Italy - Digital Transformation Plan

Three‑Year ICT Plan for the Public Administration 2024-2026

Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024-2026

Italy

RAI-IT-NA-PTPLNXX-2024
Effective: February 12, 2024
In Force(In Force)
PolicyGovernance and OversightData Protection and PrivacyRisk Management
Export PDF

The Italian Three‑Year ICT Plan 2024–2026, published by the Agency for Digital Italy (AGID) and approved by DPCM, sets strategic principles and operational lines for the digital transformation of all public administrations in Italy. It updates priorities (including AI, data governance, cloud-first, interoperability and security), introduces operational tools for administrations and defines monitoring, procurement alignment and governance roles to achieve national digital objectives.

Summary

The Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024–2026 is the national strategic and operational framework for the digital transformation of Italy’s public sector. Approved and published in February 2024, and updated through 2025 and 2026, the Plan is coordinated by the Agenzia per l'Italia Digitale (AGID) together with the Department for Digital Transformation and other institutional actors. It consolidates principles established in previous editions (digital & mobile first, cloud first, API-first/interoperability, digital identity only, once-only, data protection by design, openness and sustainability), maps objectives, identifies 59 expected results and provides a “toolbox” of operational instruments (procurement guidance, shared services, AI guidance, data governance templates, monitoring indicators and checklists).

The Plan addresses technical components (services, platforms, data & AI, infrastructures, security) and organisational levers (governance, procurement, skills, monitoring). It integrates priorities of EU-level strategies (Decade of Digital 2030) and aligns with PNRR investments where relevant. A notable addition in 2024–2026 is dedicated guidance for the responsible adoption of Artificial Intelligence in public administration and the enlargement of operational instruments available to administrations (e.g., IT Wallet, Data Quality, document dematerialisation, classifiers and validators). The Plan sets monitoring and reporting obligations for public administrations, links targets to procurement instruments (Consip strategic frameworks), and foresees oversight by AGID, with audit review by Corte dei Conti where appropriate. Implementation relies on a combination of recommendations, technical standards, DPCM approval and annual updates; while the Plan itself is not a penal code, non‑compliance may affect access to funding, procurement eligibility and administrative accountability.

Full article

Read full text ↗

Overview

The Piano Triennale per l'Informatica nella Pubblica Amministrazione 2024-2026 is the Italian government's programmatic framework for the digital transformation of the public sector. Approved and published in February 2024, with subsequent updates in 2025 and 2026, it establishes strategic principles ("digital & mobile first", "cloud first", "API-first/interoperability", "digital identity only", "once-only" and "data protection by design") and operational lines for central, regional and local administrations. The document unites high-level direction and granular instruments: it presents strategic components (governance, organisation, skills), technological components (services, platforms, data & AI, infrastructures, security), and a new "Tools" section that supplies templates, checklists and case studies to support implementation. The Plan is published and hosted by the Agency for Digital Italy (AGID - Three-Year Plan page) and the dedicated portal (pianotriennale-ict.italia.it), and its approved text is available as an official PDF (Piano triennale 2024-2026 (PDF)).

Definitions

The Plan defines core terms used throughout the framework, including: "public administration" (any national, regional, local, health or independent public entity covered by the Codice dell'Amministrazione Digitale), "platforms" (national/shared digital platforms that provide services or attest attributes), "services" (digital front-end or back-office functionalities delivered to citizens, businesses or other PAs), "data governance" (policies, roles and processes for data quality, stewardship and reuse), "AI systems" (software performing tasks with machine-based inference and learning), and "tools" (templates, procurement models and operational checklists provided to administrations to facilitate adoption). Definitions emphasise interoperability, accessibility, user-centric design and privacy by design and are aligned with references to the CAD and EU instruments cited inside the Plan.

Governance and Institutional Framework

The Plan assigns coordination and oversight responsibilities primarily to the Agenzia per l'Italia Digitale (AGID) and the Dipartimento per la Trasformazione Digitale of the Presidency of the Council of Ministers, and sets up a concertation process (a permanent "Tavolo di concertazione") that involved central and local administrations, research bodies and industry stakeholders during drafting. AGID is responsible for issuing technical guidelines, monitoring implementation and publishing indicators; the Plan was formally approved by a DPCM and received the Corte dei Conti's review. Implementation governance is layered: national-level direction and standards; regional/regulatory coordination; and entity-level operational responsibility, including appointment of the Responsible for Digital Transition (Responsabile per la Transizione Digitale, RTD) and, where applicable, an Office for Digital Transition (Ufficio Transizione Digitale). The Plan also updates the role of procurement authorities (Consip) by providing mappings between Plan indicators and strategic procurement vehicles to ensure alignment between contracting and national digital objectives (AGID mapping with Consip).

