Compliance in Italy: Navigating the Cloud Italy Strategy
Cloud Computing | ISO Certifications | CSA STAR Program
Published: Feb 24, 2023
Last Updated: Dec 11, 2025
As the world becomes increasingly digital, governments globally have taken measures to ensure the safety and security of their citizens' data.
One such example is the Cloud Italy Strategy, initiated by the Italian Agency for National Cybersecurity (ACN), which outlines specific compliance requirements for cloud service providers serving the Italian public sector.
Whether your organization is based in Italy or elsewhere, this framework may impact your cloud services and compliance efforts. That’s why, in this article, we’re going to leverage our extensive experience with the relevant ISO standards and Cloud Security Alliance (CSA) STAR Programs to disseminate Cloud Italy Strategy requirements so that cloud providers understand this standard for cybersecurity more clearly.
Cloud Italy Strategy Data and Service Classifications
If you’re a cloud service provider that currently services or would potentially seek to service the Italian public sector, you will need to meet the requirements of this ACN Cloud Italy Strategy.
From what we know, there are three classifications of data and services within the Cloud Italy Strategy:
- Ordinary (QC1)
- Critical (QC2)
- Strategic (QC3)
Though Strategic is the highest classification—meaning it requires the most certifications—the ACN anticipates that the majority of CSPs will be considered Ordinary or Critical. Still, however you classify, you’ll have to demonstrate the related minimum compliance requirements that, depending on the classification, could include the following:
- ISO 9001 certification
- ISO 27001 certification (including ISO 27017 and ISO 27018)
- ISO 22301 self-attestation and/or certification
- ISO 20000-1 self-attestation and/or certification
- CSA STAR Level 2 attestation or certification
Cloud Italy Strategy Compliance Requirements
The following table demonstrates how these certifications and requirements break down by classification:
|
Classification |
Requirements |
|---|---|
|
Ordinary (QC1) |
*As an alternative to the above ISO 27001 requirement, you can instead acquire Cloud Security Alliance - Star Level 2 certification. |
|
Critical (QC2) |
|
|
Strategic (QC3) |
|
Such certification requirements demonstrate a clear commitment to cybersecurity, but in fact, there’s more to do—in addition to these mandates noted above, cloud service providers will also have to ensure that they have controls and processes in place based on the Italian National Cybersecurity Framework as relevant to the cloud service provider’s classification.
How Schellman Can Help with the New Cloud Italy Strategy
At Schellman, we have been working with CSA STAR for years and now field a team of highly trained experts in ISO 9001, ISO 27001, ISO 22301, and ISO 20000-1. As such, we can help you navigate these requirements and ensure that you are fully compliant with the standards required for servicing the Italian public sector.
With our support, you can be confident in your ability to provide the best service to your customers while meeting compliance obligations. To start the process, please reach out to us directly to schedule a consultation.
About Danny Manimbo
Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).