Grants and incentives

The beneficiary declares the starting point.
The supplier must have verified it.

·GrantsIncentivesMIMITCloudCybersecurity
FAQs updated2 and 15 September
Connectivity30 Mbps nominal
Products in the planAt least 70%
Application drafting opens20 October, 12:00

Less than a month before application drafting opens — 12:00 on 20 October 2026 — MIMIT (the Italian Ministry of Enterprises and Made in Italy) has updated the FAQs of the Cloud and Cybersecurity Voucher twice: on 2 September with answers 43 to 46 and on 15 September with answers 47 to 49. They are seven short clarifications, written for suppliers, that nevertheless change how businesses and professionals need to prepare their spending plan. One of them, FAQ 48, answers the question we have been asked most often in recent weeks: who declares the starting point, and who is accountable for it.

The overall picture of the measure — 150 million euro from the Development and Cohesion Fund, a 50% non-repayable grant of up to €20,000 on a minimum plan of €4,000, under the de minimis regime, with €71,065,813.34 reserved for Southern Italy — is covered in our practical guide to the spending plan and in the news about the supplier list. Here we focus on what changed in September and on how to turn it into documents before 20 October.

The 2 September FAQs: who can sell what

The four answers of 2 September resolve the most frequent doubts about the relationship between the list of approved suppliers — defined by the directorial decree of 29 July 2026 and no longer amendable — and what those suppliers can actually include in an offer. The common thread is one: what matters is the approved type, not the individual product.

FAQWhat it clarifiesWhat it means for applicants
43The MSP (Managed Service Provider) model is compatible with category D if the MSP partner that invoices is on the list, the service type is registered and the service is delivered as SaaSThe voucher supplier is whoever issues the invoice, not the platform manufacturer. The managed service must however be in the cloud: a service installed on premises does not fall into category D
44An approved supplier may provide products and services from vendors that are not listed, provided they are of the type it is approved forThere is no need to look for the brand in the list: you need a supplier approved for that type. The make of the firewall or of the backup software may not appear anywhere
45A supplier approved only for category E may offer configuration and support, but the plan must contain at least 70% in products from the other categories with a code in the listWhoever provides only professional services must work alongside a product supplier. A plan made of configuration alone cannot be funded
46The supplier’s offer is not limited to the products declared in the registration application: everything within the approved types is allowedThe supplier may propose a different solution from the one indicated in May, if of the same type. The identification code remains the one for the type

FAQs 41 and 42, published shortly before, complete the picture on identification codes: each supplier has one code per type, in the format VCCFA26000xxxxx-C1, and a single code covers several services of the same type. The code must appear in the offer, in the application and on the invoice. How to read the codes, and which ones are ours, is explained on our dedicated voucher page.

The 15 September FAQs: existing equipment, customised offers, 30 Mbps

The three answers of 15 September go into the substance of spending plans and, for the first time, into the content of offers. We report them in full because the literal text is what will count during the assessment of applications.

  • 47Configuring a VPN on equipment you already own is not eligible. In our translation of the Italian text: “The activity of configuring, activating and commissioning a VPN falls among the professional services of category E); however, these must be connected to one or more of the other services or products in categories A, B, C or D; the latter are eligible in spending plans only if new or an improvement over the services already in use. In the specific case, the network infrastructure and equipment, being already available to the beneficiary, are not included in the spending plan and therefore the related configuration activities are not eligible.” It refers to a VPN, but the principle is general: category E funds work on what the plan buys, not on what the company already owns. A new firewall with its configuration is in; reconfiguring the existing one is out.
  • 48No standard price list: the offer describes the starting point and the upgrade. “It is not necessary to follow a standard price list, since offers must be drawn up and customised according to the client’s specific needs: the supplier’s offer must contain a description of the applicant’s starting point in terms of adoption of cloud computing and cybersecurity services and the upgrade guaranteed through the services and/or products included in the offer itself. When submitting the application, the beneficiary must declare the actual starting point and the improvement expected through the acquisition of the services/products indicated. Finally, when entering the application, it will be possible to produce any other documentation deemed useful to prove the declared improvement.” This is the FAQ we analyse in the next section.
  • 49The 30 Mbps are nominal. The connectivity requirement “is to be understood as nominal speed: on the date the application is submitted, the beneficiary must hold a contract for the supply of connectivity services with a nominal or maximum download speed equal to or greater than 30 Mbps.” There is no need to measure actual bandwidth: you need an active contract with that value written on it, kept at hand because a copy must be attached to the disbursement request.

Who declares the starting point

FAQ 48 assigns two tasks to two different parties, and it pays to keep them apart. The supplier writes into the offer a description of the applicant’s starting point and of the upgrade guaranteed by the products and services offered. The beneficiary, when applying, declares the actual starting point and the expected improvement. According to FAQ 48 the declaration belongs to the beneficiary, and the beneficiary carries the responsibility for it. The liability aspects of that declaration should be confirmed with your own adviser — it is not a matter on which an IT supplier can give opinions.

