Cloud & Cybersecurity Voucher 2026: Grants of up to €20,000 for SMEs and Professionals in Italy
Updated 7 September 2026
Investing in digital transformation and cybersecurity is becoming more accessible for businesses operating in Italy thanks to the new Cloud & Cybersecurity Voucher.
The scheme, introduced by the Italian Ministry of Enterprises and Made in Italy — MIMIT, provides SMEs and self-employed professionals with a non-repayable grant equal to 50% of eligible expenditure, up to a maximum of €20,000 per beneficiary.
The programme has a total budget of €150 million. Of this amount, €71,065,813.34 is reserved for investment plans implemented in Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardinia and Sicily, making the voucher particularly relevant to businesses investing in Southern Italy.
What is the Cloud & Cybersecurity Voucher?
The Cloud & Cybersecurity Voucher is governed by the Ministerial Decree of 18 July 2025.
Its purpose is to help Italian SMEs and independent professionals adopt:
- new digital solutions that are not already available within the business;
- more advanced cloud services;
- stronger and more secure cybersecurity tools;
- technologies capable of delivering a measurable improvement to business processes.
Simply replacing an existing product with an equivalent one or purchasing additional licences will not normally qualify. The investment must provide a substantial and demonstrable technological improvement.
Who can apply?
Applications may be submitted by:
- micro, small and medium-sized enterprises that are properly incorporated, active and registered with the Italian Business Register;
- self-employed individuals with an active Italian VAT number;
- professionals registered with a professional body where such registration is legally required;
- professionals carrying out activities that are not organised through a regulated professional association.
The scheme is available throughout Italy.
Main eligibility requirements
At the time of application, the applicant must:
- have an active internet service contract providing a minimum download speed of 30 Mbps;
- be fully operational and able to exercise its legal rights;
- not be undergoing voluntary liquidation or insolvency proceedings with a liquidation purpose;
- not be subject to sanctions or restrictions preventing access to public funding;
- not operate in a sector excluded under the applicable EU de minimis rules;
- provide a certified email address, known in Italy as a PEC;
- comply, where applicable, with the obligation to hold insurance against damage caused by natural disasters and catastrophic events.
For companies, social security contribution compliance is verified through the Italian DURC certificate during the grant-payment stage.
The complete eligibility conditions are established by Article 4 of the Ministerial Decree of 18 July 2025.
What investments are eligible?
The voucher may finance one or more products or services from the following categories.
Cybersecurity hardware
Eligible solutions may include:
- firewalls;
- next-generation firewalls, or NGFWs;
- secure routers and switches;
- intrusion prevention systems, such as IPS devices.
Cybersecurity software
Potentially eligible software includes:
- antivirus and antimalware solutions;
- network-monitoring software;
- data-encryption tools;
- Security Information and Event Management systems, known as SIEM;
- vulnerability-management software.
IaaS and PaaS cloud services
Eligible cloud infrastructure and platform services may include:
- virtual machines;
- cloud databases;
- storage and backup services;
- virtual private networks and VPN services;
- DDoS protection;
- network and security services;
- cloud infrastructure and development platforms.
Software as a Service
Eligible SaaS solutions may include:
- accounting software;
- human resources management systems;
- Customer Relationship Management systems;
- Enterprise Resource Planning and workflow-management systems;
- content management systems and e-commerce platforms;
- collaboration tools and virtual telephone systems;
- business productivity solutions incorporating artificial intelligence;
- dashboards, including Power BI solutions, when provided through an eligible SaaS model.
According to the official MIMIT FAQs, CRM and ERP systems are eligible only when delivered as cloud-based SaaS services. On-premises versions are generally excluded unless the product qualifies as specific cybersecurity software.
Configuration, monitoring and technical support
The investment plan may also include technical and professional services directly connected to implementing and managing the funded solutions.
These services:
- may represent no more than 30% of the overall investment plan;
- must be linked to at least one other eligible product or service;
- cannot consist solely of theoretical consultancy;
- cannot include training courses.
The supplier must be included in the official register
Supplier selection is one of the most important aspects of the programme.
Products and services must be purchased from suppliers included in the official register established by MIMIT. The register was approved through the Directorial Decree of 29 July 2026.
Applicants can access the official register of authorised suppliers and eligible services using one of the accepted digital identification systems.
Before requesting a quotation, applicants should verify both that the supplier appears in the register and that the proposed product, service or service category is eligible.
How much funding is available?
The grant is equal to 50% of recognised eligible expenditure, subject to the following thresholds:
- minimum investment plan: €4,000;
- maximum grant: €20,000;
- expenditure required to obtain the maximum grant: at least €40,000 in fully eligible costs.
