Italy’s gambling regulator has stopped treating certification as one date. It has split it into a sequence, and the order of the sequence is the part that reshapes a supplier’s roadmap: the game system has to be certified before the operators who are going to carry it can finish their own checks.
The Agenzia delle Dogane e dei Monopoli, ADM, had spent a year telling remote-gaming concessionaires that 13 November 2026 was the date by which the new “Sistema del concessionario” had to pass the conformity verification carried out by a recognised verification body, an Organismo di Verifica, or ODV. That date has not been removed. It has been given a narrower job. Under the staged calendar, 13 November 2026 is the deadline for the concessionari fornitori di servizi — service-provider concessionaires, known as CFS — to file the results of the conformity checks on the applications that contain game systems offered to other concessionaires, together with the components that populate the shared library. The concessionaires that use those CFS-supplied game systems then file by 13 January 2027. The technical-functional verifications complete by 12 February 2027, and the new game system goes into production from 15 February 2027.
That staged calendar was reported by the Italian trade press on 7 October 2026. It sits on top of two documents that are the framework for everything below: ADM’s letter of 27 February 2026, which moved the original spring deadline out to 13 November 2026, and ADM’s operating instructions of 7 August 2026 on the certification of the concessionaire system for the new licences. The dates are the regulator’s; check the current calendar with the Agenzia before you plan a launch against it.

Why the supplier goes first
The whole staged order comes from one rule in ADM’s certification guidelines. A concessionaire that intends to use a game system already certified and made available by a service-provider concessionaire is still required to have its own concessionaire system verified as a whole. But in that case the ODV is required to verify only the integration of the CFS game system with the other components of the system that is being verified.
That single carve-out creates the dependency. A consuming concessionaire cannot demonstrate an integration with a game system that does not yet hold its own verification result. So the certified systems have to exist first and be visible in the library, and only then can the operators that carry them finish their own path. ADM has since restated the point: the technical conformity verification always applies to the concessionaire system in its entirety, and not to single elements considered separately, and where one or more CFS-provided systems are in use the checking body must also verify the correct integration between the CFS systems and the other components.
For a studio, a platform or a CFS that wants to supply the Italian market, that is the practical meaning of the timetable. Your certification work is on the critical path for somebody else’s deadline.
What the verification body actually examines
ADM’s August instructions describe an examination that is broader than a maths audit. The ODV works from a technical report that has to describe the system, its components and how they interact, and then checks the documentation and the hardware and software components, the critical files, the systems that verify software integrity, and the communication between the different components and with ADM’s central system. Conformity tests, statistical analyses and functional checks follow from the technical rules and the applicable regulation.
The source-code discipline is the part that surprises teams used to a laboratory submission. The source delivered for inspection has to carry, for each file, module or function, its component, a short description of what it does, and a change history, with the certified version identified uniquely by version. Critical files are identified by a digest, and the ODV has to be able to demonstrate that the binaries it examined are the result of compiling the source that was handed over. A build log with source digests and a timestamp is part of the submission, and so is the script that produced the digest file.
That is the same discipline the certification submission guide asks for at a testing laboratory, applied to a whole platform and its integration, and it is where the RGS integration requirements meet a regulator’s paperwork rather than another operator’s wallet API.
The engineering obligations that land on the supplier
The guidelines put a set of measurable obligations on the concessionaire system, and in a CFS supply chain most of them land on whoever builds the game system.
- Replication. Data replicated to the secondary site within 120 seconds, with the secondary site geographically distinct but inside the EEA, and the disaster-recovery process itself demonstrated. The backup and restore verification discipline is the right rehearsal for that claim.
- Cloud. Cloud platforms are permitted, but only from providers enrolled in the register kept by the Italian cybersecurity agency and meeting the technical requirements of the digital agency, with digital sovereignty of the data and encryption both in transit and at rest. The data residency and cross-border transfer question is not a policy preference here; it is a certification input.
- Data windows. Real-time availability of stored gameplay and operational information for the last six months; accounting and transaction information on demand for the last two years; five-year archival with integrity and readability; and custom queries that can be exported within 48 hours of a request.
- Real-time reporting. Game transactions, bonuses and outcomes transmitted to ADM’s central system in real time, with every step of the game flow traceable and reconstructible.
- Integrity and access. Automated integrity verification for the components, with the affected component blocked when verification fails, and multi-factor authentication for back-office access — the subject of the back-office access control requirements.
- AI disclosure. Where outcomes can be influenced by automated decision-making or external computing tools, the game rules have to state that before the player takes part.
The first-run check happens in production
Certification is not the last gate. On a first certification, ADM provides for a technical-functional verification carried out in the production environment. It covers the configuration actually destined for the concession, runs across all the game systems included in the certification application, and takes place at the first production start of each type of game. The checks are operational: the sale, the acceptance of wagers, the accounting of transactions, the crediting of wins, payments, and the exchange of information with ADM’s central system. Five test accounts registered to a legal person are set up for it and their schedules published. Where CFS-provided systems are in use, the CFS has to supply technical support during the checks.
That is a production-readiness rehearsal with a regulator watching, and it is the point at which an integration that only ever ran against a mock is found out.
