Grants and incentives

The spending plan is written before the application.
Not after.

·GrantsIncentivesMIMITCloudCybersecurity
Application drafting opens20 October, 12:00
Submission window10 Nov 2026 – 20 Jan 2027
Eligible expensesOnly after applying
Professional servicesMax 30% of the plan

The Cloud and Cybersecurity Voucher run by MIMIT (the Italian Ministry of Enterprises and Made in Italy) is usually described as “50% non-repayable, up to €20,000”. That is true, but it is the least important part. Read in full, the directorial decree of 4 August 2026 describes a mechanism quite unlike a rebate: the grant rewards a documented improvement over a declared starting point, and rejects anything that merely renews, extends or replicates what the business already has. Anyone arriving on 10 November with the idea “buy first, claim later” will get it wrong three times in a row: they will have bought before applying, attached a quote that is not enough, and asked for money for a plan that falls under one of the four exclusions. The SMEs that lose out on the voucher will lose out like this — not for lack of funds.

We have already covered the list of approved suppliers and the application dates. This is the practical guide: what to do, in which order, with which documents, and above all what not to do. Everything below comes from the text of the decrees and the Ministry’s official FAQ, with the article reference.

The operational timeline, from application to payment

There are two public dates, but seven deadlines that really matter. Almost all of them run from a moment the business does not control: the notification of the grant decision, which arrives after a 60-day assessment in chronological order.

WhenWhat happensReference
20 October 2026, 12:00Drafting opens: access with SPID, CNS or CIE digital identity, an active PEC certified email is mandatory, PDF form signed digitally, issue of the “application preparation code”DD 4/8/2026, art. 5 para. 2 lett. a
10 November 2026, 12:00Submission opens: the preparation code is entered, the platform issues the receipt and the CUP project code. From this instant expenses may be incurredart. 5 para. 1 and para. 2 lett. b; art. 4 para. 5
20 January 2027, 12:00The window closes, unless funds run out earlier: in that case applications without cover are suspended and then lapseart. 5 para. 1 and para. 7
Within 60 days of submissionAssessment by Invitalia in chronological order, then notification of the grant decisionart. 6 para. 1-3
Grant + 30 daysDeadline to sign any subscription; the signing must be communicated within 60 days, or the grant is forfeitedart. 4 para. 5
Grant + 3 monthsEarliest date on which payment can be requestedart. 7 para. 2
Grant + 12 monthsDeadline to incur and pay all direct-purchase expenses; the balance request must be filed within 30 days of this deadlineart. 4 para. 4 lett. a; art. 7 para. 3

The constraint that decides everything: you buy after applying

Article 4, paragraph 5 is the most expensive sentence in the decree for anyone who does not read it: spending plans “must be started after the date the application is submitted”. Expenses must be incurred after that date. There is no pro-rata reduction for those who have already begun — an earlier expense simply does not enter the plan. And the decree also closes the most common loophole: advance invoices are allowed, but only if issued after the application has been submitted (art. 4 para. 4 lett. a).

This reverses the usual sequence. You do not buy and then claim: you build the plan, collect the offers in the required format, submit the application, and only then sign the contract or place the order. For a business with a cloud migration or security refresh already ready to go, the practical consequence is hard but clear: if the project is worth the voucher, it has to wait until 10 November. If it cannot wait, the voucher is not the right instrument for that project.

What the application must contain, or it is inadmissible

The application is a sworn declaration and Article 5, paragraph 3 lists nine elements whose absence makes it inadmissible — not curable, rejected. Three of them surprise anyone who has only read the press releases:

  • Connectivity of at least 30 Mbps download — having it is not enough: an active contract is required at the time of application (art. 3 para. 1), and a copy of that contract must be attached to the payment request (art. 7 para. 4 lett. b). Infratel checks it on a sample basis.
  • Declaration on catastrophe-risk insurance — the obligation under Italian Law 213/2023 (art. 1 para. 101) is an access requirement (Ministerial Decree 18/7/2025, art. 4 para. 2 lett. c) and must be declared in the application (art. 5 para. 3 lett. i). A business not compliant on this point is out before its plan is even read.
  • The starting point and the expected improvement — the declaration must describe the actual current adoption of cloud and cybersecurity and the improvement the plan delivers, “with evidence of the new technological solutions acquired and/or the more advanced solutions chosen compared with those already in use” (art. 5 para. 3 lett. d). It is the heart of the application, and it is also what no quote contains.

