Voucher Cloud & Cybersecurity: the window opens 10 November, the “starting point” stays scattered across six systems
8 min read
A typical scenario, not our own case. A mechanical design firm near Modena, eight employees, in the manufacturing sector, is weighing whether to apply for the public grant to replace its backup system and add a next-generation firewall. Admin has the invoices for the subscriptions running today, not how many seats are active on the accounting software; IT knows how many licences are in use, not whether the one already paid for includes a feature equivalent to what’s about to be bought. Neither can answer the form’s first question: an improvement compared to what, exactly?
Three decrees, and what the Gazette actually publishes
Italy’s Official Gazette, General Series No. 193 of 21 August 2026, publishes, on page 45, notice 26A04230 from the Ministry of Enterprises and Made in Italy: “By decree of the director-general for business incentives of 4 August 2026, the terms and operating procedures were set for the window for submitting applications for the benefits provided for by ministerial decree 18 July 2025.” The measure — “Voucher Cloud & Cybersecurity” on the Ministry’s own site — “is intended to support demand for cloud computing and cybersecurity services from small and medium-sized enterprises and self-employed professionals […], through a non-repayable grant for acquiring technological solutions new and additional to those already available and/or […] more advanced and secure than those in use.” Applications run “from 12:00 on 10 November 2026 until 12:00 on 20 January 2027.”
Behind it runs a longer chain. Gazette No. 286 of 10 December 2025 published the Minister’s decree of 18 July 2025, setting up the scheme with savings from the Development and Cohesion Fund 2014-2020, and the directorial decree of 21 November 2025, opening supplier registration “from 12:00 on 4 March 2026 until 12:00 on 23 April 2026.” Extended to 27 May, the final list — “not modifiable,” says the decree that closes it — arrived only on 29 July 2026: six days before the 4 August decree fixed the figures and requirements.
The legal basis for publication does not change along the chain: the 2025 notices cite Art. 8(3) of enabling law 160/2023; the 2026 one cites Art. 22(3) of Legislative Decree 184/2025, which restates the same rule — and reserves for the Gazette only “summary notices on the general measures adopted to govern and grant access to incentives.” Legal publicity itself sits on the Ministry’s website and on Incentivi.gov.it: which is exactly what we have just read, a notice, not the decree.
The 4 August decree allocates €150 million from the Development and Cohesion Fund 2014-2020 to the window — €71,065,813.34 reserved for the eight southern regions — with a non-repayable grant of 50% of eligible spend (minimum €4,000), up to €20,000. The window opens in two stages: drafting from 12:00 on 20 October 2026, submission — using the “application pre-drafting code” generated in the first stage — from 12:00 on 10 November to 12:00 on 20 January 2027, processed “in the chronological order in which applications are submitted.”
Where the data actually sits
The decree does not entrust the proof to a single office: the application — a “substitutive declaration of a notorial deed” — must contain, on pain of inadmissibility, six kinds of information, each living somewhere else. The first, and most important, is the starting point: a “declaration on the applicant’s actual starting point […], evidencing the new technological solutions acquired and/or the more advanced solutions chosen compared with those already in use” — sitting in the licence, seat and user inventory, if one exists and is current. The second is the connectivity contract, “with a minimum download speed of 30 Mbps”: that sits with the telecom provider. The third is the location of the local unit “where the spending plan chiefly takes effect”: it sits in the chamber-of-commerce register, and decides access to the southern reserve. The fourth is suppliers’ quotes, bearing “the identification codes assigned […] by the list”: suppliers must be on that “non-modifiable” list, reachable only by authenticating with SPID, CNS or CIE — not a page archivable as proof of what was available at that moment. The fifth is the “de minimis” ceiling, checked “through the National State Aid Register”: a public register that, alone, can block an application already under review. The sixth is what the application invokes without generating: the DURC compliance certificate checked automatically, the insurance obligation under Art. 1(101) of Law 213/2023, and the unique project code that “must appear on every supporting expenditure document” — on invoices third-party suppliers will issue in later months.
The same duty to document a before and an after, with the proof scattered across offices that do not talk to each other, recurs in the “starting point” required by the hyper-depreciation scheme for predictive maintenance, in the still-criterionless accreditation of managed security services, in the file the national cybersecurity agency demands at inspection and in the NIS2 documentary proof, and in the migration of critical data to qualified cloud.
The one piece of data no corporate system holds in full
The missing piece is not one of the six: it is their sum, dated to the same day. Art. 4(3) excludes from the grant spending on products “with performance similar to that of products and/or services already in use,” version upgrades “where they do not simultaneously deliver a substantial improvement,” and “extending a licence already held” or increasing seats and users. To declare — under notorial-deed liability — that none of these three is true takes, together, the licence inventory, the seat and user count as of the application date, and the actual features of the solution in use: information in different places, which no SME keeps aligned unless someone has already asked it to.
There is also a sequencing problem. Review follows chronological order, and drafting — with its duty to declare the starting point — opens on 20 October, three weeks before submission, when only speed is at stake. The starting point should therefore be fixed earlier, with supporting documents — our own reading of Articles 5 and 6, not a deadline in the decree — but whoever chose a supplier did so without yet knowing the rules by which that choice would be judged.
If, a year from now, the Ministry asked you, “on a sample basis,” to prove that the firewall you bought did not have performance similar to what you already had, how many of these six places would you have to enter — and who, on the day of the application, would actually have known the answer?
See the service · Talk to an engineer
Where we stop
The application invokes the insurance obligation under Art. 1(101) of Law 213/2023: we have not verified its content, and do not describe it. We do not know whether the supplier list will reopen: the 29 July decree declares it closed without ruling out a future round. The link between chronological order and the starting-point timing is our own inference, not a deadline set by the decree. We have not tracked concrete cases of funds running out early. The opening scenario is a typical model, stated as such.
The two axes, applied
Complying. The starting-point declaration the decree demands as a notorial deed becomes, in our system, a control that runs on the client’s documents and systems — licences, seats, supplier contracts, configurations, DURC, the de minimis ceiling — with an alert when what was declared no longer matches the underlying records. An exportable, dated file, ready for a sample check or for the payment request.
Deciding. The same system brings purchasing, IT, admin and local units together into one operating model, on which AI agents execute decisions with a human operator in command: not just answering a check, but knowing in advance whether a purchase risks being judged to have “similar performance” to what’s already in use. For organisations with multiple sites, supplier networks and public administration, always in two delivery modes: on-premises, on autonomous machines needing no deep integration into the client’s network, or dedicated cloud, with a dedicated VPN and a data centre in Italy — always with shared management.
From the first session, at no cost, comes the dated map of which of the six pieces of the starting point are already in place, which system holds them and who updates them — blank boxes included. It stays yours even if we do not go on together. Talk to one of our engineers.
Sources
- Official Gazette — Notice 26A04230 (General Series No. 193 of 21 August 2026)
- Official Gazette — Notice 25A06572 (General Series No. 286 of 10 December 2025)
- Official Gazette — Notice 25A06573 (General Series No. 286 of 10 December 2025)
- MIMIT — Support for demand for cloud computing and cyber security services (Voucher Cloud & Cybersecurity page)
- MIMIT — Directorial decree of 4 August 2026, Voucher Cloud & Cybersecurity
- MIMIT — Directorial decree of 29 July 2026, definition of the supplier list
- Normattiva — Legislative Decree of 27 November 2025, No. 184, Art. 22