Scope: This dossier examines public cybersecurity support, regulatory implementation and operational resilience in Italy, the United Kingdom, France, Germany, Austria, Spain, the Netherlands, Finland and Ireland, using official records available by 8 October 2026 and a strategic horizon extending to 2031.

Executive Summary / BLUF

Italy has established a substantial cybersecurity investment incentive and transposed NIS2 relatively early, but neither achievement establishes that supported organisations will become operationally resilient.
Its €150 million Cloud & Cybersecurity voucher combines security expenditure with broader digital modernisation.
The central weakness is the potential separation between subsidised technology purchases and the skills, governance, maintenance and recovery capabilities needed to use them effectively.
European alternatives offer useful design lessons: Dutch support explicitly includes awareness training and backup testing; Ireland links assistance to prior assessment; the UK emphasises baseline assurance and supply-chain governance.
Those countries also have weaknesses, including limited grant coverage, discontinued funding rounds and unfinished legislative reform.
France’s technological-sovereignty ambitions coexist with documented NIS2 transposition delays; Germany’s implementation also arrived after the European deadline.
A 2026 European Court of Auditors assessment identifies shortcomings in information sharing, implementation and performance monitoring across EU mechanisms.
The decisive policy question is whether public expenditure produces sustained, independently demonstrable reductions in disruption and loss.

Italy’s cyber funding buys systems. Resilience depends on who runs them.

Italy’s €150 million cloud and cybersecurity voucher confronts a contradiction that European funding policy has not resolved: public money can accelerate technological adoption without financing the competence and continuity that make it protective. The MIMIT programme reduces acquisition costs, but excludes training and purely theoretical assessments without implementation, while requiring beneficiaries to finance expenditure before reimbursement. Those choices favour projects that can be purchased and documented over capabilities that must be maintained and tested. The fiscal question is whether the state buys additional resilience or subsidises a change of supplier. The industrial question is whether the expenditure strengthens European capability or deepens dependence on shared infrastructure. Italy’s answer will emerge after applications open on 10 November 2026, when procurement decisions become recurring operating commitments.

The grant ceiling conceals the longer obligation

Under the MIMIT voucher, support covers 50% of eligible expenditure up to €20,000, with a minimum project of €4,000. The maximum contribution is reached at €40,000; a €60,000 eligible project receives an effective subsidy of 33.33%. These are acquisition incentives, not a commitment to meet half of a firm’s continuing security costs. Beneficiaries still have to fund the operation of what they purchase, and the first payment request cannot be submitted before three months have elapsed from award communication.

The territorial reservation of €71,065,813.34 represents 47.38% of the programme envelope, protecting expenditure plans in eight southern regions against unrestricted national competition. It does not establish that those regions will absorb the resources or retain the resulting capability. Technical and administrative costs can consume up to 2.5% of the envelope. The appropriate fiscal comparison is consequently between public expenditure and verified additional capability, rather than between the announced budget and invoices submitted.

The gap between adoption and operational resources is visible in two different statistical populations. ISTAT records intermediate or advanced cloud purchases by 68.1% of Italian enterprises with at least ten employees in 2025. Eurostat places ICT specialists at 3.8% of Italian employment, against 5% across the EU and 7.8% in Finland. These figures do not measure a cybersecurity performance gap, but they expose the burden placed on procurement and supervision when adoption rests on limited internal technical capacity.

The same constraint survives in a developed cybersecurity market. The UK’s September 2026 skills report records basic technical gaps in 57% of businesses, up from 49%, alongside an estimated cybersecurity workforce of approximately 145,900. Europe cannot assume that a larger commercial supply of protective services removes the need for competent customers. Outsourcing changes who performs the work; it does not settle who understands the service, approves its configuration or recognises its failure.

A crowded supplier catalogue can conceal a common dependency

The CMA’s July 2025 cloud investigation shows why the MIMIT purchasing model needs visibility below the contracting vendor. In its 2024 UK and EEA capacity measure, Microsoft accounts for 40–50%, AWS for 20–30% and Google for 10–20%. These ranges describe data-centre capacity, not Italian revenue or the market for every digital service. Their significance is structural: several application vendors can depend on the same infrastructure, leaving customers with more contracts but fewer independent routes to continuity.

ENISA’s NIS Investments 2025 report identifies the corresponding problem among managed operators. In its surveyed ICT service-management category, 43% reported no cybersecurity testing in the preceding year, and 45% took more than three months to apply critical patches to critical systems. The category includes managed service and managed security service providers. Buying professional support can improve a small firm’s access to expertise, but the purchase also imports the operator’s maintenance practices and its dependencies.

The procurement consequence for the MIMIT programme is to distinguish delivery from acceptance. An invoice establishes expenditure; it does not establish that privileged access is controlled, that a backup restores the relevant business process or that a supplier can be replaced. Public support would produce stronger evidence of value if acceptance included proportionate operational tests and disclosed the underlying operator of a critical service. Otherwise, the programme risks rewarding a visible purchase while leaving its most consequential dependency outside the evaluation.

