Scope: This dossier examines public cybersecurity support, regulatory implementation and operational resilience in Italy, the United Kingdom, France, Germany, Austria, Spain, the Netherlands, Finland and Ireland, using official records available by 8 October 2026 and a strategic horizon extending to 2031.
Executive Summary / BLUF
Italy has established a substantial cybersecurity investment incentive and transposed NIS2 relatively early, but neither achievement establishes that supported organisations will become operationally resilient.
Its €150 million Cloud & Cybersecurity voucher combines security expenditure with broader digital modernisation.
The central weakness is the potential separation between subsidised technology purchases and the skills, governance, maintenance and recovery capabilities needed to use them effectively.
European alternatives offer useful design lessons: Dutch support explicitly includes awareness training and backup testing; Ireland links assistance to prior assessment; the UK emphasises baseline assurance and supply-chain governance.
Those countries also have weaknesses, including limited grant coverage, discontinued funding rounds and unfinished legislative reform.
France’s technological-sovereignty ambitions coexist with documented NIS2 transposition delays; Germany’s implementation also arrived after the European deadline.
A 2026 European Court of Auditors assessment identifies shortcomings in information sharing, implementation and performance monitoring across EU mechanisms.
The decisive policy question is whether public expenditure produces sustained, independently demonstrable reductions in disruption and loss.
Italy’s cyber funding buys systems. Resilience depends on who runs them.
Italy’s €150 million cloud and cybersecurity voucher confronts a contradiction that European funding policy has not resolved: public money can accelerate technological adoption without financing the competence and continuity that make it protective. The MIMIT programme reduces acquisition costs, but excludes training and purely theoretical assessments without implementation, while requiring beneficiaries to finance expenditure before reimbursement. Those choices favour projects that can be purchased and documented over capabilities that must be maintained and tested. The fiscal question is whether the state buys additional resilience or subsidises a change of supplier. The industrial question is whether the expenditure strengthens European capability or deepens dependence on shared infrastructure. Italy’s answer will emerge after applications open on 10 November 2026, when procurement decisions become recurring operating commitments.
The grant ceiling conceals the longer obligation
Under the MIMIT voucher, support covers 50% of eligible expenditure up to €20,000, with a minimum project of €4,000. The maximum contribution is reached at €40,000; a €60,000 eligible project receives an effective subsidy of 33.33%. These are acquisition incentives, not a commitment to meet half of a firm’s continuing security costs. Beneficiaries still have to fund the operation of what they purchase, and the first payment request cannot be submitted before three months have elapsed from award communication.
The territorial reservation of €71,065,813.34 represents 47.38% of the programme envelope, protecting expenditure plans in eight southern regions against unrestricted national competition. It does not establish that those regions will absorb the resources or retain the resulting capability. Technical and administrative costs can consume up to 2.5% of the envelope. The appropriate fiscal comparison is consequently between public expenditure and verified additional capability, rather than between the announced budget and invoices submitted.
The gap between adoption and operational resources is visible in two different statistical populations. ISTAT records intermediate or advanced cloud purchases by 68.1% of Italian enterprises with at least ten employees in 2025. Eurostat places ICT specialists at 3.8% of Italian employment, against 5% across the EU and 7.8% in Finland. These figures do not measure a cybersecurity performance gap, but they expose the burden placed on procurement and supervision when adoption rests on limited internal technical capacity.
The same constraint survives in a developed cybersecurity market. The UK’s September 2026 skills report records basic technical gaps in 57% of businesses, up from 49%, alongside an estimated cybersecurity workforce of approximately 145,900. Europe cannot assume that a larger commercial supply of protective services removes the need for competent customers. Outsourcing changes who performs the work; it does not settle who understands the service, approves its configuration or recognises its failure.
A crowded supplier catalogue can conceal a common dependency
The CMA’s July 2025 cloud investigation shows why the MIMIT purchasing model needs visibility below the contracting vendor. In its 2024 UK and EEA capacity measure, Microsoft accounts for 40–50%, AWS for 20–30% and Google for 10–20%. These ranges describe data-centre capacity, not Italian revenue or the market for every digital service. Their significance is structural: several application vendors can depend on the same infrastructure, leaving customers with more contracts but fewer independent routes to continuity.
ENISA’s NIS Investments 2025 report identifies the corresponding problem among managed operators. In its surveyed ICT service-management category, 43% reported no cybersecurity testing in the preceding year, and 45% took more than three months to apply critical patches to critical systems. The category includes managed service and managed security service providers. Buying professional support can improve a small firm’s access to expertise, but the purchase also imports the operator’s maintenance practices and its dependencies.
The procurement consequence for the MIMIT programme is to distinguish delivery from acceptance. An invoice establishes expenditure; it does not establish that privileged access is controlled, that a backup restores the relevant business process or that a supplier can be replaced. Public support would produce stronger evidence of value if acceptance included proportionate operational tests and disclosed the underlying operator of a critical service. Otherwise, the programme risks rewarding a visible purchase while leaving its most consequential dependency outside the evaluation.
Europe is removing exit charges, not the engineering cost of exit
The Data Act prohibits switching charges within its scope from 12 January 2027. The regulation distinguishes those charges from ordinary service fees and early termination penalties, and it does not eliminate every cost of migration assistance or redesign. A legal right to move is therefore economically useful only where the customer has usable data, documentation and an alternative capable of reproducing the necessary function. Portability belongs in the purchasing decision, before a firm discovers the practical cost of leaving.
The UK’s competition process addresses a related constraint through Microsoft’s business software ecosystem. The CMA opened its strategic market status investigation on 14 May 2026, with a statutory decision deadline of 13 February 2027. That is an investigation, not a designation or a completed remedy. Its relevance to European procurement lies in whether licensing and interoperability conditions create workable alternatives; UK intervention does not automatically change an EU customer’s contract.
DORA’s first list of 19 critical ICT third-party providers, published in November 2025, recognises that systemic dependence extends beyond cloud infrastructure. Oversight can improve scrutiny of provider governance and risk management, but designation does not certify that a customer has no residual exposure. For Italy, the external constraint is consequently both commercial and supervisory: national purchase incentives operate inside service chains whose concentration and contractual conditions cannot be corrected by a voucher alone.
Cyber appropriations compete with the digital ambitions they must protect
The ECCC’s consolidated work programme adopted in July 2026 reduced its indicative 2025–2027 cybersecurity envelope from €390 million to €355 million, reallocating €35 million to AI Gigafactories. The reduction does not establish a fall in all European cyber spending. It demonstrates that an announced security allocation can be redirected toward another digital priority, even while organisations are expected to strengthen their protection. A beneficiary’s maintenance plan cannot safely depend on the assumption that the next funding round will preserve the previous allocation.
The ECCC call opened in September 2026 provides an estimated €96 million across deployment and capacity topics, with applications due by 14 January 2027. It offers continuing investment opportunities rather than a universal purchase entitlement. Its delivery problem resembles Italy’s at a different scale: shared tools and platforms must reach ordinary firms, remain usable and acquire an operating budget after the funded project. A completed development project is not evidence of sustained customer capability.
The Recovery and Resilience Facility adds a separate fiscal boundary. Its milestone completion deadline passed on 31 August 2026, final payment requests were due by 30 September, and Commission payments must conclude by 31 December. Those deadlines do not govern Italy’s separate voucher instrument. They do illustrate the wider European transition from temporary investment to continuing operation. The proposed 2028–2034 EU budget is not a settled cybersecurity appropriation on which firms or public bodies can book their future running costs.
National programmes leave different parts of the capability chain unpaid
France’s Diagnostic Cybersécurité finances a structured diagnosis and prioritised recommendations; Italy’s MIMIT voucher excludes a purely theoretical assessment without implementation. The French model addresses the risk of buying the wrong intervention, but recommendations still require finance. Austria’s KMU.DIGITAL normally connects supported consultation to implementation, while the Netherlands’ Mijn Cyberweerbare Zaak includes awareness training and risk assessment among eligible measures. These are alternatives for closing a capability gap, not evidence that any country has eliminated it.
Ireland’s completed NCC-IE Cyber Security Improvement Grant connected a prior Enterprise Ireland review to implementation and post-implementation retesting. Its closure leaves the importance of that sequence intact while exposing the financing question: a review does not correct the weakness it identifies. Germany’s publicly funded Transferstelle Cybersicherheit reduces the cost of initial guidance, but external commercial assistance can still incur charges and financial access varies geographically. Each model removes a particular barrier while leaving another to the beneficiary.
Italy’s choice should therefore be to connect the MIMIT acquisition subsidy to practical competence, proportionate acceptance and a credible maintenance commitment. This need not impose a major-project bureaucracy on every small purchase. Standard diagnostic schedules and sample-based verification can concentrate scrutiny where business functions are critical. The public objective is to establish that the intervention works and persists, rather than to maximise the documentation surrounding it.
The next two years will transfer the bill to operators and customers
Over the 12–24 months following October 2026, the MIMIT programme’s applications and awards will begin to expose whether its beneficiaries can execute and maintain their projects. The decisive results will be completion, withdrawal, continuing operation and successful restoration, with separate denominators for each. A high approval rate will mean little if liquidity constraints prevent implementation; a high spending rate will mean little if the resulting services lapse or cannot recover a critical process.
The Data Act’s January 2027 switching provisions and the CMA’s February 2027 decision point will make supplier choice more observable, but neither will supply the staff needed to operate an alternative. If Italy leaves competence and verification outside the funded intervention, small firms will pay through additional advisory and operating expenditure or through dependence they cannot effectively supervise. Public bodies will face the same choice through maintenance appropriations and the cost of interrupted services.
The final fiscal test for the MIMIT voucher is whether public support enables a business function to remain protected, recoverable and affordable after the initial contribution. Without that evidence, taxpayers finance acquisition while firms, their customers and users of public services retain the cost of failure. Over the next two years, reporting retained capability alongside expenditure will determine whether Italy can justify continuation of the instrument—or must redesign it before committing another funding cycle.
Navigational Index
Pillar I — Regulation, institutions and the changing threat
- Chapter 1: Cybersecurity as an economic-security obligation: NIS2, the Cyber Resilience Act and institutional responsibilities.
- Chapter 2: Artificial intelligence, legacy systems and the distinction between attack activity and economic damage.
Pillar II — Public investment and national policy comparisons
- Chapter 3: Italy: voucher design, territorial allocation, accessibility and implementation risks.
- Chapter 4: The United Kingdom, France and Germany: assurance, sovereignty and regulatory execution.
- Chapter 5: Austria, Spain, the Netherlands, Finland and Ireland: implementation timing and alternative support models.
Pillar III — Structural contradictions and policy choices
- Chapter 6: Skills, procurement, cloud concentration, industrial dependencies and supply-chain exposure.
- Chapter 7: The 2026–2031 outlook: funding continuity, enforcement and operational scenarios.
- Chapter 8: Policy options, measurable outcomes and final comparative assessment.
Master Abstract
Europe’s central problem is converting expenditure into capability
European cybersecurity policy increasingly combines legal obligations with financial assistance. However, these instruments address different objects: organisational security, the cybersecurity of products, the development of defensive technologies and collective incident response. Treating them as interchangeable obscures both the beneficiaries and the outcomes that governments should measure.
The strongest official evidence of this implementation problem comes from the European Court of Auditors’ Special Report 19/2026. The auditors concluded that EU actions only partially facilitate the detection of and response to significant and large-scale incidents. They identified limited information sharing, reporting weaknesses, substantial implementation delays and shortcomings in performance monitoring. In their sample of eleven projects, four were assessed as satisfactory, two showed weaknesses, three were unsatisfactory and two were too early to assess. This is a bounded audit sample, not an estimate of the failure rate of all European cybersecurity programmes. Nevertheless, it directly challenges any assumption that a funded project is equivalent to an operational capability. eca.europa.eu
The resulting analytical judgment is that European policy should be evaluated through the capabilities it creates and sustains: effective access controls, timely remediation, tested recovery, trained management, usable incident reporting and dependable suppliers. Expenditure, contracts and purchased licences are intermediate outputs.
Italy has a credible intervention, but its purpose is broader than cybersecurity
Italy’s MIMIT programme provides €150 million, including €71,065,813.34 reserved for expenditure plans in eight southern regions. Assistance covers up to 50% of eligible expenditure, capped at €20,000, with a minimum expenditure plan of €4,000. Applicants must have contracted connectivity of at least 30 Mbps download speed. Formal applications open on 10 November 2026, following pre-completion from 20 October, and close on 20 January 2027 unless resources are exhausted. These are programme allocations and prospective application dates, not evidence of money already disbursed. mimit.gov.it
The intervention is explicitly designed to support digital transition and more advanced cloud and cybersecurity solutions. Its breadth therefore reflects its stated purpose. The analytical problem arises when this mixed instrument is evaluated as if every euro financed a security control. A cloud accounting system, an enterprise-management application and a vulnerability-management service can all contribute to digital modernisation, but their security effects require different evidence. mimit.gov.it
Italy nevertheless deserves recognition for its legislative timing. Legislative Decree 138/2024, transposing NIS2, entered into force on 16 October 2024. This distinguishes Italy from countries whose transposition followed considerably later. Legal adoption, however, must be distinguished from the subsequent implementation, supervision and effectiveness of organisational controls. gazzettaufficiale.it
Funding channels must remain separate
Three verified envelopes illustrate why a single headline total can mislead.
Italy’s voucher supports qualifying purchases by Italian SMEs and self-employed professionals. SECURE’s second call provides €11.5 million across eligible European micro, small and medium-sized enterprises, with 50% co-financing and a maximum grant of €30,000. Its purpose is to support Cyber Resilience Act compliance, and applications are evaluated for relevance, impact and implementation quality. It is not a general cybersecurity reimbursement programme for every SME. secure4sme.eu
The ECCC’s separate €96 million call supports seven European deployment priorities, including AI-based security, SME solutions, preparedness, cable hubs, national coordination centres, legislative implementation and dual-use technologies. Applications run until 14 January 2027, and security eligibility restrictions apply. This envelope is European, competitive and topic-specific; it is not an additional Italian allocation. cybersecurity-centre.europa.eu
Calculated from the three published envelopes, their arithmetic sum is €257.5 million. That figure describes three distinct funding opportunities. It does not measure Italian cybersecurity expenditure, immediate business assistance, committed grants or realised investment.
AI increases urgency without establishing a universal attack multiplier
The UK government’s July 2026 parliamentary answer attributes to the NCSC an assessment that AI will make elements of cyber intrusion more effective and efficient. It also reports an assessment that, by 2028, attackers are highly likely to use AI capabilities against known vulnerabilities in legacy critical infrastructure. These are attributed threat assessments with specified horizons. They do not establish a uniform numerical increase across all countries, sectors or attack types. UK Parliament
The UK’s 2025/2026 Cyber Security Breaches Survey found that 43% of businesses identified a breach or attack in the preceding twelve months, unchanged from the previous survey. The survey explicitly covers incidents respondents detected and were willing to report. Consequently, stable reported prevalence does not establish stable severity, and lower reported prevalence among smaller firms may partly reflect weaker detection. GOV.UK
Spain’s INCIBE recorded 122,223 cybersecurity incidents in 2025, 26% more than in 2024, in data consolidated on 9 February 2026. This is an institutional incident count, whereas the UK figure is a survey percentage of organisations. The two cannot support a national security ranking. incibe.es
For public policy, the relevant implication is that faster hostile activity increases the value of timely patching, dependable identity controls and recovery preparation. AI-branded defensive procurement should still demonstrate additional benefit over those foundations.
National comparisons reveal different strengths and different failures
The following comparison concerns verified policy architecture. It does not assign a numerical ranking to national cybersecurity performance.
| Country | Verified policy position | Comparison with Italy | Principal contradiction or implementation problem |
|---|---|---|---|
| Italy | NIS2 transposition entered into force in October 2024; the MIMIT voucher supports cloud and cybersecurity investment. | Combines an established legal framework with substantial purchase assistance. | Investment eligibility does not itself demonstrate effective configuration, sustained operation or recovery capability. |
| United Kingdom | Cyber Essentials forms part of the government’s business-security approach. The Cyber Security and Resilience Bill remained a parliamentary bill in the retrieved record; its latest listed version was amended in Lords Grand Committee on 7 September 2026. | Places greater emphasis on a recognisable baseline and supply-chain assurance. | A baseline certificate cannot provide sufficient assurance for every supplier or critical service; proposed legislative expansion must remain distinct from enacted obligations. GOV.UK |
| France | The 2026–2030 strategy prioritises skills, resilience, threat disruption and reduced technological dependencies. France was included in the Commission’s July 2026 referral for failure to notify complete NIS2 transposition. | Provides an explicit national link between cybersecurity, industrial capacity and freedom of action. | Strategic ambition and institutional expertise have coexisted with legislative delay. The July referral is a dated finding, not proof of every subsequent development. SGDSN |
| Germany | The NIS2 implementation law entered into force on 6 December 2025 and extended requirements for businesses and federal administration. DIN SPEC 27076 provides a structured security-assessment approach for smaller businesses. | Offers a useful model for diagnosing needs before specifying investment. | A stronger statutory framework still requires affordable expertise and implementation capacity among newly covered organisations. Bundesregierung |
| Austria | NISG 2026 establishes a new federal cybersecurity authority; the examined substantive provision entered into force on 1 October 2026. | Makes national coordination and leadership responsibility explicit. | The immediate test is the new institution’s staffing, procedures and practical support, rather than its formal creation. bmi.gv.at |
| Spain | INCIBE provides incident-response capability. The government described the cybersecurity governance legislation as under preparation in March 2026; Spain was included in the July NIS2 referral. | Combines business-facing support with a large incident-response function. | Operational activity does not remove legislative implementation gaps. Historical digitalisation programmes must also be separated from currently open assistance. 17/03/2026 [Consejo de Ministros/Referencias] |
| Netherlands | The Cyberbeveiligingswet and critical-entity resilience law entered into force on 15 August 2026. The 2026 small-business subsidy includes awareness training and backup testing. | Offers a direct contrast to Italy’s exclusion of training from its voucher. | The subsidy’s €1 million envelope and €1,250 applicant cap support limited interventions; allocation also follows application order. Rijksoverheid.nl |
| Finland | NIS2 obligations began on 8 April 2025. Traficom describes separate supervisory responsibilities and CSIRT assistance, with safeguards governing voluntarily supplied information. | Provides an institutional lesson on maintaining trust in technical incident assistance. | Sector-specific supervision still requires coordination where an organisation operates across several sectors. Traficom |
| Ireland | Enterprise Ireland advertises an 80%-funded €3,000 security review. The separate NCC-IE improvement grant has finished; its official page reports €1,743,513.22 awarded to 50 SMEs in 2024/2025. | Demonstrates an assessment-before-remediation model and higher co-financing. | A useful programme design does not guarantee continuing availability. The improvement grant is closed and additional rounds will not open. Enterprise Ireland |
The Netherlands illustrates the importance of updating a legal comparison through successive records. Its inclusion in the Commission’s July referral cannot justify describing Dutch implementation as still absent after the government’s August commencement announcement.
