---
title: Supplier offer for the cloud and cybersecurity voucher
description: "The MIMIT supplier offer template section by section: identification codes, starting position and expected improvement, cost breakdown and signature."
canonical: https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-supplier-offer/
url: /en/cms/insights/cloud-cybersecurity-voucher-supplier-offer/
lang: en
---

![](https://www.aegister.com/static/images/header-contact.webp)

# Cloud and cybersecurity voucher: the supplier's offer, section by section

The supplier's offer is a mandatory attachment to the application. This guide follows the template the Ministry published on 8 October 2026: the parties' details, products and services with their identification codes, starting position and expected improvement, cost breakdown and signature, with the consistency checks against the application.

October 08, 2026
12 min read

![Consultant and company owner reviewing a document together](https://www.aegister.com/static/images/cms/theme-advisor-client.webp)
Made with AI

24-month subscription vouchercloud and cybersecurity vouchercloud and cybersecurity voucher quoteMIMIT voucher offer template

Contents

1. [Supplier and recipient details](#supplier-and-recipient-details)
2. [A. Description of the products and services offered (Descrizione prodotti e servizi offerti)](#a-description-of-the-products-and-services-offered-descrizio)
3. [B. Starting position and expected improvement (Stato di partenza e miglioramento previsto)](#b-starting-position-and-expected-improvement-stato-di-parten)
4. [C. Cost breakdown (Quadro economico)](#c-cost-breakdown-quadro-economico)
5. [Signature and consistency with the application](#signature-and-consistency-with-the-application)
6. [The offer does not start the programme](#the-offer-does-not-start-the-programme)
7. [Aegister's offer](#aegisters-offer)
8. [References](#references)

Every application for the cloud and cybersecurity voucher must be submitted together with the offers of the chosen suppliers, showing the related cost items. This is required by the directorial decree of 4 August 2026, article 5(4)(a). On 8 October 2026 the Ministry of Enterprises and Made in Italy (MIMIT) published the [template of the supplier's offer](https://www.mimit.gov.it/images/stories/moduli/Fac-simile-Offerta-Fornitore-VCC.pdf), in Italian. The document states that the format does not have to be used, but the information it contains must be present.

This guide follows the template section by section and shows, for each one, the part of the application it corresponds to. It is written for the applicant who must attach the offers, and it is worth reading before asking any supplier for a quote.

The letters A, B and C here name the sections of the document: they are not the macro-categories of products and services, nor the acquisition methods, which also use letters.

## Supplier and recipient details

The offer is written on the supplier's letterhead and opens with the details of both parties.

| Supplier | Recipient |
| --- | --- |
| Company name | Company name |
| Registered office | Registered office |
| VAT number or tax code | VAT number or tax code |
| Supplier identifier (VCCFA260000xxxx) |  |
| Contacts | Contacts |

Then comes the subject line, with the offer number, its date and the services supplied. The supplier identifier is the one assigned by the list of approved suppliers, and it is the root of the identification codes of its own products and services. Resold products carry the accredited supplier's code instead, as section A explains.

The applicant needs the supplier's tax code as well: section D of the application form asks for it next to the supplier's name, for each product or service.

*Supplier offer template, header; application form template, section D.*

## A. Description of the products and services offered (Descrizione prodotti e servizi offerti)

Section A lists the products and services covered by the voucher request. For each item it gives:

- the **identification code** of the product or service, made of the supplier identifier followed by the type;
- the **supplier**;
- the **name** of the product or service;
- the **description**.

The identification codes must be the ones assigned in the supplier list, and they must also appear in the beneficiary's application. The official FAQ give VCCFA2600009999-C1 as an example: a supplier's code for type C.1, virtual machines.

### Several services under one code

A single identification code can be associated with several services, provided they all belong to the same type. A supplier can therefore offer the same beneficiary several services under one code.

### Products of other suppliers

The template covers the case where the supplier is not directly accredited for a product or service, for example when reselling. The first two columns then show the identification code of the product or service and the name of the **accredited supplier**, which the beneficiary also enters in the application. Invoicing always stays with the supplier that presents the offer.

The official FAQ confirm this arrangement. The offer clearly names the original supplier and the identification code of its service, and the same code goes into the spending plan in the application. Invoicing and delivery remain with the supplier the applicant took the offer from, for example a system integrator.