Key Focus Areas

The Plan organizes action around interconnected focus areas: 1) Services: accelerate delivery of user-centric, accessible and interoperable digital services (incl. Single Digital Gateway alignment). 2) Platforms: rationalize and govern national platforms and attribute services to avoid fragmentation. 3) Data & AI: strengthen open data, enterprise data governance, data quality and provide first-time guidance for responsible AI adoption in the PA (risk-based approach aligned to the EU AI Act). 4) Infrastructures: prioritize cloud-first architectures, public connectivity and shared procurement to ensure resilience and cost-effectiveness. 5) Security: adopt an integrated cybersecurity posture with updated minimum security measures, incident reporting and risk management. 6) Procurement and market levers: align public procurement with Plan targets using Consip frameworks and standardized indicators to promote reuse and economies of scale. 7) Skills & organisation: scale e-leadership, RTD roles and training to raise digital maturity. 8) Monitoring and indicators: modernize the monitoring system with a set of measurable results (59 expected results) and annual targets; the Plan links indicators to procurement and funding instruments to support execution. These priorities are accompanied by an expanded "Tools" toolbox (procurement templates, AI decalog, validators, data governance models) to facilitate replicable implementation across ~23,000 PAs.

Implementation Framework

Implementation is structured across national, regional and entity levels with differentiated responsibilities. AGID issues guidelines and tools; central administrations coordinate strategic initiatives; regions and large entities manage shared services and local implementations; each administration must prepare its own technical roadmap aligning with Plan targets and report progress via the monitoring platform. The Plan recommends appointing or strengthening RTDs and UTDs, adopting the "cloud first" approach and privileging national shared platforms (e.g., SPID, PagoPA, Fascicolo Sanitario Elettronico where applicable). Procurement guidance ties specific Plan indicators to Consip framework contracts to accelerate adoption of standardised services and to allow administrations to select procurement vehicles that directly contribute to national targets. For AI projects, the Plan directs risk-based assessments, documentation, and coordination with national competence centers and regional AI competence hubs.

Monitoring and Evaluation

The Plan establishes an annual monitoring cycle that collects quantitative and qualitative indicators mapped to the 59 expected results. AGID maintains a public monitoring platform (Monitoraggio Piano Triennale) to track progress, provide dashboards and publish aggregated results. Monitoring data are used to: (i) inform annual updates to the Plan (the document foresees annual updates within the triennium), (ii) identify gaps and prioritize interventions, and (iii) align procurement choices to results through mappings to strategic Consip frameworks. The Plan also provides guidance on indicator definitions and data collection methods to ensure comparability; for high-impact domains (health, finance, social benefits), monitoring includes service-level and outcome indicators, not only technical adoption metrics.

Penalties, Liability, and Appeals

The Piano Triennale is a framework and planning instrument; it does not create criminal sanctions. However, compliance (or lack of it) has administrative consequences: (1) non-compliance may affect eligibility for certain funding streams or access to centrally sponsored procurement frameworks, (2) repeated or systemic failures to implement required digital transformation actions can be noted in AGID monitoring reports and may trigger administrative follow-ups or recommendations, and (3) financial and managerial accountability remains subject to ordinary administrative and audit mechanisms (including Corte dei Conti reviews) and to the rules governing the use of public funds. The Plan also references the legal frameworks that govern liability and redress (e.g., provisions within the Codice dell'Amministrazione Digitale and sector-specific legislation). Appeal or remedial paths follow ordinary administrative and judicial channels; AGID’s actions can be subject to administrative review where applicable.

Relationship to Other Instruments

The Plan is explicitly designed to operate in a layered regulatory and policy environment: it is anchored to the Codice dell'Amministrazione Digitale (CAD), references PNRR investments and aligns with EU initiatives (Decade of Digital 2030, Digital Services/Markets and the AI regulatory trajectory). It cross-references existing technical rules (Linee guida AGID), minimum ICT security measures, interoperability standards, and procurement law instruments (Consip frameworks). The Plan also consolidates prior three-year Plans (2017-2019; 2019-2021; 2020-2022 with updates) and is intended to be updated annually within the 2024-2026 window to reflect regulatory or technological changes.