The other elements: identity details and PEC address; the local unit where the plan mainly produces its effects (the plan may cover more than one, but a single one determines any access to the southern reserve); the services chosen with the identification codes from the list and the acquisition mode; the names of the suppliers, who must be on the list; the duration of the plan or of the subscription; the amount of eligible expenses and of the grant requested. The application must be written in Italian and may be drafted by a delegate (art. 5 para. 1). Each applicant may submit only one (art. 5 para. 6): there is no second chance to fix a weak plan.

Supplier offers are not quotes. Article 5, paragraph 4 requires every attached offer to itemise costs, carry the identification codes from the list, and describe the applicant’s starting point together with the upgrade guaranteed by the services offered — or, for a new product, state that it is not already available to the business. A supplier who sends a price list is handing over a document that does not satisfy the decree. It is worth asking for the right format explicitly, and asking before 20 October.

The four plans that are excluded

Article 4, paragraph 1 sets the positive criterion: solutions “new and additional to those available” or “more advanced and secure than those in use”. Paragraph 3 translates the criterion into four exclusions. They are worded to hit exactly the plans SMEs tend to write first.

  • 1Performance equivalent to what is already in use — the decree lists no cases: the criterion is functional. If the new product does what the old one does, changing brand is not enough.
  • 2Version upgrade without a substantial improvement — here the decree offers its only explicit example: a substantial improvement can be achieved “for instance through the introduction of new automation or artificial intelligence functions”. A plan upgrade is defensible if it brings functions that were not there before, not if it changes the number on the label.
  • 3Extension of a licence already held — renewing what is already in use, even for several years, is out.
  • 4Increase in the number of licensed seats or user accounts — more users of the same service is growth, not improvement. The decree excludes it.

The official FAQ add two boundaries worth knowing before writing the plan: a generic server, even with virtualisation and a server operating system, does not count as eligible cybersecurity hardware; and ERP and CRM are eligible only in the SaaS category — a management system installed in the customer’s own data centre is not eligible because the delivery mode is not cloud.

Direct purchase or subscription: a choice you cannot change

Article 4, paragraph 4 provides three acquisition modes — direct purchase, subscription, or a combination of the two — with different rules on timing and eligible expenses. Article 8, paragraph 4 adds the constraint that makes the choice matter: it is not permitted to switch from direct purchase to subscription or vice versa compared with what was stated in the application. You decide first, and you stay there.

Direct purchaseSubscription
What it isDirect payment for products or services, including advance invoices issued after the application; no recurring fees. Also allowed for durable services, with any validity periodPeriodic fees for a fixed-term service
DurationExpenses and payments within 12 months of notification of the grantNo less than 24 months
Eligible expensesThe amount paid within the 12 monthsOnly the fees for the first 24 months; later fees do not count even if the contract is longer
ObligationsInvoices bearing the CUP and the service identification codeSigning within 30 days of the grant, communication within 60 days or the grant is forfeited; copy of the contract at payment stage
Specific risksThe 12-month deadline applies to payments too, not only to ordersEarly termination or a change of supplier interrupt the grant and forfeit the remaining amount (art. 8 para. 2)

The official FAQ clarify a point that confuses many: a SaaS contract can be treated as a direct purchase, so it is not forced onto the 24-month track. It is a choice of convenience to be made with the numbers in hand, remembering that the two tracks have different deadlines, documents and risks.

The 30% cap on professional services, and what they are not

The list of eligible services has five categories: cybersecurity hardware, cybersecurity software, infrastructure and platform cloud services, SaaS services, and “configuration, monitoring and ongoing support services, including professional services”. On this last category Article 4, paragraph 2, letter e) sets two limits: it is eligible for at most 30% of the total spending plan, and it must be linked to one or more of the other services in the plan. In practice at least 70% of the plan must consist of products and services from the other four categories: a plan built around the work of whoever configures and manages, with little technology inside, does not hold.

The Ministry’s FAQ also clarify what that category does not contain: professional services “are distinct from mere consultancy: they are operational and technical services directly tied to implementing and managing the solutions. Training courses and pure consultancy remain excluded”. Staff training is excluded as a service in its own right too (art. 4 para. 2 lett. e). Whoever designs the plan must therefore carefully separate technical work — configuration, migration, monitoring, support — from advisory work, which has to stay outside the voucher perimeter.