Europe is removing exit charges, not the engineering cost of exit

The Data Act prohibits switching charges within its scope from 12 January 2027. The regulation distinguishes those charges from ordinary service fees and early termination penalties, and it does not eliminate every cost of migration assistance or redesign. A legal right to move is therefore economically useful only where the customer has usable data, documentation and an alternative capable of reproducing the necessary function. Portability belongs in the purchasing decision, before a firm discovers the practical cost of leaving.

The UK’s competition process addresses a related constraint through Microsoft’s business software ecosystem. The CMA opened its strategic market status investigation on 14 May 2026, with a statutory decision deadline of 13 February 2027. That is an investigation, not a designation or a completed remedy. Its relevance to European procurement lies in whether licensing and interoperability conditions create workable alternatives; UK intervention does not automatically change an EU customer’s contract.

DORA’s first list of 19 critical ICT third-party providers, published in November 2025, recognises that systemic dependence extends beyond cloud infrastructure. Oversight can improve scrutiny of provider governance and risk management, but designation does not certify that a customer has no residual exposure. For Italy, the external constraint is consequently both commercial and supervisory: national purchase incentives operate inside service chains whose concentration and contractual conditions cannot be corrected by a voucher alone.

Cyber appropriations compete with the digital ambitions they must protect

The ECCC’s consolidated work programme adopted in July 2026 reduced its indicative 2025–2027 cybersecurity envelope from €390 million to €355 million, reallocating €35 million to AI Gigafactories. The reduction does not establish a fall in all European cyber spending. It demonstrates that an announced security allocation can be redirected toward another digital priority, even while organisations are expected to strengthen their protection. A beneficiary’s maintenance plan cannot safely depend on the assumption that the next funding round will preserve the previous allocation.

The ECCC call opened in September 2026 provides an estimated €96 million across deployment and capacity topics, with applications due by 14 January 2027. It offers continuing investment opportunities rather than a universal purchase entitlement. Its delivery problem resembles Italy’s at a different scale: shared tools and platforms must reach ordinary firms, remain usable and acquire an operating budget after the funded project. A completed development project is not evidence of sustained customer capability.

The Recovery and Resilience Facility adds a separate fiscal boundary. Its milestone completion deadline passed on 31 August 2026, final payment requests were due by 30 September, and Commission payments must conclude by 31 December. Those deadlines do not govern Italy’s separate voucher instrument. They do illustrate the wider European transition from temporary investment to continuing operation. The proposed 2028–2034 EU budget is not a settled cybersecurity appropriation on which firms or public bodies can book their future running costs.

National programmes leave different parts of the capability chain unpaid

France’s Diagnostic Cybersécurité finances a structured diagnosis and prioritised recommendations; Italy’s MIMIT voucher excludes a purely theoretical assessment without implementation. The French model addresses the risk of buying the wrong intervention, but recommendations still require finance. Austria’s KMU.DIGITAL normally connects supported consultation to implementation, while the Netherlands’ Mijn Cyberweerbare Zaak includes awareness training and risk assessment among eligible measures. These are alternatives for closing a capability gap, not evidence that any country has eliminated it.

Ireland’s completed NCC-IE Cyber Security Improvement Grant connected a prior Enterprise Ireland review to implementation and post-implementation retesting. Its closure leaves the importance of that sequence intact while exposing the financing question: a review does not correct the weakness it identifies. Germany’s publicly funded Transferstelle Cybersicherheit reduces the cost of initial guidance, but external commercial assistance can still incur charges and financial access varies geographically. Each model removes a particular barrier while leaving another to the beneficiary.

Italy’s choice should therefore be to connect the MIMIT acquisition subsidy to practical competence, proportionate acceptance and a credible maintenance commitment. This need not impose a major-project bureaucracy on every small purchase. Standard diagnostic schedules and sample-based verification can concentrate scrutiny where business functions are critical. The public objective is to establish that the intervention works and persists, rather than to maximise the documentation surrounding it.

The next two years will transfer the bill to operators and customers

Over the 12–24 months following October 2026, the MIMIT programme’s applications and awards will begin to expose whether its beneficiaries can execute and maintain their projects. The decisive results will be completion, withdrawal, continuing operation and successful restoration, with separate denominators for each. A high approval rate will mean little if liquidity constraints prevent implementation; a high spending rate will mean little if the resulting services lapse or cannot recover a critical process.

The Data Act’s January 2027 switching provisions and the CMA’s February 2027 decision point will make supplier choice more observable, but neither will supply the staff needed to operate an alternative. If Italy leaves competence and verification outside the funded intervention, small firms will pay through additional advisory and operating expenditure or through dependence they cannot effectively supervise. Public bodies will face the same choice through maintenance appropriations and the cost of interrupted services.

