ECP vs AGID Misure Minime (Italy): Private-Sector MSP vs Italian PA Security Baseline
The AGID Misure Minime di Sicurezza ICT per le Pubbliche Amministrazioni is Italy's mandatory ICT security baseline for public administrations — 8 control families issued by AGID (Agenzia per l'Italia Digitale) in 2017, structured in three implementation levels and based on the CIS Critical Security Controls. Easy Cyber Protection is a Belgian MSP platform that packages CyFun audit-readiness for private-sector SMEs. These are not competing products for the same buyer: the AGID framework is for Italian public bodies, ECP is for private-sector MSPs. This page names the difference honestly, explains where they share common ground, and clarifies what NIS2 in Italy actually demands — which is neither of them alone.
At a glance
| AGID Misure Minime (Italy) | Easy Cyber Protection / CyFun | |
|---|---|---|
| What it is | Mandatory ICT security baseline for Italian public administration (PA) | MSP compliance platform (SaaS) for private-sector SMEs |
| Owning authority | AGID — Agenzia per l'Italia Digitale (Italian government) | CCB — Centre pour la Cybersécurité Belgique (ECP implements CyFun) |
| Published / last update | Circular 2/2017, April 18, 2017; Gazzetta Ufficiale n. 103, May 5, 2017 — not formally updated since | CyFun 2025 (aligned with NIST CSF 2.0) |
| Legal status | Mandatory for all Italian PA (centrale and locale) since December 31, 2017; self-assessed | Commercial SaaS; supports Belgian CyFun (CCB's official NIS2 compliance path) |
| Who must comply | ALL Italian public administrations regardless of size — from ministries to small municipalities | Belgian entities registered under NIS2 (CCB portal); MSPs serving them |
| Structure | 8 control families (ABSC — AgID Basic Security Controls), derived from CIS Controls 1-5, 8, 10 and 13; three levels: Minimo / Standard / Alto | 3 levels: Basic (34 controls), Important (133), Essential (218), each with YAML-implemented controls |
| Framework basis | CIS Critical Security Controls v6.0 (formerly SANS 20), October 2015 | CyFun 2025 aligned with NIST CSF 2.0 |
| Certification / assessment | Self-declaration by the responsible manager — no accredited external certification body | CAB audit by accredited body; ECP generates signed .ecpbundle.zip audit bundle |
| Private-sector applicability | Not designed for the private sector. Italian private-sector NIS2 compliance runs through ACN (D.Lgs. 138/2024). | Built for private-sector MSP delivery; CyFun is Belgium's NIS2 path for private and regulated entities |
| MSP / portfolio model | No product: AGID Misure Minime is a specification; no multi-tenant track | Partner dashboard, white-label, per-client branding, signed audit bundles |
| NIS2 relationship | Does NOT satisfy NIS2 in Italy — Italian NIS2 is D.Lgs. 138/2024, supervised by ACN | CyFun is Belgium's official NIS2 compliance path (CCB-issued); CCB audits against it |
| Cost | Framework document: free (Gazzetta Ufficiale). Implementation cost: internal effort + optional consultancy | One fee per client per month, by client size in employees; no monthly base |
Sources: AGID Circular 2/2017 (Gazzetta Ufficiale n. 103, 05-05-2017); cert-agid.gov.it; Italian D.Lgs. 138/2024 (Gazzetta Ufficiale, 01-10-2024); acn.gov.it. Last verified 2026-09-07.
Where AGID Misure Minime applies
- You are (or you serve) an Italian public administration — ministries, regional bodies, municipalities, schools, universities, public hospitals — for which compliance has been mandatory since December 31, 2017
- You need a lightweight, self-assessed baseline grounded in the well-established CIS Controls: the ABSC give any PA a clear starting point without an external auditor
- You are a supplier to Italian PA and your customer asks for alignment with AGID Misure Minime as part of a tender or supply agreement
- You want a free, government-issued framework document that covers 8 control families across three progressive levels (Minimo, Standard, Alto)
- You are advising Italian PA on how to structure an ICT security programme before committing to a full ISO 27001 or NIS2 (ACN) compliance project
Where Easy Cyber Protection fits better
- You are an MSP and your clients are private-sector SMEs (Belgian, Irish, or pan-EU) that need CyFun audit-readiness delivered as a repeatable packaged service — not a bespoke project per client
- You want one fee per client by client size (Micro to Large), no monthly platform base, and full features for every client from day one
- You need NL / FR / EN multilingual materials with Belgian regulatory context (CCB alignment, VLAIO kmo-portefeuille guidance for Flemish clients)
- Your clients need a CAB audit deliverable: ECP generates the signed .ecpbundle.zip that an accredited Belgian audit body accepts
- You want a compliance engine that already adapts to multiple EU national frameworks — CyFun today, with the ADR-0039 multi-framework activation model as the mechanism for hosting more
The cost comparison
These are not two products you choose between. AGID Misure Minime is a free government specification; its cost is the internal effort and optional consultancy to implement it. ECP is a SaaS platform sold to MSPs. The numbers below show what each path costs a representative organisation — an Italian PA vs a Belgian SME via an MSP.
