Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Compliance in Italy: Navigating the Cloud Italy Strategy

Cloud Computing | ISO Certifications | CSA STAR Program

Published: Feb 24, 2023

Last Updated: Dec 11, 2025

As the world becomes increasingly digital, governments globally have taken measures to ensure the safety and security of their citizens' data.

One such example is the Cloud Italy Strategy, initiated by the Italian Agency for National Cybersecurity (ACN), which outlines specific compliance requirements for cloud service providers serving the Italian public sector.

Whether your organization is based in Italy or elsewhere, this framework may impact your cloud services and compliance efforts. That’s why, in this article, we’re going to leverage our extensive experience with the relevant ISO standards and Cloud Security Alliance (CSA) STAR Programs to disseminate Cloud Italy Strategy requirements so that cloud providers understand this standard for cybersecurity more clearly.

Cloud Italy Strategy Data and Service Classifications

If you’re a cloud service provider that currently services or would potentially seek to service the Italian public sector, you will need to meet the requirements of this ACN Cloud Italy Strategy.

From what we know, there are three classifications of data and services within the Cloud Italy Strategy:

  • Ordinary (QC1)
  • Critical (QC2)
  • Strategic (QC3)

Though Strategic is the highest classification—meaning it requires the most certifications—the ACN anticipates that the majority of CSPs will be considered Ordinary or Critical. Still, however you classify, you’ll have to demonstrate the related minimum compliance requirements that, depending on the classification, could include the following:

Cloud Italy Strategy Compliance Requirements

The following table demonstrates how these certifications and requirements break down by classification:

Classification

Requirements

Ordinary (QC1)

*As an alternative to the above ISO 27001 requirement, you can instead acquire Cloud Security Alliance - Star Level 2 certification.

Critical (QC2)

  • Meet all QC1 requirements, AND
  • Self-attestation for ISO 22301: Requires your attesting to compliance with the Business Continuity Management System standard for your cloud service that is subject to qualification.
  • Self-attestation for ISO 20000-1: Requires your attesting to compliance with the Service Management System standard for your cloud service that is subject to qualification.

Strategic (QC3)

Such certification requirements demonstrate a clear commitment to cybersecurity, but in fact, there’s more to do—in addition to these mandates noted above, cloud service providers will also have to ensure that they have controls and processes in place based on the Italian National Cybersecurity Framework as relevant to the cloud service provider’s classification. 

How Schellman Can Help with the New Cloud Italy Strategy

At Schellman, we have been working with CSA STAR for years and now field a team of highly trained experts in ISO 9001, ISO 27001, ISO 22301, and ISO 20000-1. As such, we can help you navigate these requirements and ensure that you are fully compliant with the standards required for servicing the Italian public sector.

With our support, you can be confident in your ability to provide the best service to your customers while meeting compliance obligations. To start the process, please reach out to us directly to schedule a consultation.

About Danny Manimbo

Danny Manimbo is a Principal at Schellman based in Denver, Colorado, where he leads the firm’s Artificial Intelligence (AI) and ISO services and serves as one of Schellman’s CPA principals. In this role, he oversees the strategy, delivery, and quality of Schellman’s AI, ISO, and broader attestation services. Since joining the firm in 2013, Danny has built more than 15 years of expertise in information security, data privacy, AI governance, and compliance, helping organizations navigate evolving regulatory landscapes and emerging technologies. He is also a recognized thought leader and frequent speaker at industry conferences, where he shares insights on AI governance, security best practices, and the future of compliance. Danny has achieved the following certifications relevant to the fields of accounting, auditing, and information systems security and privacy: Certified Public Accountant (CPA), Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Internal Auditor (CIA), Certificate of Cloud Security Knowledge (CCSK), and Certified Information Privacy Professional – United States (CIPP/US).