Spain illustrates a different temporal problem. Red.es’ current Kit Digital chronology records that the five historical calls closed during 2024–2025. Continuing implementation, reporting and evaluation should not be confused with a newly open application window. kitdigital
Italy’s most consequential contradictions
Technology assistance without funded training. MIMIT’s FAQ excludes training, including training content delivered through cloud e-learning platforms. It also clarifies that supplier certifications concern the supplier and need not necessarily cover the subsidised product or service. These distinctions matter: catalogue admission is a funding-eligibility condition, not comprehensive assurance that a specific deployment is secure. Risposte alle domande frequenti (FAQ)
The training exclusion is a programme-level weakness, rather than proof that all Italian cybersecurity policy neglects skills. SECURE’s second-call documentation expressly includes CRA requirements training and technical cybersecurity training. The contradiction is therefore between complementary instruments: the broadly accessible purchasing incentive excludes an activity that the more specialised product-compliance programme recognises as necessary. Call2
Application speed versus security need. The August 2026 implementing decree requires applications to be examined in chronological order. It also states that disbursement cannot be requested before three months after notification of the award, and the first instalment requires at least 50% of the expenditure plan to have been incurred. These rules can favour applicants with administrative readiness and available cash over equally vulnerable organisations lacking those resources. That distributional effect is a design risk, not an observed outcome of a window that has yet to open. mimit.gov.it
Modernisation versus sustained protection. The underlying ministerial decree supports new or substantially improved solutions and excludes equivalent replacements and certain expansions of existing licences. Additionality protects public money from simply financing routine purchases. However, security also depends on maintaining controls as organisations grow. The policy trade-off is between demonstrating a new investment and sustaining an existing, effective protective capability. mimit.gov.it
Territorial cohesion versus risk targeting. Calculated from MIMIT’s published allocation, the southern reserve represents approximately 47.38% of the programme. A territorial reserve can support cohesion, but geography does not establish cyber exposure. Evaluation should therefore distinguish territorial distribution from security outcomes and examine whether vulnerable firms within each allocation can actually access assistance.
National sovereignty versus procurement assurance. A subsidised cloud migration can improve security where it replaces poorly maintained infrastructure. It can also create reliance on a provider’s identity systems, availability, support and exit arrangements. The appropriate policy response is to examine these dependencies explicitly. Hosting location, supplier certification, ownership and operational independence are different attributes.
Product compliance and organisational resilience operate on different clocks
The CRA’s manufacturer-reporting obligations have applied since 11 September 2026. Manufacturers must report actively exploited vulnerabilities and severe product-security incidents, with an initial warning within 24 hours and a fuller notification within 72 hours. Final-report deadlines differ according to the event. Shaping Europe’s digital future
Most CRA obligations apply from 11 December 2027. Article 13 also creates a lifecycle vulnerability-handling requirement: the support period must generally be at least five years, with an exception where the product’s expected use is shorter. Accordingly, a short grant-funded compliance project may help establish processes but cannot substitute for the manufacturer’s continuing responsibility. EUR-Lex
NIS2 principally addresses covered organisations’ risk management, reporting and supervision. The Commission describes a reporting sequence of 24-hour early warning, 72-hour notification and a subsequent final report. An organisation purchasing a CRA-compliant product does not thereby satisfy all its organisational responsibilities. Similarly, a company outside direct NIS2 coverage may face security requirements from customers whose supply chains are regulated. Shaping Europe’s digital future
This distinction is particularly consequential for SMEs: assistance depends on the programme’s eligibility rules, while legal and contractual responsibilities depend on the firm’s activities, products and relationships. The populations overlap only partly.
Key Evidence Table
All monetary values below are nominal euros. Funding envelopes, grant ceilings, awards and incident statistics are deliberately kept separate.
| Indicator | Value/status | Reference date | Definition/scope | Issuer | Exact source |
|---|---|---|---|---|---|
| Italian voucher allocation | €150 million; maximum €20,000 per beneficiary; up to 50% support | Application window November 2026–January 2027 | Mixed cloud and cybersecurity purchasing incentive | MIMIT | Sostegno alla domanda di servizi di cloud computing e cyber security. mimit.gov.it |
| SECURE second call | €11.5 million; maximum €30,000; 50% co-financing | 1 October–11 December 2026 | Competitive support for eligible European SMEs’ CRA compliance | SECURE consortium | Second SECURE Open Call. secure4sme.eu |
| ECCC deployment call | €96 million | 1 September 2026–14 January 2027 | Seven European cybersecurity deployment topics | ECCC | New ECCC call for proposals under the Digital Europe Programme is open for applications. cybersecurity-centre.europa.eu |
| Dutch small-business subsidy | €1 million; maximum €1,250; 50% support | 7 September–30 November 2026 | Specified controls, assessments and awareness training | Netherlands NCSC | Mijn Cyberweerbare Zaak. NCSC |
| Irish improvement-grant awards | €1,743,513.22 to 50 SMEs; programme finished | 2024/2025 awards | Reported awards under a closed remediation scheme | Ireland NCSC / NCC-IE | NCC-IE Cyber Security Improvement Grant. ncsc.gov.ie |
| UK identified breaches or attacks | 43% of businesses | 2025/2026 survey; preceding twelve months | Survey prevalence, subject to detection and reporting limitations | DSIT / Home Office | Cyber security breaches survey 2025/2026. GOV.UK |
| Spanish incident activity | 122,223 incidents; 26% annual increase | Calendar 2025; consolidated February 2026 | INCIBE institutional incident count | INCIBE | Balance de Ciberseguridad 2025. incibe.es |
The Italian and Dutch envelopes cannot establish relative national effort without reconciling programme scope, eligible populations, other support instruments and actual expenditure. The UK and Spanish threat statistics likewise measure different phenomena.
Competing Explanations or Pathways
The evidence supports three possible implementation pathways. They may coexist across sectors and regions; no numerical probabilities are assigned.
| Pathway | Mechanism | Evidence that would support it | Evidence that would weaken it |
|---|---|---|---|
| Sustained resilience improvement | Public support funds prioritised controls, competent implementation and continuing maintenance. | Retested controls remain effective after funding; recovery exercises meet business requirements; suppliers remediate vulnerabilities promptly. | Purchased tools remain unused, poorly configured or unsupported. |
| Compliance centred on documentation | Organisations optimise for applications, certificates and audit files while operational weaknesses persist. | Reported compliance rises without improvement in recovery or remediation; repeated incidents exploit unresolved weaknesses. | Independent technical testing demonstrates durable improvements. |
| Uneven adoption and dependency | Better-resourced applicants obtain assistance while vulnerable firms remain excluded or become reliant on services they cannot sustain. | High uptake among administratively mature firms, affordability problems after support ends, concentration among a few providers. | Vulnerable first-time adopters obtain support and sustain controls at manageable cost. |
The central judgment would strengthen if programmes publish verified operational outcomes. It would weaken if assistance principally produces transactions and compliance documentation without durable capability.
Principal Gaps and Watch Indicators
| Consequential question | Record or observation needed | Decision implication |
|---|---|---|
| Who receives Italy’s voucher? | Award and payment records by firm size, region, sector and prior security maturity | Determines whether support reaches vulnerable organisations or predominantly capable applicants. |
| Does implementation improve protection? | Before-and-after assessments, independent retesting and recovery exercises | Distinguishes purchased technology from functioning controls. |
| Can beneficiaries sustain services? | Renewal costs, staffing arrangements and control performance after subsidised periods | Tests whether improvements survive the funding cycle. |
| Does the supplier catalogue preserve competition? | Award concentration, comparable pricing and switching arrangements | Identifies dependence and potential distortion without assuming either has occurred. |
| Have France and Spain completed the outstanding legislative steps? | Promulgated national instruments and updated Commission notification records | Resolves the gap between the July referral and the cut-off date. |
| Can Austria’s new authority perform its responsibilities? | Staffing, operational procedures, reporting performance and supervisory activity | Tests institutional execution following October commencement. |
| Are European coordination mechanisms becoming operationally effective? | Follow-up to the ECA’s recommendations and project performance records | Measures progress beyond the creation of additional structures. |
| Does AI alter realised loss? | Consistently defined incident severity, disruption and loss series | Separates greater hostile activity from greater economic damage. |
A defensible programme evaluation should treat expenditure and application volume as delivery indicators. It should assess security outcomes separately, using controls and recovery requirements appropriate to the organisation’s actual risks.
Visualisation — The funding and compliance timing gap
The component below shows verified sequencing. It does not imply that a funding deadline is a payment date or that one programme finances every obligation.
Obligations precede some funding decisions
As of 8 October 2026. Orange: legal milestones. Blue: funding milestones. Events are ordered by date; vertical spacing is not a time scale.
11 September 2026 — Reporting applies
CRA manufacturer reporting obligations begin.
1 October 2026 — SECURE opens
Second call opens for eligible SME product-compliance projects.
10 November 2026 — Italian applications open
Formal submission begins for the MIMIT voucher.
14 January 2027 — ECCC call closes
European deployment proposals reach their submission deadline.
11 December 2027 — Main CRA obligations apply
Most product requirements become applicable.
Implication: organisations must meet applicable obligations independently of whether assistance is awarded.
Sources: European Commission: CRA reporting; SECURE: second call; MIMIT: voucher; ECCC: deployment call; CRA: Article 71.
Pillar I — Regulation, institutions and the changing threat
Chapter 1 — Cybersecurity as an economic-security obligation: NIS2, the Cyber Resilience Act and institutional responsibilities
Principal judgment. Europe’s cybersecurity framework increasingly makes the continuity of economic and public services a responsibility of management, manufacturers and supervisory authorities. Italy’s central challenge is to turn these responsibilities into demonstrable operational capability: functioning recovery arrangements, controlled supplier access, timely remediation and decisions that executives can take during disruption. Registration, documentation and procurement are necessary inputs; their economic value depends on whether services withstand an incident.
The comparative question is therefore broader than which country has adopted legislation first. It concerns whether national institutions connect supervision, technical assistance, product security and business continuity effectively. A central authority can reduce ambiguity but become overloaded. A distributed system can provide sector expertise but generate inconsistent expectations. Neither institutional design establishes effectiveness without evidence of implementation.
Evidence and legislative status checked against the official record available on 8 October 2026. Publication dates and underlying observation periods are distinguished below.
The regulatory division of labour
NIS2, the Cyber Resilience Act and DORA address different parts of the same dependency chain. Confusing their functions creates two problems: organisations may duplicate compliance work unnecessarily, or assume that another actor’s compliance discharges their own responsibility.
| Instrument | Main object of regulation | Principal responsibility | Economic-security function | What it does not establish |
|---|---|---|---|---|
| NIS2 | Security and continuity of covered organisations’ network and information systems | Essential and important entities, their management and national competent authorities | Reduce disruption of services and propagation through interconnected sectors | That every supplier is directly covered, or every compliant organisation can withstand every attack |
| Cyber Resilience Act — CRA | Hardware and software products with digital elements made available on the EU market | Manufacturers and other relevant economic operators | Improve security throughout the product lifecycle and reduce vulnerabilities entering supply chains | That installing a compliant product makes an organisation’s architecture, permissions or recovery arrangements secure |
| DORA | Digital operational resilience of the financial sector | Financial entities, financial supervisors and oversight authorities for designated critical ICT providers | Control ICT disruption, testing and third-party dependence in finance | That every ICT incident is malicious, or every provider receives direct European oversight |
| Cyber Solidarity Act | Collective detection, preparedness and response capacity | European and national institutions, with participating service providers | Mobilise shared capabilities when incidents exceed individual capacity | A standing entitlement for every business to receive unrestricted incident-response assistance |
| EU cyber crisis blueprint | Coordination during large-scale incidents and crises | Member states and relevant European networks and institutions | Connect technical, operational and political crisis management | A European command structure replacing national responsibility |
Sources: European Commission, NIS2 FAQs; European Commission, CRA legislative summary; ESMA, Digital Operational Resilience Act; Council, adoption of the cybersecurity package, 2 December 2024 and EU cyber crisis blueprint, 6 June 2025. Shaping Europe’s digital future
Analytical implication. A manufacturer, a managed service provider and its customer can all have relevant obligations, but those obligations attach to different activities. The manufacturer addresses product vulnerabilities. The provider manages its service and access arrangements. The customer must understand how failure of either affects its own essential functions.
This division becomes economically significant when contracts divide responsibility more narrowly than the service actually operates. A supplier may promise infrastructure availability while excluding application recovery; another may manage applications while excluding identity administration. The customer still needs an integrated recovery sequence.
Italy: management accountability must reach operational decisions
Article 23 of Italy’s Legislative Decree 138/2024 requires the administrative and management bodies of covered entities to approve how cybersecurity risk-management measures are implemented, oversee relevant obligations and undertake cybersecurity training. They must also receive periodic—or, where appropriate, timely—information about incidents and notifications.
This establishes a governance responsibility above the technical team. Its practical meaning is that executive decisions about investment, supplier dependence and tolerated disruption must be informed by cybersecurity risk.
Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 23 — administrative and management bodies, published 1 October 2024. gazzettaufficiale.it
The following table translates that responsibility into evidence a board or public-sector leadership team should request. These are analytical implementation criteria, rather than additional statutory requirements.
| Management decision | Evidence needed to make it credible | Weak substitute | Consequence of the weakness |
|---|---|---|---|
| Approve risk treatment | Named services, dependencies, exposure and accountable owners | Approval of a generic security policy | Leadership cannot identify which operational risk it has accepted |
| Approve recovery arrangements | A tested sequence for restoring identity, infrastructure, applications and data | Confirmation that backups exist | Backups may be available while the service remains unusable |
| Accept a critical supplier | Access boundaries, incident cooperation, subcontractor visibility and an executable exit plan | Certification or questionnaire alone | Assurance does not reveal dependence on a shared failure point |
| Accept an unsupported system temporarily | Compensating controls, funding, replacement deadline and escalation conditions | Repeated annual risk acceptance | Temporary exceptions become permanent exposure |
| Authorise emergency containment | Pre-agreed authority to isolate systems or suspend operations | A contact list | Decisions stall while the incident spreads |
| Assess improvement | Service recovery results, remediation completion and recurrence | Spending totals and tools purchased | Activity is mistaken for reduced risk |
The contradiction is particularly acute where cybersecurity leaders carry responsibility for explaining risk but cannot influence procurement, staffing or service architecture. Formal accountability will have limited operational effect if the budget owner, system owner and risk owner cannot resolve disagreements before a crisis.
For Italy, a meaningful supervisory question is therefore whether management can show how a known weakness was treated, including why a delay was accepted, which interim protections exist and when the decision will be revisited.
Proportionality does not remove the obligation to understand consequences
Italy’s Article 24 requires appropriate and proportionate technical, operational and organisational measures. The assessment includes exposure, organisational size, likelihood, severity and social and economic impact. Its minimum areas include continuity, supplier security, vulnerability management, effectiveness assessment, training, access control and authentication.
The law also requires consideration of direct suppliers’ vulnerabilities and cybersecurity practices. Procurement therefore falls inside risk management: the quality of the supplier relationship matters alongside the purchased technology.
Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 24 — cybersecurity risk-management measures. gazzettaufficiale.it
Analytical judgment. Proportionality should change the method and scale of implementation; it should preserve the ability to explain the risk. A smaller organisation may reasonably use a managed service instead of maintaining its own security operations centre. It still needs to know who can disconnect compromised access, how essential data will be recovered and whether its provider can support several affected customers simultaneously.
There is also a supply-chain asymmetry. A small supplier outside direct regulatory scope may be indispensable to a large regulated customer. Contractual demands can transmit security expectations downstream, but this may produce duplicated questionnaires and costs without supplying the smaller firm with implementation capability.
