Upcoming Webinar | Navigating Global Privacy Trends in 2026 on December 3rd @ 1:00 PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Compliance in Italy: Navigating the Cloud Italy Strategy

Cloud Computing | ISO Certifications | CSA STAR Program

Published: Feb 24, 2023

Last Updated: Dec 4, 2025

As the world becomes increasingly digital, governments globally have taken measures to ensure the safety and security of their citizens' data.

One such example is the Cloud Italy Strategy, initiated by the Italian Agency for National Cybersecurity (ACN), which outlines specific compliance requirements for cloud service providers serving the Italian public sector.

 

Whether your organization is based in Italy or elsewhere, this framework may impact your cloud services and compliance efforts. 

That’s why, in this article, we’re going to leverage our extensive experience with the relevant ISO standards and Cloud Security Alliance (CSA) STAR Programs to disseminate Cloud Italy Strategy requirements so that cloud providers understand this standard for cybersecurity more clearly.

 

Cloud Italy Strategy Data and Service Classifications

If you’re a cloud service provider that currently services or would potentially seek to service the Italian public sector, you will need to meet the requirements of this ACN Cloud Italy Strategy.

 

From what we know, there are three classifications of data and services within the Cloud Italy Strategy:

  • Ordinary (QC1)
  • Critical (QC2)
  • Strategic (QC3)

Though Strategic is the highest classification—meaning it requires the most certifications—the ACN anticipates that the majority of CSPs will be considered Ordinary or Critical. Still, however you classify, you’ll have to demonstrate the related minimum compliance requirements that, depending on the classification, could include the following:

 

Cloud Italy Strategy Compliance Requirements

The following table demonstrates how these certifications and requirements break down by classification:

 

Classification

Requirements

Ordinary (QC1)

o   ISO/IEC 27017 certification; and

o   ISO/IEC 27018

*As an alternative to the above ISO 27001 requirement, you can instead acquire Cloud Security Alliance - Star Level 2 certification.

Critical (QC2)

  • Meet all QC1 requirements, AND
  • Self-attestation for ISO 22301: Requires your attesting to compliance with the Business Continuity Management System standard for your cloud service that is subject to qualification.
  • Self-attestation for ISO 20000-1: Requires your attesting to compliance with the Service Management System standard for your cloud service that is subject to qualification.

Strategic (QC3)

 

Such certification requirements demonstrate a clear commitment to cybersecurity, but in fact, there’s more to do—in addition to these mandates noted above, cloud service providers will also have to ensure that they have controls and processes in place based on the Italian National Cybersecurity Framework as relevant to the cloud service provider’s classification. 

How Schellman Can Help with the New Cloud Italy Strategy

At Schellman, we have been working with CSA STAR for years and now field a team of highly trained experts in ISO 9001, ISO 27001, ISO 22301, and ISO 20000-1. As such, we can help you navigate these requirements and ensure that you are fully compliant with the standards required for servicing the Italian public sector.

With our support, you can be confident in your ability to provide the best service to your customers while meeting compliance obligations. To start the process, please reach out to us directly to schedule a consultation.

About Danny Manimbo

Danny Manimbo is a Principal with Schellman based in Denver, Colorado. As a member of Schellman’s West Coast / Mountain region management team, Danny is primarily responsible for leading Schellman's AI and ISO practices as well as the development and oversight of Schellman's attestation services. Danny has been with Schellman for 10 years and has over 13 years of experience in providing data security audit and compliance services.