Catastrophe insurance and the cloud and cybersecurity voucher: the self-declaration to attach

For the Cloud & Cybersecurity Voucher, the business declares in its application that it complies with the catastrophe insurance obligation and attaches a self-declaration (DSAN). This guide explains the requirement, the three boxes of the DSAN, the deadlines by business size, leased or rented assets and the check at disbursement stage.

October 08, 2026 7 min read

Catastrophe insurance and the cloud and cybersecurity voucher: the self-declaration to attach Made with AI
Contents
  1. The requirement in the decrees
  2. The self-declaration to attach to the application
  3. Deadlines by business size
  4. Premises and assets the business does not own
  5. The check at disbursement stage
  6. Before submitting the application
  7. References

To access the Cloud & Cybersecurity Voucher, a business must comply with the obligation to insure its business assets against natural disasters and catastrophic events. The requirement appears at four points of the measure:

  • it is an access condition set by the ministerial decree of 18 July 2025;
  • the application must contain the declaration that the obligation has been met, on pain of the application being inadmissible;
  • a self-declaration (DSAN) on the policy is attached to the application form, using a template MIMIT published on 8 October 2026;
  • compliance is checked again at disbursement stage.

This guide sets out what the official texts say. It is not insurance advice: for the cover of your own assets, your insurer or adviser remains the reference.

The requirement in the decrees

Article 4(2)(c) of the ministerial decree of 18 July 2025 requires businesses to comply with the insurance obligations covering damage directly caused by natural disasters and catastrophic events. It refers to article 1(101) of law no. 213 of 30 December 2023 and to decree-law no. 39 of 31 March 2025.

The recitals of the same decree summarise the statutory rule. The obligation to take out these contracts, for damage occurring in Italy, applies to businesses with their registered office in Italy, and to those with a registered office abroad and a permanent establishment in Italy, that are required to register in the Business Register. The DSAN also refers to the arrangements set by interministerial decree no. 18 of 30 January 2025 and by the decree of the Minister of Enterprises and Made in Italy of 18 June 2025.

On the procedural side, the directorial decree of 4 August 2026 lists a required content of the application: the declaration that the obligation to take out insurance contracts has been met. The contents of that list are required on pain of inadmissibility. In the template application form it is declaration (e).

Ministerial decree of 18 July 2025, recitals and article 4(2)(c); directorial decree of 4 August 2026, article 5(3)(i); template application form, declaration (e); catastrophe insurance DSAN, point 1.

The self-declaration to attach to the application

In its Allega (attachments) section the application form lists three items: the offers for the services and products requested, the DSAN Polizza catastrofale and other documents. MIMIT has published its template as a Word file.

The DSAN is made under articles 46 and 47 of Presidential Decree no. 445 of 28 December 2000, in awareness of the criminal liability for false declarations. It is signed by the legal representative, who gives their own details and those of the business: registered office, tax code or VAT number, Business Register entry. The template provides for a digital signature where available; otherwise a copy of a valid identity document must be attached.

Under point 1 the declarant ticks one of three boxes.

Obligation met

The business declares that it has taken out the insurance contract covering damage to business assets directly caused by natural disasters and catastrophic events occurring in Italy. It gives the policy details: number, issuing insurer and date.

Obligation not yet met, deadline not passed

The business declares that it has not yet met the obligation. The stated reason: on the date of the application, the deadline for its size category (large, medium, small or micro enterprise) has not yet passed. The box refers to decree-law 39/2025 and to article 1(2) of the ministerial decree of 18 June 2025.

Obligation not met, deadline passed

The business declares that it has not met the obligation although the deadline for its size category has already passed. This box should be read together with point 2 of the same DSAN. There the business declares that it is aware that access to the grant is allowed only if the insurance obligation has been met.

Under point 3 the business also declares that it is aware that Invitalia takes a failure to comply into account in the procedures it manages or assists, and that Invitalia is required to inform the Ministry promptly.

SMEs and self-employed workers

The official FAQ list the catastrophe insurance DSAN among the documents needed to complete the application with the note for SMEs. Among the access requirements they list compliance with the insurance obligation in the case of SMEs. For a self-employed worker who is not required to register in the Business Register, the ministerial decree requires a VAT number and the further requirements where compatible. Self-employed workers should check their own position on the obligation with their adviser.

Template application form, Allega section; catastrophe insurance DSAN, points 1, 2 and 3; ministerial decree of 18 July 2025, article 4(3); official MIMIT FAQ, section 2, no. 6 and no. 30.

