There is a question that people rarely ask before signing a contract with a provider managing a SOC or Vulnerability Assessment service: what exactly happens to the information we exchange every day?
Logs, alerts, indicators of compromise, details on vulnerabilities not yet patched. Material that, if it fell into the wrong hands, would be worth more than a stolen password.
Article 17 of the NIS2 decree (Legislative Decree 138/2024) attempts to bring order right here.
For months, it remained in the background compared to the most discussed topics of the regulation: Board of Directors’ responsibility, security measures, incident notification, and supply chain management. The FAQs published by the ACN (National Cybersecurity Agency) have brought it back to center stage, and the reason is simple: it concerns almost all organizations that rely on an external provider for security activities.
What Article 17 is really about
The regulation allows essential and important entities, and their third parties, to voluntarily exchange cybersecurity information: threats, near misses, vulnerabilities, attacker tactics, indicators of compromise, and configuration recommendations. Sharing remains voluntary; what the regulation imposes is the discipline surrounding it: when it occurs, it must be governed by an agreement that defines its scope and protection tools.
Here comes the clarification that surprised more than one IT manager: according to the ACN, contracts that involve, even partially, cybersecurity services fall into this category. NOC, MDR, SOC, CSOC, CERT, Vulnerability Assessment and Penetration Testing, Red Teaming, Cyber Threat Intelligence: the list of services that almost every structured company has been purchasing for years, often without ever re-reading the confidentiality clauses on the data exchanged.
A matter that also concerns people, not just lawyers
Those involved in awareness training know it: behind every sharing agreement, there is a relationship between people. Does the person managing the relationship with the SOC provider know what information can be sent via email and what cannot? Does the person receiving a Penetration Test report understand that if shared incorrectly, that document becomes a map of corporate vulnerabilities offered for free to those who shouldn’t see it?
Contracts set the boundaries. People respect or ignore them every day when they attach a file to a ticket, when they forward an alert to an external collaborator without checking the content classification, or when they use an unsanctioned channel because “it was urgent.” NIS2 formalizes legal obligations; organizational culture decides whether those obligations remain on paper or become daily behavior.
Deadlines to keep in mind
The ACN has planned a gradual implementation. For the 2025 annual update, only agreements signed after the decree came into force must be notified. Previous agreements—those signed years ago, perhaps without a single thought for NIS2—must be analyzed and potentially adapted by the 2026 annual update. The general deadline to align with the requirement, in line with the adoption of basic security measures, falls in October 2026.
It should be taken for what it is, not as an excuse to procrastinate. Delaying the review means risking reaching the deadline with contracts that have never been re-read, information shared for years without a clear scope, and responsibilities that no one has ever truly assigned. Those who wait until the last quarter of 2026 to open the drawer of vendor contracts will almost certainly find more than one surprise.
What to do, concretely
There is no need to rush out a new document for every vendor. You need to start with a real mapping: who provides SOC, MDR, VA/PT, Red Teaming, or Threat Intelligence services, what information is actually exchanged with each, and what the existing contract already says. From there, you evaluate whether a dedicated agreement is needed or if integrating confidentiality clauses into the existing one is sufficient.
And then, the step that is often skipped: those in the company who operationally manage those relationships must be informed about what the agreement means in practice. Not an isolated webinar, but a path that makes the distinction between shareable information and information to be protected familiar, along with the concrete consequences of a careless exchange.
The takeaway
Article 17 asks to make explicit something that already happens: the exchange of sensitive information with those who manage our digital defense. There is no need to rewrite corporate security from scratch. The technical and legal parts can be delegated to specialists. The human part—the people who decide every day what to write in a ticket or attach to an email—remains the point on which we build our training approach: a well-written agreement is only as good as the habits of those who apply it every day.



