SWR7
Home/Insights/Compliance · ADM (Italy)
Compliance · ADM (Italy)

ADM Italy: gaming platform certification, verification bodies (ODV) and security testing

Italy is the only one of the three regulators that has written 'penetration test' into a guideline. It is also the one where the framework is changing under your feet. Here is what the documents say, old and new.

SWR7 teamPublished 5 min read
Scope noteThis page summarizes public ADM documents as of September 2026 and links to each. It is not legal advice; the concession, the Regole tecniche and the Linee guida as published by ADM prevail. Italian terms are kept where they are the terms a concessionaire will meet.

Two regimes, side by side

Online gaming (gioco a distanza) in Italy runs on concessions. Existing authorizations follow the legacy framework — Decreto Direttoriale AAMS of 5 February 2010 and later decrees — with the Linee Guida per la certificazione della piattaforma di gioco v2.0 (2018). New concessions under D.Lgs. 41/2024, article 6, follow the Regole tecniche (determinazione 777860 of 17 December 2024) and the Linee guida per organismi di verifica (determinazione 336762 of 16 June 2025).

Who verifies

Certification is requested by the concessionaire from an Organismo di Verifica (ODV) recognized by ADM — a verification body under a convention with the Agency. The AAMS-era convention template required ODVs to be accredited to UNI CEI EN ISO/IEC 17025 by a national accreditation body (in Italy, ACCREDIA) and to hold an independence policy (2011 convention template; lists of ODV on the ADM certification page). Under the 2024 rules, verification goes to "one of the Organismi di Verifica under convention with ADM or, where provided, to Sogei S.p.A." — Sogei operating ADM's sistema centralizzato, to which every concessionaire's system must speak in real time. The 2018 guidelines add that "the certification of conformity issued by the ODV does not in any way replace the authorisation issued by ADM".

The legacy guidelines (2018): explicit penetration tests and a 12-month audit

The 2018 Linee Guida are unusually explicit. Section 2.9.5: the Sistema di Gioco a Distanza (SGAD) "must pass external penetration tests on the SGAD's public IP addresses (penetration test) and vulnerability assessments of the systems performed on the internal networks hosting them (vulnerability assessment) in order to obtain certification". The ODV must be able to run them itself, or may evaluate results "provided by accredited third parties or holders of suitable certification"; results obtained "by the applicant itself" are not acceptable. The penetration test covers all public interfaces used for gaming and for managing gaming accounts (§2.9.5.1); the vulnerability assessment runs from inside the network — misconfigurations, missing patches, weak firewall rules — with the concessionaire providing the ODV "a VPN with full access to the subnet's resources or physical access to the server farm" (§2.9.5.2).

Frequency: security documentation must be integrated with the results of these tests "before the SGAD goes into service, at the annual audit and in any case at regular intervals" (§1.2.5.1), and "for an already approved platform a periodic audit every 12 months of the hardware and software components" is foreseen (§1.5), with security-requirement checks "also through on-site inspections" as part of the annual review (§2.9). ISO 27001 is not mandatory; attestations "will be assessed positively". Section 2.9.4 lists the operational controls: malware protection, removable media, user/administrator/error logging with log protection, formal user provisioning, least privilege, authenticated remote access, network segregation, a session timeout of at most 20 minutes "applicable also to any SGAD management interface (e.g. back office)", and formal key management.

The new framework (2024–2025): integrity, logging, encryption, qualified cloud

The Regole tecniche attached to the new concessions list, among the concessionaire's obligations, "submission to conformity verification, by one of the bodies identified by ADM, of the concessionaire's system, including all its components and including the website and the Apps". Verification methods are source-code analysis, documentary analysis, conformity tests with emulated play, integration between components, communication with the central system, game-rule implementation, RNG statistical tests and the mathematical model. Changes to verified components trigger a new request to the ODV, "which proceeds, where deemed necessary, to a new verification". Collection for the games in article 6(3) "takes place exclusively following certification by ADM".

The security requirements are framed differently from 2018. Infrastructure must sit within the European Economic Area, "including cloud computing solutions" — but cloud services must meet the requirements set by AgID and the Agenzia per la Cybersicurezza Nazionale (ACN) to qualify for use by the public administration. Data must be "encrypted both in transit and once stored"; operator and administrator audit logs must be protected "against alteration and unauthorised access"; backups must be documented; the system must implement "automated integrity verification procedures providing for component-blocking mechanisms", with message digests of file critici sent to the central system; the 20-minute session timeout stays; a relazione tecnica is due before network start-up and updated on extraordinary maintenance. The 2025 Linee guida for ODV (136 pages) define a minimum set of verification objectives per rule, require the ODV to prove that deployed binaries derive from the delivered source, and check cloud services against the ACN catalogue.

What the new texts do not say matters as much: a full-text search of the 2024 Regole tecniche and the 2025 Linee guida returns no occurrence of "penetration", "vulnerability" or "27001". Whether the 2018 requirements continue to apply to concessions granted under D.Lgs. 41/2024 is not stated in either document. A concessionaire should treat the 2018 penetration-test and annual-audit expectations as the baseline the ODV will still recognize, and the 2024 integrity/logging/encryption/cloud requirements as the new floor.

What this means in practice

Italy's regime is built around correspondence between source, binary and running system, verified by an accredited third party, and around the central system as the arbiter of every play. For the concessionaire, the operational consequences are three: every change to a critical component is a verification event, not a deploy; the ODV, not you, runs or validates the penetration test; and integrity of file critici is checked continuously by machinery that can block a component.

Where SWR7 fitsSWR7 is not an ODV, is not accredited under ISO/IEC 17025, and its results cannot replace the ODV's penetration test — the 2018 guidelines exclude tests run by the applicant itself, and results supplied to the ODV must come from accredited or suitably certified third parties. What SWR7 does is make the ODV's visit uneventful: continuous non-destructive detection on the public interfaces the ODV will test (TLS and secure protocols, exposed paths, headers, session behavior observable from outside, new hosts), a remediation for each finding, and — under signed Rules of Engagement, on staging — controlled and intrusive tests that surface before certification what would otherwise surface during it.

Frequently asked questions

Does ADM require a penetration test?

The 2018 Linee Guida for platform certification explicitly require an external penetration test on public IP addresses and an internal vulnerability assessment, run or validated by the ODV; results produced by the concessionaire itself are not accepted. The 2024 Regole tecniche and 2025 ODV guidelines do not repeat that wording and frame security as integrity, logging, encryption and ACN-qualified cloud.

Who can certify a gaming platform in Italy?

An Organismo di Verifica under convention with ADM — historically required to be accredited to ISO/IEC 17025 — or, where provided, Sogei S.p.A. The ODV's certificate does not replace ADM's authorization.

How often is the platform re-verified?

Under the 2018 guidelines, a periodic audit every 12 months of hardware and software components, plus re-certification on changes to essential characteristics. The 2024–2025 texts tie re-verification to changes of verified components and to ADM's own periodic checks, without a fixed cadence.

Is the Polo Strategico Nazionale (PSN) required for hosting?

No ADM document we found requires PSN. The rule is EEA residency and, for cloud services, qualification under the AgID/ACN requirements for the public administration.

Want to know what your surface looks like from outside?

An intro call, no commitment. If it makes sense, you receive the Rules of Engagement — nothing is tested before you sign.

Book an intro call