For example:
- an eligible investment of €4,000 may receive a €2,000 grant;
- an eligible investment of €20,000 may receive a €10,000 grant;
- an eligible investment of €40,000 may receive the maximum €20,000 grant;
- expenditure above €40,000 will not increase the grant beyond €20,000.
Funding is not automatic. The final amount depends on the eligible expenditure recognised by the authorities and the applicant’s compliance with all programme conditions.
Direct purchases and subscriptions
Eligible solutions may be acquired through:
- a direct purchase;
- a subscription;
- a combination of direct purchases and subscriptions.
Where the plan consists exclusively of direct purchases, it must be completed within 12 months of the grant-award notification.
Where a subscription is included, the subscription must run for at least 24 months. If the contract is longer, only expenditure relating to the first 24 months is eligible.
Which costs are excluded?
The following costs will not normally qualify:
- products or services offering substantially the same functionality as solutions already used by the applicant;
- routine software version upgrades that do not provide a significant improvement;
- extensions of existing licences;
- increases in the number of licensed users or workstations;
- training;
- theoretical consultancy that is not followed by implementation;
- products or services purchased from suppliers not admitted to the MIMIT register.
An upgrade may be eligible when it introduces a substantial technological improvement, such as new automation, artificial intelligence or advanced security capabilities.
How do the de minimis rules apply?
The voucher is granted under the European Union’s de minimis State aid regime, governed by EU Regulation 2023/2831.
As a general rule, the total amount of de minimis aid received by a single undertaking must not exceed €300,000 over a three-year period, subject to the applicable aggregation rules and sector-specific exclusions.
Before applying, businesses should review the public aid they have already received and determine their remaining de minimis capacity.
Application dates and deadlines
The Directorial Decree of 4 August 2026 established the following timetable:
- 20 October 2026 at 12:00: the application form becomes available for completion;
- 10 November 2026 at 12:00: the formal submission window opens;
- 20 January 2027 at 12:00: the submission window is scheduled to close.
The application window may close earlier if the available funding is exhausted.
Applications admitted to the assessment stage will be examined according to their chronological order of submission. Each applicant may submit only one application.
The official notice concerning the decree was published in the Italian Official Gazette, General Series No. 193 of 21 August 2026.
How to submit an application
Applications must be completed in Italian and submitted exclusively through the online procedure that will be published on the official MIMIT Cloud & Cybersecurity Voucher page.
Access is reserved for the applicant’s legal representative or an authorised delegate. Authentication requires one of the following:
- SPID, Italy’s Public Digital Identity System;
- a National Service Card, or CNS;
- an Italian Electronic Identity Card, or CIE.
The application must include information such as:
- the applicant’s details and PEC address;
- the business location where the investment will have its main effect;
- the applicant’s current cloud and cybersecurity arrangements;
- the expected technological improvement;
- the selected products and services;
- the chosen suppliers;
- the intended purchase or subscription method;
- the duration of the investment plan;
- the eligible expenditure and requested grant amount.
Applicants must also submit supplier quotations showing the relevant product or service identification codes and a detailed cost breakdown.
Italian companies registered with the Business Register should record their details in Invitalia’s Company Details and Delegations platform before submitting the application.
Why preparing early matters
The Cloud & Cybersecurity Voucher is not an automatic reimbursement. The application must be complete, internally consistent and linked to an investment that delivers a genuine improvement over the applicant’s existing technology.
Before the application window opens, businesses should:
- verify their eligibility;
- review the de minimis aid already received;
- document their current technology and security arrangements;
- define the expected improvements;
- select suppliers and services from the official MIMIT register;
- obtain quotations containing the correct identification codes;
- prepare their PEC, digital identity, delegations and supporting documents.
Waiting until the submission window opens to begin this work could reduce the chances of filing a complete and timely application.
How ItalyStartUp can help
ItalyStartUp can assist companies and self-employed professionals throughout the process, including:
- preliminary eligibility assessment;
- analysis of the proposed digital investment;
- review of potentially eligible expenditure;
- coordination with suppliers and professional advisers;
- collection of quotations and supporting documents;
- preparation and submission of the application;
- assistance during the assessment and reporting stages.
Grant approval always remains subject to the competent authority’s assessment, the availability of funding and compliance with all applicable requirements.
Timing matters. Contact ItalyStartUp to request a preliminary assessment and start preparing your investment plan before the application window opens.
Official sources and institutions involved
- Official programme page — MIMIT
- Ministerial Decree of 18 July 2025
- Directorial Decree of 4 August 2026
- Official MIMIT FAQs
- Official register of authorised suppliers and eligible services
- Invitalia
- Infratel Italia
- Italian Official Gazette No. 193 of 21 August 2026
- EU Regulation 2023/2831 on de minimis aid
The information in this article is provided for general guidance and does not replace a professional assessment of an individual case. Requirements, application documents and submission links should be checked on the official MIMIT page before filing.