Compliance in Italy: Navigating the Cloud Italy Strategy
Cloud Computing | ISO Certifications | CSA STAR Program
Published: Feb 24, 2023
Last Updated: Dec 4, 2025
As the world becomes increasingly digital, governments globally have taken measures to ensure the safety and security of their citizens' data.
One such example is the Cloud Italy Strategy, initiated by the Italian Agency for National Cybersecurity (ACN), which outlines specific compliance requirements for cloud service providers serving the Italian public sector.
Whether your organization is based in Italy or elsewhere, this framework may impact your cloud services and compliance efforts.
That’s why, in this article, we’re going to leverage our extensive experience with the relevant ISO standards and Cloud Security Alliance (CSA) STAR Programs to disseminate Cloud Italy Strategy requirements so that cloud providers understand this standard for cybersecurity more clearly.
Cloud Italy Strategy Data and Service Classifications
If you’re a cloud service provider that currently services or would potentially seek to service the Italian public sector, you will need to meet the requirements of this ACN Cloud Italy Strategy.
From what we know, there are three classifications of data and services within the Cloud Italy Strategy:
- Ordinary (QC1)
- Critical (QC2)
- Strategic (QC3)
Though Strategic is the highest classification—meaning it requires the most certifications—the ACN anticipates that the majority of CSPs will be considered Ordinary or Critical. Still, however you classify, you’ll have to demonstrate the related minimum compliance requirements that, depending on the classification, could include the following:
- ISO 9001 certification
- ISO 27001 certification (including ISO 27017 and ISO 27018)
- ISO 22301 self-attestation and/or certification
- ISO 20000-1 self-attestation and/or certification
- CSA STAR Level 2 attestation or certification
Cloud Italy Strategy Compliance Requirements
The following table demonstrates how these certifications and requirements break down by classification:
|
Classification |
Requirements |
|---|---|
|
Ordinary (QC1) |
o ISO/IEC 27017 certification; and *As an alternative to the above ISO 27001 requirement, you can instead acquire Cloud Security Alliance - Star Level 2 certification. |
|
Critical (QC2) |
|
|
Strategic (QC3) |
|
Such certification requirements demonstrate a clear commitment to cybersecurity, but in fact, there’s more to do—in addition to these mandates noted above, cloud service providers will also have to ensure that they have controls and processes in place based on the Italian National Cybersecurity Framework as relevant to the cloud service provider’s classification.
How Schellman Can Help with the New Cloud Italy Strategy
At Schellman, we have been working with CSA STAR for years and now field a team of highly trained experts in ISO 9001, ISO 27001, ISO 22301, and ISO 20000-1. As such, we can help you navigate these requirements and ensure that you are fully compliant with the standards required for servicing the Italian public sector.
With our support, you can be confident in your ability to provide the best service to your customers while meeting compliance obligations. To start the process, please reach out to us directly to schedule a consultation.
About Danny Manimbo
Danny Manimbo is a Principal with Schellman based in Denver, Colorado. As a member of Schellman’s West Coast / Mountain region management team, Danny is primarily responsible for leading Schellman's AI and ISO practices as well as the development and oversight of Schellman's attestation services. Danny has been with Schellman for 10 years and has over 13 years of experience in providing data security audit and compliance services.