Authorization program · Last verified
ACN Cloud Qualification Scheme
ACN's Regolamento sets three qualification tracks — AI, AC and QC — for Italian public bodies and their cloud providers to move data to the cloud. Administrations must complete migration by 30 June 2026; providers selling cloud services to them must hold the matching AI, AC or QC qualification level.
- Class
- Authorization program
- Owner
- Agenzia per la Cybersicurezza Nazionale (ACN)
- Public register
- Tested — link not working
- Last verified
What it is
The scheme is set out in the Regolamento per le infrastrutture digitali e per i servizi cloud per la pubblica amministrazione (Determinazione ACN n. 21007/2024, signed by Director Bruno Frattasi on 27 June 2024), in force since 1 August 2024 under its own text: "il presente Regolamento si applica a decorrere dal 1 agosto 2024" (this Regulation applies from 1 August 2024). It replaced an earlier two-code transitional regime ("QC"/"QI") that this same Regolamento abrogates (art. 26).
It defines three separate qualification tracks, not one ladder: AI1–AI4 for digital infrastructure operators (art. 12–14, self-assessment plus a compliance report to ACN — "adeguamento"); AC1–AC4 for cloud services provided by a public body, an in-house company or a publicly controlled company under Legislative Decree 175/2016 (art. 15–16, also "adeguamento"); and QC1–QC4 for cloud services provided by any other, i.e. private or commercial, supplier (art. 17–19, "qualificazione", reviewed directly by ACN).
For the QC track, ACN itself runs the review: "Entro sessanta giorni dalla ricezione di una domanda di qualificazione ... l'ACN verifica la conformità ai requisiti previsti per i livelli di qualificazione" (within sixty days of receiving a qualification application, ACN verifies conformity with the requirements set for the qualification levels), and it may "svolgere accertamenti di carattere tecnico, incluse le verifiche di sicurezza ... anche mediante accesso all'infrastruttura fisica e logica" (carry out technical checks, including security checks, including by accessing the physical and logical infrastructure). A QC qualification is valid for a maximum of 36 months (art. 19/6).
Migrating to compliant infrastructure or to a qualified/adequate cloud service is a direct legal duty placed on Italian public administrations, not on providers: "Le amministrazioni ... migrano ... i dati e servizi digitali verso le infrastrutture digitali per la pubblica amministrazione che ... rispettano ... i livelli minimi ... ovvero verso i servizi cloud, adeguati ... o qualificati" (administrations migrate their data and digital services towards public-administration digital infrastructures that meet the minimum levels, or towards adequate or qualified cloud services) (art. 9/1), with a completion deadline of 30 June 2026: "Le amministrazioni completano le attività previste dal piano di migrazione ... entro il 30 giugno 2026" (art. 11/4). ACN can revoke a qualification or an adequacy finding for non-compliance (art. 21).
Who owns it
The Agenzia per la Cybersicurezza Nazionale (ACN), Italy's national cybersecurity agency, holds this function under Decree-Law 82/2021 art. 7(1)(m) and (m-ter), which transferred it from the earlier Agenzia per l'Italia Digitale (AgID).
Who assesses it
For the QC track (private/commercial providers), ACN reviews applications directly rather than delegating to accredited third parties, though a supplier's own international certificates may be submitted as supporting evidence within the application file. For the AI and AC tracks, the process is self-assessment ("adeguamento") followed by a compliance declaration to ACN, not an ACN-run review.
Qualification tracks and levels
- AI1–AI4 (Adeguamento — digital infrastructure operators, Regolamento art. 12–14)
- AC1–AC4 (Adeguamento — cloud service provided by a public body, in-house company or publicly controlled company, art. 15–16)
- QC1–QC4 (Qualificazione — cloud service provided by any other supplier, reviewed directly by ACN, art. 17–19)
Who asks for it
Statutory (scoped). Legal for Italian public administrations directly (Regolamento art. 9, migration deadline 30 June 2026). For cloud providers, the driver is market access: the qualification is required only to sell IaaS/PaaS/SaaS to an Italian public administration, not for the wider market.
Italian public administrations, central and local as defined by Law 196/2009 art. 1(3), are directly obligated to migrate to compliant infrastructure or to qualified/adequate cloud services. Cloud providers are not directly regulated by the Regolamento, but any supplier — public or private, Italian or foreign — that wants to sell IaaS, PaaS or SaaS to an Italian public administration must obtain the matching AI, AC or QC qualification: "I fornitori cloud che intendono erogare servizi ... destinati alle pubbliche amministrazioni devono ottenere, per questi servizi, la qualificazione rilasciata dall'Agenzia per la Cybersicurezza Nazionale" (cloud providers intending to supply services to public administrations must obtain, for those services, the qualification issued by the National Cybersecurity Agency). No requirement was found in the sources reviewed for providers who do not sell to an Italian public administration.
Sources
- ACN — Regolamento per le infrastrutture digitali e per i servizi cloud per la pubblica amministrazione (Determinazione ACN n. 21007/2024, full text) ↗ — accessed
- cloud.italia.it — Il percorso di qualificazione dei servizi cloud della PA ↗ — accessed
- cloud.italia.it — homepage (migration start date verified on this page, 19 January 2023) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.