MIMIT cloud and cybersecurity voucher
A non-repayable grant for SMEs and self-employed workers buying cloud computing and cybersecurity services: requirements, deadlines and eligible categories.
Application deadlines and procedures
The procedure has two distinct phases: compiling the application and submitting it.
20 October 2026, 12:00
Compiling the application
Access to the procedure, entry of the data, generation of the form as a non-editable PDF, digital signature and issue of the application preparation code.
10 November 2026, 12:00
Submitting the application
Entry of the application preparation code and issue of the submission receipt, carrying the unique project code (CUP).
20 January 2027, 12:00
Window closure
Unless earlier notice is given that the available financial resources are exhausted.
Grants are awarded through an assessment procedure operated as a rolling window, in chronological order of submission. Compiling is not submitting: position depends on when the application is sent.
Full guide to submitting the applicationGrants available
50%
20,000
4,000
30%
Grants take the form of a non-repayable contribution, under the de minimis regulation, equal to 50% of eligible expenses and for an amount not exceeding EUR 20,000. Eligible expenses must not be below EUR 4,000. A spending plan of EUR 40,000 exhausts the ceiling.
The measure is endowed with EUR 150,000,000, of which EUR 71,065,813.34 is reserved for operations in Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardegna, Sicilia.
The 30% limit on professional services
Configuration, monitoring and ongoing support services are eligible up to a maximum of 30% of the total spending plan and must be connected to one or more of the plan's other services. The remaining share, at least 70%, therefore covers products and services in the other macro-categories.
| Spending plan | Grant | Maximum services (30%) | Minimum other categories (70%) |
|---|---|---|---|
| 4,000 € | 2,000 € | 1,200 € | 2,800 € |
| 10,000 € | 5,000 € | 3,000 € | 7,000 € |
| 20,000 € | 10,000 € | 6,000 € | 14,000 € |
| 40,000 € | 20,000 € | 12,000 € | 28,000 € |
Eligible products and services
Spending plans must provide for the acquisition of products and services supplied by the entities on the official list, divided into five macro-categories and 23 types.
- A1 Firewall
- A2 Next-generation firewall (NGFW)
- A3 Router/switch
- A4 Intrusion prevention devices (IDS/IPS)
- A9 Other
- B1 Antivirus and antimalware
- B2 Network monitoring software
- B3 Data encryption solutions
- B4 Security information and event management systems (SIEM)
- B5 Vulnerability management software
- B9 Other
- C1 Virtual machines
- C2 Storage and backup services
- C3 Network and security (including VPN connectivity and DDoS services)
- C4 Databases
- C9 Other
- D1 Accounting software
- D2 Human resources management solutions (HRM)
- D3 Productivity/workflow management systems (ERP), including business productivity solutions with integrated artificial intelligence features
- D4 Digital content management (CMS) and e-commerce software
- D5 Customer interaction management tools (CRM) including, among others, collaboration services and virtual switchboard (UCC and PABX)
- D9 Other
- E1 Professional configuration, monitoring and ongoing support services
Ineligible expenses
- Products and services performing equivalently to those already in use by the beneficiary.
- Version updates of a service or product already in use that do not simultaneously deliver a substantial improvement, for instance through new automation or artificial intelligence features.
- Extension of a licence already held, or an increase in the number of licensed seats or user accounts.
- Training services for beneficiaries; for systems that deliver training, only the costs relating to the training content are excluded.
Beneficiaries and eligibility requirements
Grants are available to SMEs and self-employed workers operating throughout national territory which, at the time the application is submitted, hold a contract for the supply of connectivity services with a minimum download speed of 30 Mbps. All SMEs are eligible regardless of legal and organisational form, as are all self-employed workers regardless of role and activity.
- Duly incorporated, entered in the Companies Register and active; self-employed workers not required to register must hold a VAT number and, where the profession requires it, be registered with the relevant professional body.
- In full and free exercise of their rights, not in voluntary liquidation nor subject to insolvency proceedings for liquidation purposes.
- Compliant with the obligation to insure against damage caused by natural disasters and catastrophic events (law no. 213 of 30 December 2023, article 1, paragraph 101, and decree-law no. 39 of 31 March 2025).
- Not among businesses that have failed to repay aid declared unlawful or incompatible by the European Commission.
- Not active in the sectors excluded by article 1 of the de minimis regulation.
- Not subject to disqualification sanctions or other sanctions barring contracts with the public administration, with no legal representative or director convicted by final judgment of offences that exclude from public procurement, and in no other condition that the law treats as barring access to public aid.
- A connectivity contract with a download speed of at least 30 Mbps, active at the moment of submission.
The application is rejected if the National State Aid Register shows that the de minimis ceiling has been exceeded.