Products of vendors that are **not on the list** are a different case. A supplier may offer them, even on their own, as long as they fall within a type for which the supplier is accredited, and therefore under one of its identification codes. The offer is not limited to the products named when the supplier applied to the list, as long as they fall within the types admitted.

*Supplier offer template, section A and note (\*); official MIMIT FAQ, section 1, nos. 41, 44 and 46; section 2, no. 28.*

## B. Starting position and expected improvement (Stato di partenza e miglioramento previsto)

Section B describes the beneficiary's situation and what the offer changes. The template splits it into two parts.

- **Starting position**: the beneficiary's actual starting position in its adoption of cloud and cyber security services and products, in relation to the services and products covered by the voucher.
- **Expected improvement**: the upgrade guaranteed by the services included in the offer or, for a new product or service, the fact that the applicant does not already have it.

The same description appears in the application. Section B of the form asks for the starting position and the objectives of the programme: the new solutions acquired or the more advanced solutions chosen over those in use. With declaration d) the applicant confirms that it is true. The offer and the application must therefore describe the same situation.

### What is not eligible

The voucher only funds solutions that are new or significantly better than those in use. The following, among others, are not eligible:

- products or services with performance similar to those already in use;
- extensions of licences already held;
- more workstations, users or accounts on services already in use;
- version upgrades that bring no substantial improvement (for example new automation or artificial intelligence features);
- work that only maintains the existing infrastructure, without new functions or higher levels of security.

The official FAQ give an example: configuring a VPN on firewalls or routers the beneficiary already owns is not eligible, because that equipment is not part of the spending plan.

### Checks and supporting documents

At disbursement the Ministry, supported by Infratel, checks a sample of requests. It verifies that the plan includes solutions that are new and additional to those available to the beneficiary, or more advanced and secure than those in use. Section B should therefore name concrete systems and services, not intentions.

When the application is entered, any other document that supports the declared improvement can be submitted. Among the attachments, the form has an "Other" entry.

*Supplier offer template, section B; application form template, section B and declaration d); directorial decree of 4 August 2026, article 4(3), article 5(3) and (4), and article 7(5)(b); official MIMIT FAQ, section 1, nos. 47 and 48; section 2, nos. 22 and 23.*

## C. Cost breakdown (Quadro economico)

Section C shows the following columns for each item.

| Column | Content |
| --- | --- |
| Product/service identification code | The same as in section A |
| Supplier | The supplier accredited for that code, including when reselling |
| Category and type | The macro-category and type from the list |
| Acquisition method | A direct purchase, B subscription, C combination of the two |
| Product/service | The name, as in section A |
| Frequency of the fees | Subscriptions only |
| Amount of the periodic fee | Subscriptions only |
| Taxable amount, VAT and total | In euro, with the total of the offer |

The acquisition method is stated for each service. For a subscription or a combination, the offer also states the length of the subscription and the frequency and amount of the fees. A subscription must last at least 24 months.

### Subscriptions: the amount to enter

For a subscription, the "Imponibile" (taxable amount) entry in the spending plan is the sum of the fees for the first 24 months, as shown in the offer. This holds even if the subscription runs longer: fees beyond 24 months are not eligible expenses. The programme duration to enter is 24 months.

The measure does not set a payment frequency: fees can be monthly, quarterly or annual. Paying one or more years in advance is also allowed, provided the expenses are invoiced and paid within 24 months of signing and relate to the first 24 months.

### Direct purchase

With a direct purchase, expenses and payments must fall within 12 months of notification of the award decision. Advance invoices are allowed, provided they postdate the application. The method stated in the application cannot be changed later: switching from direct purchase to subscription, or the other way round, is not permitted.

### The limits of the plan

- The plan must include eligible expenses of at least EUR 4,000.
- The grant is 50% of eligible expenses, up to EUR 20,000.
- Macro-category E services (configuration, monitoring and ongoing support) are eligible up to 30% of the plan and must be connected to listed products or services of the other macro-categories.

If the plan includes offers from several suppliers, the limits apply to the plan as a whole, not to each offer. The [spending plan guide](https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-spending-plan/) works through two examples.