Reporting clocks: similar numbers, different legal triggers
A recurring compliance error is to treat every “24-hour” or “72-hour” requirement as the same obligation. The responsible actor, triggering event and final-report deadline differ.
| Reporting obligation | Trigger | Responsible actor | Initial stages | Final stage |
|---|---|---|---|---|
| Italian NIS framework | Awareness of a significant incident affecting service provision | Covered essential or important entity | Early notification within 24 hours; incident notification within 72 hours | Generally within one month of the incident notification, with provisions for continuing incidents |
| Italian trust-service exception | Significant incident affecting the provision of trust services | Relevant trust-service provider | The incident-notification deadline is 24 hours | Applicable subsequent reporting requirements remain relevant |
| CRA: exploited vulnerability | Awareness of an actively exploited product vulnerability | Manufacturer | Early warning within 24 hours; notification within 72 hours | Within 14 days after a corrective measure becomes available |
| CRA: severe product-security incident | Awareness of a severe incident affecting product security | Manufacturer | Early warning within 24 hours; notification within 72 hours | Within one month of the 72-hour notification |
Sources: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 25 — incident notification; European Commission, CRA reporting obligations, updated 11 September 2026. gazzettaufficiale.it
The operational consequence is that reporting readiness requires a classification process. Someone must determine which services and products are affected, which entity holds the obligation and when sufficient awareness arose. Waiting for complete forensic certainty can undermine early reporting; premature certainty can contaminate subsequent analysis.
Italy’s Article 25 also provides that notification itself does not expose the reporting entity to greater liability than that arising from the incident. That provision should not be interpreted as immunity from underlying non-compliance. Its purpose must be distinguished from the separate question of whether safeguards were adequate.
CRA: lifecycle responsibility changes procurement economics
The CRA’s central economic effect is to make product support a matter of security and market responsibility. Article 13 ties the support period to expected use and establishes a minimum of five years, except where expected use is shorter. A product expected to remain in service longer requires consideration of that longer use.
A separate provision requires security updates issued during the support period to remain available for at least ten years after issue, or the remainder of the support period, whichever is longer. Continued availability of an issued update is different from continued development of new updates.
Source: Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13, adopted 23 October 2024. EUR-Lex
This distinction matters for industrial and public-sector purchasing. A device may remain physically useful after support expires, while its continuing operation generates replacement, isolation or maintenance costs that were absent from the original procurement calculation.
| Procurement issue | Decision consequence | Contradiction to resolve |
|---|---|---|
| Product life exceeds support life | Budget for replacement, isolation or supported maintenance | The lowest purchase price may generate the highest later security cost |
| Updates exist but deployment is difficult | Evaluate testing, downtime and compatibility requirements | Manufacturer remediation does not establish successful customer remediation |
| Essential functions depend on remote processing | Examine the complete product-service dependency | The local device may appear resilient while its remote dependency is unavailable |
| Third-party components enter the product | Require visibility sufficient to manage relevant dependencies | Product branding can obscure common components used across suppliers |
| Conformity assessment is completed | Continue operational monitoring and risk assessment | Conformity is a point of assurance, not a guarantee against future vulnerabilities |
| An existing product is substantially modified | Reassess the regulatory position and responsibility | Maintenance, integration and modification can change who bears relevant duties |
The Commission’s 27 July 2026 guidance addresses scope, remote processing, open-source software, substantial modification, support periods and reporting through 67 practical examples. It is explicitly non-binding. This is an implementation aid; it does not replace the regulation.
Source: European Commission, new guidance supporting CRA implementation, 27 July 2026. Shaping Europe’s digital future
Two other distinctions prevent overstatement. Products supplied outside commercial activity are treated differently from products made available on the market; open-source software stewards have a separate regime. Equally, CE marking does not mean every covered product has undergone the same independent assessment: the applicable conformity route depends on product classification and the relevant conditions.
Source: European Commission, CRA legislative summary — scope and conformity assessment, retrieved 8 October 2026. Shaping Europe’s digital future
Institutional comparison: authority, assistance and enforcement
The useful comparison across Italy and its peers concerns how operational assistance connects to regulatory supervision. The table focuses on that architecture, rather than repeating a legislative commencement timeline.
| Country | Officially documented institutional feature | Potential advantage | Problem requiring scrutiny |
|---|---|---|---|
| Italy | ACN is the national NIS competent authority and single point of contact; CSIRT Italia performs incident-management functions | Clear national reference point | Whether central capacity and sector expertise scale with the regulated population |
| Germany | BSI provides a common portal for NIS2 registration and incident reporting, including voluntary reports from entities outside scope | A shared administrative and reporting interface | A functioning portal does not establish consistency or depth of supervision |
| France | ANSSI supports territorial, sectoral and ministerial CSIRTs; ReCyF provides recommended security measures | Assistance closer to local and sector-specific conditions | Consistent service quality and clarity about guidance versus enforceable requirements |
| Austria | NISG 2026 provides for a Federal Office for Cybersecurity under the Interior Ministry; USP services support registration and reporting | A dedicated institutional structure with an established business interface | Staffing, technical capability and workflows during the new system’s initial operation |
| Netherlands | NCSC manages the entity register and assistance; supervision is allocated by sector | Separation between technical support and sector supervision | Coordination across authorities and avoidance of inconsistent information requests |
| Spain | INCIBE-CERT’s official guidance describes governance, proportional controls and the interaction with DORA | Accessible implementation guidance for affected organisations | Guidance must be distinguished from the final national allocation of enforceable powers |
| United Kingdom | NCSC provides technical guidance; the Cyber Security and Resilience Bill remained in parliamentary proceedings at the cutoff | Strong technical guidance alongside legislative reform | Proposed obligations must not be presented as already enacted |
Sources: Italy, Article 10 — ACN responsibilities and Article 15 — CSIRT Italia; Germany, BSI NIS2 portal information; France, ANSSI’s response-centre network, 8 January 2026; Austria, NIS2 implementation and USP services; Netherlands, NCSC–supervisor cooperation agreements, 7 October 2026; Spain, INCIBE-CERT NIS2 FAQs; UK Parliament, Bill stages. gazzettaufficiale.it
Several details sharpen the comparison.
The Netherlands has made coordination explicit. On 7 October 2026, NCSC and four supervisory authorities signed cooperation agreements covering information exchange, coordination of supervisory activity and mutual involvement. Further practical working arrangements were still to be developed, with evaluation after one year. This is evidence of institutional preparation, not yet evidence of successful implementation.
France separates preparation from binding status. ANSSI’s English NIS2 page identifies ReCyF as a working document, non-binding by default, and describes preregistration pending forthcoming national transposition. Its guidance is operationally useful, but that page cannot establish that every provision of the national framework is already enforceable.
The UK also requires a status distinction. Parliament’s record listed a Lords report stage for 26 October 2026, beyond this report’s cutoff. The reform should consequently be analysed as a bill at this point.
Sources: Dutch cooperation agreements, 7 October 2026; ANSSI’s NIS2 implementation page, retrieved 8 October 2026; UK parliamentary stages, retrieved 8 October 2026. NCSC
Cross-border dependence complicates national accountability
Italy’s Article 5 applies different jurisdictional rules to different categories. For specified digital providers—including cloud, data centres and managed services—the main establishment in the Union is central to jurisdiction. Public electronic communications follow a service-location rule, while public administration follows the state establishing it.
For relevant digital providers, the main-establishment test considers where cybersecurity risk-management decisions are predominantly taken, with further criteria where that location cannot be determined.
Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 5 — jurisdiction and territoriality. gazzettaufficiale.it
Analytical implication. An Italian customer’s ability to recover may depend on a provider supervised elsewhere. Effective protection therefore requires cross-border cooperation and usable contractual arrangements. Domestic registration cannot by itself resolve dependence on foreign-controlled operational decisions.
DORA addresses part of this problem through European oversight of designated critical ICT providers. The European Supervisory Authorities published their designation list on 18 November 2025, moving the framework beyond a purely prospective mechanism.
Source: ESMA, designation of critical ICT third-party providers, 18 November 2025. esma.europa.eu
Nevertheless, a provider’s importance to an individual hospital, municipality or manufacturer can be substantial even when it is outside that financial-sector designation mechanism. Systemic oversight and organisation-specific dependency management answer different questions.
The implementation evidence: compliance demand exceeds delivery capacity
ENISA’s December 2025 investment findings provide a useful test of the assumption that legal obligations automatically produce resilience.
| Indicator | Reported value | What it establishes |
|---|---|---|
| Organisations identifying compliance as a main investment driver | 70% | Regulation strongly influences investment decisions |
| Organisations reporting difficulty attracting cybersecurity professionals | 76% | Recruitment constrains implementation |
| Organisations reporting difficulty retaining professionals | 71% | Maintaining capability is also difficult |
| Respondents identifying patching as challenging | 50% | Remediation remains a practical bottleneck |
| Respondents identifying business continuity as challenging | 49% | Recovery obligations require substantial operational work |
| Respondents identifying supply-chain risk management as challenging | 37% | Dependence is difficult to assess and control |
| Respondents citing supply-chain or third-party compromise as a future concern | 47% | Organisations recognise a risk that outsourcing can intensify |
Source: ENISA, What’s Driving Cybersecurity Investments and where lie the challenges?, 8 December 2025. Results concern surveyed organisations; questions permitting multiple selections are not mutually exclusive distributions. ENISA
The policy contradiction is clear. Regulation increases demand for expertise, assessment and remediation precisely where those capabilities are constrained. Outsourcing can alleviate a local shortage while increasing collective dependence on a limited provider base.
For Italy, the relevant comparison with France and the Netherlands is therefore how assistance and supervision reduce this implementation burden. For Germany and Austria, a common administrative interface is useful, but implementation quality still depends on technical capacity behind it. For Spain and the UK, accessible guidance can support preparation while legislative status and final powers remain separate questions.
Key judgments
- Management accountability is economically meaningful only when leadership can resolve operational trade-offs. Training and approval should lead to decisions about service priorities, replacement, isolation and recovery.
- Product security and organisational resilience remain complementary responsibilities. Neither supplier assurance nor product conformity establishes service continuity.
- Institutional effectiveness depends on capacity and coordination. Centralisation and sector-based supervision each have strengths and failure modes.
- The most consequential compliance gap is the distance between a documented control and a demonstrated result.
What would change the assessment
The assessment would strengthen with published evidence that supervision results in completed remediation, recovery tests meet service tolerances and assistance reaches organisations with limited internal capability.
It would weaken if registrations, notifications and expenditure rise while severe recovery failures persist, unsupported-system exceptions accumulate or supplier concentration remains poorly understood.
Open official record
The decisive missing comparison is a harmonised account of supervisory outcomes: inspections completed, material weaknesses identified, corrective actions closed and operational improvement demonstrated. The retrieved record does not support a defensible league table of the seven countries’ regulatory effectiveness.
Chapter 2 — Artificial intelligence, legacy systems and the distinction between attack activity and economic damage
Principal judgment. Artificial intelligence can accelerate offensive activity and defensive work, but the severity of economic harm remains strongly mediated by ordinary operational weaknesses: exposed systems, slow remediation, excessive privileges, unsupported technology and recovery arrangements that fail under pressure. Public policy should distinguish attack attempts, successful compromise, service interruption and economic loss. Treating those measures as interchangeable can misdirect investment and exaggerate—or conceal—national weakness.
The most useful current evidence combines threat observations, organisational surveys and regulated incident reporting. Each measures a different population. None should be converted into an all-purpose national cyber-risk score.
What the latest European threat evidence actually measures
ENISA’s Threat Landscape 2026, published on 22 September 2026, covers observations from 1 January to 31 December 2025. Its publication year must therefore be distinguished from the year of the underlying activity.
| Observation | Value | Denominator or interpretation |
|---|---|---|
| DDoS | 51.3% | Incident types in ENISA’s analysed dataset |
| Unauthorised access | 39.5% | Incident types in the same dataset |
| Unauthorised-access incidents with an identifiable intrusion vector | 5.2% | A small subset of unauthorised-access observations |
| Vulnerability exploitation | 60.4% | Only the subset with an identifiable intrusion vector |
| Misconfiguration or accidental exposure | 20.7% | The same identifiable-vector subset |
| Phishing | 77.8% | Identified social-engineering techniques; not all incidents |
Source: ENISA, Threat Landscape 2026, overview and methodology, September 2026. enisa.europa.eu
The denominator is decisive. The finding that 60.4% of identified intrusion vectors involved vulnerabilities does not establish that vulnerabilities caused 60.4% of all European intrusions. Most unauthorised-access observations did not provide an identifiable vector.
This limits both causal attribution and year-to-year comparison. A change in the composition of disclosed cases can change the reported share without an equivalent change in the underlying threat.
ENISA also distinguishes frequency from consequence: ransomware remains particularly impactful in the short term, while public administration remains heavily targeted and geopolitical developments influence hacktivist activity.
Source: ENISA, How dependencies weaken digital resilience, 22 September 2026. ENISA
Analytical implication. A dataset dominated by visible availability attacks can be useful for understanding operational pressure without identifying the greatest source of economic loss. Public claims, readily observed outages and covert espionage have different visibility and disclosure patterns.
An attack counter is not a damage measure
| Measurement | What it captures | What it cannot establish alone |
|---|---|---|
| Scanning or blocked connection attempts | Exposure and attempted interaction | Successful compromise |
| Security alerts | Events matching detection rules | Distinct attacks or confirmed incidents |
| Attacker claims | Claimed targeting or compromise | Verification, duration or damage |
| Confirmed incidents | Events meeting a defined classification | Comparable economic severity |
| Service downtime | Loss of availability | Permanent loss of output or revenue |
| Records exposed | Confidentiality impact | Realised financial loss or subsequent misuse |
| Reported financial costs | Costs recorded under a particular method | Complete social or economic harm |
| Insurance claims | Covered losses submitted to insurers | Uninsured losses or losses outside policy scope |
This distinction matters directly to comparisons between Italy, the UK, France, Germany, Austria, Spain and the Netherlands. Reporting may be higher where detection, disclosure and supervisory coverage are stronger. Lower recorded activity can reflect fewer attacks, fewer detections, narrower thresholds or incomplete reporting.
Analytical judgment. A country can improve detection and become statistically “worse” on an incident-count measure while reducing economic harm. Conversely, a country can report fewer incidents while remaining exposed to a small number of severe failures.
AI: capability acceleration is credible; a universal loss multiplier is not established
In their 22 June 2026 joint statement, Five Eyes cybersecurity agencies warned that frontier AI was accelerating the speed, scale and sophistication of cyber threats and shrinking the interval between vulnerability discovery and exploitation. Their recommended response emphasised attack-surface reduction, faster patching, legacy-system treatment, stronger identity controls and rehearsed incident response.
This is an institutional threat assessment and call to action. It does not provide a measured percentage of European incidents caused by AI or a quantified multiplier for economic damage.
Source: NCSC, The AI shift in cyber risk: why leaders must act now, 22 June 2026. National Cyber Security Centre
The distinction prevents speculative forecasts from becoming apparent statistics.
| AI-related mechanism | Potential operational effect | Evidence needed to quantify the effect |
|---|---|---|
| Faster reconnaissance and code analysis | More candidate weaknesses examined | Valid findings and subsequent exploitation compared with a baseline |
| More persuasive social engineering | More credible or localised deception | Campaign conversion rates, with verified attribution |
| Assistance with exploit development | Reduced time or skill required for some tasks | Working exploitation under realistic conditions |
| Defensive analysis and triage | Faster handling of alerts and investigations | Detection quality, false positives and time to containment |
| Automated remediation support | Faster preparation of fixes | Successful deployment, regression rate and exposure reduction |
| Autonomous agents with system access | Actions executed at greater speed | Permission scope, error rates, reversibility and containment performance |
These mechanisms should be evaluated separately. A model’s ability to explain a vulnerability does not establish its ability to compromise a real environment. Faster generation of phishing content does not establish successful fraud. Faster defensive triage does not establish that analysts can act on the result.
The policy problem is that offensive speed can increase before organisational change-management, procurement and maintenance processes adapt. AI may accelerate one side of the interaction while the defender remains constrained by operational approval and compatibility testing.
Agentic AI creates a second risk channel inside the organisation
AI is also part of the defended environment. Agents can interact with data, tools and production systems, creating exposure through excessive permissions, unintended actions and malicious instructions embedded in material they process.
The NCSC’s 20 August 2026 advice links greater autonomy to greater potential impact and explicitly warns against treating built-in model safeguards as sufficient protection. It calls for proportionate additional safeguards, observability, monitoring and response arrangements. The publication identifies its advice as interim, ahead of formal guidance.
Source: NCSC, Managing the cyber risk of agentic AI, 20 August 2026. National Cyber Security Centre
| Deployment choice | Risk mechanism | Practical control objective |
|---|---|---|
| Agent can read sensitive information | Disclosure through outputs or connected tools | Limit accessible data and destinations |
| Agent can modify production systems | Unintended changes become service incidents | Restrict changes and preserve rollback |
| Agent can authorise transactions | Fraud or error receives execution capability | Separate recommendation from authorisation |
| Agent processes external documents | Untrusted content influences actions | Keep external content from acquiring authority |
| Several agents share powerful credentials | A local failure crosses task boundaries | Separate identities and permissions |
| Logs record outputs but not actions | Investigators cannot reconstruct decisions | Record tool use, authorisations and system changes |
These are analytical control objectives. Their importance depends on the actual deployment rather than the “AI” label.