Change control after the certificate
A certificate describes a version, and the rules follow it. ADM’s August instructions state that later modifications to an already certified system that could affect the critical components, the functions that were verified or conformity with the technical rules have to be submitted to the verification body in advance. An emergency update needed to restore correct operation is permitted before the application is filed, but the concessionaire still has to obtain the ODV’s conformity certification of the change, within two weeks.
Two other rhythms sit underneath. Authorisations are effective for 12 months, after which audits verify, per platform and per game, that the operating system still matches what was certified, that changes not touching the random-number generator or the symbol-generation software are conformant, and that the real prize pool or return to player actually offered matches what the game artwork told the player — measured against game data for the previous 12 months. And the transitional rules ADM issued in June 2026 keep the live-dealer, bingo, poker and betting-exchange applications moving through the existing certification route until the new technical rules for those verticals start on 13 November 2026.
What this means for a commission
Two decisions follow from the timetable, and they are commercial before they are technical.
Which side of the integration you are on. A studio or platform that becomes a service-provider concessionaire certifies a game system once and offers it to concessionaires that then verify only the integration. That is the earliest track and it is where the shared library is populated. A supplier that instead places its titles inside a single operator’s concessionaire system inherits that operator’s 13 January date and the operator’s own whole-system verification — cheaper to enter, but you are a passenger on somebody else’s certification.
Whether your evidence is versioned. The source digests, the build log, the certified version identifier and the emergency-update window all assume the artefact that was certified is the artefact in production. A live-ops change that ships without a version bump is not a small shortcut in this framework; it is the exact state the change-control rule is written to prevent.
Italy is not the only market asking for that, which is why the casino game development side of a commission and its certification and compliance side are cheaper to hold together from the design stage than to reconcile at the ODV.
The decisions that belong on one page
- The route. CFS certifying a system for several concessionaires, or a supplier integrating into one concessionaire’s system.
- The date you actually own. 13 November 2026, 13 January 2027, 12 February 2027 or 15 February 2027.
- The deliverable. Technical report, component inventory, critical-file digests, build log, digest script, unique version identifiers.
- The infrastructure claims. 120-second replication, EEA disaster recovery, an approved cloud register, encryption at rest and in transit.
- The data windows. Six months live, two years on demand, five years archived, 48-hour exports.
- The first run in production. Test accounts, published schedules, and the CFS technical support that has to be present.
- The change rule. Modifications to critical components or verified functions go to the ODV first; emergency updates are certified within two weeks.
Questions studios and platforms ask
Do the new certification dates apply to the whole online market at once?
No. The staged calendar gives the earliest date, 13 November 2026, to service-provider concessionaires filing the conformity results for applications that contain game systems offered to other concessionaires, plus the components that populate the shared library. Concessionaires that use those CFS-supplied game systems follow by 13 January 2027, the technical-functional verifications complete by 12 February 2027, and the new system goes into production from 15 February 2027. The dates were reported by the Italian trade press on 7 October 2026; confirm the current calendar with ADM.
If a concessionaire uses a game system that is already certified, what still has to be verified?
The concessionaire system, as a whole. The guidelines allow a concessionaire to use a certified game system made available by a service-provider concessionaire, but the requirement to have its own system verified in its entirety remains; what changes is that the verification body is required to verify only the integration of the CFS game system with the rest of the system under review. ADM’s August 2026 instructions repeat that the conformity verification covers the system in its entirety rather than single elements considered separately.
What does a verification body inspect?
A technical report describing the system, its components and their interactions; the documentation plus the hardware and software components; the critical files; the automated integrity-verification mechanisms; and the communications between components and with ADM’s central system. Conformity tests, statistical analyses and functional checks follow the technical rules. Source code must carry a description and change history for each file or module, the certified version must be uniquely identified, and the reviewer must be able to show that the binaries match the compiled source, with a build log and the digests of critical files.
What are the infrastructure obligations?
Replication of data to a geographically distinct secondary site within the EEA in a maximum of 120 seconds, with the disaster-recovery process demonstrated; cloud providers enrolled in the Italian cybersecurity agency’s register and meeting the digital agency’s technical requirements, with encryption of data in transit and at rest; real-time availability of gameplay information for the last six months; accounting and transaction data on demand for two years; five-year archival; and custom query results exportable within 48 hours of a request.
What happens after a system has already been certified?
Modifications that could affect critical components, the functions that were verified, or conformity with the technical rules have to be submitted to the verification body in advance. An emergency update needed to restore correct operation may be applied before the application is filed, but conformity certification of the change must still be obtained from the verification body within two weeks. Authorisations are effective for 12 months and are renewed through an audit that compares the operating system with the certified version and checks the real prize pool or return to player against 12 months of game data.
Is there a check after certification, before the games go live?
Yes, on a first certification. A technical-functional verification takes place in the production environment, on the configuration actually destined for the concession, covering all the game systems in the certification application and running at the first production start of each type of game. It exercises sales, wager acceptance, accounting, the crediting of wins, payments and the exchange of information with ADM’s central system, and it uses five test accounts registered to a legal person with published schedules. Where service-provider systems are used, the CFS has to provide technical support during those checks.








