*Supplier offer template, section C; directorial decree of 4 August 2026, article 4(2), (4) and (6), and article 8(4); official MIMIT FAQ, section 1, nos. 38 and 45; section 2, nos. 33, 34 and 40.*

## Signature and consistency with the application

The offer closes with the date, the stamp and the signature of the supplier. The official FAQ confirm that attaching a quote signed by the supplier is mandatory. The document must make it possible to identify the supplier, the products and services with their identification codes and the cost items. It must also state the starting position and the guaranteed improvement or, for a new service, the fact that the applicant does not already have it.

Offers do not have to follow a standard price list: they are drawn up and tailored to the customer's needs.

In the [application form](https://www.mimit.gov.it/images/stories/moduli/Fac-simile-Format-Domanda-VCC.pdf), section D repeats the offer line by line: identification code, supplier, supplier's tax code, category, type, acquisition method (a, b or c), product or service *as stated in the supplier's offer*, taxable amount, VAT and total. Each applicant may submit only one application, so the items of every chosen supplier go into the same section D and their offers are attached to the same application.

### Checks before attaching the offer

- Every identification code in section A appears unchanged in section C and in section D of the application.
- For resold products, the code and name are those of the accredited supplier.
- The name of each product or service in the application is the one written in the offer.
- The acquisition method of each item is the same in the offer and in the application.
- For subscriptions, the taxable amount is the sum of the fees for the first 24 months.
- The starting position and expected improvement match section B of the application.
- The offer carries the supplier's date, stamp and signature.

Besides the offers, the form lists among the attachments the self-declaration on catastrophe insurance, described in its [own guide](https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-catastrophe-insurance/). The application is digitally signed by the applicant's legal representative or by the self-employed applicant, or by a special attorney registered on the platform. A person delegated only to fill it in cannot sign it. The steps are described in the [guide to submitting the application](https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-how-to-submit-the-application/).

*Supplier offer template; application form template, section D and attachments; directorial decree of 4 August 2026, article 5(6); official MIMIT FAQ, section 1, no. 48; section 2, nos. 32 and 35.*

## The offer does not start the programme

The offer necessarily comes before the application, since it is attached to it, but it must not turn into a commitment. With declaration i) of the form the applicant declares that it has not yet started the programme on the date of the application. Note 2 of the form treats the programme as started if any of these conditions is met:

- the business has entered into legally binding commitments, including signing a contract, issuing order confirmations or any other commitment that makes the programme irreversible;
- invoices have been issued for one or more items of the programme;
- payments have been made, even as deposits, for one or more items of the programme.

Only expenses incurred after the application is sent are eligible: services activated earlier cannot be funded. Orders, contracts, invoices and payments therefore come after submission.

After the award, a subscription must be signed within 30 days of notification of the decision. Within 60 days of the same date the notice that it has been signed must be sent, or the grant is forfeited. Invoices carry the CUP and the identification code of each product or service, the same code as in the offer.

*Application form template, declaration i), note 2 and commitments; directorial decree of 4 August 2026, article 4(4) and (5), and article 7(4)(a); official MIMIT FAQ, section 2, no. 25.*

## Aegister's offer

Aegister S.p.A. is an approved supplier, on the list under the identifier VCCFA2600000933 (directorial decree of 29 July 2026). These are the codes to enter in the offer and in the application for our services. All of them are delivered through [Cyber Console](https://www.aegister.com/en/solutions/cyber-console/), the platform from which we run them.

| Identification code | Service | Type |
| --- | --- | --- |
| VCCFA2600000933-A1 | [Threat Blocker](https://www.aegister.com/en/solutions/atb/) | A.1 Firewall |
| VCCFA2600000933-B2 | [Threat Intelligence](https://www.aegister.com/en/solutions/threat-intelligence/) | B.2 Network monitoring software |
| VCCFA2600000933-C3 | [VPN](https://www.aegister.com/en/solutions/vpn/) | C.3 Network and security (including VPN connectivity and DDoS services) |
| VCCFA2600000933-C3 | [Cloud Defender](https://www.aegister.com/en/solutions/cloud-defender/) | C.3 Network and security (including VPN connectivity and DDoS services) |
| VCCFA2600000933-D9 | [NIS 2 incident notification](https://www.aegister.com/en/solutions/compliance/nis2/incident-notification/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | [NIS 2 compliance](https://www.aegister.com/en/solutions/compliance/nis2/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | [NIS 2 documentation audit](https://www.aegister.com/en/solutions/compliance/nis2/documentation-audit/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | [ISO 27001 certification path](https://www.aegister.com/en/solutions/compliance/iso27001/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | [Integrated ISO 27001 + NIS 2 management](https://www.aegister.com/en/solutions/compliance/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | [Log analysis](https://www.aegister.com/en/solutions/log-analysis/) | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-D9 | Integrated assessment | D.9 Other (SaaS cloud services) |
| VCCFA2600000933-E1 | [Virtual CISO](https://www.aegister.com/en/solutions/virtual-ciso/) | E.1 Professional configuration, monitoring and ongoing support services |

The type labels reproduce the wording of the decree and indicate the category in the list, not the functions of the service.