European financial authorities have also moved this issue into supervisory practice. On 31 July 2026, EBA, EIOPA and ESMA called for consistent, risk-based supervision of ICT risks from frontier AI models, with attention to governance, prevention, detection, management and critical-provider oversight under DORA.
Source: ESMA, joint supervisory statement on frontier AI risks, 31 July 2026. esma.europa.eu
The European and UK positions converge on an operational principle: AI risk belongs inside established governance, access management and resilience arrangements. Purchasing an AI security tool cannot substitute for those arrangements.
Legacy systems: age, support and recoverability must be separated
“Legacy” can describe unsupported software, obsolete architecture, scarce expertise or a system that is difficult to change without disrupting service. These conditions overlap but are not identical.
An old system with maintained support, constrained access and tested recovery can present a different risk from a newer application with excessive privileges and undocumented dependencies.
| Legacy condition | Economic risk | Decision required |
|---|---|---|
| Unsupported software | Vulnerabilities may have no supported fix | Replacement or tightly bounded continued operation |
| Specialist knowledge has disappeared | Recovery depends on unavailable expertise | Documentation, knowledge transfer or migration |
| Integration is poorly documented | Change can interrupt dependent services | Dependency discovery and staged transition |
| Patching requires downtime | Security improvement competes with continuity | Planned maintenance and interim controls |
| Hardware is difficult to replace | Failure extends restoration time | Spares, alternative capacity or redesign |
| Recovery cannot be demonstrated | Backups may not restore the full service | End-to-end recovery testing |
The strongest official quantitative example in the retrieved record concerns the UK public sector. It is useful as evidence of the problem, but it must not be treated as a European average.
| UK official measure | Value | Date and scope |
|---|---|---|
| Identified government legacy IT systems | At least 228 | March 2024 inventory reported by NAO in January 2025 |
| Legacy systems rated red for likelihood and impact of risk | 63 of 228 — 28% | Subset of that inventory |
| Independently assessed critical IT systems showing fundamental control gaps | 58 systems assessed | 2024 GovAssure evidence |
| Government technology estate estimated to be legacy | 28% | Estimate cited in the January 2026 Government Cyber Action Plan |
Sources: NAO, Government cyber resilience, January 2025; UK Government, Government Cyber Action Plan, January 2026. nao.org.uk
The two 28% figures have different denominators. One concerns the risk rating of identified legacy systems; the other concerns the estimated legacy share of the technology estate. Combining them would create a false measurement.
NAO also found that the legacy assessments were insufficiently detailed and that those systems had not been included in GovAssure. Consequently, the government lacked a detailed assessment of their cybersecurity exposure and how effectively it had been managed.
Comparative limitation. The retrieved official sources do not provide equivalent, consistently defined inventories for Italy, France, Germany, Austria, Spain and the Netherlands. The UK’s greater visibility into weaknesses cannot establish that its legacy exposure is greater than theirs.
Remediation capacity is the measurable bottleneck
ENISA’s NIS Investments 2025 survey covered 1,080 professionals representing organisations across all 27 EU member states. The sample was predominantly large enterprises: 83% large organisations and 17% SMEs. It therefore offers evidence about the surveyed high-criticality sectors, rather than a representative census of European businesses.
| Implementation measure | Reported result | Interpretation |
|---|---|---|
| Organisations without a cybersecurity assessment in the preceding 12 months | 30% | Significant gaps in checking security posture |
| SMEs without such an assessment | 63% | Particularly limited assessment capacity in the SME sample |
| Organisations taking a month or longer to apply critical patches | 63% | Exposure can persist beyond rapid exploitation cycles |
| Organisations taking more than three months | 28% | A substantial long-delay group |
| SMEs taking more than three months | 51% | Remediation constraints are more pronounced in the SME sample |
Source: ENISA, NIS Investments 2025 — main report, methodology and patching findings. enisa.europa.eu
These findings identify a practical mechanism through which AI could worsen exposure: faster offensive work interacting with a remediation process that already takes weeks or months.
They do not establish that every delayed patch is managerial neglect. Industrial and healthcare environments can require compatibility testing and carefully controlled maintenance. The appropriate response is to distinguish unavoidable delay from unmanaged delay, and require interim protection where replacement or patching cannot occur immediately.
ENISA’s NIS360 2026 assessment illustrates the sector problem in healthcare: moderate maturity coexists with heterogeneous organisations, resource constraints, asset-tracking weaknesses, legacy infrastructure and uneven incident readiness. It also identifies limitations in sector-specific supervisory expertise.
Source: ENISA, NIS360 2026 — health-sector assessment, May 2026. enisa.europa.eu
DORA evidence: incident frequency and economic harm diverge
The European Supervisory Authorities’ first report on major ICT-related incidents in 2025 provides an important counterweight to attack-count narratives.
| DORA observation | Reported result |
|---|---|
| Major ICT-related incidents reported | 3,383 |
| Incidents per financial entity subject to DORA | 0.18 on average |
| Incidents with cross-border impact | Around one third |
| Incidents attributable to third-party failure | 29% |
| Incidents reporting no direct or indirect costs | Almost 40% |
| Incidents reporting costs below €1,000 | Around 10% |
| Incidents leaving the cost field unfilled | 15% |
The report warns that some cost reporting may be incorrect because staff time allocated to incident handling should count. It also acknowledges divergent reporting practices. The apparently low costs therefore require qualification.
A further inconsistency appears in its transaction-impact text: 32% with no affected transactions plus 26% affecting fewer than 1,000 transactions equals 58%, although the passage describes “two thirds”. The discrepancy is left unresolved here.
Source: EBA, EIOPA and ESMA, 2025 report on major ICT-related incidents, June 2026, especially sections 3.3–3.5. esma.europa.eu
Analytical judgment. This evidence supports two conclusions simultaneously. Incident frequency does not establish equivalent economic damage; incomplete cost recording does not establish that damage is negligible.
The dataset also concerns ICT incidents, including non-malicious failures. Describing all 3,383 as cyberattacks would misstate its coverage.
Economic damage requires a consistent accounting boundary
A credible loss assessment should identify whose loss is measured, when it is measured and which costs are included. Otherwise, incident totals can mix firm expenditure, customer losses and social harm.
| Damage category | Appropriate measurement | Main accounting trap |
|---|---|---|
| Immediate response | Investigation, containment and attributable labour | Excluding internal staff costs |
| Technical restoration | Rebuild, recovery, validation and replacement | Counting planned upgrades entirely as incident losses |
| Business interruption | Irrecoverable output or contribution lost | Treating every delayed transaction as permanently lost revenue |
| Customer consequences | Compensation, fraud and additional recovery costs | Omitting losses outside the affected organisation |
| Contractual and legal consequences | Liabilities and costs within a stated boundary | Combining contingent and realised amounts |
| Information loss | Observable consequences of stolen or corrupted information | Assigning speculative values to every exposed record |
| Public-service harm | Cancelled services, backlogs and reduced access | Assuming cash expenditure captures the entire impact |
| Financial recovery | Insurance and other recoveries reported separately | Mixing gross loss with net retained loss |
This is an analytical accounting framework, rather than a new estimate of European losses.
For Italy, the policy consequence is that successful cybersecurity investment should be assessed through restored service capability and reduced exposure. Spending can increase because an organisation is improving, because it has suffered a severe failure or because obligations have expanded. The expenditure figure alone does not distinguish these explanations.
The same discipline is necessary when assessing France’s local assistance network, German or Austrian implementation systems, Dutch sector supervision or UK resilience reform. Comparable outputs require consistent definitions of disruption and loss.
The defence paradox: containment can interrupt the business it protects
Isolation, credential revocation and shutdown can prevent escalation while immediately reducing service availability. A sound plan therefore identifies which interruption is tolerable, who can authorise it and how essential operations continue.
The NCSC’s 20 April 2026 severe-threat guidance explicitly distinguishes ordinary assurance from readiness for severe disruption. It calls for mapping critical IT and operational technology, planning degraded operations and rehearsing isolation and rebuilds. An organisation meeting normal Cyber Assessment Framework expectations may still need to reconsider its response under severe threat.
Source: NCSC, Preparing for severe cyber threat: why leaders must act now, 20 April 2026. National Cyber Security Centre
| Decision under pressure | Benefit | Operational cost | Preparation needed |
|---|---|---|---|
| Isolate a compromised environment | Limit propagation | Applications become unavailable | Minimum-service arrangements |
| Revoke privileged access | Restrict attacker control | Administrators and suppliers may lose access | Trusted recovery access |
| Suspend transactions | Prevent fraud or corruption | Delays and backlog | Reconciliation and restart sequence |
| Rebuild rather than repair | Increase confidence in system integrity | Longer restoration | Reproducible configurations and clean dependencies |
| Disconnect a supplier | Reduce external exposure | Shared service interruption | Alternative provision or degraded operation |
The contradiction is not a reason to avoid containment. It is a reason to make the decision before the incident. A plan that leaves every disruptive action to improvised approval can lose its value precisely when speed matters most.
A more useful performance dashboard for Italy and its peers
A comparative framework should preserve both activity and impact measures, without collapsing them into one number.
| Dimension | Useful indicator | Why it matters |
|---|---|---|
| Exposure | Critical assets with an accountable owner and known support status | Identifies unmanaged dependencies |
| Remediation | Critical exposed vulnerabilities remaining beyond the agreed treatment period | Measures persistent risk |
| Privilege control | Critical administrative access subject to strong authentication and review | Tests containment of identity compromise |
| Recovery | Essential services restored within approved tolerances during exercises | Measures demonstrated capability |
| Supplier dependence | Critical functions concentrated in shared providers or infrastructure | Identifies common failure points |
| Incident consequence | Service interruption and irrecoverable output by severity | Separates volume from harm |
| Cost quality | Reports including attributable labour and distinct gross/net losses | Improves economic comparability |
| AI deployment | Autonomous systems with bounded permissions and reconstructable actions | Connects capability to control |
| Supervisory outcome | Material findings closed and retested | Measures change following intervention |
These are proposed analytical indicators. The current record does not provide a harmonised dataset covering all seven countries.
Publishing them would make policy evaluation more demanding and more useful. A rising incident count alongside faster containment and lower service interruption could indicate improvement. Falling counts alongside longer outages or unresolved critical vulnerabilities could indicate deterioration.
Key judgments
- AI acceleration is a credible operational concern; a universal numerical multiplier for European economic damage is not established by the retrieved official evidence.
- Legacy risk is a combination of support, exposure, expertise and recoverability. System age alone is an inadequate prioritisation rule.
- Attack activity, confirmed compromise and economic loss require separate measures. Their relationship depends on detection, containment and recovery.
- European evidence identifies remediation and assessment gaps, particularly among surveyed SMEs. Those gaps provide a concrete mechanism through which faster threats can become more damaging.
- A low reported cost can reflect effective containment or incomplete accounting. The DORA findings require both possibilities to remain visible.
- For Italy, the most useful policy test is demonstrated service resilience under realistic conditions.
What would change the assessment
The assessment would strengthen if AI-assisted defence measurably reduces exposure and containment time, legacy exceptions receive funded treatment plans and recovery exercises demonstrate continuity despite provider or identity failure.
It would weaken if autonomous systems gain broad production access without effective boundaries, critical patch delays persist, recovery remains untested or economic reporting continues to omit substantial categories of cost.
Open official record
The principal unresolved questions are the share of verified incidents materially enabled by AI, comparable national inventories of unsupported critical systems, consistently measured incident losses and the demonstrated ability of shared providers to support simultaneous customer recovery.
Without those records, precise country rankings or AI-attributed loss totals would exceed the evidence.
Pillar II — Public investment and national policy comparisons
Assessment cutoff: 8 October 2026. Monetary amounts are nominal; programme budgets, grant awards, payments and observed results are distinguished throughout.
Chapter 3 — Italy: voucher design, territorial allocation, accessibility and implementation risks
Principal judgment. Italy’s voucher can finance substantial technological upgrades, but its allocation mechanism does not establish that the most exposed or least capable firms will receive support first. The decisive implementation questions concern financing before reimbursement, administrative readiness, the distribution of expenditure between cloud adoption and cybersecurity, and whether funded systems remain effective after the subsidy ends.
The funding envelope is larger than the amount necessarily available for grants
The programme has a €150 million envelope, with €71,065,813.34 reserved for expenditure plans in eight specified southern regions. That reservation represents 47.38% of the headline envelope, calculated from the published amounts. The remainder is unreserved funding; describing it as an exclusive allocation to central and northern Italy would misstate the instrument. Sostegno alla domanda di servizi di cloud computing e cyber security — MIMIT — programme page. mimit.gov.it
| Funding component | Published amount or calculated value | Correct interpretation |
|---|---|---|
| Overall programme envelope | €150,000,000 | Programme resources, rather than expenditure already delivered |
| Territorial reservation | €71,065,813.34 | Reserved for plans in Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardinia and Sicily |
| Reservation as a proportion of the envelope | 47.38% | Calculated territorial floor within this instrument |
| Unreserved remainder | €78,934,186.66 | Not an exclusive central/northern quota |
| Maximum permitted technical and administrative charges | €3,750,000 | Calculated from the legal ceiling of 2.5% |
| Resources remaining if that ceiling were fully used | €146,250,000 | Conditional calculation, not a published final grant allocation |
The founding decree permits technical and administrative costs, including checks, to be charged to the programme within a 2.5% ceiling. Consequently, €150 million should not automatically be presented as the amount ultimately transferred to beneficiaries. Decreto ministeriale 18 luglio 2025 — MIMIT — July 2025, Article 3. mimit.gov.it
The territorial reservation protects resources against unrestricted national competition, but money reserved geographically is not equivalent to money absorbed effectively. A region can have a protected allocation while its firms encounter difficulties preparing applications, obtaining eligible quotations or financing projects. Assessing territorial success therefore requires separate measures of applications, approvals, implementation and payments.
The relevant denominator also matters. A large regional award total could reflect the number of eligible firms, greater supplier activity or larger average projects. It would not, by itself, demonstrate that the regional capability gap had narrowed.
The subsidy becomes less generous above €40,000
The contribution covers 50% of eligible expenditure, subject to a €20,000 ceiling and a €4,000 minimum expenditure plan. The ceiling is reached at €40,000: spending beyond that point increases the beneficiary’s contribution without increasing the grant. Sostegno alla domanda di servizi di cloud computing e cyber security — MIMIT — programme page. mimit.gov.it
| Eligible project expenditure | Calculated grant | Beneficiary’s eligible-cost contribution | Effective subsidy |
|---|---|---|---|
| €4,000 | €2,000 | €2,000 | 50% |
| €10,000 | €5,000 | €5,000 | 50% |
| €20,000 | €10,000 | €10,000 | 50% |
| €40,000 | €20,000 | €20,000 | 50% |
| €60,000 | €20,000 | €40,000 | 33.33% |
| €100,000 | €20,000 | €80,000 | 20% |
Calculated from the programme’s contribution rate and ceiling. The beneficiary column excludes ineligible costs and any applicable tax treatment.
This structure supports bounded projects more strongly than comprehensive transformations. A firm requiring several interdependent changes can face an incentive to limit the funded package to €40,000, postpone complementary work or fund it separately. That is a plausible behavioural effect of the ceiling, rather than an observed outcome: implementation data would be needed to establish whether project values cluster around that threshold.
For evaluation, project size should therefore be examined alongside the completeness of the resulting system. A smaller, fully configured intervention may outperform a larger collection of disconnected purchases.
Accessibility depends on legal form and connectivity, not merely business size
MIMIT’s updated clarification introduces distinctions that materially affect access. Individual professionals can qualify, whereas associated professional practices are excluded. Each legal entity can submit an application, while the relevant de minimis assessment remains sensitive to the wider undertaking. The connectivity threshold refers to nominal or maximum download speed; mobile-network connections are excluded, although qualifying fixed wireless and satellite connections are accepted. Sostegno domanda servizi di cloud computing e cyber security: Risposte alle domande frequenti — MIMIT — updated October 2026. Risposte alle domande frequenti (FAQ)
| Access distinction | Policy consequence |
|---|---|
| Individual professional versus associated practice | Similar activities can receive different treatment because of organisational form |
| Application per legal entity versus aid assessment across an undertaking | Corporate organisation affects application opportunities without removing State-aid constraints |
| Nominal connection speed versus demonstrated service quality | The threshold verifies contractual eligibility rather than actual reliability |
| Eligible fixed connection versus excluded mobile connection | Firms using mobile connectivity face a categorical barrier even where performance is adequate |
These distinctions expose a tension between administrative classifications and economic vulnerability. A professional practice does not necessarily face lower cyber risk because several professionals operate jointly. Likewise, a nominal connection speed does not establish reliable cloud access, resilience during an outage or effective recovery capability.
The connectivity rule is especially relevant to territorial policy. A geographically reserved budget cannot fully compensate for an eligibility barrier affecting firms with particular connectivity arrangements. The distributional question is therefore broader than whether the reserved funds are spent: it includes which firms remain outside the applicant population.
