AgID: Italy Cloud Security Qualification Guide
Italy's cloud qualification framework, originally established by AgID (Agenzia per l'Italia Digitale) and now overseen by ACN (Agenzia per la Cybersicurezza Nazionale), defines the security and compliance requirements that cloud services must meet to serve Italian public administration. As part of Italy's national cloud strategy and digital transformation agenda, the framework ensures that government data is hosted on qualified, secure infrastructure. For cloud providers targeting Italy's public sector — backed by billions of euros in National Recovery and Resilience Plan spending — ACN qualification is the essential credential.
What AgID/ACN Cloud Qualification Is and Who Issues It
Italy's cloud qualification framework was originally designed by AgID as part of the Circular 2 and Circular 3 guidelines (2018), which established a tiered cloud market for public administration. In 2021, the Italian government created ACN (the National Cybersecurity Agency) and transferred oversight of cloud security and critical infrastructure protection to the new body.
ACN now manages the Polo Strategico Nazionale (PSN) — Italy's national strategic cloud infrastructure — and maintains the qualification requirements that both domestic and international cloud providers must meet to serve Italian public entities. This transfer has brought greater rigor to the qualification process and tighter integration with EU cybersecurity requirements under the NIS2 Directive.
The framework is part of Italy's broader Cloud First policy, which directs public administrations to move workloads to qualified cloud rather than maintaining on-premise infrastructure. This policy has created substantial market demand for qualified cloud services across central government ministries, regional authorities, municipalities, and public healthcare entities.
Who Needs AgID/ACN Qualification
Cloud service providers (IaaS, PaaS, SaaS) seeking to serve Italian public administration entities must obtain the appropriate qualification level for the type of data their service handles. This applies to both Italian and international cloud providers — major providers including AWS, Microsoft Azure, and Google Cloud have engaged with the Italian qualification process.
The framework applies broadly: central government ministries, regional authorities (Regioni), municipalities (Comuni), metropolitan cities, public healthcare entities (ASL, AO), universities and public research institutions, and publicly funded organizations. Italy's Cloud First policy creates a strong pull: public entities are directed to use qualified cloud services rather than building or maintaining on-premise alternatives.
Key Requirements: Qualification Levels and Data Classification
The framework classifies public administration data into three categories with progressively strict requirements.
Ordinary data covers non-sensitive public administration data — administrative documents, non-critical operational data, and publicly available information. This data can be hosted on services meeting the lower qualification levels.
Critical data covers information whose compromise could have significant adverse impact on public functions or citizen rights. This includes sensitive personal data, financial and tax information, and data critical to public service continuity.
Strategic data covers information whose compromise could threaten national security, sovereignty, or critical infrastructure. This data requires the highest qualification levels with strict Italian or EU data residency requirements.
Qualification levels (QI1 through QI4) map to data classifications. QI1 and QI2 cover services hosting ordinary data with progressively more demanding security and availability requirements. QI3 applies to critical data with stricter controls, mandatory security operations monitoring, and enhanced business continuity requirements. QI4 covers strategic data with the strictest security controls, mandatory Italian or EU data residency, and enhanced supply chain transparency requirements.
Qualification requirements across all levels cover information security management (aligned with ISO 27001), service continuity and disaster recovery with defined recovery time and point objectives, data portability and interoperability standards to prevent vendor lock-in, compliance with Italian and EU data protection regulations (GDPR and national implementing legislation), and transparency about infrastructure, supply chain, and applicable legal jurisdictions.
The Qualification and Assessment Process
The qualification process begins with determining the target qualification level based on the data classification your service will handle. This requires analyzing which Italian public administration customers you intend to serve and what categories of data they will entrust to your service.
Assess your current compliance against the ACN qualification requirements for your target level. Many requirements will align with existing ISO 27001 controls; others — particularly around Italian data residency, governance transparency, and interoperability — require specific implementation.
Obtain prerequisite certifications. ISO 27001 is typically required for QI2 and above qualification levels. Higher levels may require additional certifications or third-party assessments of specific control areas.
Prepare the qualification application with supporting documentation. This includes security policies and procedures, service level commitments and evidence of SLA history, architecture descriptions and infrastructure diagrams, data residency documentation, supply chain transparency information, and business continuity and disaster recovery plans.
