Update, 14 August 2026
With the directorial decree of 4 August 2026, MIMIT has set the application dates: drafting opens at 12:00 on 20 October 2026 (with SPID/CNS/CIE, an active certified email and a digital signature) and submission runs from 12:00 on 10 November 2026 to 12:00 on 20 January 2027, in chronological order until funds run out. Around €71 million of the €150 million budget is reserved for the Mezzogiorno regions. Three constraints not to underestimate: the application must include a declaration of the actual cloud and security starting point and the expected improvement (a quote is not enough: suppliers’ offers must also describe the starting point and the guaranteed upgrade, with the service identification codes); the plan is rejected if it amounts to services similar to those already in use, a version change without substantial improvement, a licence extension or an increase in seats; and expenses are eligible only if incurred after the application has been submitted.
The step Italian SMEs had been waiting for has arrived: with the directorial decree of 29 July 2026, MIMIT (the Italian Ministry of Enterprises and Made in Italy) defined the list of suppliers approved to provide the services and products eligible under the Cloud & Cybersecurity Voucher — the €150 million scheme that will cover 50% of cloud and cybersecurity expenditure, up to €20,000 per beneficiary. The list is the key to the whole mechanism: the voucher can only be spent with the suppliers on it. One piece is still missing — the application window — arrived with the decree of 4 August: application drafting from 20 October, submission from 10 November 2026. The time left is exactly the time to prepare.
What has happened, and what is missing
| Milestone | When | Status |
|---|---|---|
| Scheme rules (ministerial decree) | 18 July 2025 | Done |
| Rules for forming the supplier list | 21 November 2025 | Done |
| Supplier registration (Invitalia platform) | 4 March – 27 May 2026 | Closed |
| Approved supplier list defined | 29 July 2026 | Done — the news |
| Application window opening | Drafting from 20 October, submission 10 November 2026 – 20 January 2027 | Dates set (decree of 4 August) |
| Grant payment | After the award | Max 2 instalments (50% + balance) |
The operational point: applications are not open yet, and anyone promising otherwise is selling smoke. But publishing the list was the last formal prerequisite — from the official incentive page: “the terms and procedures for submitting applications will be defined by a further directorial decree, following the formation of the list”. The list is formed — and the move has arrived: the decree of 4 August 2026 set the window dates.
How to consult the list (and how to read it)
The list is published on the Invitalia platform and can be consulted with digital identity access. For each supplier it shows the company name, certified email, tax code and — this is the part that matters — the individual service types it is approved for, each with an identification code made of the supplier code plus the service suffix (for example VCCFA2600000145-C2 for storage and backup). Those codes will go into the grant application.
The uncomfortable detail worth knowing: approval is per service type, not per supplier. A supplier may be listed only for hardware but not for cloud services, or the other way round. If the spending plan mixes firewalls, cloud backup and configuration — the most common scenario — every item must match a type the chosen supplier is approved for. Checking first avoids discovering at the window that half the plan is not eligible.
AtWorkStudio is listed, with every category
As for us: AtWorkStudio is an approved supplier with code VCCFA2600000145, for all five categories of the scheme — cybersecurity hardware (firewalls, NGFW, routers and switches, IDS/IPS), cybersecurity software (antivirus, monitoring, encryption, SIEM, vulnerability management), cloud IaaS and PaaS (virtual machines, storage and backup, network and security, databases), cloud SaaS (accounting, HRM, ERP with AI features, CMS and e-commerce, CRM and virtual PBX) and professional configuration and support services. 23 approved services in total: a complete spending plan can be built with a single supplier, codes included. The full list, item by item, is on our voucher page.
One necessary caveat, as always: the approval concerns the supplier — it does not guarantee the grant to the beneficiary, which will depend on the requirements, the available de minimis headroom and the order of submission once the window opens.
What to do now, before the window
- 1Check the requirements — SME or self-employed professional with a VAT number, at least 30 Mbps download connectivity and de minimis headroom available over the three-year period. These are the conditions the Ministry will check first.
- 2Spending plan — minimum €4,000, with solutions that are new or improved compared to those already in use (duplicates are not eligible) and professional services within 30% of the total. Direct purchase, a subscription of at least 24 months, or a combination.
- 3Supplier and quotes — choose a supplier approved for every item of the plan and have the quotes prepared with the correct identification codes. Chronological windows reward those who arrive with the application already complete.
Sources
- MIMIT — Directorial decree of 4 August 2026: terms and procedures for submitting applications
- MIMIT — Directorial decree of 29 July 2026: definition of the list of suppliers approved to provide the eligible services and products
- MIMIT — Ministerial decree of 18 July 2025: scheme rules
- MIMIT — Directorial decree of 21 November 2025: rules for forming the list
- MIMIT — incentive page “Sostegno alla domanda di servizi di cloud computing e cyber security”, updated 30 July 2026
- Invitalia — List of approved suppliers, vcc-elencofornitori.npi.invitalia.it platform
Related
Frequently asked questions
Answers to the most common questions about the MIMIT approved supplier list.
With the directorial decree of 29 July 2026, MIMIT defined the list of suppliers approved to provide the services and products eligible under the Cloud & Cybersecurity Voucher. Only expenses incurred with these suppliers will be eligible for the grant: registration in the list gives the declared services the qualification required for eligibility. The list can be consulted on the Invitalia platform, accessing with the digital identity systems provided.
The dates were set by the directorial decree of 4 August 2026: application drafting opens at 12:00 on 20 October 2026 on the MIMIT online procedure (with SPID/CNS/CIE, an active certified email and a digital signature), and submission runs from 12:00 on 10 November 2026 to 12:00 on 20 January 2027, in chronological order until funds run out. The budget is €150 million — around €71 million of which is reserved for the Mezzogiorno regions — and the grant covers 50% of eligible expenditure up to €20,000 per beneficiary, under the de minimis regime. Expenses are eligible only if incurred after the application has been submitted.
By consulting the list published on the Invitalia platform (vcc-elencofornitori.npi.invitalia.it), with digital identity access. For each supplier the list shows the company name, certified email, tax code and — item by item — the service types it is approved for, each with its own identification code (for example VCCFA2600000145-C2). Note: a supplier may be approved only for some types; every item of the spending plan must match a type the chosen supplier is approved for.
Yes, with supplier code VCCFA2600000145 and for all five categories of the scheme: cybersecurity hardware, cybersecurity software, cloud IaaS/PaaS, cloud SaaS and professional configuration and support services — 23 approved services in total. This means a complete spending plan (technologies plus professional services) can be built with a single approved supplier.
Three things: check the basic requirements (SME or self-employed professional with a VAT number and at least 30 Mbps download connectivity, plus available de minimis headroom); define the spending plan — minimum €4,000, with services that are new or improved compared to those in use and professional services within 30% of the total; choose an approved supplier and have the quotes prepared with the correct identification codes. Chronological windows reward those who arrive with the application already complete.