AGID Misure Minime: Italian municipality, ~200 employees
- • Framework document: free (Gazzetta Ufficiale / cert-agid.gov.it)
- • Self-assessment: responsible manager declares compliance — no external audit fee required
- • Internal implementation effort (gap analysis, policy writing, controls rollout): typically 1–4 months of internal IT staff time depending on maturity
- • Optional external consultancy for gap analysis or remediation: €10,000–€40,000 range (market rates, not officially published)
- • No recurring certification fee: self-declaration is renewed as needed
- • Note: AGID Misure Minime does NOT satisfy Italian NIS2 (D.Lgs. 138/2024). ACN compliance adds a separate, higher-effort obligation for PA entities in NIS2 scope.
Implementation cost range is indicative, based on Italian cybersecurity consultancy market rates, not an official AGID figure. AGID publishes no official cost estimate for compliance. The self-assessment model means some administrations have declared formal compliance with minimal actual implementation — the framework relies on the responsible manager's accountability, not external verification.
ECP / CyFun: Belgian SME via MSP (Core client, 13 – 29 employees)
- • Direct end-client price (Core, 13 – 29 employees): €169 / month
- • Billed per client per month; no separate MSP onboarding base fee
- • MSP delivers the service and sets its own client-facing fee
- • Annual client cost: €2,028 — the platform does the compliance heavy-lifting
ECP charges one fee per client per month, by the client's size in employees: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Partners buy below the published rate; the partner rate card is on request. One-time €400 MSP onboarding per partner. Every client gets the full feature set including AI assistance and integrations from day one. Evaluate via the live demo (no signup).
Framework coverage: what the 8 ABSC control families cover vs CyFun
AGID Misure Minime and CyFun both trace back to the CIS Controls lineage (AGID via CIS v6.0; CyFun via NIST CSF 2.0 which maps to CIS v8). The control areas overlap considerably in spirit. The difference is jurisdiction (Italian PA vs Belgian private sector), delivery model (self-assessed spec vs MSP-delivered platform), and currency (2017 framework vs 2025 framework aligned to modern threats).
| Control area | AGID Misure Minime (ABSC) | CyFun / ECP |
|---|---|---|
| Inventory & asset management | ABSC 1 (devices) + ABSC 2 (software) — the first two controls, highest weight; part of "essential five" | CyFun ID.AM controls; ECP entity registers (devices, users, apps, vendors, sites) |
| Vulnerability & patch management | ABSC 4 (continuous vulnerability assessment) — part of "essential five" | CyFun PR.IP controls + ECP integration-based patching evidence collection |
| Admin privileges & access control | ABSC 5 (controlled use of admin privileges) — part of "essential five"; ABSC 16 (account monitoring) | CyFun PR.AC controls; ECP access register + evidence |
| Secure configuration | ABSC 3 (secure configurations for hardware/software) — part of "essential five" | CyFun PR.IP controls; ECP checks hardening against policy templates |
| Malware defences | ABSC 8 (malware defences) | CyFun DE.CM + PR.IP; ECP integrates with EDR (Sophos, SentinelOne, NinjaOne) |
| Email & web security | Not covered — the ABSC set stops at CIS 1-5, 8, 10 and 13 | CyFun PR.AT + PR.AC; ECP policy templates cover email security and user awareness |
| Network monitoring & incident response | Not covered — the ABSC set stops at CIS 1-5, 8, 10 and 13 | CyFun DE.CM + RS controls; ECP incident log + CSIRT notification workflow |
| Data protection & backup | ABSC 10 (data recovery); ABSC 13 (data protection) | CyFun PR.DS + RC controls; ECP backup register and evidence collection |
| Wireless / boundary defences | Not covered — the ABSC set stops at CIS 1-5, 8, 10 and 13 | CyFun PR.PT controls |
| NIS2 Article 21 satisfaction | No — AGID Misure Minime predates NIS2 and is not the Italian NIS2 compliance path | Yes — CyFun is Belgium's official NIS2 Article 21 implementation, CCB-issued |
Sources: AGID Circular 2/2017 (ABSC control list); CIS Critical Security Controls v6.0 (October 2015); CCB CyFun 2025 documentation. Mapping is indicative. A professional gap analysis is required for any cross-framework compliance project.
Common questions
Does AGID Misure Minime satisfy NIS2 in Italy?
No. AGID Misure Minime is a 2017 framework for Italian public administrations. Italy's NIS2 transposition is D.Lgs. 138/2024, in force since October 16, 2024, managed by the ACN (Agenzia per la Cybersicurezza Nazionale). The ACN has issued its own technical security guidelines for NIS2-obligated entities. An Italian PA or private entity audited under NIS2 is assessed against the ACN framework, not AGID Misure Minime. The two frameworks share some control areas (both draw on CIS Controls), but AGID Misure Minime does not provide legal coverage for NIS2 obligations. Italian PA in NIS2 scope must satisfy both: AGID Misure Minime for their PA-baseline obligations and the ACN NIS2 framework for their NIS2 obligations.