The final fiscal test for the MIMIT voucher is whether public support enables a business function to remain protected, recoverable and affordable after the initial contribution. Without that evidence, taxpayers finance acquisition while firms, their customers and users of public services retain the cost of failure. Over the next two years, reporting retained capability alongside expenditure will determine whether Italy can justify continuation of the instrument—or must redesign it before committing another funding cycle.


Navigational Index

Pillar I — Regulation, institutions and the changing threat

  • Chapter 1: Cybersecurity as an economic-security obligation: NIS2, the Cyber Resilience Act and institutional responsibilities.
  • Chapter 2: Artificial intelligence, legacy systems and the distinction between attack activity and economic damage.

Pillar II — Public investment and national policy comparisons

  • Chapter 3: Italy: voucher design, territorial allocation, accessibility and implementation risks.
  • Chapter 4: The United Kingdom, France and Germany: assurance, sovereignty and regulatory execution.
  • Chapter 5: Austria, Spain, the Netherlands, Finland and Ireland: implementation timing and alternative support models.

Pillar III — Structural contradictions and policy choices

  • Chapter 6: Skills, procurement, cloud concentration, industrial dependencies and supply-chain exposure.
  • Chapter 7: The 2026–2031 outlook: funding continuity, enforcement and operational scenarios.
  • Chapter 8: Policy options, measurable outcomes and final comparative assessment.

Master Abstract

Europe’s central problem is converting expenditure into capability

European cybersecurity policy increasingly combines legal obligations with financial assistance. However, these instruments address different objects: organisational security, the cybersecurity of products, the development of defensive technologies and collective incident response. Treating them as interchangeable obscures both the beneficiaries and the outcomes that governments should measure.

The strongest official evidence of this implementation problem comes from the European Court of Auditors’ Special Report 19/2026. The auditors concluded that EU actions only partially facilitate the detection of and response to significant and large-scale incidents. They identified limited information sharing, reporting weaknesses, substantial implementation delays and shortcomings in performance monitoring. In their sample of eleven projects, four were assessed as satisfactory, two showed weaknesses, three were unsatisfactory and two were too early to assess. This is a bounded audit sample, not an estimate of the failure rate of all European cybersecurity programmes. Nevertheless, it directly challenges any assumption that a funded project is equivalent to an operational capability. eca.europa.eu

The resulting analytical judgment is that European policy should be evaluated through the capabilities it creates and sustains: effective access controls, timely remediation, tested recovery, trained management, usable incident reporting and dependable suppliers. Expenditure, contracts and purchased licences are intermediate outputs.

Italy has a credible intervention, but its purpose is broader than cybersecurity

Italy’s MIMIT programme provides €150 million, including €71,065,813.34 reserved for expenditure plans in eight southern regions. Assistance covers up to 50% of eligible expenditure, capped at €20,000, with a minimum expenditure plan of €4,000. Applicants must have contracted connectivity of at least 30 Mbps download speed. Formal applications open on 10 November 2026, following pre-completion from 20 October, and close on 20 January 2027 unless resources are exhausted. These are programme allocations and prospective application dates, not evidence of money already disbursed. mimit.gov.it

The intervention is explicitly designed to support digital transition and more advanced cloud and cybersecurity solutions. Its breadth therefore reflects its stated purpose. The analytical problem arises when this mixed instrument is evaluated as if every euro financed a security control. A cloud accounting system, an enterprise-management application and a vulnerability-management service can all contribute to digital modernisation, but their security effects require different evidence. mimit.gov.it

Italy nevertheless deserves recognition for its legislative timing. Legislative Decree 138/2024, transposing NIS2, entered into force on 16 October 2024. This distinguishes Italy from countries whose transposition followed considerably later. Legal adoption, however, must be distinguished from the subsequent implementation, supervision and effectiveness of organisational controls. gazzettaufficiale.it

Funding channels must remain separate

Three verified envelopes illustrate why a single headline total can mislead.

Italy’s voucher supports qualifying purchases by Italian SMEs and self-employed professionals. SECURE’s second call provides €11.5 million across eligible European micro, small and medium-sized enterprises, with 50% co-financing and a maximum grant of €30,000. Its purpose is to support Cyber Resilience Act compliance, and applications are evaluated for relevance, impact and implementation quality. It is not a general cybersecurity reimbursement programme for every SME. secure4sme.eu

The ECCC’s separate €96 million call supports seven European deployment priorities, including AI-based security, SME solutions, preparedness, cable hubs, national coordination centres, legislative implementation and dual-use technologies. Applications run until 14 January 2027, and security eligibility restrictions apply. This envelope is European, competitive and topic-specific; it is not an additional Italian allocation. cybersecurity-centre.europa.eu

Calculated from the three published envelopes, their arithmetic sum is €257.5 million. That figure describes three distinct funding opportunities. It does not measure Italian cybersecurity expenditure, immediate business assistance, committed grants or realised investment.

