HomeFrameworksNational Cyber & Cloud SchemesACN

Framework  National Cyber & Cloud Schemes

ACN

In compliance lists "ACN" refers to the cloud qualification regime run by Italy's Agenzia per la Cybersicurezza Nazionale, the national cybersecurity agency, for cloud services and infrastructure sold to Italian public administrations.

Responsibility passed from AgID to ACN on January 19, 2023, and ACN consolidated the rules in Directorial Decree 21007/24 of June 27, 2024, with the ordinary qualification regime in force from August 2024.

Services are qualified at levels QC1 to QC4 and infrastructures at QI1 to QI4, matched to the classification of the data and services the public body will place on them (ordinary, critical, strategic). Public administrations may only procure cloud services that appear in ACN's qualification catalog at the level their data classification requires.

Qualification is largely evidence-based: the provider submits a self-assessment against ACN's technical and organizational requirements (which build on ISO/IEC 27001, 27017, and 27018 and add Italian requirements on data localization, personnel, and reversibility), attaches certifications and audit reports, and ACN reviews before listing.

Higher levels add requirements such as EU data location, EU-controlled operations, and stronger assurance.

In writing, a provider needs the ISO/IEC 27001 certificate and statement of applicability, a service description and data flow, the completed requirement matrix with evidence, contractual terms (SLA, exit and portability, subprocessors), incident management and notification procedures, and personnel and access control policies.

AI-compiled
Share
Sponsored
ACN
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with ACN
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service providers and cloud infrastructure operators that want to sell to Italian public administrations; the public administrations themselves must classify their data and buy only qualified services at the matching level. The trigger is public sector procurement, not company size.

What the assessor asks to see

Service catalog entry and level requested; ISO/IEC 27001 certificate, scope, and statement of applicability (plus 27017 and 27018 where applicable); requirement matrix with evidence per requirement; data location and processing map; ownership and control information for higher levels; SLA and contract templates including exit and portability; incident and breach notification procedures; personnel security and access control policies; penetration test and vulnerability management records; business continuity plans.

Levels

Services are qualified QC1 through QC4 and infrastructures QI1 through QI4. In practice the catalog groups them as ordinary (QC1), critical (QC2), and strategic (QC3 and above), and public bodies must match the level to the classification of the data and services they migrate.

Assessors

Who assesses ACN

ACN itself reviews applications and lists qualified services. Supporting ISO/IEC 27001 and related certificates come from accredited certification bodies, and ACN may require independent audit reports for higher levels. No separate class of ACN-licensed assessors exists.

Accredited by ACCREDIA (Italian national accreditation body) for the ISO/IEC certification bodies whose certificates support the application; ACN for the qualification decision itself.

Public register of assessors: https://www.acn.gov.it/en/strategia/strategia-cloud-italia/qualificazione-cloud

No firm has claimed a ACN assessor listing yet. Claim yours →

Consultants

Who helps with ACN

Italian and international consultancies with ISO 27001 practices help providers classify their offerings, complete the requirement matrix, and gather evidence; law firms advise on the localization and control requirements at QC3 and above. Engagements run a few months per service family.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a ACN consultant listing yet. Claim yours →

Software

Tools for ACN

Tools that name this framework in their own material.

No firm has claimed a ACN tool listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for ACN

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with ACN

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.