Entities on the official list may also apply, provided the services requested are acquired from suppliers other than the applicant and included in the list.
Eligible spending plans and acquisition methods
Direct purchase: 12 months from the award
Expenses must be incurred within 12 months from the date of notification of the award; the related payments must also be made within the same term. Advance invoices are admitted, provided they come after the application is submitted.
Subscriptions: at least 24 months
Eligible expenses correspond to the fees falling within the 24-month period. For subscriptions running longer, the fees beyond that period are not eligible.
Professional services within 30%
Configuration, monitoring and ongoing support services are eligible up to a maximum of 30% of the total spending plan and must be connected to one or more of the plan's other services. Training services for beneficiaries are excluded.
Signature within 30 days, notification within 60
The subscription must be signed within 30 days of notification of the award and notification that it has been signed transmitted within 60 days, on pain of forfeiting the grant.
Expenses after the application is submitted
Spending plans must begin after the date the application is submitted. Switching the acquisition method between direct purchase and subscription, relative to what was stated in the application, is not permitted.
One application per applicant
Each applicant may submit only one application.
Frequently asked questions
Pre-compilation opens at 12:00 on 20 October 2026. Submission runs from 12:00 on 10 November 2026 to 12:00 on 20 January 2027, unless resources are exhausted earlier.
The non-repayable grant is 50% of eligible expenses and cannot exceed EUR 20,000. Eligible expenses must not be below EUR 4,000; a EUR 40,000 plan exhausts the ceiling (ministerial decree of 18 July 2025, articles 5 and 6).
Grants are awarded through an assessment procedure operated as a rolling window, in chronological order of submission. There is no comparative assessment between projects (ministerial decree of 18 July 2025, article 7).
Yes, up to a maximum of 30% of the total spending plan, and they must be connected to one or more of the plan's other services. Training services for beneficiaries are excluded (directorial decree of 4 August 2026, article 4).
Yes. Spending plans must cover products and services supplied by the entities on the list of approved suppliers published by the Ministry (directorial decree of 29 July 2026).
Not less than 24 months. If the term is longer, eligible expenses are limited to those attributable to the first 24 months of the subscription (ministerial decree of 18 July 2025, article 5).
From the date the grant award is notified. The related payments must also be made within the same period (directorial decree of 4 August 2026, article 4).
The subscription must be signed within 30 days of notification of the award, and notification that it has been signed must be transmitted within 60 days, on pain of forfeiting the grant (directorial decree of 4 August 2026, article 4).
No. Each applicant may submit only one application (ministerial decree of 18 July 2025, article 7; directorial decree of 4 August 2026, article 5).
SMEs and self-employed workers operating in Italy with a connectivity contract of at least 30 Mbps download, duly incorporated and active, not in voluntary liquidation nor subject to insolvency proceedings aimed at liquidation, compliant with the catastrophe insurance obligation and not excluded by sanctions or convictions (ministerial decree of 18 July 2025, article 4). The application is rejected if the National State Aid Register shows the de minimis ceiling has been exceeded (directorial decree of 4 August 2026, article 6, paragraph 4).
Grants are awarded under the de minimis regulation and may be combined with other State aid, including de minimis, within the limits set by the relevant European rules (ministerial decree of 18 July 2025, article 6).
The grant is paid on request in two instalments, or in a single instalment once the spending plan is completed. The first instalment can be requested after at least 50% of the approved plan has been spent, and no payment can be requested before 3 months from the notice of the grant decision. The request for the last or single instalment must be filed within 30 days of the deadline for completing the plan (directorial decree of 4 August 2026, article 7).
Insights on the measure
Practical guides on the cloud and cybersecurity voucher and the obligations it funds.
Made with AI
24 Sep 2026
The cloud and cybersecurity voucher and NIS 2 technical measures
Part of the technical measures common to NIS 2 alignment programmes falls within the eligible product and service types: perimeter protection, monitoring, vulnerability management, backup and encryption. The voucher funds purchases and certifies no compliance. This article sets out the correspondences, the exclusions and the sequencing constraint between expenditure and submission.
Made with AI
24 Sep 2026
Cloud and cybersecurity voucher: disbursement, variations and controls
The grant is not paid in advance: it is disbursed against completion of the plan and its documentation. This guide covers the assessment deadline, the obligations running from the award, how and when disbursement is requested, the effect of variations on the residual contribution, the controls and the grounds for revocation.
Made with AI
24 Sep 2026
Cloud and cybersecurity voucher: beneficiaries and requirements
Eligibility is set by article 4 of the ministerial decree of 18 July 2025 and must be met when the application is submitted. This guide lists each requirement, clarifies that social security compliance is not an access requirement but a disbursement-stage check, and flags which steps cannot be completed quickly.