AI increases urgency without establishing a universal attack multiplier

The UK government’s July 2026 parliamentary answer attributes to the NCSC an assessment that AI will make elements of cyber intrusion more effective and efficient. It also reports an assessment that, by 2028, attackers are highly likely to use AI capabilities against known vulnerabilities in legacy critical infrastructure. These are attributed threat assessments with specified horizons. They do not establish a uniform numerical increase across all countries, sectors or attack types. UK Parliament

The UK’s 2025/2026 Cyber Security Breaches Survey found that 43% of businesses identified a breach or attack in the preceding twelve months, unchanged from the previous survey. The survey explicitly covers incidents respondents detected and were willing to report. Consequently, stable reported prevalence does not establish stable severity, and lower reported prevalence among smaller firms may partly reflect weaker detection. GOV.UK

Spain’s INCIBE recorded 122,223 cybersecurity incidents in 2025, 26% more than in 2024, in data consolidated on 9 February 2026. This is an institutional incident count, whereas the UK figure is a survey percentage of organisations. The two cannot support a national security ranking. incibe.es

For public policy, the relevant implication is that faster hostile activity increases the value of timely patching, dependable identity controls and recovery preparation. AI-branded defensive procurement should still demonstrate additional benefit over those foundations.

National comparisons reveal different strengths and different failures

The following comparison concerns verified policy architecture. It does not assign a numerical ranking to national cybersecurity performance.

CountryVerified policy positionComparison with ItalyPrincipal contradiction or implementation problem
ItalyNIS2 transposition entered into force in October 2024; the MIMIT voucher supports cloud and cybersecurity investment.Combines an established legal framework with substantial purchase assistance.Investment eligibility does not itself demonstrate effective configuration, sustained operation or recovery capability.
United KingdomCyber Essentials forms part of the government’s business-security approach. The Cyber Security and Resilience Bill remained a parliamentary bill in the retrieved record; its latest listed version was amended in Lords Grand Committee on 7 September 2026.Places greater emphasis on a recognisable baseline and supply-chain assurance.A baseline certificate cannot provide sufficient assurance for every supplier or critical service; proposed legislative expansion must remain distinct from enacted obligations. GOV.UK
FranceThe 2026–2030 strategy prioritises skills, resilience, threat disruption and reduced technological dependencies. France was included in the Commission’s July 2026 referral for failure to notify complete NIS2 transposition.Provides an explicit national link between cybersecurity, industrial capacity and freedom of action.Strategic ambition and institutional expertise have coexisted with legislative delay. The July referral is a dated finding, not proof of every subsequent development. SGDSN
GermanyThe NIS2 implementation law entered into force on 6 December 2025 and extended requirements for businesses and federal administration. DIN SPEC 27076 provides a structured security-assessment approach for smaller businesses.Offers a useful model for diagnosing needs before specifying investment.A stronger statutory framework still requires affordable expertise and implementation capacity among newly covered organisations. Bundesregierung
AustriaNISG 2026 establishes a new federal cybersecurity authority; the examined substantive provision entered into force on 1 October 2026.Makes national coordination and leadership responsibility explicit.The immediate test is the new institution’s staffing, procedures and practical support, rather than its formal creation. bmi.gv.at
SpainINCIBE provides incident-response capability. The government described the cybersecurity governance legislation as under preparation in March 2026; Spain was included in the July NIS2 referral.Combines business-facing support with a large incident-response function.Operational activity does not remove legislative implementation gaps. Historical digitalisation programmes must also be separated from currently open assistance. 17/03/2026 [Consejo de Ministros/Referencias]
NetherlandsThe Cyberbeveiligingswet and critical-entity resilience law entered into force on 15 August 2026. The 2026 small-business subsidy includes awareness training and backup testing.Offers a direct contrast to Italy’s exclusion of training from its voucher.The subsidy’s €1 million envelope and €1,250 applicant cap support limited interventions; allocation also follows application order. Rijksoverheid.nl
FinlandNIS2 obligations began on 8 April 2025. Traficom describes separate supervisory responsibilities and CSIRT assistance, with safeguards governing voluntarily supplied information.Provides an institutional lesson on maintaining trust in technical incident assistance.Sector-specific supervision still requires coordination where an organisation operates across several sectors. Traficom
IrelandEnterprise Ireland advertises an 80%-funded €3,000 security review. The separate NCC-IE improvement grant has finished; its official page reports €1,743,513.22 awarded to 50 SMEs in 2024/2025.Demonstrates an assessment-before-remediation model and higher co-financing.A useful programme design does not guarantee continuing availability. The improvement grant is closed and additional rounds will not open. Enterprise Ireland

The Netherlands illustrates the importance of updating a legal comparison through successive records. Its inclusion in the Commission’s July referral cannot justify describing Dutch implementation as still absent after the government’s August commencement announcement.