The point that concerns us is technical, not legal. The supplier’s offer is the document the beneficiary’s declaration rests on: if the offer describes an inaccurate starting point — a backup that “does not exist” when it actually does, multi-factor authentication “absent” when it is active for half the users — the declaration built on top of it will be inaccurate too. That is why our position is simple: the supplier writes only what it has verified. You cannot describe a company’s starting point without having surveyed it, and you cannot survey it with a phone call.

Why the assessment comes before the offer. The decree of 4 August excludes plans with performance similar to what is already in use, version upgrades without substantial improvement, licence extensions and increases in the number of users. To know whether a plan falls into one of these exclusions you need to know precisely what the company uses today. The starting point is not a formality to fill in: it is the eligibility test of the plan.

The procedure we follow, and which we suggest asking of any supplier, has three steps:

  • 1Documented technical assessment, before the offer — inventory of endpoints and servers, backup (what is saved, where, how often and whether immutable copies exist), firewall and network segmentation, identity and authentication (MFA, privileged access, shared accounts), email (SPF, DKIM, DMARC, filtering). Every item with evidence: a screenshot, a configuration export, a report. The free starting point is the NIST CSF 2.0 assessment, which returns a structured picture by function; where a deeper check is needed, we move on to a vulnerability assessment.
  • 2A “starting point as surveyed” document, countersigned by the client — the result of the assessment becomes a short document, in non-technical language, that the client reads, corrects and signs. It is the shared basis: the supplier has verified, the beneficiary has confirmed. If the declaration is questioned during the review, this document and its evidence are the answer.
  • 3An offer that cites the assessment and attaches the evidence — the description of the starting point required by FAQ 48 refers to the document from step 2; the guaranteed upgrade is described item by item, in terms of what the plan does that is not done today, or does more securely. The evidence is the “documentation deemed useful to prove the declared improvement” that the beneficiary can upload when entering the application.

A concrete example. A company has a backup on a local NAS, with no off-site copy and no documented restore test. The surveyed starting point says exactly that, with the screenshot of the job and the date of the last restore attempted. The guaranteed upgrade is an immutable off-site copy with a quarterly restore test. It is neither a licence extension nor a newer version of the same product: it is a function that did not exist before. The plan survives the exclusion, and the beneficiary’s declaration can be verified line by line.

What to do before 20 October

The directorial decree of 4 August 2026, announced in the Italian Official Gazette (Serie Generale no. 193 of 21 August 2026), sets drafting from 12:00 on 20 October and submission from 12:00 on 10 November 2026 until 12:00 on 20 January 2027, one application per applicant. The application template and the link to the procedure have not yet been published: the Ministry will make them available “with adequate notice”. In the meantime, the list is this:

  • Access requirements — SPID, CIE or CNS digital identity of the person drafting the application; active PEC certified email; valid digital signature; connectivity contract with at least 30 Mbps nominal download; declaration on the catastrophe insurance policy required by Italian Law 213/2023.
  • Starting-point assessment — done, documented and countersigned before requesting offers. If the supplier proposes skipping it, it is proposing to write something into the offer that it has not verified.
  • Offers in the FAQ 48 format — starting point, guaranteed upgrade, cost items, identification codes per type. At least 70% of the plan in products and services from categories A-D; professional services within 30% and linked to products included in the plan, not to equipment already in use.
  • Acquisition method decided — direct purchase (expenses within 12 months of the grant) or subscription (minimum duration 24 months): the choice cannot be changed after the application. Disbursement cannot be requested earlier than 3 months after the grant, the balance within 30 days of the end of the plan, with checks within 60 days.
  • Suppliers on the list — the list defined on 29 July 2026 can be consulted with SPID, CIE or CNS and can no longer be amended. AtWorkStudio is an approved supplier with code VCCFA2600000145 for all categories.

A note on method

The MIMIT FAQs are addressed to suppliers, and the section dedicated to beneficiaries was still empty at the time of writing. This means that applicants depend to a large extent on the quality of their supplier’s work: on the precision with which it describes the starting point, on the choice of codes, on respecting the 70/30 split. Before signing anything, it is worth asking how the supplier verified what it writes. Our answer is the assessment, the evidence and the countersigned document. How working with our team looks is described on the Cloud and Cybersecurity Voucher page.

Sources

  • MIMIT, FAQ “Sostegno alla domanda di servizi di cloud computing e cyber security”, updates of 2 and 15 September 2026 (FAQs 41-49)
  • MIMIT, Directorial Decree of 4 August 2026, terms and procedures for submitting applications
  • Gazzetta Ufficiale, Serie Generale no. 193 of 21 August 2026, notice
  • MIMIT, Directorial Decree of 29 July 2026, definition of the list of suppliers

Frequently asked questions

Answers to the most common questions about the September 2026 updates to the MIMIT FAQs and the starting-point declaration.

Has your starting point already been verified?

We are an approved supplier in all five categories. Before writing an offer we survey the starting point with a documented assessment, share it with you and attach the evidence. The first step is free.