Deadlines by business size

Point 2 of the DSAN gives the dates from which the condition applies to applications submitted:

  • 30 June 2025 for large enterprises;
  • 2 October 2025 for medium-sized enterprises;
  • 1 January 2026 for micro and small enterprises;
  • and in any case after publication of the ministerial decree of 18 June 2025, which took place on 25 July 2025.

Voucher applications are submitted from 12:00 on 10 November 2026 to 12:00 on 20 January 2027. All the dates listed in the DSAN fall before the application window opens. The date for large enterprises appears because the template lists it, but the measure is aimed at SMEs and self-employed workers.

Catastrophe insurance DSAN, point 2; ministerial decree of 18 July 2025, article 4(1); directorial decree of 4 August 2026, article 5(2)(b).

Premises and assets the business does not own

The official FAQ clarify two common cases. The obligation covers the assets used in the business that fall into the Civil Code categories of land, buildings, plant, machinery and equipment. It does not depend on ownership: assets used under lease, leasing, free loan or any other title must also be insured.

The exception is assets already covered by equivalent insurance against the same risks, even if taken out by someone else, for example the owner of the building or the machinery. If the business operates in third-party premises already covered by a compliant catastrophe policy, the cover does not need to be duplicated on the same building. It remains to check whether the land, plant, machinery or equipment in use is covered: anything that is not requires cover of its own.

For questions about the policy itself, the voucher FAQ refer to a separate MIMIT set: Polizze catastrofali, risposte alle domande frequenti (in Italian).

Official MIMIT FAQ, section 2, no. 7, no. 8 and no. 9.

The check at disbursement stage

The declaration made in the application does not settle the requirement. Under point 4 of the DSAN the business declares that it is aware that compliance must also exist, and be checked, when the grant awarded is disbursed.

The directorial decree of 4 August 2026 says so explicitly. Before paying the grant the Ministry carries out checks, with the support of Invitalia and Infratel. They include verification that the obligation to take out insurance contracts has been met. If the checks are negative, the Ministry requests the necessary additional documents. Failing to send them, or sending unsuitable documents, results in a reduced payment or in partial or total revocation.

The cover must therefore also be in place at disbursement, not only on the application date. The stages after the award are described in the guide to reporting and disbursement.

Catastrophe insurance DSAN, point 4; directorial decree of 4 August 2026, article 7(5)(d) and (6).

Before submitting the application

A short check, to complete before the form is digitally signed:

  • the policy details (number, insurer, issue date), to be entered in the DSAN;
  • the assets covered, including those used under lease, leasing or free loan, and any policies taken out by the owner;
  • the DSAN completed and signed by the legal representative, digitally or with a copy of an identity document;
  • declaration (e) of the application form, consistent with the box ticked in the DSAN.

The other access requirements are described in the guide to beneficiaries and requirements; the procedure, from digital identity to PEC, in the guide to submitting the application. The requirements are also summarised on the voucher page.

References

  • Ministerial decree of 18 July 2025, recitals and article 4(1) and (2).
  • Directorial decree of 4 August 2026, article 5(2) and (3), and article 7(5) and (6).
  • Law no. 213 of 30 December 2023, article 1(101); decree-law no. 39 of 31 March 2025, converted by law no. 78 of 27 May 2025.
  • Template application form and catastrophe insurance self-declaration (MIMIT, 8 October 2026).
  • Official MIMIT FAQ, section 2, no. 6, 7, 8, 9 and 30.

This article is current as of October 2026 and does not replace the official texts.

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

Aegister services for the voucher

The identification codes of our services to enter in the offer and in the application, and how we prepare the offer in the format the measure requires.

Learn more
Share this post:

Related news

September 24, 2026

Cloud and cybersecurity voucher: who can apply, requirements and de minimis

Eligibility is set by article 4 of the ministerial decree of 18 July 2025 and must be met when the application is submitted. This guide sets out who …

September 09, 2026

MIMIT cloud and cybersecurity voucher: guide to the measure

The measure supports demand for cloud computing and cyber security services from SMEs and self-employed workers with a non-repayable grant of 50% of …

October 08, 2026

NIS 2 vs ISO 27001: what certification covers and the gaps

Your company holds or plans ISO/IEC 27001 and falls under NIS 2. What the certification already covers, the obligations D.Lgs. 138/2024 adds (registr…