Two regimes, side by side
Online gaming (gioco a distanza) in Italy runs on concessions. Existing authorizations follow the legacy framework — Decreto Direttoriale AAMS of 5 February 2010 and later decrees — with the Linee Guida per la certificazione della piattaforma di gioco v2.0 (2018). New concessions under D.Lgs. 41/2024, article 6, follow the Regole tecniche (determinazione 777860 of 17 December 2024) and the Linee guida per organismi di verifica (determinazione 336762 of 16 June 2025).
Who verifies
Certification is requested by the concessionaire from an Organismo di Verifica (ODV) recognized by ADM — a verification body under a convention with the Agency. The AAMS-era convention template required ODVs to be accredited to UNI CEI EN ISO/IEC 17025 by a national accreditation body (in Italy, ACCREDIA) and to hold an independence policy (2011 convention template; lists of ODV on the ADM certification page). Under the 2024 rules, verification goes to "one of the Organismi di Verifica under convention with ADM or, where provided, to Sogei S.p.A." — Sogei operating ADM's sistema centralizzato, to which every concessionaire's system must speak in real time. The 2018 guidelines add that "the certification of conformity issued by the ODV does not in any way replace the authorisation issued by ADM".
The legacy guidelines (2018): explicit penetration tests and a 12-month audit
The 2018 Linee Guida are unusually explicit. Section 2.9.5: the Sistema di Gioco a Distanza (SGAD) "must pass external penetration tests on the SGAD's public IP addresses (penetration test) and vulnerability assessments of the systems performed on the internal networks hosting them (vulnerability assessment) in order to obtain certification". The ODV must be able to run them itself, or may evaluate results "provided by accredited third parties or holders of suitable certification"; results obtained "by the applicant itself" are not acceptable. The penetration test covers all public interfaces used for gaming and for managing gaming accounts (§2.9.5.1); the vulnerability assessment runs from inside the network — misconfigurations, missing patches, weak firewall rules — with the concessionaire providing the ODV "a VPN with full access to the subnet's resources or physical access to the server farm" (§2.9.5.2).
Frequency: security documentation must be integrated with the results of these tests "before the SGAD goes into service, at the annual audit and in any case at regular intervals" (§1.2.5.1), and "for an already approved platform a periodic audit every 12 months of the hardware and software components" is foreseen (§1.5), with security-requirement checks "also through on-site inspections" as part of the annual review (§2.9). ISO 27001 is not mandatory; attestations "will be assessed positively". Section 2.9.4 lists the operational controls: malware protection, removable media, user/administrator/error logging with log protection, formal user provisioning, least privilege, authenticated remote access, network segregation, a session timeout of at most 20 minutes "applicable also to any SGAD management interface (e.g. back office)", and formal key management.
The new framework (2024–2025): integrity, logging, encryption, qualified cloud
The Regole tecniche attached to the new concessions list, among the concessionaire's obligations, "submission to conformity verification, by one of the bodies identified by ADM, of the concessionaire's system, including all its components and including the website and the Apps". Verification methods are source-code analysis, documentary analysis, conformity tests with emulated play, integration between components, communication with the central system, game-rule implementation, RNG statistical tests and the mathematical model. Changes to verified components trigger a new request to the ODV, "which proceeds, where deemed necessary, to a new verification". Collection for the games in article 6(3) "takes place exclusively following certification by ADM".
The security requirements are framed differently from 2018. Infrastructure must sit within the European Economic Area, "including cloud computing solutions" — but cloud services must meet the requirements set by AgID and the Agenzia per la Cybersicurezza Nazionale (ACN) to qualify for use by the public administration. Data must be "encrypted both in transit and once stored"; operator and administrator audit logs must be protected "against alteration and unauthorised access"; backups must be documented; the system must implement "automated integrity verification procedures providing for component-blocking mechanisms", with message digests of file critici sent to the central system; the 20-minute session timeout stays; a relazione tecnica is due before network start-up and updated on extraordinary maintenance. The 2025 Linee guida for ODV (136 pages) define a minimum set of verification objectives per rule, require the ODV to prove that deployed binaries derive from the delivered source, and check cloud services against the ACN catalogue.
What the new texts do not say matters as much: a full-text search of the 2024 Regole tecniche and the 2025 Linee guida returns no occurrence of "penetration", "vulnerability" or "27001". Whether the 2018 requirements continue to apply to concessions granted under D.Lgs. 41/2024 is not stated in either document. A concessionaire should treat the 2018 penetration-test and annual-audit expectations as the baseline the ODV will still recognize, and the 2024 integrity/logging/encryption/cloud requirements as the new floor.
What this means in practice
Italy's regime is built around correspondence between source, binary and running system, verified by an accredited third party, and around the central system as the arbiter of every play. For the concessionaire, the operational consequences are three: every change to a critical component is a verification event, not a deploy; the ODV, not you, runs or validates the penetration test; and integrity of file critici is checked continuously by machinery that can block a component.
Frequently asked questions
Does ADM require a penetration test?
The 2018 Linee Guida for platform certification explicitly require an external penetration test on public IP addresses and an internal vulnerability assessment, run or validated by the ODV; results produced by the concessionaire itself are not accepted. The 2024 Regole tecniche and 2025 ODV guidelines do not repeat that wording and frame security as integrity, logging, encryption and ACN-qualified cloud.
Who can certify a gaming platform in Italy?
An Organismo di Verifica under convention with ADM — historically required to be accredited to ISO/IEC 17025 — or, where provided, Sogei S.p.A. The ODV's certificate does not replace ADM's authorization.
How often is the platform re-verified?
Under the 2018 guidelines, a periodic audit every 12 months of hardware and software components, plus re-certification on changes to essential characteristics. The 2024–2025 texts tie re-verification to changes of verified components and to ADM's own periodic checks, without a fixed cadence.
Is the Polo Strategico Nazionale (PSN) required for hosting?
No ADM document we found requires PSN. The rule is EEA residency and, for cloud services, qualification under the AgID/ACN requirements for the public administration.