Spain illustrates a different temporal problem. Red.es’ current Kit Digital chronology records that the five historical calls closed during 2024–2025. Continuing implementation, reporting and evaluation should not be confused with a newly open application window. kitdigital

Italy’s most consequential contradictions

Technology assistance without funded training. MIMIT’s FAQ excludes training, including training content delivered through cloud e-learning platforms. It also clarifies that supplier certifications concern the supplier and need not necessarily cover the subsidised product or service. These distinctions matter: catalogue admission is a funding-eligibility condition, not comprehensive assurance that a specific deployment is secure. Risposte alle domande frequenti (FAQ)

The training exclusion is a programme-level weakness, rather than proof that all Italian cybersecurity policy neglects skills. SECURE’s second-call documentation expressly includes CRA requirements training and technical cybersecurity training. The contradiction is therefore between complementary instruments: the broadly accessible purchasing incentive excludes an activity that the more specialised product-compliance programme recognises as necessary. Call2

Application speed versus security need. The August 2026 implementing decree requires applications to be examined in chronological order. It also states that disbursement cannot be requested before three months after notification of the award, and the first instalment requires at least 50% of the expenditure plan to have been incurred. These rules can favour applicants with administrative readiness and available cash over equally vulnerable organisations lacking those resources. That distributional effect is a design risk, not an observed outcome of a window that has yet to open. mimit.gov.it

Modernisation versus sustained protection. The underlying ministerial decree supports new or substantially improved solutions and excludes equivalent replacements and certain expansions of existing licences. Additionality protects public money from simply financing routine purchases. However, security also depends on maintaining controls as organisations grow. The policy trade-off is between demonstrating a new investment and sustaining an existing, effective protective capability. mimit.gov.it

Territorial cohesion versus risk targeting. Calculated from MIMIT’s published allocation, the southern reserve represents approximately 47.38% of the programme. A territorial reserve can support cohesion, but geography does not establish cyber exposure. Evaluation should therefore distinguish territorial distribution from security outcomes and examine whether vulnerable firms within each allocation can actually access assistance.

National sovereignty versus procurement assurance. A subsidised cloud migration can improve security where it replaces poorly maintained infrastructure. It can also create reliance on a provider’s identity systems, availability, support and exit arrangements. The appropriate policy response is to examine these dependencies explicitly. Hosting location, supplier certification, ownership and operational independence are different attributes.

Product compliance and organisational resilience operate on different clocks

The CRA’s manufacturer-reporting obligations have applied since 11 September 2026. Manufacturers must report actively exploited vulnerabilities and severe product-security incidents, with an initial warning within 24 hours and a fuller notification within 72 hours. Final-report deadlines differ according to the event. Shaping Europe’s digital future

Most CRA obligations apply from 11 December 2027. Article 13 also creates a lifecycle vulnerability-handling requirement: the support period must generally be at least five years, with an exception where the product’s expected use is shorter. Accordingly, a short grant-funded compliance project may help establish processes but cannot substitute for the manufacturer’s continuing responsibility. EUR-Lex

NIS2 principally addresses covered organisations’ risk management, reporting and supervision. The Commission describes a reporting sequence of 24-hour early warning, 72-hour notification and a subsequent final report. An organisation purchasing a CRA-compliant product does not thereby satisfy all its organisational responsibilities. Similarly, a company outside direct NIS2 coverage may face security requirements from customers whose supply chains are regulated. Shaping Europe’s digital future

This distinction is particularly consequential for SMEs: assistance depends on the programme’s eligibility rules, while legal and contractual responsibilities depend on the firm’s activities, products and relationships. The populations overlap only partly.

Key Evidence Table

All monetary values below are nominal euros. Funding envelopes, grant ceilings, awards and incident statistics are deliberately kept separate.

IndicatorValue/statusReference dateDefinition/scopeIssuerExact source
Italian voucher allocation€150 million; maximum €20,000 per beneficiary; up to 50% supportApplication window November 2026–January 2027Mixed cloud and cybersecurity purchasing incentiveMIMITSostegno alla domanda di servizi di cloud computing e cyber security. mimit.gov.it
SECURE second call€11.5 million; maximum €30,000; 50% co-financing1 October–11 December 2026Competitive support for eligible European SMEs’ CRA complianceSECURE consortiumSecond SECURE Open Call. secure4sme.eu
ECCC deployment call€96 million1 September 2026–14 January 2027Seven European cybersecurity deployment topicsECCCNew ECCC call for proposals under the Digital Europe Programme is open for applications. cybersecurity-centre.europa.eu
Dutch small-business subsidy€1 million; maximum €1,250; 50% support7 September–30 November 2026Specified controls, assessments and awareness trainingNetherlands NCSCMijn Cyberweerbare Zaak. NCSC
Irish improvement-grant awards€1,743,513.22 to 50 SMEs; programme finished2024/2025 awardsReported awards under a closed remediation schemeIreland NCSC / NCC-IENCC-IE Cyber Security Improvement Grant. ncsc.gov.ie
UK identified breaches or attacks43% of businesses2025/2026 survey; preceding twelve monthsSurvey prevalence, subject to detection and reporting limitationsDSIT / Home OfficeCyber security breaches survey 2025/2026. GOV.UK
Spanish incident activity122,223 incidents; 26% annual increaseCalendar 2025; consolidated February 2026INCIBE institutional incident countINCIBEBalance de Ciberseguridad 2025. incibe.es

The Italian and Dutch envelopes cannot establish relative national effort without reconciling programme scope, eligible populations, other support instruments and actual expenditure. The UK and Spanish threat statistics likewise measure different phenomena.

