The spending plan is what the application is about: it determines the grant, the completion deadlines and what will have to be reported. This guide describes how to compose it within the constraints set by article 4 of the directorial decree of 4 August 2026.
What the plan must provide for
Spending plans must provide for the purchase of technology solutions that are new and additional to those already available, or of more advanced and secure solutions than those in use. A plan that replicates existing capability is therefore not eligible: the application requires the starting position and the expected improvement to be declared, and the attached offers must evidence the upgrade delivered.
That implies an order of work: identify the gaps first, then the services that close them, and only then request the offers. A plan built from a supplier's catalogue is hard to justify against this requirement.
The plan must provide for eligible expenses of no less than EUR 4,000. The grant, non-repayable, is 50% of eligible expenses and may not exceed EUR 20,000.
The plan must start after the application is submitted: expenses must be incurred after that date, and the same applies to signing subscriptions.
Directorial decree of 4 August 2026, article 4(1), (5) and (6).
Composition: the 30% limit on macro-category E
Configuration, monitoring and ongoing support services, including professional services, are eligible up to a maximum of 30% of the total spending plan and must be connected to one or more of the other services identified in the plan, being understood as ancillary services. The official FAQ specifies that they must relate to one or more products or services of the other categories included in the list. The remaining share, at least 70%, covers macro-categories A, B, C and D.
The limit is calculated on the plan total, not on the remainder. Official FAQ no. 45 makes the point with an example: a supplier approved for category E may offer configuration and support alone, but the beneficiary must include in the plan, for at least 70% of its value, the product that service relates to, with its identification code.
| Spending plan | Grant | Maximum macro-category E | Minimum other categories |
|---|---|---|---|
| EUR 4,000 | EUR 2,000 | EUR 1,200 | EUR 2,800 |
| EUR 10,000 | EUR 5,000 | EUR 3,000 | EUR 7,000 |
| EUR 20,000 | EUR 10,000 | EUR 6,000 | EUR 14,000 |
| EUR 40,000 | EUR 20,000 | EUR 12,000 | EUR 28,000 |
Directorial decree of 21 November 2025, article 5; directorial decree of 4 August 2026, article 4(2)(e); official MIMIT FAQ nos. 38 and 45.
Identifying the macro-category
The macro-category depends on the type of solution and, for software, on the delivery mode: cybersecurity software falls in B whether installed or in the cloud; business applications, ERP and CRM are eligible only as SaaS (D); generic hardware is not eligible.
The macro-category determines whether the item falls under the 30% limit. The duration rule depends instead on the acquisition method: 12 months for direct purchase, at least 24 months for a subscription, for any product or service.
| Solution | Macro-category |
|---|---|
| Security appliances: firewalls, next-generation firewalls, routers/switches, IDS/IPS devices. Generic hardware, such as a server, is not among the eligible solutions | A, cybersecurity hardware |
| Cybersecurity software (antivirus and antimalware, network monitoring, data encryption, SIEM, vulnerability management), installed at the beneficiary's premises or delivered in the cloud | B, cybersecurity software |
| Infrastructure or platform services delivered from the supplier's cloud: virtual machines, storage and backup, network and security, databases | C, IaaS and PaaS cloud services |
| Applications delivered as a service: accounting, human resources management, ERP, CMS and e-commerce, CRM including collaboration and virtual switchboard services (UCC and PABX), systems for delivering training excluding the training content. This software is eligible only in this form | D, SaaS cloud services |
| Configuration, monitoring and ongoing support, including professional services, relating to products or services of the other categories included in the list | E, professional services |
A firewall illustrates this well: as an appliance it falls in macro-category A; delivered from the supplier's cloud it falls in C, which expressly covers network and security including VPN connectivity and DDoS services.
The professional and ongoing services typical of a macro-category B solution, such as a security monitoring service based on antimalware technology, may be treated as part of macro-category B, and therefore outside the 30% limit, provided the solution is delivered as SaaS. Alternatively they can always be classified under E.
Professional services under E are operational and technical services directly linked to implementing and running the solutions. Training courses and pure consultancy, meaning theoretical assessments not followed by implementation, are excluded.
Macro-categories A to D also have a residual Other type. It is preferable to use it only where no specific type applies, because during assessment the Ministry verifies the correspondence between the services approved on the list and the spending plan submitted.
Directorial decree of 4 August 2026, article 4(2) and (4), and article 6(1); official MIMIT FAQ nos. 18, 20, 36, 37, 38 and 39.
Acquisition methods and deadlines
The acquisition methods apply to any solution, product or service included in the list. A SaaS cloud service, for example, can also be acquired by direct purchase.
Direct purchase
This involves direct payment for the products or services, including advance invoices provided they come after the application is submitted. Expenses must be incurred within 12 months from the date of notification of the award, and the related payments must fall within the same term. Purchases may also relate to services that last over time, with any validity period.