A chronological procedure rewards readiness
Applications can be prepared from 20 October 2026 at noon and submitted from 10 November 2026 at noon until 20 January 2027 at noon. Thus, at this assessment cutoff, the beneficiary application window has not opened. Decreto direttoriale 4 agosto 2026: Voucher cloud cybersecurity, termini e modalità di presentazione delle domande — MIMIT — August 2026. mimit.gov.it
The chronological procedure creates a foreseeable advantage for applicants that already have advice, supplier quotations and administrative documentation. This does not establish improper allocation. It means that application readiness is part of the selection mechanism, while the procedure does not rank projects principally by their expected reduction of economic exposure.
| Administrative stage | Operative requirement | Implementation implication |
|---|---|---|
| Assessment | Normally within 60 days, with permitted interruptions or extensions | The deadline is not an unconditional payment promise |
| Direct purchases | Expenditure and payment within 12 months of award communication | Execution must fit the grant calendar |
| Subscription | Contract signed within 30 days of award communication | Supplier and contract choices must be ready promptly |
| Subscription notification | Within 60 days of award communication | A separate compliance deadline follows contracting |
| First payment request | At least three months after award communication | The award does not immediately resolve liquidity needs |
| First instalment | At least 50% of the expenditure plan already paid | Beneficiaries must bridge part of the financing |
| Final settlement | Second instalment, or a single request after completion | Documentary closure affects cash recovery |
Source: Decreto direttoriale 4 agosto 2026 — MIMIT — August 2026, Articles 4–7. mimit.gov.it
The grant reduces eventual eligible cost, but it does not remove the need for working capital. Firms with limited liquidity can struggle to reach the expenditure threshold required for reimbursement. Consequently, the nominally equal contribution rate may produce unequal practical access.
A useful implementation response would be targeted assistance with application preparation and project financing, accompanied by reporting on withdrawals after award. Withdrawals would help distinguish weak demand from projects that were approved but could not be executed.
Purchasing technology and building capability remain different funding decisions
The eligible categories include business cloud applications alongside dedicated security technologies. The founding instrument therefore supports digital adoption as well as protection. An accounting or customer-management migration can improve operations, but the amount spent on it cannot automatically be counted as equivalent cybersecurity expenditure. Decreto ministeriale 18 luglio 2025 — MIMIT — July 2025, Article 5. mimit.gov.it
The October FAQ also excludes training and purely theoretical assessments without implementation. It distinguishes an eligible learning platform from the excluded educational content delivered through it. Risposte alle domande frequenti — MIMIT — updated October 2026. Risposte alle domande frequenti (FAQ)
This produces a substantive policy contradiction: the instrument can subsidise the infrastructure used to deliver knowledge while excluding the knowledge itself. The administrative boundary is understandable as a way to constrain expenditure, but it leaves beneficiaries responsible for acquiring skills that may determine whether the purchased systems are used correctly.
The appropriate evaluation should therefore follow the chain from procurement to operational use:
| Evaluation question | Evidence needed | What an invoice cannot establish |
|---|---|---|
| Was the purchase additional? | Baseline inventory and investment plans | Whether the firm would have bought it anyway |
| Was it configured correctly? | Acceptance records and technical checks | Whether default or ineffective settings remain |
| Is responsibility assigned? | Named operator and maintenance arrangements | Whether anyone owns the ongoing task |
| Can operations recover? | Documented restoration test | Whether a backup is usable |
| Does protection persist? | Follow-up checks after subsidy expiry | Whether subscriptions and controls remain active |
| Did territorial capability improve? | Comparable regional results | Whether allocation translated into sustained capability |
These are proposed evaluation requirements, not reported programme results.
Key judgments
Italy’s main implementation risk is a gap between formally eligible purchases and sustained operational capability. Territorial protection improves the distribution of available resources, but its effectiveness depends on the ability of firms to apply, finance and complete projects.
What would change the assessment
Evidence of strong participation among small and administratively inexperienced firms, low post-award withdrawal, independently verified implementation and continued operation after support expires would strengthen the assessment.
Open official record
The consequential missing results are regional applications and rejection reasons, grant commitments versus payments, expenditure by product category, applicant size and legal form, project completion, and post-support performance. Before the application window opens, these cannot be presented as realised outcomes.
Chapter 4 — The United Kingdom, France and Germany: assurance, sovereignty and regulatory execution
Principal judgment. The three countries illustrate different ways to turn public policy into business behaviour. The United Kingdom uses recognised assurance and procurement demand; France combines diagnostic support with requirements for sensitive public-sector cloud use; Germany combines standardised advice with geographically differentiated financial assistance. Each addresses a particular obstacle, but none of these mechanisms alone establishes economy-wide resilience.
The United Kingdom: assurance has commercial value, but coverage remains uneven
The UK’s procurement policy makes cybersecurity assurance relevant to access to public contracts. PPN 014 requires proportionate application, accepts equivalent controls and warns against blanket certification requirements that unnecessarily deter smaller suppliers. It also states that Cyber Essentials does not assure the specific products or services being supplied. PPN 014: Cyber essentials scheme — Cabinet Office — February 2025. GOV.UK
The economic mechanism is important. Procurement can create a recurring commercial reason to maintain controls: assurance becomes relevant to revenue and customer access rather than depending entirely on a temporary grant. However, this mechanism is strongest where buyers request it. Businesses outside those supply chains may experience a much weaker incentive.
The official management information records 61,430 certificates issued between July 2025 and June 2026, including 15,185 Cyber Essentials Plus certificates. Issuances include renewals and should not be treated as a count of distinct newly protected businesses. Cyber Essentials management information — UK Government — September 2026. GOV.UK
| UK assurance indicator | Value | Period and interpretation |
|---|---|---|
| Cyber Essentials certificate issuances | 46,245 | July 2025–June 2026 |
| Cyber Essentials Plus issuances | 15,185 | Same period |
| Combined issuances | 61,430 | Includes renewal activity |
| Plus share of issuances | 24.72% | Calculated; not the share of all UK firms independently audited |
| Businesses reporting Cyber Essentials certification | 5% | 2025/2026 survey |
| Small businesses reporting certification | 12% | Survey size category |
| Large businesses reporting certification | 35% | Survey size category |
Survey source: Cyber security breaches survey 2025/2026 — UK Government — 2026. GOV.UK
The evidence points to a mature assurance mechanism with uneven penetration. Certificate activity and economy-wide coverage measure different things: a substantial renewal market can coexist with limited participation across the business population. The size gradient also suggests that procurement incentives and implementation capacity should be assessed together.
The relevant policy question is whether smaller firms lack awareness, face implementation costs, see insufficient commercial benefit or encounter several of these barriers simultaneously. Certificate totals cannot resolve that question.
Free assessment does not mean free implementation
The NCSC’s funded Cyber Essentials programme is now closed. Its design included practical assistance and certification, but did not finance additional hardware or software required to meet the standard. Funded Cyber Essentials Programme — NCSC — current programme notice. National Cyber Security Centre
This exposes a difference from Italy’s purchase subsidy. Removing the cost of advice and assessment can help a firm identify deficiencies without enabling it to finance the corrections. Conversely, subsidising products can enable purchases without guaranteeing an independent check of the resulting configuration.
The two mechanisms are complementary. Their effectiveness depends on whether firms can move from diagnosis to implementation and from implementation to verification.
The Government Cyber Action Plan also announces more than £210 million for government cybersecurity. This is a public-sector programme, not a directly comparable SME voucher budget. Government Cyber Action Plan — UK Government — January 2026. GOV.UK
| UK policy instrument | Main mechanism | Appropriate performance measure |
|---|---|---|
| Procurement assurance | Makes controls relevant to contract access | Supplier participation, justified requirements and verified scope |
| Assisted certification | Reduces advice and assessment barriers | Corrections completed and firms subsequently certified |
| Central government investment | Finances public-sector execution | Completed milestones and tested public-service capability |
| Certificate renewal | Encourages periodic reassessment | Retention and continuing compliance |
The table identifies evaluation measures, rather than asserting that all are currently published.
France: diagnosing the problem is a distinct investment
France’s Diagnostic Cybersécurité provides an eight-day intervention, with a listed price of €8,800 excluding VAT and 50% support. Its output includes a diagnosis and prioritised recommendations. The remaining €4,400 is the firm’s contribution to the diagnostic service, rather than a comprehensive implementation budget. Diagnostic Cybersécurité — France Num — official programme guide. francenum.gouv.fr
The French diagnostic model confronts a problem that a catalogue subsidy can leave unresolved: firms may not know which purchase offers the highest value. An external review can improve sequencing and identify responsibilities before expenditure is committed.
Its limitation is equally clear. Recommendations do not finance themselves. A programme that produces high-quality plans can still leave firms unable to implement them.
| Diagnostic-stage question | French model’s contribution | Remaining implementation dependency |
|---|---|---|
| What is the baseline? | Structured review | Accurate disclosure and access |
| Which weaknesses matter most? | Prioritised recommendations | Management acceptance |
| What should be purchased or changed? | Costed action plan | Financing and procurement |
| Who must act? | Organisational recommendations | Staff time and authority |
| Were the changes effective? | A basis for later comparison | Follow-up verification |
These are analytical implications of the diagnostic model, not measured programme outcomes.
Sovereignty requirements have a defined public-sector scope
The order of 12 August 2026 approves SecNumCloud version 3.2 for commercial cloud providers serving State administrations, State operators and public-interest groupings where particularly sensitive data are involved. Published on 14 August, it entered into force the following day. Its scope should not be expanded into a claim that every French SME must use a sovereign cloud. Arrêté du 12 août 2026 portant approbation du référentiel d’exigences relatif aux prestataires de services d’informatique en nuage — French Government — August 2026. Légifrance
The economic-security logic differs from a general purchase grant. Sensitive public-sector procurement can create demand for providers meeting a specified assurance framework. That may support investment in qualified services, but the resulting market should be evaluated through actual contracts, qualified capacity, interoperability and operating costs.
A sovereignty requirement can reduce particular dependencies while creating others. Concentration among qualifying suppliers, migration costs and the availability of specialised services remain relevant. These are implementation questions; neither a qualification label nor domestic ownership alone answers them.
France also opened a June–July 2026 call concerning the security of cybersecurity ecosystems, with notifications scheduled for September. The announcement establishes a selection process, not proof that funded sector capabilities were already operating at the cutoff. Appel à manifestation d’intérêt « Sécurité des écosystèmes de cybersécurité » — ANSSI — June 2026. ANSSI
Germany: standardised guidance reduces uncertainty, while funding access varies geographically
Germany’s Transferstelle Cybersicherheit im Mittelstand offers publicly funded initial support, including assessment and guidance. Its FAQ distinguishes these services from external commercial assistance that may incur charges. FAQ: Häufig gestellte Fragen zur Transferstelle Cybersicherheit im Mittelstand — programme operator — current FAQ. CYBERsicher
The CyberRisikoCheck associated with DIN SPEC 27076 provides a standardised assessment approach. It should not be represented as a certificate proving comprehensive regulatory compliance. DIN SPEC 27076 — DIN Media — May 2023. DIN Media
Standardisation can reduce the search problem facing a small firm: whom to consult, what questions to ask and how to compare recommendations. Nevertheless, a consistent diagnosis remains dependent on financing and execution afterward.
Bavaria illustrates the financial layer. Digitalbonus provides up to 50% support, with current ceilings of €7,500 for Standard and €30,000 for Plus projects with particular innovative content. These are Bavarian conditions, not national entitlements. Digitalbonus Bayern: Förderprogramm — Bavarian Ministry of Economic Affairs — current programme. digitalbonus.bayern
| Bavarian provision | Current condition | Consequence |
|---|---|---|
| Geographic access | Eligible establishment in Bavaria | Comparable firms elsewhere cannot assume access |
| Standard ceiling | €7,500 | Supports a smaller project than Italy’s maximum contribution |
| Plus ceiling | €30,000 | Requires particular innovative content |
| Minimum eligible expenditure | €4,000 | Excludes smaller interventions |
| Linked consultation and training | Up to 50% of eligible expenditure | Allows implementation-related capability expenditure |
| Application availability | Monthly quota | Readiness and timing affect practical access |
Sources: Digitalbonus funding provisions — Bavarian legislation portal — effective November 2025 and Häufig gestellte Fragen — Digitalbonus Bayern — current FAQ. Bürgerservice
The monthly quota creates a different timing problem from Italy’s national window. It spreads opportunities over successive months, but can still reward applicants ready at reopening. The inclusion of implementation-related training addresses a capability expenditure that Italy’s voucher excludes.
At federal level, a 2026 amendment suspended the 1 August project-outline submission round for transfer-oriented projects under the relevant IT-security funding programme. This concerns a funding round; it does not establish that existing advisory services ceased. Amendment to the IT-security funding guideline — Federal Ministry for Economic Affairs and Energy — published May 2026. bundesanzeiger.de
The comparison concerns mechanisms, not a spending league table
| Country | Mechanism examined | Principal strength | Principal unresolved problem |
|---|---|---|---|
| Italy | Subsidised cloud and security purchases | Reduces acquisition cost | Additionality, financing and effective operation |
| United Kingdom | Assurance linked to procurement | Gives controls recurring commercial value | Uneven coverage and implementation cost |
| France | Diagnostics and sensitive public-cloud requirements | Improves prioritisation and defines assurance demand | Financing recommendations and supplying qualified capacity |
| Germany | Standardised advice and regional grants | Reduces uncertainty and supports local implementation | Geographic variation and continuity between funding rounds |
This is an analytical comparison of the documented instruments. It is not a complete national expenditure inventory or a ranking of cyber performance.
Key judgments
The UK’s distinctive contribution is the use of procurement to sustain demand for assurance. France separates diagnostic investment from acquisition and uses sensitive public procurement to shape cloud supply. Germany demonstrates that free guidance can coexist with substantial regional differences in financial access.
What would change the assessment
The strongest evidence would connect these instruments to completed corrections: certification uptake among smaller firms, implementation of French diagnostic recommendations, performance and cost of qualified cloud procurement, and conversion of German advisory contacts into verified improvements.
Open official record
A comparable account remains incomplete without beneficiary-level outcomes, full implementation costs and consistent follow-up periods. Budget announcements and participation counts cannot substitute for those records.
Chapter 5 — Austria, Spain, the Netherlands, Finland and Ireland: implementation timing and alternative support models
Principal judgment. These countries offer useful alternatives to Italy’s acquisition model, particularly assessment before investment, support for inexpensive controls, advance payments and verification after implementation. Their programmes also show that a published funding offer may be closed, narrowly targeted or directed toward producers rather than ordinary business users.
Austria: diagnosis before implementation, with a lower subsidy rate
Austria’s KMU.DIGITAL framework provides €35 million for 2024–2026 across its digital and green strands. That is a broader transformation budget, not a cybersecurity-only appropriation. Cybersecurity is one of the supported themes. KMU.DIGITAL — Federal Ministry for Economy, Energy and Tourism — programme framework. bmwet.gv.at
The implementation rules provide 30% support, capped at €6,000, for eligible projects costing €2,000–€30,000 excluding VAT. A preceding supported consultation is normally required, subject to the specified exception mechanism. Richtlinie KMU.DIGITAL 4.0: Modul Umsetzung — Austrian federal ministry — programme guideline. Modul Umsetzung
| Eligible implementation cost | Calculated Austrian contribution | Beneficiary contribution | Effective subsidy |
|---|---|---|---|
| €2,000 | €600 | €1,400 | 30% |
| €10,000 | €3,000 | €7,000 | 30% |
| €20,000 | €6,000 | €14,000 | 30% |
| €30,000 | €6,000 | €24,000 | 20% |
Calculated from the implementation rate and ceiling; these examples do not establish current remaining budget or acceptance of a particular project.
The Austrian model can improve expenditure sequencing because advice generally precedes implementation. Its lower minimum project size also permits smaller interventions than Italy’s minimum plan. However, the lower contribution rate leaves a larger share to the beneficiary.
The two strands should not be treated as an automatic €12,000 entitlement for one project. Separate programme opportunities do not permit the same cost to be funded twice. The broader lesson is that accessible diagnosis and accessible implementation require separate design choices: linking them improves coherence, but insufficient financing can still interrupt the process.
Spain: a large delivery infrastructure does not mean an open application window
Spain’s Kit Digital illustrates the importance of distinguishing new applications from continuing programme delivery. The published calls closed on different dates: the earlier main calls in December 2024, the larger-company call in June 2025, and the remaining listed calls in October 2025. At the October 2026 cutoff, those listed application windows are closed. Convocatorias — Red.es, Kit Digital — current official call record. kitdigital
| Published call grouping | Closing date | Interpretation at 8 October 2026 |
|---|---|---|
| Calls I and II | 31 December 2024 | Historical application rounds |
| Call V | 30 June 2025 | Historical application round |
| Calls III and IV | 31 October 2025 | Historical application rounds |
| Continuing delivery and evaluation | Separate from application deadlines | Does not reopen closed calls |
Kit Digital reports substantial administrative automation: 39 robots, 24,363,519 checks and 736,958 automatically processed files, representing 45% of files in the reported measure. Checks and files are administrative units, not counts of independently secured firms. Convocatorias — Red.es, Kit Digital — current official programme record. kitdigital
The useful comparison with Italy concerns administrative capacity. Automated checks can reduce repetitive processing and support delivery at scale. They can also reproduce classification errors consistently unless applicants have a workable correction process. Automation should therefore be assessed alongside rejection reasons, appeals, incomplete applications and processing times.