Competing Explanations or Pathways

The evidence supports three possible implementation pathways. They may coexist across sectors and regions; no numerical probabilities are assigned.

PathwayMechanismEvidence that would support itEvidence that would weaken it
Sustained resilience improvementPublic support funds prioritised controls, competent implementation and continuing maintenance.Retested controls remain effective after funding; recovery exercises meet business requirements; suppliers remediate vulnerabilities promptly.Purchased tools remain unused, poorly configured or unsupported.
Compliance centred on documentationOrganisations optimise for applications, certificates and audit files while operational weaknesses persist.Reported compliance rises without improvement in recovery or remediation; repeated incidents exploit unresolved weaknesses.Independent technical testing demonstrates durable improvements.
Uneven adoption and dependencyBetter-resourced applicants obtain assistance while vulnerable firms remain excluded or become reliant on services they cannot sustain.High uptake among administratively mature firms, affordability problems after support ends, concentration among a few providers.Vulnerable first-time adopters obtain support and sustain controls at manageable cost.

The central judgment would strengthen if programmes publish verified operational outcomes. It would weaken if assistance principally produces transactions and compliance documentation without durable capability.

Principal Gaps and Watch Indicators

Consequential questionRecord or observation neededDecision implication
Who receives Italy’s voucher?Award and payment records by firm size, region, sector and prior security maturityDetermines whether support reaches vulnerable organisations or predominantly capable applicants.
Does implementation improve protection?Before-and-after assessments, independent retesting and recovery exercisesDistinguishes purchased technology from functioning controls.
Can beneficiaries sustain services?Renewal costs, staffing arrangements and control performance after subsidised periodsTests whether improvements survive the funding cycle.
Does the supplier catalogue preserve competition?Award concentration, comparable pricing and switching arrangementsIdentifies dependence and potential distortion without assuming either has occurred.
Have France and Spain completed the outstanding legislative steps?Promulgated national instruments and updated Commission notification recordsResolves the gap between the July referral and the cut-off date.
Can Austria’s new authority perform its responsibilities?Staffing, operational procedures, reporting performance and supervisory activityTests institutional execution following October commencement.
Are European coordination mechanisms becoming operationally effective?Follow-up to the ECA’s recommendations and project performance recordsMeasures progress beyond the creation of additional structures.
Does AI alter realised loss?Consistently defined incident severity, disruption and loss seriesSeparates greater hostile activity from greater economic damage.

A defensible programme evaluation should treat expenditure and application volume as delivery indicators. It should assess security outcomes separately, using controls and recovery requirements appropriate to the organisation’s actual risks.

Visualisation — The funding and compliance timing gap

The component below shows verified sequencing. It does not imply that a funding deadline is a payment date or that one programme finances every obligation.

Obligations precede some funding decisions

As of 8 October 2026. Orange: legal milestones. Blue: funding milestones. Events are ordered by date; vertical spacing is not a time scale.

11 September 2026 — Reporting applies

CRA manufacturer reporting obligations begin.

1 October 2026 — SECURE opens

Second call opens for eligible SME product-compliance projects.

10 November 2026 — Italian applications open

Formal submission begins for the MIMIT voucher.

14 January 2027 — ECCC call closes

European deployment proposals reach their submission deadline.

11 December 2027 — Main CRA obligations apply

Most product requirements become applicable.

Implication: organisations must meet applicable obligations independently of whether assistance is awarded.

Sources: European Commission: CRA reporting; SECURE: second call; MIMIT: voucher; ECCC: deployment call; CRA: Article 71.

Pillar I — Regulation, institutions and the changing threat

Chapter 1 — Cybersecurity as an economic-security obligation: NIS2, the Cyber Resilience Act and institutional responsibilities

Principal judgment. Europe’s cybersecurity framework increasingly makes the continuity of economic and public services a responsibility of management, manufacturers and supervisory authorities. Italy’s central challenge is to turn these responsibilities into demonstrable operational capability: functioning recovery arrangements, controlled supplier access, timely remediation and decisions that executives can take during disruption. Registration, documentation and procurement are necessary inputs; their economic value depends on whether services withstand an incident.

