Italy's Cloud & Cybersecurity voucher 2026: up to 20,000 euro
Cloud & Cybersecurity voucher: up to 20,000 euro on the software you will use every day
Italy's Ministry of Enterprises has put 150 million euro behind SMEs buying cloud software and information security. It covers 50% of the spend, up to 20,000 euro, as a non-repayable grant. On a 40,000 euro plan, half of it is paid for you.
Applications can be drafted from 20 October and submitted from 10 November to 20 January 2027, in order of arrival and until the funds run out.
There is one condition you cannot fix later, and it is the one worth knowing first: the services must be bought from a supplier entered in a register held by the Ministry. Registration closed on 27 May 2026, and the decree that established the list declares it non-modifiable.
Advinser is on that list. If you are weighing up a project, this is the window.
What it covers, and the rule that decides everything
Five categories are eligible: cybersecurity hardware, cybersecurity software, cloud infrastructure and platform services, cloud SaaS services, and configuration and support services.
Within the SaaS category the decree names management software, ERP, CRM, accounting, HR, CMS and e-commerce. The Ministry has clarified something important, though: the categories are exhaustive, the examples inside them are not. A piece of software does not have to appear by name in that list, it has to fall inside one of the five categories.
And here is the rule that separates fundable projects from the rest: what counts is how the software is delivered, not what it does. In the cloud, as a service, it qualifies. The exact same software installed on your own servers qualifies nowhere, because the only category that admits on-premise software is cybersecurity.
Two practical consequences. Configuration and rollout services are capped at 30% of the plan, so at least 70% has to be the cloud service itself. And custom-built software is eligible too, provided it is delivered as SaaS.
Who can apply
SMEs and self-employed professionals anywhere in Italy. At the time of application you need a connectivity contract with at least 30 Mbps nominal download speed, active registration in the Business Register, full exercise of your rights, and insurance against natural disasters and catastrophic events, which is the requirement that surprises people most because it has nothing to do with digital and is a condition of access all the same.
One application per company, so the spending plan has to be thought through as a whole, not in pieces.
What you can put in it, working with us
Our products are all delivered in the cloud, as a service, which is the condition the measure requires. They are also the services we can supply you under the voucher.
- /.MES, if you manufacture. Knowing what is happening on the shop floor while it happens: progress, downtime, real times per job. It is the system that stops you reconstructing at month end what happened three weeks ago.
- /.QControl, if you run quality control. Control plans, results recorded as the check is made, non-conformities traced back to the supplier that caused them. It earns its keep with long supply chains and outsourced production.
- MainFlow, if you do service and maintenance. Jobs, scheduling, reports signed on site from the app, van stock, vehicle and certification expiry dates. With F-GAS handling that prepares the database filing for you.
- AiKITO, the AI assistant inside your platform. It answers the questions of the people using the software and prepares the operations, asking for confirmation before saving. It is what stops the questions that are not faults from reaching your support desk.
The voucher covers half of it. Rollout, configuration and user training fall under the services category, within the 30% cap.
Why the choice of supplier has already been made
Getting onto the register was not a matter of applying. You had to be approved by the National Cybersecurity Agency, or else prove specific certifications for each category: ISO 9001 and ISO/IEC 27001 in every case, plus ISO/IEC 27017 or CSA Star Level 2 for anyone offering cloud and SaaS services. Valid and already held at the date of application, with no provisional admissions.
The window opened on 4 March and was extended to 27 May. On 29 July the Ministry closed the register and declared it non-modifiable.
Which means a company that wants to use the voucher does not pick the supplier it prefers: it picks one from that register. And it means a lot of good suppliers are, this time round, out.
The reverse is also true, and it is why it pays to move now: the budget is 150 million, applications enter assessment in chronological order of submission, and entitlement holds only within what is left. Submitting on 10 November is not the same as submitting on 10 January.
What does not qualify
Worth knowing before you build a plan that would be rejected.
- Replacing a service with one equivalent to what you already use.
- Upgrading the version of something you already have, if the upgrade brings no substantial improvement, such as new automation or artificial intelligence functions.
- Extending an existing licence, or adding seats and users.
- Generic hardware: a server is not a cybersecurity device.
- Standalone training, and pure consultancy, meaning analysis that does not lead to an implementation.
What to do now
There are a few weeks to go, and the time is all needed for preparation, not for filling in the form.
First: decide what you actually need. The spending plan is submitted once, and has to sit between the 4,000 euro minimum and the 40,000 that earns the full grant. Think about the whole, not a single module.
Second: check the formal requirements. Connectivity, company status, and above all the catastrophe insurance policy, which is the one that risks blocking everything on the day.
Third: prepare the quotation with your supplier. The plan is built on the offer, and the offer comes from someone on the register.
Let's talk now, not in November. Write to us and we will look together at what you need, what can go into the spending plan, and how to reach 10 November with the quotation already in hand.
Frequently asked questions
How much is the Cloud and Cybersecurity voucher worth?
50% of eligible spend as a non-repayable grant, up to a maximum of 20,000 euro. The minimum project spend is 4,000 euro, so the full grant is reached with a 40,000 euro plan. It is granted under the de minimis regime.
Does management software or a MES qualify for the voucher?
It depends on how they are delivered, not on what they do. In the cloud, as a service, they fall into the SaaS category. Installed on company servers they are not eligible: the only category that admits on-premise software is cybersecurity.
Can I choose any supplier I want?
No. Services have to be bought from suppliers entered in the Ministry's register, established by decree on 29 July 2026 and declared non-modifiable. Registration closed on 27 May 2026.
When are applications submitted?
Drafting opens at 12:00 on 20 October 2026, submission at 12:00 on 10 November 2026, and the window closes at 12:00 on 20 January 2027. Applications enter assessment in chronological order, within the limits of the available funds.
Is the catastrophe insurance policy really required?
Yes, it is one of the access requirements the decree sets for beneficiaries, alongside registration in the Business Register and a connectivity contract of at least 30 Mbps nominal.
References: Ministerial Decree of 18 July 2025 and Directorial Decrees of 21 November 2025, 22 April 2026, 29 July 2026 and 4 August 2026, published on the website of the Italian Ministry of Enterprises and Made in Italy. What you read here describes the content of the measure: the application is made by the company, and the assessment of any specific case rests with the company and its own adviser.