ACN Qualified Cloud Infrastructure for Public Administration

Hosts public data and services on cloud environments compliant with national directives, ensuring maximum protection of the State's information assets.

Drive the public sector's digital transition from the ground up

Meeting the digital transformation goals of the Public Administration requires infrastructures that combine the certainty of the Italian regulatory framework with technological flexibility. CloudFire enables the Cloud-First strategy by simplifying migration processes for Local and Central Authorities and technological partners of the Public Administration with OpenStack as a Service.

Data Location Assurance and Data Sovereignty

Protecting institutional information excludes any compromise on data residency.Digital Sovereignty is the de facto standard for knowing who controls IT assets and who has access to them. CloudFire guarantees complete data permanence within national borders across its Italian regions.

Explore the impact of digital sovereignty →

Cloud Engineer at Work
Donna al lavoro in un ufficio moderno, seduta a una scrivania con doppio schermo, che utilizza un mouse mentre guarda i documenti sul monitor principale.

Native compliance and ACN requirements fulfillment

The cybersecurity criteria established by the National Cybersecurity Agency (ACN) define the quality of an entity's governance. Choosing an ACN-qualified provider is not just a bureaucratic formality, but a strategic positioning that guarantees citizens expertise, transparency, and experience in managing their data.

View all our qualifications and certifications →

Autonomy and Continuity Throughout Cloud Migration

The mandatory migration from on-premise data centers should not lead to operational paralysis. CloudFire eliminates the friction of cloud migration by providing an IaaS environment based on the open standard OpenStack. This eliminates vendor lock-in risk and to maintain the continuity of public services during the switch-off.

openstack server create \
  --image "Ubuntu 24.04" \
  --flavor m1.large \
  --network private \
  --key-name prod-key \
  --security-group web-rules \
  Production-Server

Status: ACTIVE | Time: 12.4s

Business Continuity and Enterprise-Class Architecture

Multi-region Architecture
Maximum resilience for critical services, thanks to geographical distribution and native Disaster Recovery policies.
Standard OpenStack
Total interoperability between public administrations and workload portability, in compliance with open-source software guidelines for the public sector.
Multilevel Security
Logical Layer 2 isolation, data encryption at rest and in transit, and constant SOC/NOC monitoring.

Resources

FAQ

Is CloudFire listed in the ACN catalog of qualified Cloud services? With which services?

Yes, CloudFire is an infrastructure service provider qualified by Italy's National Cybersecurity Agency (ACN) and is listed in the official catalog of cloud providers for the Public Administration (PA). Each physical infrastructure located in an Italian region, along with the OpenStack as a Service, VMware as a Service, and Veeam Cloud Platform services, fully meets the security, compliance, and resilience requirements for hosting ordinary and critical public data and services. This qualification is backed by the ISO/IEC 27001, ISO/IEC 27017 (cloud security), and ISO/IEC 27018 (protection of personal data in the cloud) security certifications.

How is data sovereignty ensured in compliance with GDPR?

Digital sovereignty and full GDPR compliance are guaranteed by the operational and permanent localization of data within Italian territory and by the application of Italian law to the company. CloudFire's infrastructure is deployed solely in data centers located in Italy, which rules out the application of non-EU regulations (such as the US CLOUD Act) that could allow foreign government access to citizens' data. Logical tenant isolation at the networking level (Layer 2) and the use of advanced encryption protocols ensure total and exclusive control of information assets by the public entity acting as data controller.

Do you support cloud migration under the PNRR funding calls?

Yes. CloudFire actively supports local and central government bodies in carrying out migration projects under PNRR Measure 1.2 ("Cloud Migration"). Because the infrastructure is based on the open OpenStack standard, public bodies can execute migration strategies with zero technological friction. CloudFire's engineering team works alongside PA engineers and partner System Integrators to plan the transition path, correctly configure compute flavors, and verify the security requirements needed for reporting and completing the funding call milestone.

Can you set up Disaster Recovery solutions across different Italian regions?

Yes. CloudFire provides a native Multi-Region architecture within Italy. This enables Public Administration (PA) bodies to implement structured Business Continuity and Disaster Recovery (DRaaS) plans. Engineers can configure asynchronous data replication and geographic failover policies across distant infrastructures, ensuring very low recovery times (RTO) and minimal data loss (RPO) if the primary site becomes unavailable, without hidden costs or punitive data transfer charges (egress fees).