Red.es’s impact material reports an application-ease rating of 4.7 out of five and a processing rating of 3.7. These are programme-reported experience measures; they do not demonstrate a reduction in cyber incidents or losses. Evaluación de impacto — Red.es, Kit Digital — official evaluation page. kitdigital
| Spanish measure | What it helps establish | What remains unproven |
|---|---|---|
| Automated checks | Administrative processing activity | Accuracy and fair treatment |
| Automatically processed files | Use of delivery technology | Unique beneficiary reach |
| Application satisfaction | Respondents’ experience of applying | Technical quality of implementation |
| Processing satisfaction | Experience of administration | Long-term business resilience |
| Funded digital solutions | Acquisition and programme delivery | Cyber-specific additionality |
Spain demonstrates why a broad digitalisation programme needs a separate cybersecurity evaluation. Aggregate digital adoption can include many services with different security implications. The evaluation must identify which controls were implemented and whether they remained operational.
The Netherlands: modest grants support controls that large purchase schemes can overlook
Mijn Cyberweerbare Zaak opened on 7 September 2026 and is scheduled to close on 30 November, subject to budget exhaustion. The 2026 envelope is €1 million, with 50% support capped at €1,250. Eligible categories include authentication, password management, patching, backup setup and testing, risk assessment and awareness training. Mijn Cyberweerbare Zaak in het kort — NCSC Netherlands — 2026 programme guidance. NCSC
This is a narrower security intervention than Italy’s cloud-and-cyber voucher. Its inclusion of awareness and assessment is significant: small expenditures on these activities can address organisational weaknesses without requiring a larger technology package.
The detailed rules nevertheless create a financing constraint. Applicants must implement and pay for qualifying measures before applying. A CyberVeilig Check action list is mandatory; eligible expenditure starts at €400. General cloud-workplace subscriptions are excluded. Mijn Cyberweerbare Zaak — Netherlands Enterprise Agency, RVO — checked September 2026. RVO.nl
| Dutch design feature | Advantage | Limitation |
|---|---|---|
| €400 expenditure threshold | Permits inexpensive improvements | Very small measures still fall below the threshold |
| €1,250 maximum contribution | Supports basic controls | Insufficient for a comprehensive transformation |
| Required action list | Connects expenditure to identified needs | Completion does not independently validate the diagnosis |
| Training and risk assessment eligible | Supports human and organisational capability | Quality must still be assessed |
| Payment before application | Provides evidence of real expenditure | Transfers financing and allocation uncertainty to the firm |
| Narrow security categories | Limits diversion into general digitalisation | Excludes broader migration needs |
The Netherlands highlights a distinction between low administrative scale and low financial risk. A small grant can still require a firm to spend before it knows whether funds remain available. Conversely, a larger programme can reserve an award before expenditure while requiring more documentation.
The Dutch approach is particularly relevant to firms whose immediate deficiencies can be corrected cheaply. Its ceiling should be judged against that purpose, rather than against Italy’s maximum grant for a much broader project.
Finland: the current call funds producers, while an earlier call supported compliance implementation
Finland’s September 2026 call supports the commercialisation of innovative cybersecurity solutions. It has a €700,000 envelope and an application deadline of 4 November 2026. It is directed toward developing market-ready solutions, rather than providing a general purchase voucher to ordinary business users. Kansalliset rahoitustuet — Traficom — current national funding page. Traficom
The operative notice allows grants of €10,000–€100,000 covering up to 70% of eligible expenditure incurred in 2027. It provides 70% of the awarded grant after the positive decision and the remaining 30% after completion and accepted reporting. The aid intensity and payment schedule are separate percentages. Hakuilmoitus rahoitustuesta innovatiivisten kyberturvallisuusratkaisujen kaupallistamisen edistämiseen — Traficom — September 2026, pp. 2–3. kyberturvallisuuskeskus.fi
| Finnish funding round | Main purpose | Contribution | Implementation period |
|---|---|---|---|
| 2025 round | Implementation of cybersecurity-law requirements by eligible organisations | Up to 50% | 2026 |
| 2026 round | Commercialisation of innovative cybersecurity solutions | Up to 70% | 2027 |
The distinction prevents a misleading comparison. Finland’s current contribution rate cannot be presented as a 70% subsidy available to any SME buying security software.
For a hypothetical €50,000 eligible development project receiving the maximum rate, the grant would be €35,000. The initial payment would then be €24,500—70% of the grant—with €10,500 retained for final settlement. The beneficiary would contribute at least €15,000. These are calculations illustrating the rules, not an actual award.
The advance materially changes financing needs relative to reimbursement schemes. It can help execute a selected project, while increasing the importance of selection quality, monitoring and recovery of funds where conditions are not fulfilled.
The Finnish official record contains a numerical revision that should remain visible
Traficom’s 3 February 2026 announcement reported 35 recipients and €1.65 million awarded under the 2025 round. Its current funding page records 36 recipients and €1.67 million. The opened records do not explain the difference. Liikenne- ja viestintävirasto myönsi rahoitustukea yhteensä 1,65 milj. euroa — Traficom — February 2026 and Kansalliset rahoitustuet — Traficom — current record. Kyberturvallisuuskeskus
| 2025-round indicator | Official value |
|---|---|
| Applications | 89 |
| Funding requested | €4.7 million |
| Announced round budget | €2 million |
| February 2026 announcement | 35 recipients; €1.65 million |
| Current programme record | 36 recipients; €1.67 million |
| Current recipients divided by applications | 40.45%, calculated |
| Requested funding divided by round budget | 2.35 times, calculated |
The fact that demand exceeded the budget while awards remained below it does not, by itself, establish administrative failure. Eligibility and minimum assessment thresholds can produce that combination. The decisive evidence would be the distribution of rejection reasons and the treatment of qualifying applications.
An evaluation of Finland’s earlier 2023–2024 support provides additional, qualified evidence. Traficom reports 50 beneficiaries, 44 survey responses and self-reported improvements, while only 40% had undertaken audits. Financial support provided by the National Coordination Centre improved the cybersecurity of companies — Traficom — February 2025. Traficom
This is stronger than a simple award count because it examines implementation, but it remains insufficient to attribute a precise reduction in losses to the subsidy. Respondent reports, audits and causal outcome measurement provide different levels of evidence.
Ireland: a coherent assessment-to-retest model, with a closed implementation grant
Ireland’s NCC-IE Cyber Security Improvement Grant has finished, and the official notice states that additional application rounds will not open. Its historical design required a prior Enterprise Ireland review, funded implementation and included post-implementation retesting. Contributions ranged from €20,000 to €60,000, with 20% beneficiary financing. NCC-IE Cyber Security Improvement Grant — NCSC Ireland — current closure notice. ncsc.gov.ie
Enterprise Ireland separately lists an 80% contribution toward a €3,000 cybersecurity review. That implies €2,400 support and a €600 company contribution; it should not be confused with a reopened implementation grant. Cyber Security Review Grant — Enterprise Ireland — current programme page. Enterprise Ireland
The Irish sequence addresses several failures discussed elsewhere: choosing an intervention without diagnosis, implementing recommendations without expert support, and accepting completion without retesting. Its limitation is continuity. A diagnostic service can remain available after the associated implementation funding ends.
Ireland also publishes unusually useful administrative results for the completed grant.
| Round | Applications | Awards | Unsuccessful applications | Calculated award rate | Grant agreements |
|---|---|---|---|---|---|
| October 2024 | 23 | 2 | 21 | 8.70% | €61,644.80 |
| January 2025 | 52 | 31 | 21 | 59.62% | €1,085,228.82 |
| June 2025 | 41 | 17 | 24 | 41.46% | €596,639.60 |
| Total | 116 | 50 | 66 | 43.10% | €1,743,513.22 |
Source: Cyber Security Improvement Grant Report 2025, version 1.3 — NCSC Ireland — February 2026. Percentages are calculated from published counts. ncsc.gov.ie
The agreements represent 87.18% of the €2 million envelope, and the calculated average award is €34,870.26. These figures concern awards, not proof that every euro was paid or that a corresponding amount of economic damage was prevented.
The variation between rounds is material. It warrants investigation into eligibility, applicant preparation and procedural changes, but the figures alone do not identify which explanation predominates. Publishing refusal reasons by round would make that distinction possible.
Contribution rates conceal differences in access and purpose
| Instrument examined | Rate | Ceiling | Eligible expenditure needed to reach ceiling | Important qualification |
|---|---|---|---|---|
| Italy cloud/cyber voucher | 50% | €20,000 | €40,000 | Broad acquisition programme |
| Austria implementation support | 30% | €6,000 | €20,000 | Consultation normally precedes implementation |
| Bavaria Digitalbonus Standard | Up to 50% | €7,500 | €15,000 at maximum rate | Regional eligibility |
| Netherlands MCZ | 50% | €1,250 | €2,500 | Narrow basic-security measures |
| Finland 2026 call | Up to 70% | €100,000 | Approximately €142,857 | Commercialisation projects |
| Ireland completed improvement grant | 80% | €60,000 | €75,000 | Closed implementation instrument |
Thresholds are calculated from the documented rates and ceilings cited above. The instruments differ in eligibility, purpose, selection and availability; the table does not imply that every firm can access them.
A high contribution rate can coexist with restrictive eligibility, a large minimum project or a closed application window. A low ceiling can be well suited to inexpensive controls. The appropriate comparison therefore concerns the intervention each programme is designed to produce, together with the obstacles it leaves to the beneficiary.
Implementation timing is itself a policy variable
| Instrument | Position at the cutoff | Why timing matters |
|---|---|---|
| Italy voucher | Submission scheduled to begin in November 2026 | Programme design precedes beneficiary results |
| UK funded Cyber Essentials programme | Closed | Historical assistance cannot be offered as current access |
| French ecosystem call | Application period closed | Scheduled notifications do not prove deployed capability |
| Bavaria Digitalbonus | Programme through 2027, with monthly quotas | Access can vary within a continuing framework |
| Austria KMU.DIGITAL | 2024–2026 funding framework | Framework duration does not guarantee remaining resources |
| Spain’s listed Kit Digital calls | Closed | Continuing delivery differs from new applications |
| Netherlands MCZ | 2026 window open, subject to exhaustion | Firms spend before applying |
| Finland 2026 commercialisation call | Open; implementation in 2027 | Present applications finance future development |
| Ireland improvement grant | Finished; no additional rounds announced | The assessment-to-implementation funding chain has ended |
Status derives from the adjacent official programme records. Austria’s entry describes its framework, rather than asserting verified remaining application capacity.
This timing comparison changes the interpretation of public investment. A budget can exist before firms can apply; awards can exist before projects are completed; expenditure can continue after applications close. Treating all three as simultaneous support overstates the assistance actually accessible at a given date.
Lessons for Italian execution
The comparative evidence supports five practical priorities.
| Priority | Decision consequence | Implementation burden and risk |
|---|---|---|
| Connect purchases to a diagnosis | Reduces poorly prioritised expenditure | Additional assessment can delay small projects |
| Permit proportionate capability expenditure | Helps firms operate funded systems | Requires clear boundaries and quality checks |
| Address financing before reimbursement | Improves access for liquidity-constrained firms | Advances require stronger monitoring |
| Verify operation after installation | Distinguishes delivery from effectiveness | Follow-up costs must be budgeted |
| Publish refusal, payment and completion data | Reveals where the process fails | Reporting must protect sensitive information |
These are analytical options drawn from the comparison, rather than assertions that one country has solved every implementation problem. They can be introduced proportionately: inexpensive projects need a lighter process than large, complex interventions.
Key judgments
Austria demonstrates the value of connecting advice and implementation. The Netherlands targets inexpensive organisational and technical controls. Finland’s current advance-payment model addresses financing for selected producers. Ireland’s completed programme connects diagnosis, implementation and retesting, while Spain demonstrates administrative delivery at scale.
For Italy, the central opportunity is to combine acquisition support with evidence that firms can finance, operate and retain the resulting capability. The central risk is judging success through allocated money and invoices before those later stages are observed.
What would change the assessment
Consistent evidence of verified improvements, participation by less-prepared firms, manageable financing burdens and retained capability after funding expires would strengthen confidence. High withdrawal, unresolved recommendations, weak follow-up or dependence on subscriptions that lapse after support would weaken it.
Open official record
The decisive comparative gap is a common set of implementation results: qualifying applicants, refusal reasons, grant commitments, actual payments, completion, independent verification and retention. Until those measures are available on compatible definitions and periods, a numerical ranking of national cybersecurity investment performance would exceed the evidence.
Pillar III — Structural contradictions and policy choices
Assessment cutoff: 8 October 2026. The outlook extends to 2031. Announced allocations, contractual commitments, payments and operational results remain separate measures.
Chapter 6 — Skills, procurement, cloud concentration, industrial dependencies and supply-chain exposure
Principal judgment. Europe’s central structural contradiction is that investment in digital protection can increase dependence on external operators without creating sufficient capacity to supervise them. Italy faces a particularly important execution challenge: widespread cloud adoption coexists with a relatively small ICT specialist workforce. Subsidised acquisition can improve protection, but its effectiveness depends on procurement competence, operational responsibility and the ability to recover when a supplier fails.
Italy’s adoption indicators and workforce indicators describe different capabilities
Eurostat records 10.45 million ICT specialists in EU employment in 2025, representing 5% of employed people. Italy’s share was 3.8%, compared with Finland’s 7.8%. These are ICT employment measures, not counts of cybersecurity professionals or direct measurements of defensive effectiveness. Number of ICT specialists in the EU continues to grow — Eurostat — May 2026. Eurostat
| Workforce indicator | Value | Reference period | Interpretation |
|---|---|---|---|
| EU ICT specialist employment | 10.45 million | 2025 | Broad ICT workforce |
| EU ICT specialists as a share of employment | 5.0% | 2025 | Comparable employment denominator |
| Italy | 3.8% | 2025 | Below the EU employment share |
| Finland | 7.8% | 2025 | Larger relative ICT workforce |
| Italy–EU difference | −1.2 percentage points | Calculated | Does not establish a corresponding cyber-performance gap |
| Women’s share of EU ICT specialist employment | 19.5% | 2025 | Indicates a narrow recruitment base |
Against this workforce background, ISTAT reports that 68.1% of Italian enterprises with at least ten employees purchased intermediate or advanced cloud services in 2025. The figure was 67.7% among enterprises with 10–249 employees and 87% among larger firms. Imprese e ICT: Anno 2025 — ISTAT — December 2025, p. 2. istat.it
| Italian cloud adoption | Share purchasing intermediate or advanced services |
|---|---|
| Enterprises with at least ten employees | 68.1% |
| Enterprises with 10–249 employees | 67.7% |
| Enterprises with at least 250 employees | 87.0% |
| Difference between the latter two groups | 19.3 percentage points, calculated |
The statistical populations must remain explicit. These enterprise figures exclude businesses with fewer than ten employees, whereas public support can reach much smaller organisations. They also measure service acquisition, not whether customers understand access permissions, contractual responsibilities, recovery arrangements or supplier dependencies.
The analytical implication is that adoption policy and capability policy should be assessed separately. Purchasing a service transfers some operational tasks to a provider, but the customer still needs enough competence to choose the service, configure its use and recognise failures. A workforce constraint can therefore remain consequential even when firms outsource most technical work.
The latest UK evidence shows that an established cyber market does not eliminate skills gaps
The UK’s September 2026 labour-market study estimates approximately 145,900 people in the cybersecurity workforce, an increase of 2%. It reports basic technical skills gaps in 57% of businesses, compared with 49% in the preceding study. Its estimates and survey measures should not be combined with Eurostat’s broader ICT employment series. Cyber security skills in the UK labour market 2026 — UK Government — September 2026. GOV.UK
| UK indicator | Latest reported value | Relevant qualification |
|---|---|---|
| Estimated cybersecurity workforce | Approximately 145,900 | Occupational estimate |
| Workforce growth | 2% | Comparison with the previous year |
| Businesses with basic technical skills gaps | 57% | Survey-defined gap |
| Previous study’s corresponding figure | 49% | Eight-percentage-point increase |
| Cybersecurity graduates | 7,950 | Academic year 2023/2024 |
| Change in cybersecurity apprenticeship enrolment | −15% | 2023/2024 to 2024/2025 |
The apprenticeship figure comes from the full study. Cyber security skills in the UK labour market 2026 — UK Government — September 2026, summary. GOV.UK
The coexistence of more graduates, slower workforce growth and widespread basic gaps suggests several different policy problems. Graduate supply does not automatically produce experienced staff. Firms may need supervised entry routes, technical management, practical retraining or access to reliable shared services. An aggregate workforce target cannot identify which of these constraints prevents a particular business from operating securely.
For Italy, this evidence argues against treating the number of training participants as the sole skills outcome. A more useful measure is whether participants subsequently perform defined tasks successfully: administering access, restoring data, supervising a provider or executing an incident procedure.
Outsourcing concentrates scarce expertise, but also concentrates exposure
ENISA’s 2025 investment study surveyed 1,080 public and private organisations across the EU; 83% were large enterprises and 17% SMEs. It reports persistent difficulties attracting and retaining cybersecurity professionals. This sample supports analysis of critical-sector organisations, but it is not representative of every European microbusiness. What’s Driving Cybersecurity Investments and where lie the challenges? — ENISA — December 2025. ENISA
The report’s supplier findings expose a particularly important contradiction.
| Supplier-related indicator | Reported share | What it measures |
|---|---|---|
| Organisations implementing specific third-party or supply-chain controls | 90% | Reported control adoption |
| Requiring supplier standards or certifications | 63% | Assurance requirements |
| Supplier risk assessments or audits | 54% | Assessment activity |
| Cybersecurity requirements in supplier contracts | 48% | Contractual provisions |
| ICT service-management entities without cybersecurity testing in the preceding year | 43% | Reported testing gap |
| ICT service-management entities taking over three months to patch critical systems | 45% | Reported remediation delay |
Source: NIS Investments 2025 — ENISA — December 2025, pp. 26–27. The service-management category includes managed service and managed security service providers. enisa.europa.eu
These measures are not mutually exclusive, and they do not prove that certifications are ineffective. They show that contractual assurance and operational maintenance are different activities.