International Alignment

The Plan situates Italy’s national digital priorities in a European context, aligning objectives and timelines with EU instruments such as the Commission’s "Decade of Digital 2030" decision and integrating references to the emerging EU AI regulatory approach (risk-based AI governance). It encourages adoption of interoperable standards and cross-border principles (once-only, cross-border services), and promotes compatibility with EU procurement and state-aid discipline when financing digital investments. The Plan also references international best practices and invites cooperation with EU competence centers and research networks to consolidate AI governance, cybersecurity resilience and data interoperability.

Implementation Timeline

PeriodMilestone
Dec 2023 – Feb 2024Draft completion, DPCM approval and publication of the Plan (official PDF), Corte dei Conti review.
2024Roll‑out of tools, start of monitoring cycle, alignment of procurement indicators with Consip frameworks.
2025Annual update (Aggiornamento 2025) integrating IT Wallet, Data Quality and dematerialisation guidance; expansion of "Tools" section.
2026Further update (Aggiornamento 2026) consolidating AI projects, monitoring on document management and toolset expansion; end of triennium review.

Sources and References

SourceType
Piano triennale per l'informatica nella PA 2024-2026 (AGID PDF)Primary Source
AGID - Piano Triennale (web page)Primary Source
DPCM approval - 12 Feb 2024 (AGID PDF)Primary Source

Requirements for a company

What an organisation has to do under Italy - Digital Transformation Plan, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

10
  • Conduct risk-based assessments and documentation for AI projects, coordinating with national competence centers.Public administrations deploying AI systems
  • Prepare a technical roadmap aligned with Plan targets and report progress via the monitoring platform.Each public administration entity
  • Appoint a Responsible for Digital Transition (RTD) and, where applicable, an Office for Digital Transition.Each public administration entity
  • Align public procurement with Plan targets using Consip frameworks and standardized indicators.Public administrations involved in procurement
  • Strengthen open data, enterprise data governance, and data quality policies and processes.All public administrations
  • Prioritize cloud-first architectures, public connectivity, and shared procurement for infrastructure.Public administrations managing IT infrastructure
  • +4 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Italy - Digital Transformation Plan, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public administrations deploying AI systemsConduct risk-based assessments and documentation for AI projects, coordinating with national competence centers.
For AI projects, the Plan directs risk-based assessments, documentation, and coordination with national competence centers and regional AI competence hubs.
Before deploying AI systemsImplementation FrameworkCritical
2Each public administration entityPrepare a technical roadmap aligned with Plan targets and report progress via the monitoring platform.
each administration must prepare its own technical roadmap aligning with Plan targets and report progress via the monitoring platform.
AnnuallyGovernance and Institutional FrameworkCritical
3Each public administration entityAppoint a Responsible for Digital Transition (RTD) and, where applicable, an Office for Digital Transition.
including appointment of the Responsible for Digital Transition (Responsabile per la Transizione Digitale, RTD) and, where applicable, an Office for Digital Transition.
Governance and Institutional FrameworkCritical
4Public administrations involved in procurementAlign public procurement with Plan targets using Consip frameworks and standardized indicators.
align public procurement with Plan targets using Consip frameworks and standardized indicators to promote reuse and economies of scale.
OngoingKey Focus AreasCritical
5All public administrationsStrengthen open data, enterprise data governance, and data quality policies and processes.
Data & AI: strengthen open data, enterprise data governance, data quality and provide first-time guidance for responsible AI adoption in the PA
OngoingKey Focus AreasCritical
6Public administrations managing IT infrastructurePrioritize cloud-first architectures, public connectivity, and shared procurement for infrastructure.
Infrastructures: prioritize cloud-first architectures, public connectivity and shared procurement to ensure resilience and cost-effectiveness.
OngoingKey Focus AreasCritical
7All public administrationsAdopt an integrated cybersecurity posture with updated minimum security measures, incident reporting, and risk management.
Security: adopt an integrated cybersecurity posture with updated minimum security measures, incident reporting and risk management.
OngoingKey Focus AreasCritical
8All public administrationsAccelerate delivery of user-centric, accessible, and interoperable digital services.
Services: accelerate delivery of user-centric, accessible and interoperable digital services (incl. Single Digital Gateway alignment).
OngoingKey Focus AreasImportant
9Public administrations using or developing national platformsRationalize and govern national platforms and attribute services to avoid fragmentation.
Platforms: rationalize and govern national platforms and attribute services to avoid fragmentation.
OngoingKey Focus AreasImportant
10All public administrationsScale e-leadership, RTD roles, and training to raise digital maturity within the administration.
Skills & organisation: scale e-leadership, RTD roles and training to raise digital maturity.
OngoingKey Focus AreasImportant

© Regulations.AI · updated on 13-Jun-2026