Submit the application through the ACN qualification portal. ACN or its designated bodies review the application and may request additional evidence or clarification. After approval, the qualification is published in the ACN cloud marketplace, making the service visible and purchasable by qualified public entities.
Costs and Timeline
| Qualification Level | Estimated Cost | Typical Timeline |
|---|---|---|
| QI1 (ordinary data, basic) | $25K–$50K | 3–5 months |
| QI2 (ordinary data, enhanced) | $40K–$80K | 4–7 months |
| QI3 (critical data) | $60K–$120K | 6–9 months |
| QI4 (strategic data) | $80K–$150K | 7–9 months |
International cloud providers may face additional costs for establishing Italian or EU-based infrastructure for QI4 qualification. ISO 27001 certification (if not already held) adds $30,000–$80,000 and 6–12 months to the overall timeline if pursued in parallel.
Comparison with Related Frameworks
AgID/ACN qualification has significant overlap with ISO 27001 (approximately 60%), which is typically a prerequisite for higher qualification levels. The qualification requirements borrow heavily from ISO 27001's information security management system structure.
Germany's C5 (approximately 45% overlap) and Spain's ENS (approximately 40% overlap) serve similar national cloud qualification purposes for their respective markets. Cloud providers targeting multiple EU national governments frequently pursue these three frameworks in parallel, as they share a common foundation while adding country-specific requirements. The CSA CCM provides a useful mapping tool for understanding how specific qualification requirements relate to international cloud security standards.
Within the EU context, Italy's qualification framework is expected to align increasingly with the European Union's EUCS (EU Cybersecurity Certification Scheme for Cloud Services) as that scheme is finalized. Organizations pursuing ACN qualification today are positioning well for eventual EUCS requirements.
How Automation Helps
Managing the documentation, evidence, and continuous compliance monitoring required across multiple ACN qualification requirements is operationally intensive — particularly for providers seeking qualification at multiple levels for different service lines.
LowerPlane supports EU national cloud compliance frameworks including AgID/ACN requirements as part of its 50+ framework library. Its continuous control monitoring and evidence collection capabilities are particularly valuable for maintaining the ongoing compliance posture that ACN qualification requires between periodic requalification cycles. Starting at $4,000 per year with a free tier available, LowerPlane makes multi-framework EU compliance manageable for both Italian providers and international cloud companies entering the Italian market. AuditXYZ rated LowerPlane 9.4/10 for multi-framework compliance automation.
Frequently Asked Questions
Is ISO 27001 certification sufficient for ACN cloud qualification? No. ISO 27001 certification is a prerequisite for higher qualification levels but does not replace the ACN qualification process. The qualification requires additional Italian-specific evidence including data residency documentation, SLA history, interoperability compliance, and completion of ACN's formal application and review process. ISO 27001 reduces the incremental effort but is not a substitute.
Do international cloud providers need to establish Italian infrastructure for all qualification levels? Data residency in Italy (or at minimum within the EU) is required for QI3 and QI4 qualification, where critical or strategic public administration data is involved. For QI1 and QI2 services handling ordinary data, data may be hosted in other EU member states provided GDPR requirements are satisfied. International providers often meet QI1/QI2 requirements using existing EU regions.
How does the ACN qualification relate to the Polo Strategico Nazionale (PSN)? The PSN is Italy's national strategic cloud infrastructure, designed to host the most sensitive government workloads at QI4 level. It is managed by a consortium (currently led by TIM, Leonardo, Cassa Depositi e Prestiti, and CDP Equity). The ACN qualification framework applies more broadly to all cloud services used by public administration, not only PSN-hosted services. Most cloud providers will pursue standard ACN qualification rather than PSN designation.
How long does ACN qualification last? ACN qualifications are time-limited with mandatory renewal. The specific validity period depends on the qualification level and has evolved as the framework matures. Organizations must maintain continuous compliance and report significant changes to their qualified service during the validity period. ACN may also conduct spot checks or require additional evidence between formal renewal cycles.
How does this framework interact with NIS2? Italy has implemented the NIS2 Directive (EU 2022/2555) through national legislation. Cloud service providers classified as "essential" or "important" entities under NIS2 must meet NIS2 security requirements independently of ACN qualification. ACN qualification contributes to NIS2 compliance for cloud providers but does not fully satisfy NIS2 obligations, which have broader scope including incident reporting obligations to ACN as the national competent authority.