The comparative question is therefore broader than which country has adopted legislation first. It concerns whether national institutions connect supervision, technical assistance, product security and business continuity effectively. A central authority can reduce ambiguity but become overloaded. A distributed system can provide sector expertise but generate inconsistent expectations. Neither institutional design establishes effectiveness without evidence of implementation.

Evidence and legislative status checked against the official record available on 8 October 2026. Publication dates and underlying observation periods are distinguished below.

The regulatory division of labour

NIS2, the Cyber Resilience Act and DORA address different parts of the same dependency chain. Confusing their functions creates two problems: organisations may duplicate compliance work unnecessarily, or assume that another actor’s compliance discharges their own responsibility.

InstrumentMain object of regulationPrincipal responsibilityEconomic-security functionWhat it does not establish
NIS2Security and continuity of covered organisations’ network and information systemsEssential and important entities, their management and national competent authoritiesReduce disruption of services and propagation through interconnected sectorsThat every supplier is directly covered, or every compliant organisation can withstand every attack
Cyber Resilience Act — CRAHardware and software products with digital elements made available on the EU marketManufacturers and other relevant economic operatorsImprove security throughout the product lifecycle and reduce vulnerabilities entering supply chainsThat installing a compliant product makes an organisation’s architecture, permissions or recovery arrangements secure
DORADigital operational resilience of the financial sectorFinancial entities, financial supervisors and oversight authorities for designated critical ICT providersControl ICT disruption, testing and third-party dependence in financeThat every ICT incident is malicious, or every provider receives direct European oversight
Cyber Solidarity ActCollective detection, preparedness and response capacityEuropean and national institutions, with participating service providersMobilise shared capabilities when incidents exceed individual capacityA standing entitlement for every business to receive unrestricted incident-response assistance
EU cyber crisis blueprintCoordination during large-scale incidents and crisesMember states and relevant European networks and institutionsConnect technical, operational and political crisis managementA European command structure replacing national responsibility

Sources: European Commission, NIS2 FAQs; European Commission, CRA legislative summary; ESMA, Digital Operational Resilience Act; Council, adoption of the cybersecurity package, 2 December 2024 and EU cyber crisis blueprint, 6 June 2025. Shaping Europe’s digital future

Analytical implication. A manufacturer, a managed service provider and its customer can all have relevant obligations, but those obligations attach to different activities. The manufacturer addresses product vulnerabilities. The provider manages its service and access arrangements. The customer must understand how failure of either affects its own essential functions.

This division becomes economically significant when contracts divide responsibility more narrowly than the service actually operates. A supplier may promise infrastructure availability while excluding application recovery; another may manage applications while excluding identity administration. The customer still needs an integrated recovery sequence.

Italy: management accountability must reach operational decisions

Article 23 of Italy’s Legislative Decree 138/2024 requires the administrative and management bodies of covered entities to approve how cybersecurity risk-management measures are implemented, oversee relevant obligations and undertake cybersecurity training. They must also receive periodic—or, where appropriate, timely—information about incidents and notifications.

This establishes a governance responsibility above the technical team. Its practical meaning is that executive decisions about investment, supplier dependence and tolerated disruption must be informed by cybersecurity risk.

Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 23 — administrative and management bodies, published 1 October 2024. gazzettaufficiale.it

The following table translates that responsibility into evidence a board or public-sector leadership team should request. These are analytical implementation criteria, rather than additional statutory requirements.

Management decisionEvidence needed to make it credibleWeak substituteConsequence of the weakness
Approve risk treatmentNamed services, dependencies, exposure and accountable ownersApproval of a generic security policyLeadership cannot identify which operational risk it has accepted
Approve recovery arrangementsA tested sequence for restoring identity, infrastructure, applications and dataConfirmation that backups existBackups may be available while the service remains unusable
Accept a critical supplierAccess boundaries, incident cooperation, subcontractor visibility and an executable exit planCertification or questionnaire aloneAssurance does not reveal dependence on a shared failure point
Accept an unsupported system temporarilyCompensating controls, funding, replacement deadline and escalation conditionsRepeated annual risk acceptanceTemporary exceptions become permanent exposure
Authorise emergency containmentPre-agreed authority to isolate systems or suspend operationsA contact listDecisions stall while the incident spreads
Assess improvementService recovery results, remediation completion and recurrenceSpending totals and tools purchasedActivity is mistaken for reduced risk

The contradiction is particularly acute where cybersecurity leaders carry responsibility for explaining risk but cannot influence procurement, staffing or service architecture. Formal accountability will have limited operational effect if the budget owner, system owner and risk owner cannot resolve disagreements before a crisis.

For Italy, a meaningful supervisory question is therefore whether management can show how a known weakness was treated, including why a delay was accepted, which interim protections exist and when the decision will be revisited.

Proportionality does not remove the obligation to understand consequences

Italy’s Article 24 requires appropriate and proportionate technical, operational and organisational measures. The assessment includes exposure, organisational size, likelihood, severity and social and economic impact. Its minimum areas include continuity, supplier security, vulnerability management, effectiveness assessment, training, access control and authentication.