Virtual CISO, under the code VCCFA2600000933-E1, falls within the 30% limit of the plan and must be connected to other products or services in the plan.

The work starts from the starting position, which is what section B contains. The [Cyber Check-up](https://www.aegister.com/en/assessment/?source=voucher) describes your situation and identifies the priorities. At the end you can book a meeting with us, in which we define the services and prepare the offer in the format the measure requires. If you already know what you need, you can ask us for an offer directly from the [contact page](https://www.aegister.com/en/contact/?source=voucher).

Our part is the offer: identification codes, starting position and expected improvement, cost breakdown and signature. The application remains with the applicant, which fills it in and submits it directly or through a delegate of its own. It is digitally signed by the legal representative or the self-employed applicant, or by a special attorney.

The table of services is also on the [page about the measure](https://www.aegister.com/en/voucher-cloud-cybersecurity/#servizi-aegister).

## References

- MIMIT, [supplier offer template](https://www.mimit.gov.it/images/stories/moduli/Fac-simile-Offerta-Fornitore-VCC.pdf) and [application form template](https://www.mimit.gov.it/images/stories/moduli/Fac-simile-Format-Domanda-VCC.pdf), published on 8 October 2026 (in Italian).
- Directorial decree of 29 July 2026, list of approved suppliers.
- Directorial decree of 4 August 2026, articles 4, 5, 7 and 8.
- Official MIMIT FAQ, section 1, nos. 38, 41, 44, 45, 46, 47 and 48; section 2, nos. 22, 23, 25, 28, 31, 32, 33, 34, 35 and 40.
- [The measure's page on the Ministry's website](https://www.mimit.gov.it/it/incentivi/sostegno-alla-domanda-di-servizi-di-cloud-computing-e-cyber-security) (in Italian).

This article is current as of October 2026 and does not replace the official texts.

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

### Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

[Start the Cyber Check-up](https://www.aegister.com/en/assessment/?source=voucher)

Our service

### Aegister services for the voucher

The identification codes of our services to enter in the offer and in the application, and how we prepare the offer in the format the measure requires.

[Learn more](https://www.aegister.com/en/voucher-cloud-cybersecurity/#servizi-aegister)

Share this post:

Self-assessment

### Cyber Check-up

Answer the questionnaire and get your company's cyber profile: security posture and recommendations to mitigate risks.

[Start the Cyber Check-up](https://www.aegister.com/en/assessment/?source=voucher)

### Aegister services for the voucher

The identification codes of our services to enter in the offer and in the application, and how we prepare the offer in the format the measure requires.

[Learn more](https://www.aegister.com/en/voucher-cloud-cybersecurity/#servizi-aegister)

## Related news

September 24, 2026

### [Cloud and cybersecurity voucher: composing the spending plan](https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-spending-plan/)

The spending plan determines the grant, the completion deadlines and what will have to be reported. This guide explains the 30% limit on macro-catego…

24-month subscription voucher
30% macro-category E limit
ineligible voucher expenses
+5

September 09, 2026

### [MIMIT cloud and cybersecurity voucher: guide to the measure](https://www.aegister.com/en/cms/insights/mimit-cloud-cybersecurity-voucher-2026-italian-smes/)

The measure supports demand for cloud computing and cyber security services from SMEs and self-employed workers with a non-repayable grant of 50% of …

approved supplier list MIMIT
cloud and cybersecurity voucher
cloud voucher requirements
+7

September 24, 2026

### [Cloud and cybersecurity voucher: how the application is submitted](https://www.aegister.com/en/cms/insights/cloud-cybersecurity-voucher-how-to-submit-the-application/)

The procedure has two phases three weeks apart. From 20 October 2026 the application is filled in, the PDF form generated, digitally signed and the p…

application compilation 20 October 2026
application preparation code
cloud and cybersecurity voucher
+7
