more in detail about your needs and explore how we can become your ideal partner, to assist you in your business venture of innovation, digitization and sustainability