Can ECP help Italian entities comply with AGID Misure Minime or Italian NIS2?
Not natively today. ECP implements CyFun (the Belgian CCB framework). The control areas overlap — CyFun and AGID Misure Minime both trace to the CIS Controls lineage — so an Italian entity using ECP would find a familiar control structure. But ECP does not generate an AGID-format self-declaration or an ACN-ready NIS2 compliance bundle. The ECP framework engine (ADR-0039) is designed to host additional national frameworks; an Italian NIS2 path is plausible on that engine, but is not on the committed roadmap. If Italian NIS2 is your target today, engage an Italian ACN-aligned consultancy.
The AGID Misure Minime is from 2017. Is it still current?
The framework has not been formally updated since its 2017 publication. It is based on CIS Controls v6.0 (October 2015), and CIS has since released v7.1 and v8 with significant updates. Meanwhile, the threat landscape has changed dramatically — ransomware-as-a-service, supply chain attacks, and cloud-first infrastructure are all developments the 2017 document does not explicitly address. AGID has not issued an update or a revised circular. Italian public administrations that follow only the Minimum level of the 2017 framework are working from a dated baseline. Italian NIS2 (ACN framework, D.Lgs. 138/2024) is more current, but AGID Misure Minime itself has not been revised.
What is the difference between AGID Misure Minime and the ACN NIS2 framework?
They are different obligations with different scopes. AGID Misure Minime (2017): a PA-only ICT security baseline, self-assessed, free, based on 20 CIS Controls-derived controls. ACN NIS2 framework (2024): Italy's transposition of the EU NIS2 Directive, covering both public and private entities in 18 essential/important sectors. ACN has issued specific technical guidelines (Linee Guida NIS) with its own security measures, incident reporting obligations (from January 2026), and compliance deadline (October 2026). The ACN framework imposes external supervision and fines up to €10M or 2% of turnover for essential entities. AGID Misure Minime has no fine regime — it relies on the internal accountability of the responsible manager.
If I am a Belgian MSP with some Italian clients, which framework applies?
It depends on who the Italian clients are. If they are Italian public administrations: they need AGID Misure Minime (for the PA baseline) and ACN NIS2 (if they fall in NIS2 scope) — ECP does not natively address either today. If they are Italian private-sector SMEs in NIS2 scope: they need the ACN framework under D.Lgs. 138/2024 — again, ECP does not natively address this. If your Italian private clients are not in NIS2 scope: there is no mandatory Italian baseline for them; voluntary ISO 27001 is common. ECP today is purpose-built for Belgian CyFun delivery. For cross-border Italian engagements, honest advice is to partner with an Italian ACN-aligned consultancy while using ECP for your Belgian book.
Deliver CyFun audit-readiness to your Belgian clients
If you are an MSP serving private-sector Belgian SMEs under NIS2, CyFun — not AGID Misure Minime — is the compliance path your clients need. ECP packages it as a monthly MSP service: guided workflows, evidence collection, white-label reports, and a signed audit bundle your CAB auditor accepts.
Related
Fact check: sources for every claim
| Claim | Source | Access date |
|---|---|---|
| AGID Circular 2/2017 published April 18, 2017; entered into force December 31, 2017 | CERT-AgID: CircolareAgID_170418_n_2_2017 (Gazzetta Ufficiale n. 103, 05-05-2017) | 2026-09-07 |
| 8 ABSC control families derived from CIS Controls 1-5, 8, 10, 13; three levels: Minimo, Standard, Alto; based on CIS Controls v6.0 | AGID Misure Minime official framework document v1.0 | 2026-09-07 |
| Framework based on CIS Critical Security Controls v6.0 (October 2015) | AGID Misure Minime official document | 2026-09-07 |
| Mandatory for all Italian public administrations regardless of nature and size; self-assessed | AGID Misure Minime framework + ICTPower.it analysis | 2026-09-07 |
| Italy transposed NIS2 via D.Lgs. 138/2024, in force October 16, 2024 | Italy - EU NIS2 Directive / Eversheds Sutherland + ACN portal | 2026-09-07 |
| ACN is Italy's NIS2 competent authority under D.Lgs. 138/2024 | ACN — la normativa NIS | 2026-09-07 |
| ECP MSP pricing: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request; one-time €400 MSP onboarding | docs/adr/0050-two-lane-pricing-sized-by-employees.md + docs/adr/0036-msp-onboarding-fee-and-demo-only-evaluation.md | 2026-09-07 |
| CyFun is Belgium's official NIS2 compliance path, CCB-issued | CCB Centre pour la Cybersécurité Belgique | 2026-09-07 |