The cloud and cybersecurity voucher and NIS 2 technical measures

Part of the technical measures common to NIS 2 alignment programmes falls within the eligible product and service types: perimeter protection, monitoring, vulnerability management, backup and encryption. The voucher funds purchases and certifies no compliance. This article sets out the correspondences, the exclusions and the sequencing constraint between expenditure and submission.

September 24, 2026 6 min read

Two people in front of a wall planner pointing at a deadline Made with AI
Contents
  1. What the voucher funds and what it does not certify
  2. Who can apply
  3. Where the two overlap
  4. Where they do not overlap
  5. The declaration on the starting position
  6. A sequencing constraint to consider
  7. References

Organisations aligning with the basic measures set by ACN for NIS 2 entities may find that part of the technical work falls within the types of products and services funded by the Voucher Cloud & Cybersecurity. The two are not coordinated with each other. The voucher's dates are fixed: applications can be compiled from 12:00 on 20 October 2026 and submitted from 12:00 on 10 November 2026 to 12:00 on 20 January 2027. Each organisation's NIS 2 deadlines, by contrast, depend on its own situation. This article sets out where the two overlap and where they do not.

Directorial decree of 4 August 2026, article 5(1) and (2).

What the voucher funds and what it does not certify

The measure supports the acquisition of technology solutions that are new and additional to those already available, or more advanced and secure than those in use. It funds purchases: it certifies no regulatory compliance and does not replace an alignment programme, which includes risk analysis, policies, procedures and governance.

The grant is non-repayable, equal to 50% of eligible expenses, up to EUR 20,000, on a spending plan of at least EUR 4,000.

Directorial decree of 4 August 2026, article 4(1) and (6).

Who can apply

The grant is open to SMEs and self-employed workers who, when they submit the application, hold a connectivity contract with a minimum download speed of 30 Mbps. A large enterprise therefore cannot access the measure, even if it falls within the scope of NIS 2. Each applicant may submit only one application.

Applications are assessed in chronological order of submission. If the funds run out before the closing date, the Ministry announces it and closes the window: applications left without funding are suspended pending any savings and, if no further funds become available, are deemed lapsed.

Ministerial decree of 18 July 2025, article 4(1) and article 7(5) and (7); directorial decree of 4 August 2026, article 5(6) and (7), and article 6(1).

Where the two overlap

Several technical measures common to alignment programmes correspond to eligible types:

Technical areaMacro-category and eligible types
Perimeter protection and segmentationMacro-category A: firewalls, NGFW, IDS/IPS devices. Macro-category C: cloud network and security
Detection, monitoring and log collectionMacro-category B: network monitoring software, SIEM systems
Vulnerability managementMacro-category B: vulnerability management software
Business continuity, backup and recoveryMacro-category C: storage and backup services
Data protectionMacro-category B: data encryption solutions
Endpoint protectionMacro-category B: antivirus and antimalware

None of these items falls in macro-category E, configuration, monitoring and ongoing support services, which are eligible up to 30% of the plan and only if connected to other products or services in the plan. The official FAQ clarify that the professional and ongoing services typical of a macro-category B cybersecurity software solution, for example a security monitoring service based on antimalware technology, may fall within macro-category B itself, outside the 30% limit, provided the solution is delivered as SaaS. Otherwise they are classified under macro-category E.

Generic hardware stays excluded: buying a server, even one equipped with virtualisation systems, is not an eligible cybersecurity hardware solution.

Directorial decree of 4 August 2026, article 4(2); official MIMIT FAQ, answers 36 and 37.

Where they do not overlap

  • The documentary and governance component (risk analysis, policies, procedures) is not eligible: the official FAQ admit as professional services only operational and technical activities tied to implementing and managing the solutions, and exclude pure consultancy, meaning theoretical assessments not followed by implementation (FAQ 20).
  • Training for beneficiaries is excluded from the professional services macro-category. Systems that deliver training are instead eligible among SaaS cloud services, with only the costs relating to training content excluded.
  • Solutions already in use are not fundable. Expenses for products and services performing equivalently to those already in use are not eligible, nor are version updates that do not simultaneously deliver a substantial improvement, nor the extension of licences already held or an increase in licensed seats.

This last point deserves attention when composing the plan. The decree does not mention renewals expressly, but a reading of the exclusion of products and services performing equivalently to those already in use suggests that simply renewing an existing contract for the same solution is not an eligible expense. Moving to a solution with substantially different characteristics may be, provided the offer documents the upgrade on the starting position.

Directorial decree of 4 August 2026, article 4(2) and (3); official MIMIT FAQ, answer 20.

The declaration on the starting position

The application requires a declaration on the actual starting position regarding adoption of cloud computing and cyber security services and on the expected improvement, evidencing the new solutions acquired or the more advanced ones chosen over those already in use. The attached offers must also contain their own description of the starting position and of the upgrade guaranteed by the products and services offered or, for a new product or service, state that it is not already available to the applicant.

Anyone who has already carried out a gap analysis as part of an alignment programme essentially holds the material needed for that section: the exercise consists of mapping each gap to its corresponding eligible type and requesting the offer with the relevant identification code. The gap analysis itself, as a theoretical assessment, is not an eligible expense.

Directorial decree of 4 August 2026, article 5(3) and (4).

A sequencing constraint to consider

Spending plans must begin after the application is submitted, and expenses incurred before that date are not eligible. A measure carried out before submission is therefore borne entirely by the organisation: which measures to bring forward depends on how urgent each one is.

After the award the deadlines are tight:

  • for the part carried out by direct purchase, expenses and the related payments must fall within 12 months of notification of the award;
  • the subscription, lasting no less than 24 months, must be signed after the application is submitted and no later than 30 days from notification of the award; within 60 days of that date, notification that it has been signed must be transmitted, on pain of forfeiting the grant.

The obligations that follow are covered in the guide on disbursement, variations and controls; the measure's requirements, types and dates in the complete voucher guide.

Directorial decree of 4 August 2026, article 4(4) and (5).

References

  • Ministerial decree of 18 July 2025, articles 4 and 7.
  • Directorial decree of 21 November 2025, article 5.
  • Directorial decree of 4 August 2026, articles 4, 5 and 6.
  • MIMIT, official answers to frequently asked questions (20, 36 and 37).
  • Legislative decree 138/2024, transposing the NIS 2 directive.

This article is current as of September 2026 and does not replace the official texts. The voucher neither constitutes nor replaces a regulatory obligation.

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 24, 2026

Cloud and cybersecurity voucher: composing the spending plan

The spending plan determines the grant, the completion deadlines and what will have to be reported. This guide explains the 30% limit on macro-catego…

February 04, 2026

NIS2 vulnerability management plan: practical guide for ID.RA-08 approval

The vulnerability management plan is mandatory under NIS2 Appendix C (ID.RA-08). This guide covers what an approvable plan must show, a practical str…

September 24, 2026

Cloud and cybersecurity voucher: disbursement, variations and controls

The grant is not paid in advance: it is disbursed against completion of the plan and its documentation. This guide covers the assessment deadline, th…