How to build the spending plan: six steps

  • 1Check the requirements that exclude before the merits — a connectivity contract of at least 30 Mbps download; catastrophe insurance in order; an active business, not in liquidation, not in a sector excluded from de minimis (Ministerial Decree 18/7/2025, art. 4 para. 2). For self-employed professionals, a VAT number and any professional-register membership (art. 4 para. 3).
  • 2Photograph the starting point — an honest inventory of what is already in use in cloud and security: products, versions, licences, number of users. It is the basis of the declaration under art. 5 para. 3 lett. d, and also the document that lets you check in advance that the plan does not fall under the four exclusions.
  • 3Define the improvement, not the shopping list — for each item, the question to answer is: what does this solution do that we do not do today, or what does it do more securely? If the answer is “the same, but more users” or “the same, newer version”, the item comes out.
  • 4Choose listed suppliers and retrieve the codes — every service has an identification code per type that goes into the application and onto the invoice. The list is on the Invitalia platform; how to read the codes is explained on our voucher page.
  • 5Get offers in the art. 5 para. 4 format — itemised costs, codes, starting point and guaranteed upgrade. Decide here, item by item, between direct purchase and subscription, knowing it cannot be changed. Keep professional services under 30%.
  • 6Prepare the tools before 20 October — the digital identity (SPID, CNS or CIE) of whoever drafts the application, an active PEC address, a valid digital signature, the data for the National Register of State Aid. The Ministry will publish the application template “with adequate notice” (art. 5 para. 5): at the time of writing it is not yet available, and the section of the official FAQ devoted to beneficiaries is still empty.

Southern reserve, chronological order, two instalments, de minimis

Of the €150 million, €71,065,813.34 are reserved for plans carried out in Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardinia and Sicily (art. 2 para. 3). What counts is the location of the local unit where the plan mainly produces its effects, not the registered office. For everyone else in Italy roughly €79 million remain, allocated in chronological order of submission: at 12:00 on 10 November speed will count, and it will count only for those who already hold the preparation code generated from 20 October.

The grant is 50% of eligible expenses, with a minimum spend of €4,000 and a cap of €20,000 (art. 4 para. 6): the maximum is therefore reached with €40,000 of eligible expenses, beyond which the grant does not grow. It is granted under the de minimis regime (EU Regulation 2023/2831; Ministerial Decree 18/7/2025, art. 6 para. 2) and the Ministry rejects the application if the National Register of State Aid shows the ceiling has been exceeded (art. 6 para. 4): anyone who has received other de minimis aid in the last three years must check the remaining headroom with their adviser before applying.

Finally, cash flow. Payment is made in two instalments — the first after at least 50% of the plan has been spent, the second on completion — or in a single instalment, and in no case earlier than three months after the grant (art. 7). The beneficiary therefore advances 100% of the expense and recovers 50% later, after a 60-day documentary check that includes the DURC certificate. A €40,000 plan requires €40,000 of liquidity, not €20,000.

Sources

  • MIMIT — Directorial Decree of 4 August 2026, “Voucher Cloud & Cybersecurity: terms and procedures for submitting grant applications”, arts. 2-8
  • MIMIT — Ministerial Decree of 18 July 2025, “Rules for measures supporting demand for cloud computing and cyber security services”, arts. 4, 5, 6 and 12
  • MIMIT — Directorial Decree of 21 November 2025: procedure for forming the list of suppliers
  • MIMIT — Directorial Decree of 29 July 2026: definition of the list of approved suppliers
  • MIMIT — “Support for demand for cloud computing and cyber security services: frequently asked questions”, update of 2 September 2026 (FAQ 13, 18, 20, 36, 40, 45)
  • MIMIT — Press release “Cloud computing and cybersecurity voucher: terms and procedures for submitting applications set”, 7 August 2026
  • Invitalia — List of approved suppliers, platform vcc-elencofornitori.npi.invitalia.it

Frequently asked questions

Answers to the most common questions on preparing an application for the Cloud and Cybersecurity Voucher, with references to the articles of the decrees.

Does your spending plan survive the four exclusions?

We are an approved supplier in all five categories. We can help you photograph the starting point, build a plan that describes a real improvement and prepare the offers in the format the decree requires — before 20 October, not after.