The step Italian SMEs had been waiting for has arrived: with the directorial decree of 29 July 2026, MIMIT (the Italian Ministry of Enterprises and Made in Italy) defined the list of suppliers approved to provide the services and products eligible under the Cloud & Cybersecurity Voucher — the €150 million scheme that will cover 50% of cloud and cybersecurity expenditure, up to €20,000 per beneficiary. The list is the key to the whole mechanism: the voucher can only be spent with the suppliers on it. One piece is still missing — the application window — and the time left is exactly the time to prepare.
What has happened, and what is missing
| Milestone | When | Status |
|---|---|---|
| Scheme rules (ministerial decree) | 18 July 2025 | Done |
| Rules for forming the supplier list | 21 November 2025 | Done |
| Supplier registration (Invitalia platform) | 4 March – 27 May 2026 | Closed |
| Approved supplier list defined | 29 July 2026 | Done — the news |
| Application window opening | With a further decree | Pending |
| Grant payment | After the award | Max 2 instalments (50% + balance) |
The operational point: applications are not open yet, and anyone promising otherwise is selling smoke. But publishing the list was the last formal prerequisite — from the official incentive page: “the terms and procedures for submitting applications will be defined by a further directorial decree, following the formation of the list”. The list is formed. The window is the Ministry's next move.
How to consult the list (and how to read it)
The list is published on the Invitalia platform and can be consulted with digital identity access. For each supplier it shows the company name, certified email, tax code and — this is the part that matters — the individual service types it is approved for, each with an identification code made of the supplier code plus the service suffix (for example VCCFA2600000145-C2 for storage and backup). Those codes will go into the grant application.
The uncomfortable detail worth knowing: approval is per service type, not per supplier. A supplier may be listed only for hardware but not for cloud services, or the other way round. If the spending plan mixes firewalls, cloud backup and configuration — the most common scenario — every item must match a type the chosen supplier is approved for. Checking first avoids discovering at the window that half the plan is not eligible.
AtWorkStudio is listed, with every category
As for us: AtWorkStudio is an approved supplier with code VCCFA2600000145, for all five categories of the scheme — cybersecurity hardware (firewalls, NGFW, routers and switches, IDS/IPS), cybersecurity software (antivirus, monitoring, encryption, SIEM, vulnerability management), cloud IaaS and PaaS (virtual machines, storage and backup, network and security, databases), cloud SaaS (accounting, HRM, ERP with AI features, CMS and e-commerce, CRM and virtual PBX) and professional configuration and support services. 23 approved services in total: a complete spending plan can be built with a single supplier, codes included. The full list, item by item, is on our voucher page.
One necessary caveat, as always: the approval concerns the supplier — it does not guarantee the grant to the beneficiary, which will depend on the requirements, the available de minimis headroom and the order of submission once the window opens.
What to do now, before the window
- 1Check the requirements — SME or self-employed professional with a VAT number, at least 30 Mbps download connectivity and de minimis headroom available over the three-year period. These are the conditions the Ministry will check first.
- 2Spending plan — minimum €4,000, with solutions that are new or improved compared to those already in use (duplicates are not eligible) and professional services within 30% of the total. Direct purchase, a subscription of at least 24 months, or a combination.
- 3Supplier and quotes — choose a supplier approved for every item of the plan and have the quotes prepared with the correct identification codes. Chronological windows reward those who arrive with the application already complete.
Sources
- MIMIT — Directorial decree of 29 July 2026: definition of the list of suppliers approved to provide the eligible services and products
- MIMIT — Ministerial decree of 18 July 2025: scheme rules
- MIMIT — Directorial decree of 21 November 2025: rules for forming the list
- MIMIT — incentive page “Sostegno alla domanda di servizi di cloud computing e cyber security”, updated 30 July 2026
- Invitalia — List of approved suppliers, vcc-elencofornitori.npi.invitalia.it platform
Related
Frequently asked questions
Answers to the most common questions about the MIMIT approved supplier list.
With the directorial decree of 29 July 2026, MIMIT defined the list of suppliers approved to provide the services and products eligible under the Cloud & Cybersecurity Voucher. Only expenses incurred with these suppliers will be eligible for the grant: registration in the list gives the declared services the qualification required for eligibility. The list can be consulted on the Invitalia platform, accessing with the digital identity systems provided.
There is no date yet: the terms and procedures for applications by SMEs and self-employed professionals will be defined by a further directorial decree, now that the supplier list has been formed. The budget is €150 million and the grant covers 50% of eligible expenditure up to €20,000 per beneficiary, under the de minimis regime. The time before the window opens is the time to prepare the spending plan.
By consulting the list published on the Invitalia platform (vcc-elencofornitori.npi.invitalia.it), with digital identity access. For each supplier the list shows the company name, certified email, tax code and — item by item — the service types it is approved for, each with its own identification code (for example VCCFA2600000145-C2). Note: a supplier may be approved only for some types; every item of the spending plan must match a type the chosen supplier is approved for.
Yes, with supplier code VCCFA2600000145 and for all five categories of the scheme: cybersecurity hardware, cybersecurity software, cloud IaaS/PaaS, cloud SaaS and professional configuration and support services — 23 approved services in total. This means a complete spending plan (technologies plus professional services) can be built with a single approved supplier.
Three things: check the basic requirements (SME or self-employed professional with a VAT number and at least 30 Mbps download connectivity, plus available de minimis headroom); define the spending plan — minimum €4,000, with services that are new or improved compared to those in use and professional services within 30% of the total; choose an approved supplier and have the quotes prepared with the correct identification codes. Chronological windows reward those who arrive with the application already complete.