Subscription
This involves periodic payment of fees, for a term of not less than 24 months. Eligible expenses correspond to the fees falling within that period; for longer subscriptions, the fees beyond it are not eligible.
The subscription must be signed after the application is submitted and in any case within 30 days of notification of the award; within 60 days of that date, notification that it has been signed must be transmitted, on pain of forfeiting the grant.
A constraint to consider when composing the plan
The two methods may be combined, but switching the acquisition method between direct purchase and subscription relative to the application is not permitted. The choice must therefore be made before submission and is not reversible.
Variations after the award
Early withdrawal from the subscription and a change of subscription supplier must be notified promptly through the online procedure. They interrupt the benefit from the date of withdrawal or change and forfeit the right to any residual grant connected with the subscription. A change of supplier resulting from corporate transactions involving the chosen supplier does not count as such a change. Failing to notify the withdrawal or the change of supplier leads to revocation of the grant.
Changes to the breakdown of expenses and, outside subscriptions, to the supplier named in the application are instead reported with the disbursement request, where the Ministry assesses them.
Ministerial decree of 18 July 2025, article 10 and article 12(1)(c); directorial decree of 4 August 2026, article 4(4) and (5), and article 8; official MIMIT FAQ no. 40.
Ineligible expenses
- Products and services performing equivalently to those already in use by the beneficiary.
- Version updates of a service or product already in use that do not simultaneously deliver a substantial improvement, for instance through new automation or artificial intelligence features.
- Extension of a licence already held, or an increase in the number of licensed seats or user accounts.
- Training services for beneficiaries. For systems that deliver training, eligible under macro-category D, only the costs relating to training content are excluded.
- Training or skills development services, even when delivered through cloud e-learning platforms: only platforms without training content are eligible.
- Pure consultancy, meaning theoretical assessments not followed by implementation.
- Generic hardware, such as a server, which is not a cybersecurity hardware solution.
Directorial decree of 4 August 2026, article 4(2) and (3); official MIMIT FAQ nos. 20, 25 and 36.
Two worked examples
The amounts below are illustrative and serve to show how the 30% limit is checked. Actual values depend on scope and must be agreed with the supplier.
EUR 20,000 plan
- Next-generation firewall, type A.2, direct purchase: EUR 6,000
- IDS/IPS devices, type A.4, direct purchase: EUR 3,000
- Cloud network and security, macro-category C, 24-month subscription: EUR 3,600
- Vulnerability management, macro-category B, 24-month subscription: EUR 2,400
- Configuration, monitoring and ongoing support, macro-category E: EUR 5,000
Total EUR 20,000; the macro-category E share is 25%, within the limit. Grant: EUR 10,000.
EUR 40,000 plan
- Next-generation firewall, type A.2, direct purchase: EUR 16,000
- Cloud network & security, type C.3, 24-month subscription: EUR 7,200
- SIEM, type B.4, 24-month subscription: EUR 3,000
- Vulnerability management, type B.5, 24-month subscription: EUR 2,000
- Configuration, monitoring and ongoing support, macro-category E: EUR 11,800
Total EUR 40,000; the macro-category E share is 29.5%, within the EUR 12,000 limit. Grant: EUR 20,000, the ceiling.
The margin is narrow. The grant paid out is determined on the basis of the expenses reported and accepted as eligible: if at reporting stage an item in the other macro-categories came in lower than planned, the macro-category E share of the reported expenses would exceed 30%.
What the offer must contain
Offers attached to the application must carry the identification codes assigned to the products and services by the official list, with the related cost items, and must describe the applicant's starting position and the upgrade delivered, or attest that the product or service is not already available to the applicant.
The identification code combines the supplier's identifier with the type, for example VCCFA2600009999-C1 for type C.1, virtual machines, and every supplier states it on its own offer. The same code must appear on the invoices submitted for disbursement, together with the CUP issued when the application is submitted. The full list of types is set out on the measure's page.
Directorial decree of 4 August 2026, article 5(2), (3) and (4), and article 7(4); official MIMIT FAQ no. 41.
From composition to reporting
The disbursement request may be submitted no earlier than 3 months after notification of the award. The request for the second and final instalment, or for the single instalment, must be submitted within 30 days of the final deadline for completing the spending programme. The grant is determined on the expenses reported and accepted as eligible.
Documents and checks are described in the guide to reporting and disbursement.
Directorial decree of 4 August 2026, article 7(2), (3) and (5).
References
- Ministerial decree of 18 July 2025, articles 5, 6, 10 and 12.
- Directorial decree of 21 November 2025, article 5.
- Directorial decree of 4 August 2026, articles 4, 5, 6, 7 and 8.
- MIMIT, official answers to frequently asked questions, nos. 18, 20, 25, 36, 37, 38, 39, 40, 41 and 45.
This article is current as of September 2026 and does not replace the official texts.