A provider serving many customers can distribute expertise efficiently. The same arrangement can transmit a failure across those customers when they share administration, infrastructure or a vulnerable service. Procurement therefore needs to assess both the provider’s individual quality and the concentration created across the customer portfolio.
Cloud concentration must be measured at the correct market layer
The CMA’s final cloud investigation provides a useful official concentration measure: installed data-centre capacity in the UK and European Economic Area. Its published 2024 ranges place Microsoft at 40–50%, AWS at 20–30% and Google at 10–20%. These are capacity shares, not each country’s cloud revenue shares or the distribution of all cybersecurity expenditure. Cloud services market investigation: Final decision report — Competition and Markets Authority — July 2025, Table 3.4, p. 106. assets.publishing.service.gov.uk
| Provider | Published 2024 capacity range | Geographic scope |
|---|---|---|
| Microsoft | 40–50% | UK and EEA |
| AWS | 20–30% | UK and EEA |
| 10–20% | UK and EEA | |
| Oracle | 0–5% | UK and EEA |
| CoreWeave | 0–5% | UK and EEA |
| IBM | 0–5% | UK and EEA |
The CMA publishes ranges to protect confidential information. Their midpoints should not be presented as observed shares, and overlapping ranges should not be converted into a precise concentration index.
The relevant structural issue extends beyond the infrastructure invoice. A business can buy different applications from several vendors while those vendors rely on the same underlying cloud, identity system or managed operator. Apparent supplier diversity at the contractual level may therefore conceal common dependencies.
This distinction matters for public grants. A catalogue containing numerous vendors does not necessarily create infrastructure diversity. Evaluators need to identify the underlying operator where a funded service is critical to business continuity.
Procurement should disclose the dependencies that the customer cannot see
The NCSC’s cloud principles address matters including asset protection, supply-chain security, identity, administration and audit information. They provide a basis for asking what a provider secures and what remains the customer’s responsibility. The cloud security principles — National Cyber Security Centre — current guidance. National Cyber Security Centre
The following is a proposed procurement checklist, rather than a claim that every national programme already requires these disclosures.
| Dependency | Information the buyer should obtain | Evidence useful at acceptance |
|---|---|---|
| Underlying infrastructure | Operator, service region and critical hosting dependencies | Verified service architecture |
| Identity and privileged access | Who can administer systems and how emergency access works | Tested access and revocation procedure |
| Subcontracting | Material subcontractors and notification of changes | Current dependency register |
| Software maintenance | Support period, update responsibility and escalation route | Maintenance schedule and supported versions |
| Recovery | Data copies, restoration procedure and responsible parties | Successful restoration test |
| Portability | Exportable data, formats and configuration documentation | Sample export and usable documentation |
| Provider failure | Assistance, alternative arrangements and termination provisions | Exercised continuity procedure |
| Incident evidence | Log availability, retention and access conditions | Successful retrieval of required records |
A small firm should not be expected to negotiate every clause independently. Public authorities and programme operators can supply standard schedules, while specialist advisers assess more complex services.
Standardisation nevertheless needs proportionality. Requiring an elaborate supply-chain inventory for a minor purchase can consume more resources than the intervention saves. Criticality should determine the depth of disclosure: an application supporting an essential process warrants a different assessment from a peripheral tool.
The Data Act reduces an exit charge, not every cost of leaving
From 12 January 2027, the Data Act prohibits switching charges for the switching process within its scope. However, the regulation distinguishes those charges from standard service fees and early termination penalties. It does not eliminate all expenditure on migration or redesign. Regulation (EU) 2023/2854, Data Act — European Parliament and Council — December 2023, Article 2(36), Article 29 and recital 89. EUR-Lex
| Exit expenditure | Effect of the switching-charge rule | Remaining procurement question |
|---|---|---|
| Provider-imposed charges for mandated switching operations | Prohibited from the specified date | Are invoiced charges correctly classified? |
| Data egress forming part of switching | Included in the withdrawal | Is the proposed movement a qualifying switching process? |
| Ordinary service fees | Distinct from switching charges | When does the existing contract end? |
| Early termination penalties | Distinct category | Are they lawful and proportionate? |
| Customer’s migration assistance and redesign | Not universally eliminated | What skills, testing and integration remain necessary? |
The Commission also explains that switching involves contractual transparency, open interfaces and data export requirements. These measures address barriers, but they do not establish that every complex application can be moved immediately without operational disruption. Data Act explained — European Commission — current explanation. Shaping Europe’s digital future
The implication for grant design is precise: portability should be considered before purchase. A legal right to exit has limited practical value if the customer cannot reconstruct its workflow elsewhere.
Industrial autonomy requires control of functions, not a domestic address
The European supervisory authorities’ first DORA list designates 19 critical ICT third-party providers. It includes infrastructure, software and service companies, illustrating that financial-sector dependence reaches beyond the major cloud platforms. List of designated critical ICT third-party service providers — European Supervisory Authorities — November 2025. esma.europa.eu
Designation subjects providers to oversight aimed at their risk management and governance. It is not a certification that customers face no residual risk. The European Supervisory Authorities designate critical ICT third-party providers under DORA — European Supervisory Authorities — November 2025. esma.europa.eu
| Industrial-policy objective | Meaningful test | Insufficient proxy |
|---|---|---|
| Control over sensitive operations | Administrative authority, access arrangements and enforceable restrictions | Registered office alone |
| Technological substitutability | A functioning alternative for the relevant service | A list of potential vendors |
| Domestic industrial contribution | Engineering, maintenance and retained intellectual capability | Resale revenue alone |
| Continuity under supplier failure | Available expertise, documentation and recoverable data | Contractual reassurance without testing |
| Sustainable competition | Buyers can compare and change services | A large catalogue containing common underlying dependencies |
These are proposed analytical tests. They avoid assuming that domestic supply is always technically superior or that foreign supply is necessarily insecure.
A credible European industrial policy must distinguish areas where domestic capability is indispensable from areas where diversified international procurement is effective. Otherwise, autonomy requirements can produce expensive substitution without reducing the dependency that matters.
Key judgments
Italy’s workforce and adoption indicators make operational supervision a material policy concern. Outsourcing can improve access to expertise while creating common failure points. Procurement should therefore establish responsibilities, underlying dependencies and workable recovery before treating acquisition as completed capability.
What would change the assessment
Evidence of successful restoration, usable exports, effective supplier oversight and improved practical competence would strengthen confidence. Persistent common dependencies combined with weak customer visibility would weaken it.
Open official record
The consequential missing evidence concerns the underlying infrastructure of funded services, operational responsibility after installation, supplier concentration across beneficiaries, exit tests and the practical skills retained by customers.
Chapter 7 — The 2026–2031 outlook: funding continuity, enforcement and operational scenarios
Principal judgment. The next five years will be shaped by a transition from funding initial deployment to maintaining and supervising recurring services. Stronger rules can improve behaviour, but continuity depends on operating budgets and credible enforcement. The principal downside is a widening gap between formal compliance and the ability to sustain services during a shared-provider disruption.
The funding transition is already visible in the official record
The Commission’s annual RRF report, published on 7 October 2026, confirms that the completion deadline for milestones and targets passed on 31 August, and final payment requests were due by 30 September. Commission payments must conclude by 31 December 2026. These deadlines concern the Recovery and Resilience Facility; they should not be applied indiscriminately to other funding instruments. Recovery and Resilience Facility Annual Report 2026 — European Commission — October 2026. Reforms and Investments
| RRF stage | Deadline | Position at the cutoff |
|---|---|---|
| Completion of milestones and targets | 31 August 2026 | Deadline passed |
| Final payment requests | 30 September 2026 | Deadline passed |
| Commission payments | 31 December 2026 | Assessment and payment period continues |
| Subsequent operation of funded capabilities | Depends on operating arrangements | Not guaranteed by the completion deadline |
The funding risk is therefore broader than incomplete procurement. Systems financed through temporary investment programmes may continue to require subscriptions, staff, exercises, maintenance and replacement. Completing an investment does not settle who finances those activities afterward.
This is particularly important where reported completion rests on installation. The future cost of keeping a service effective should be recorded before the investment is accepted, alongside the organisation responsible for paying it.
The ECCC envelope has been revised downward
The consolidated ECCC work programme adopted in July 2026 reduces its indicative 2025–2027 envelope from €390 million to €355 million, explaining that €35 million was reallocated to support AI Gigafactories. The reduction is 8.97%, calculated from those amounts. Digital Europe Cybersecurity Work Programme 2025–2027, Consolidated Amendment 3 — ECCC — adopted July 2026, p. 13. cybersecurity-centre.europa.eu
| Updated indicative allocation | Amount |
|---|---|
| New technologies, AI and post-quantum transition | €139 million |
| Cyber Solidarity Act implementation and related capabilities | €97 million |
| Additional actions improving EU resilience | €110 million |
| Programme support, including evaluation and review | €9 million |
| Total | €355 million |
The figures are indicative work-programme allocations, not expenditure already delivered. They cover ECCC-implemented actions within this programme, rather than all European cybersecurity funding.
The reallocation does not prove that European cybersecurity investment as a whole declined. It establishes a narrower and important point: an announced cyber envelope can change as competing digital priorities are financed. Long-term planning should therefore distinguish political ambition from protected programme resources.
A new €96 million call bridges into 2027, but does not guarantee support to every SME
The September 2026 ECCC call provides an estimated €96 million across seven topics, with a deadline of 14 January 2027. It finances deployment and capacity projects; it is not a universal retail voucher. Strengthening European Cybersecurity Technologies, Capacities and Preparedness — ECCC — September 2026. cybersecurity-centre.europa.eu
| Topic | Estimated call allocation | Principal policy function |
|---|---|---|
| Cybersecurity tools and services using AI | €15 million | Development and deployment |
| AI-powered cybersecurity solutions for SMEs | €20 million | Uptake and dissemination |
| Coordinated preparedness testing and other actions | €15 million | Exercises and preparedness |
| Regional cable hubs | €5 million | Infrastructure awareness and coordination |
| National Coordination Centre network | €11 million | Ecosystem support |
| Capabilities supporting legislative requirements | €20 million | Implementation support |
| Dual-use technologies | €10 million | Civil–defence cooperation |
| Total | €96 million | Estimated call budget |
The call document gives indicative durations of 24 months for coordinated preparedness and 36 months for the other listed topics. Consequently, awards following the 2027 deadline can support work beyond the current budget-programming period. They do not establish uninterrupted assistance through 2031. Call document: DIGITAL-ECCC-2027-DEPLOY-CYBER-11 — ECCC — September 2026, pp. 46 and 56. cybersecurity-centre.europa.eu
The implementation question is how shared or intermediary projects reach ordinary firms. A funded platform can exist without substantial use; a successful pilot can remain difficult to procure; a technically strong service can require expertise unavailable to its intended customers. Beneficiary reach and sustained use should therefore be measured separately from project delivery.
Post-2027 funding remains a legislative and allocation question
The Commission’s 2028–2034 budget proposal provides a prospective framework for competitiveness, digital transition and security. The proposal should not be presented as a final cybersecurity appropriation or as guaranteed support for particular national programmes. EU budget 2028–2034 — European Commission — proposal presented July 2025. commission.europa.eu
| Funding condition | Consequence for 2026–2031 planning |
|---|---|
| Existing grant agreement | Provides defined project support, subject to its conditions |
| Open call | Offers a competitive opportunity, not an assured award |
| Indicative work programme | Establishes priorities that can be amended |
| Proposed future budget | Signals intent; adoption and detailed allocations remain decisive |
| National operating appropriation | Can maintain capability beyond the initial project |
| Unfunded continuation plan | Leaves renewal and staffing exposed |
This distinction is central to the outlook. A credible maintenance plan must identify an actual payer and budget mechanism. Assuming that the next European programme will cover recurring costs creates a dependency on decisions outside the beneficiary’s control.
Enforcement must change operational behaviour, not simply produce documentation
ENISA’s survey identifies regulatory compliance as the principal investment driver for 70% of respondents. This supports the judgment that enforcement expectations affect expenditure, while leaving open whether the resulting spending produces durable capability. What’s Driving Cybersecurity Investments and where lie the challenges? — ENISA — December 2025. ENISA
The useful enforcement sequence is to identify a material weakness, require correction, verify the change and monitor recurrence. Counting notices or penalties alone omits the central question: whether the service became more resilient.
| Enforcement measure | Decision-useful denominator | Potential misleading interpretation |
|---|---|---|
| Inspections completed | Relevant entities and risk coverage | More inspections automatically mean better supervision |
| Corrective actions issued | Material weaknesses identified | Every instruction represents a completed correction |
| Actions closed | Actions independently verified | Administrative closure equals operational success |
| Repeat findings | Previously inspected entities | Recurring weaknesses disappear from aggregate totals |
| Time to correction | Severity and operational constraints | Fast closure is always preferable to durable remediation |
| Supplier-related findings | Critical service dependencies | Each legal entity is an independent risk unit |
This is a proposed supervisory reporting framework. It would permit comparisons without assuming that authorities face identical populations or responsibilities.
The UK competition investigation is a concrete 2027 decision point
The CMA launched its strategic market status investigation into Microsoft’s business software ecosystem on 14 May 2026. Its published timetable identifies 13 February 2027 as the statutory deadline for issuing an SMS decision notice. An investigation is not a designation, and a designation would not itself prove that all competition concerns had been resolved. Microsoft’s business software ecosystem — Competition and Markets Authority — investigation opened May 2026. GOV.UK
This creates an observable policy branch. Measures affecting licensing, interoperability or customer choice could alter procurement conditions. Their practical value should be assessed through actual alternatives, contract terms and switching experience.
For EU buyers, the relevance is indirect. UK intervention does not automatically amend EU contracts, but developments in a shared software ecosystem may inform procurement and competition assessments elsewhere.
Public-sector implementation plans reveal different accountability mechanisms
France’s April 2026 roadmap provides for monthly interministerial monitoring. It also sets initial cryptographic inventory work for 2026–2027 and implementation objectives toward 2030. These are planned stages, not evidence that the transition has already been completed. Publication de la feuille de route des efforts prioritaires en matière de sécurité numérique de l’État 2026–2027 — ANSSI — April 2026. ANSSI
In an April parliamentary answer, the UK government identified initial institutional achievements and milestones due by April 2027. It stated that investment remained subject to business-case approval, without supplying the requested percentage committed in that answer. This does not establish the commitment position in October; it illustrates why milestone reporting and financial reporting must be read together. Government Cyber Action Plan: Written answer HL16287 — UK Parliament — April 2026. UK Parliament
The comparison concerns accountability rather than an unsupported ranking. France specifies a recurring coordination process; the UK exposes milestones to parliamentary scrutiny. Both still require evidence that corrections were delivered and funded.
Shared response capacity needs contracting evidence
ENISA describes a €36 million allocation supporting response and reporting under the EU Cybersecurity Reserve framework. A separate procurement notice seeks a framework involving three operators for services in nine Member States, with a maximum €18 million over four years. The notice remains marked “in progress.” EU Cybersecurity Reserve — ENISA — current programme description and Supporting ENISA for the provision of EU Cybersecurity Reserve services — ENISA — 2026 procurement notice. ENISA
The two amounts should not simply be added. A framework ceiling is also not guaranteed expenditure or proof that a specified number of experts can deploy immediately.
The operational test is availability under simultaneous demand: contractual response times, geographic coverage, specialist capacity and arrangements where several countries request assistance together. This is where pooled procurement can add value, but also where nominal capacity can exceed usable capacity.
Three operational pathways for 2026–2031
The following scenarios are analytical pathways. They can overlap across sectors and countries; no numerical probabilities are assigned.
| Pathway | Mechanism | Observable indicators | Principal consequence |
|---|---|---|---|
| Capability consolidation | Funding continues into maintenance; supervision verifies corrections; procurement supports recovery | Retained controls, successful exercises, fewer repeat findings | Better continuity despite continuing incidents |
| Uneven compliance | Better-resourced firms maintain capability while smaller organisations struggle with recurring costs | Unresolved actions, lapsed services, widening completion gaps | Persistent exposure concentrated in weaker organisations |
| Common-provider disruption | A shared service failure affects multiple customers whose alternatives are incomplete | Common dependencies, failed exit tests, constrained response capacity | Correlated interruption across firms or sectors |
The adverse pathway does not require a more sophisticated attacker. It can arise from a technical failure, a compromised administration service or an inability to restore a shared process. The distinguishing feature is correlated exposure.
Likewise, capability consolidation does not mean incidents disappear. It means organisations limit disruption, restore services and avoid repeating preventable failures.
The dated milestones and the analytical checkpoints
| Period | Documentary milestone or analytical checkpoint | Evidence that matters |
|---|---|---|
| Late 2026 | RRF payment closure; continuing programme implementation | Completed capability and identified maintenance budgets |
| January 2027 | Data Act switching-charge prohibition; ECCC call deadline | Contract compliance and subsequent awards |
| February 2027 | CMA statutory SMS decision deadline | Actual decision and subsequent measures |
| 2027–2028 | Proposed analytical checkpoint: first sustained-use assessments | Retention, restoration and withdrawal results |
| From 2028 | Proposed next EU budget period | Adopted instruments and accessible allocations |
| 2029–2030 | Proposed analytical checkpoint: mature operation | Repeat findings, staffing continuity and exercised alternatives |
| 2031 | Final horizon of this assessment | Comparable retained capability and business-interruption evidence |
The analytical checkpoints are recommendations for assessment, not official deadlines.
