Compliance › ACN qualification
What “ACN qualified”
actually means.
ACN is the Italian National Cybersecurity Agency, the Italian public body for cybersecurity. Before the Italian Public Administration can use a cloud service, the Agency checks its requirements and publishes it in its catalogue. Three AtWorkStudio services have passed this check.
In three questions
Who the Agency is, what it checks and what remains with the customer. The rest is in Cloud Regulation no. 21007/2024, in force since 1 August 2024.
The Italian National Cybersecurity Agency (ACN), established in 2021, is Italy’s cybersecurity authority. It applies the NIS2 Directive, runs CSIRT Italia and qualifies cloud services for the Public Administration.
That the cloud service meets written requirements for security, quality, performance, interoperability and portability, and that the provider holds the required certifications. Only then does it publish the service in the catalogue with a numbered record.
It is not a certification of the company and not a recommendation by the Agency: it covers the individual service, for one data level and for a validity period of up to thirty-six months.
Four levels,
by type of data.
The Italian Public Administration classifies its data and services as ordinary, critical or strategic. The qualification level says up to which class a cloud service may be used; each level adds requirements to the previous one.
Ordinary data and services, most of day-to-day work. Among other things it requires ISO 9001 and ISO/IEC 27001 with the cloud extensions 27017 and 27018. It is the level of the three AtWorkStudio services.
Critical data and services, whose compromise can affect how the body operates. It adds requirements, including certified business continuity.
Strategic data and services, linked to essential functions of the State. It adds further certifications and controls on the provider and the service.
Strategic data and services with even stricter security requirements. It is the highest level set by the Regulation.
Three services, three public records
ATWS Secure Workspace
A cloud work desktop accessed from the browser, with mandatory multi-factor authentication.
Record SA-7323 · level QC1 · valid from 12/02/2026 to 12/02/2029.
ATWS Email Security Gateway
Email filtering against spam, viruses and phishing, with rules per domain, user and group and data processed only in the European Union.
Record SA-7582 · level QC1 · valid from 13/04/2026 to 13/04/2029.
ATWS Secure Backup for Microsoft 365
Backup and granular restore of Exchange Online, SharePoint, OneDrive and Teams, with data in European Union datacentres.
Record SA-7583 · level QC1 · valid from 13/04/2026 to 13/04/2029.
Frequently asked questions about ACN qualification
The questions we hear most often from people who come across the acronym ACN for the first time. For AtWorkStudio’s ISO certifications see the certifications page.
ACN stands for Agenzia per la Cybersicurezza Nazionale, the Italian National Cybersecurity Agency: the Italian public body responsible for cybersecurity. It was established by Decree-Law no. 82 of 14 June 2021 and is Italy’s national cybersecurity authority. Among other things, it is the authority that applies the NIS2 Directive in Italy and the one that qualifies the cloud services the Italian Public Administration may purchase.
It means that the Italian National Cybersecurity Agency has verified that the cloud service meets the security, quality, performance, interoperability and portability requirements set by Cloud Regulation no. 21007/2024, and has published it in its catalogue with a record and a validity period. Italian public administrations may adopt it to process data of the level stated on the record.
They are the four qualification levels for cloud services, tied to the type of data the Public Administration may process with them. QC1 covers ordinary data and services, QC2 critical ones, QC3 and QC4 strategic ones; each level adds requirements to the previous one. The three AtWorkStudio services are qualified at QC1: suitable for ordinary data, which is most of the day-to-day work of a public body or a company.
No. It covers the individual cloud service, not the company as a whole: that is why each service has its own record. To obtain it, however, the provider must already have a certified management system: for QC1 the Regulation requires conformity with ISO 9001 and ISO/IEC 27001 certification with the cloud extensions 27017 and 27018 (alternatively, CSA STAR level 2 certification). AtWorkStudio holds all four ISO certifications, issued by an accredited certification body.
No rule requires a private company to choose ACN-qualified services. It is, however, a check carried out by a public body against written, publicly available requirements, not a self-declaration by the provider. For anyone who has to show they chose reliable suppliers, for example for the supply chain security required by NIS2 or in a customer audit, it is concrete evidence to keep on file.
Every qualified service has a public record on the Italian National Cybersecurity Agency’s portal, with a code (for example SA-7323), the qualification level, the provider’s name and the validity start and end dates. The pages of the three AtWorkStudio services link directly to their record: if a provider claims to be qualified but does not give the record code, it is worth asking for it.
Up to thirty-six months, after which it must be renewed. During the validity period the provider must keep meeting the requirements and keep the Agency informed about its qualified services. The validity dates are shown on each service’s public record.
No, and it says so on every record: publication in the catalogue, after the checks required by the Regulation, does not constitute an endorsement or promotion by the Agency. Qualification says a service meets the requirements, not that it is better than another. For the same reason AtWorkStudio does not use the Agency’s logo on its website.
Do you need a qualified service?
Whether you are a public body or a company that wants verified suppliers, we can show you the records, the requirements covered and how the service fits into your infrastructure.