Key judgments
Funding continuity will determine whether initial improvements survive. The revised ECCC envelope demonstrates that allocations can change, while the open call demonstrates continuing investment opportunities. Enforcement will be most consequential where it verifies correction and recognises common dependencies.
What would change the assessment
Protected maintenance budgets, independently verified remediation and functioning alternatives would favour capability consolidation. Repeated funding interruptions, lapsed services and untested shared dependencies would favour the adverse pathways.
Open official record
The decisive records are post-2027 appropriations, operating commitments, completed corrective actions, Reserve contract awards and deployable capacity, and follow-up assessments of funded projects.
Chapter 8 — Policy options, measurable outcomes and final comparative assessment
Principal judgment. Italy should evaluate public cybersecurity support through retained operational capability, additional private investment and reduced business interruption. The strongest policy package combines proportionate diagnosis, implementation finance, practical skills, independent acceptance and recurring maintenance. European comparison provides design lessons, but the available record does not support a numerical ranking of national resilience.
Separate the objectives before allocating money
A programme can pursue several legitimate goals: helping firms acquire protection, supporting domestic suppliers, improving regulatory implementation or building shared response capacity. Problems arise when a measure designed for one objective is evaluated using another objective’s indicators.
| Objective | Appropriate intervention | Primary outcome | Misleading substitute |
|---|---|---|---|
| Correct basic business weaknesses | Small, targeted implementation support | Critical controls functioning | Total software purchased |
| Improve management decisions | Independent diagnosis and practical advice | Recommendations implemented | Reports produced |
| Strengthen industrial capability | Development, testing and market deployment | Sustained customers and maintainable products | Prototype count alone |
| Reduce common dependencies | Dependency mapping and continuity procurement | Tested alternatives | Number of contracting vendors |
| Improve public-service resilience | Maintenance and corrective programmes | Essential functions restored within requirements | Investment announced |
| Build response capacity | Contracted assistance and exercises | Available capacity under stress | Framework ceiling |
This separation should occur in programme design and reporting. Otherwise, a broad digitalisation budget can be described as cybersecurity spending, or an industrial development project can be judged by an incident-reduction outcome it was not designed to deliver.
A complete intervention should have distinct decision gates
The following is a proposed design for future support or complementary measures. It does not describe obligations already imposed on every Italian beneficiary.
| Gate | Required evidence | Funding decision |
|---|---|---|
| Establish the baseline | Existing systems, critical processes and operational weaknesses | Confirm the problem to be addressed |
| Define the intervention | Prioritised changes and responsible operator | Exclude unnecessary or incomplete purchases |
| Assess financing | Beneficiary contribution and operating-cost plan | Identify execution and continuation risk |
| Approve implementation | Eligible procurement and delivery plan | Commit support |
| Verify acceptance | Practical tests and resolved defects | Recognise operational delivery |
| Assess retention | Continued operation after an appropriate interval | Measure lasting value |
The process should be lighter for inexpensive, standard interventions and deeper for complex or critical projects. Proportionality is essential: a small improvement should not require the documentation of a major infrastructure contract.
Acceptance also needs independence. Where the same supplier recommends, sells and declares the successful implementation of a solution, the programme should identify which evidence is independently checkable. This does not imply misconduct; it addresses an incentive conflict.
Policy options and their implementation trade-offs
| Option | Responsible level | Expected effect | Burden and time to effect | Reversibility | Principal risk |
|---|---|---|---|---|---|
| Standard diagnostic route | Ministry/programme operator, with technical input | Improves prioritisation | Moderate setup; usable within a programme cycle | High | Assessments become a paperwork market |
| Capped advances for selected applicants | Funding authority | Reduces financing barriers | Requires controls and reconciliation | Moderate | Recovery where projects fail |
| Implementation-related skills support | Funding authority and qualified providers | Improves operation of funded systems | Delivery can begin alongside installation | High | Attendance substitutes for competence |
| Independent acceptance sampling | Programme operator | Detects ineffective installation | Requires testing capacity | High | Excessive delay or supplier influence |
| Maintenance and renewal support tied to need | Budget authority and programme operator | Improves retention | Requires recurring resources | Moderate | Permanent subsidy of commercially viable services |
| Shared services for small organisations | Regional or sector bodies | Distributes scarce expertise | Longer setup and procurement | Moderate | Creates a new concentration point |
| Portability and recovery schedules | Procurement authorities | Makes exit and restoration more workable | Contract preparation plus testing | High for future contracts | Formal rights remain technically unusable |
| Supplier concentration monitoring | National and EU authorities | Identifies common dependencies | Data collection and analysis | High | Incomplete reporting obscures actual concentration |
These are options, not expenditure commitments. Their feasibility depends on the applicable instrument, budget authority and procurement rules.
The most immediate improvements concern evidence and standardisation: consistent baselines, clearer acceptance tests and comparable reporting. Larger structural changes—shared services or recurring support—require an operating model and durable financing.
Financial design should expose the full cost of operation
The acquisition price is only one part of the economic commitment. Evaluation should record recurring charges, staff time, maintenance, testing and eventual replacement or exit.
A simple illustrative case shows why grant percentages can obscure the longer-term burden.
| Hypothetical five-year cost | Assumed amount |
|---|---|
| Initial implementation | €20,000 |
| Service and maintenance | €6,000 annually |
| Five years of recurring expenditure | €30,000 |
| Total undiscounted expenditure | €50,000 |
| Hypothetical support covering half the initial implementation | €10,000 |
| Beneficiary’s remaining expenditure | €40,000 |
| Support as a share of five-year expenditure | 20% |
Illustrative assumptions only; this is not an estimate of a national programme or market price. It excludes taxes, inflation, discounting and internal labour.
The policy implication is not that acquisition support lacks value. It is that a contribution described as “50%” can finance a much smaller share of the commitment required to maintain the capability.
Applicants should therefore identify how recurring costs will be financed. For public bodies, this requires coordination between investment approval and operating appropriations. For businesses, it requires an assessment of whether the service remains affordable after support ends.
Measure the beneficiary journey using separate denominators
Programme performance cannot be represented adequately by one beneficiary count. Applications, awards, payments and completed interventions describe different stages.
| Indicator | Proposed definition | Why it matters |
|---|---|---|
| Application rate | Applicants relative to an identified eligible population | Measures reach |
| Approval rate | Approved applications divided by complete applications | Identifies access and selection |
| Execution rate | Projects started divided by awards | Reveals financing or procurement failures |
| Completion rate | Accepted projects divided by projects due for completion | Measures delivery |
| Payment rate | Grants paid relative to amounts due | Measures administrative settlement |
| Retention rate | Functioning interventions at follow-up divided by interventions assessed | Measures persistence |
| Recommendation completion | Verified priority actions completed divided by priority actions due | Connects diagnosis to implementation |
| Repeat-defect rate | Previously corrected material defects recurring at follow-up | Tests durability |
The denominator must be printed with the result. “Ninety per cent completed” can be misleading if it refers only to the projects that remained in the programme after withdrawals.
Missing follow-up should also remain visible. Organisations that close, withdraw or fail to respond should not silently disappear from the retention calculation. Their status may be relevant to the programme’s actual reach.
Operational measures should correspond to business functions
The following measures provide a practical evaluation framework. They are not universal statutory thresholds.
| Capability | Proposed measurement | Verification method | Interpretation risk |
|---|---|---|---|
| Access control | Critical accounts covered by the required controls | Configuration review and sample tests | Coverage can omit important accounts |
| Asset visibility | Critical assets identified and assigned an owner | Inventory reconciliation | A larger inventory can reflect better discovery |
| Vulnerability management | Material weaknesses corrected within approved deadlines | Technical verification | Severity and compensating measures matter |
| Recovery | Critical functions restored within business-defined requirements | Restoration exercise | A small test may not represent full recovery |
| Incident response | Time to execute agreed containment actions | Exercise or incident review | Detection time and exercise design affect comparability |
| Supplier continuity | Critical external services with exercised arrangements | Joint test | Multiple suppliers may share infrastructure |
| Skills | Defined tasks completed correctly | Practical assessment | Attendance and confidence are weaker proxies |
| Portability | Required data exported and used in an alternative environment | Controlled migration test | Export alone does not recreate the workflow |
Business-defined requirements should be approved before testing. Moving the target after an exercise can convert a failed restoration into an apparent success.
Recovery should also be assessed at the level of the service. Restoring files is not sufficient if users cannot authenticate, interfaces do not work or staff lack the procedure required to resume operations.
Economic impact requires more than counting reported incidents
The appropriate economic measures include interruption duration, direct response costs, recovery expenditure and material effects on service delivery. They should distinguish observed expenditure from modelled consequences and avoid adding overlapping categories.
| Economic measure | Useful basis | Main limitation |
|---|---|---|
| Business interruption | Hours or days of affected critical operations | Partial disruption differs from complete shutdown |
| Direct response expenditure | Documented external and internal costs | Firms record internal costs differently |
| Recovery expenditure | Rebuild, restoration and replacement costs | Can overlap with response costs |
| Lost production or transactions | Documented missed output, with recovery considered | Deferred activity is not always permanently lost |
| Customer effects | Measured service delays or cancellations | Attribution may be difficult |
| Insurance recovery | Claims paid and retained loss | Coverage differs and payments can lag |
| Public-service impact | Unavailable functions and affected users | Monetary valuation may be inappropriate |
A fall in incident reports is not sufficient evidence of programme success. Better detection can increase reporting, while fewer reports can reflect weaker visibility. Conversely, more incidents can coexist with lower interruption if response improves.
Evaluation should therefore examine several outcomes together, with incident type and severity preserved. A single national total can conceal improvements in common events and continuing exposure to rarer, more disruptive failures.
Establish additionality through a credible comparison
The central fiscal question is whether public support changes behaviour beyond what beneficiaries would otherwise have done.
A phased programme can provide an opportunity to compare similar eligible firms entering at different times. Where demand exceeds capacity, a transparent allocation method may also support stronger evaluation, subject to the programme’s legal design. Neither approach automatically produces a valid causal estimate: comparable groups, timing and follow-up remain necessary.
| Evaluation approach | What it can establish | Essential condition |
|---|---|---|
| Before-and-after beneficiary assessment | Change within participating organisations | Consistent baseline and follow-up |
| Similar non-beneficiary comparison | Whether changes differ from wider trends | Credible comparability |
| Phased entry comparison | Effects before and after support becomes available | Timing is not driven by unmeasured risk |
| Independent technical sample | Whether interventions work | Representative selection |
| Administrative-cost analysis | Cost of delivering each completed intervention | Consistent cost accounting |
| Longitudinal follow-up | Whether capability persists | Withdrawals and missing observations tracked |
Before-and-after improvement alone does not establish additionality. Beneficiaries may have invested because of customer demands, regulation or a recent incident even without the grant.
This distinction affects policy choice. If support mainly reimburses investment already planned by well-prepared firms, its fiscal value differs from support that enables otherwise unaffordable corrections.
Procurement can strengthen competition while creating capability
The UK’s cloud intervention shows that competition policy and cybersecurity policy intersect through licensing, interoperability and customer choice. The CMA’s April 2026 statement records steps by providers to reduce barriers, while its subsequent investigation creates a further assessment process. Neither establishes that switching difficulties have disappeared. CMA announces package of actions on business software and cloud services — Competition and Markets Authority — April 2026. GOV.UK
For public procurement, competition should be evaluated through workable alternatives rather than bidder count alone. Specifications that unnecessarily reproduce one supplier’s architecture can narrow the market even where several resellers compete.
Conversely, mandatory diversification can increase complexity. The appropriate test is whether the additional provider creates usable continuity, improves negotiating conditions or reduces a material dependency. Purchasing a second service that staff cannot operate may increase cost without delivering those benefits.
Industrial-policy support should be conditional on maintainable deployment
The EU’s January 2026 cybersecurity package proposes a framework addressing ICT supply-chain risks and simplifying certification and compliance. Its proposed status must remain explicit; the announcement is not itself an enacted replacement regime. Cybersecurity Package: Questions & Answers — European Commission — January 2026. Shaping Europe’s digital future
A sound industrial assessment should examine more than origin or development expenditure.
| Industrial outcome | Evidence to require |
|---|---|
| Deployable product | Working installation in the intended environment |
| Independent assurance | Relevant evaluation with defined scope |
| Maintenance capacity | Supported versions, update process and sufficient technical staff |
| Commercial durability | Customers beyond the initial subsidised deployment |
| Interoperability | Documented interfaces and tested integration |
| Reduced critical dependency | Functionally adequate substitute for the identified dependency |
| Retained European capability | Engineering, support and control arrangements verified |
Public support can reasonably finance early deployment, but continued assistance should require evidence that the product is usable and maintainable. Otherwise, industrial policy may sustain a succession of demonstrations without creating a supplier capable of supporting essential operations.
Country-specific priorities for the final assessment
The following priorities are analytical recommendations derived from the programme evidence in the preceding pillar. They do not rank countries or imply that the recommended changes have already been adopted.
| Country | Priority for the next policy cycle | Evidence that would demonstrate progress | Principal trade-off |
|---|---|---|---|
| Italy | Connect acquisition to competence, acceptance and maintenance | Retained controls and participation by less-prepared firms | More verification can increase administrative cost |
| United Kingdom | Extend practical capability beyond assurance-driven supply chains | Smaller firms implementing and maintaining required controls | Broader assistance requires sustained financing |
| France | Connect diagnosis and sensitive-service requirements to executable investment | Recommendations completed and qualified services performing effectively | Stronger requirements can narrow available supply |
| Germany | Make advice-to-implementation access more consistent | Advisory users completing verified projects across jurisdictions | National consistency must accommodate regional delivery |
| Austria | Preserve the connection between advice and execution | Priority actions implemented and retained | Additional assessment can slow small interventions |
| Spain | Separate cyber outcomes from broad digital delivery | Cyber-specific controls and follow-up results | Greater detail increases reporting demands |
| Netherlands | Retain low-cost access while addressing financing uncertainty | Small firms completing relevant improvements | Easier access requires robust but proportionate checks |
| Finland | Link producer support to sustained use and customer capability | Maintained deployments and users operating solutions effectively | Innovation support cannot substitute for general business assistance |
| Ireland | Maintain a workable route from review to implementation and retesting | Diagnosed weaknesses corrected despite the closed grant | Continuity requires a successor financing mechanism |
Programme sources: Italy — MIMIT; United Kingdom — NCSC; France — France Num; Germany — Transferstelle Cybersicherheit; Austria — BMWET; Spain — Red.es; Netherlands — RVO; Finland — Traficom; Ireland — NCSC. www.mimit.gov.it
A practical sequence for Italian policy
| Proposed sequence | Main action | Decision enabled |
|---|---|---|
| During initial delivery | Record baselines, critical functions and underlying suppliers | Establish what support is intended to change |
| At acceptance | Verify installation and selected operational tests | Distinguish acquisition from capability |
| First follow-up | Assess retention, recurring costs and withdrawals | Identify continuation problems |
| Before further allocation | Analyse access, additionality and common dependencies | Redesign eligibility and delivery |
| Through 2031 | Maintain compatible outcome series | Assess durable economic value |
This sequence does not require postponing useful expenditure until an elaborate evaluation system exists. Essential data can be collected alongside delivery, with deeper testing applied to representative samples and higher-criticality projects.
The more consequential changes should depend on results. Expanding a programme is justified where it reaches constrained firms and produces retained capability. Where results show weak additionality or ineffective implementation, redesign should precede expansion.
Final comparative assessment
Italy’s principal weakness is the possibility that a broad purchase intervention will advance adoption faster than it advances the competence needed to supervise and maintain that adoption. The latest workforce and enterprise data make this a credible structural concern, but they do not establish that Italy suffers a precisely quantified resilience deficit relative to every comparator.
The European evidence supports a combined policy approach. Advice helps identify priorities; financing enables execution; practical skills sustain operation; independent tests establish whether the intervention works; procurement and competition measures reduce avoidable dependence. These functions require coordination, and their results should be assessed separately before being combined into an overall judgment.
The strongest claim supportable at the cutoff is therefore conditional: public investment can narrow Italy’s resilience gap if it finances and verifies continuing operational capability, while exposing the dependencies it creates. Allocated budgets, completed invoices, certificates and diagnostic reports are necessary evidence of activity, but none alone establishes that outcome.
Key judgments
The appropriate measure of success is a critical business or public function that remains protected, recoverable and affordable after initial support. Italy can improve its policy design by connecting purchase finance to those outcomes. European programmes provide useful components, while also revealing unresolved financing, access and dependency problems.
What would change the assessment
A consistent body of independently checked results showing additional investment, retained capability, shorter disruption and workable supplier alternatives would strengthen the positive judgment. Persistent expenditure without those results would support redesign rather than automatic continuation.
Open official record
The final comparative judgment remains constrained by the absence of compatible national data on retention, additionality, operational testing, interruption and common-provider exposure. Publishing those measures would permit a stronger assessment of value than a league table based on spending announcements.

