The law also requires consideration of direct suppliers’ vulnerabilities and cybersecurity practices. Procurement therefore falls inside risk management: the quality of the supplier relationship matters alongside the purchased technology.

Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 24 — cybersecurity risk-management measures. gazzettaufficiale.it

Analytical judgment. Proportionality should change the method and scale of implementation; it should preserve the ability to explain the risk. A smaller organisation may reasonably use a managed service instead of maintaining its own security operations centre. It still needs to know who can disconnect compromised access, how essential data will be recovered and whether its provider can support several affected customers simultaneously.

There is also a supply-chain asymmetry. A small supplier outside direct regulatory scope may be indispensable to a large regulated customer. Contractual demands can transmit security expectations downstream, but this may produce duplicated questionnaires and costs without supplying the smaller firm with implementation capability.

Reporting clocks: similar numbers, different legal triggers

A recurring compliance error is to treat every “24-hour” or “72-hour” requirement as the same obligation. The responsible actor, triggering event and final-report deadline differ.

Reporting obligationTriggerResponsible actorInitial stagesFinal stage
Italian NIS frameworkAwareness of a significant incident affecting service provisionCovered essential or important entityEarly notification within 24 hours; incident notification within 72 hoursGenerally within one month of the incident notification, with provisions for continuing incidents
Italian trust-service exceptionSignificant incident affecting the provision of trust servicesRelevant trust-service providerThe incident-notification deadline is 24 hoursApplicable subsequent reporting requirements remain relevant
CRA: exploited vulnerabilityAwareness of an actively exploited product vulnerabilityManufacturerEarly warning within 24 hours; notification within 72 hoursWithin 14 days after a corrective measure becomes available
CRA: severe product-security incidentAwareness of a severe incident affecting product securityManufacturerEarly warning within 24 hours; notification within 72 hoursWithin one month of the 72-hour notification

Sources: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 25 — incident notification; European Commission, CRA reporting obligations, updated 11 September 2026. gazzettaufficiale.it

The operational consequence is that reporting readiness requires a classification process. Someone must determine which services and products are affected, which entity holds the obligation and when sufficient awareness arose. Waiting for complete forensic certainty can undermine early reporting; premature certainty can contaminate subsequent analysis.

Italy’s Article 25 also provides that notification itself does not expose the reporting entity to greater liability than that arising from the incident. That provision should not be interpreted as immunity from underlying non-compliance. Its purpose must be distinguished from the separate question of whether safeguards were adequate.

CRA: lifecycle responsibility changes procurement economics

The CRA’s central economic effect is to make product support a matter of security and market responsibility. Article 13 ties the support period to expected use and establishes a minimum of five years, except where expected use is shorter. A product expected to remain in service longer requires consideration of that longer use.

A separate provision requires security updates issued during the support period to remain available for at least ten years after issue, or the remainder of the support period, whichever is longer. Continued availability of an issued update is different from continued development of new updates.

Source: Regulation (EU) 2024/2847 — Cyber Resilience Act, Article 13, adopted 23 October 2024. EUR-Lex

This distinction matters for industrial and public-sector purchasing. A device may remain physically useful after support expires, while its continuing operation generates replacement, isolation or maintenance costs that were absent from the original procurement calculation.

Procurement issueDecision consequenceContradiction to resolve
Product life exceeds support lifeBudget for replacement, isolation or supported maintenanceThe lowest purchase price may generate the highest later security cost
Updates exist but deployment is difficultEvaluate testing, downtime and compatibility requirementsManufacturer remediation does not establish successful customer remediation
Essential functions depend on remote processingExamine the complete product-service dependencyThe local device may appear resilient while its remote dependency is unavailable
Third-party components enter the productRequire visibility sufficient to manage relevant dependenciesProduct branding can obscure common components used across suppliers
Conformity assessment is completedContinue operational monitoring and risk assessmentConformity is a point of assurance, not a guarantee against future vulnerabilities
An existing product is substantially modifiedReassess the regulatory position and responsibilityMaintenance, integration and modification can change who bears relevant duties

The Commission’s 27 July 2026 guidance addresses scope, remote processing, open-source software, substantial modification, support periods and reporting through 67 practical examples. It is explicitly non-binding. This is an implementation aid; it does not replace the regulation.

Source: European Commission, new guidance supporting CRA implementation, 27 July 2026. Shaping Europe’s digital future

Two other distinctions prevent overstatement. Products supplied outside commercial activity are treated differently from products made available on the market; open-source software stewards have a separate regime. Equally, CE marking does not mean every covered product has undergone the same independent assessment: the applicable conformity route depends on product classification and the relevant conditions.

Source: European Commission, CRA legislative summary — scope and conformity assessment, retrieved 8 October 2026. Shaping Europe’s digital future

Institutional comparison: authority, assistance and enforcement

The useful comparison across Italy and its peers concerns how operational assistance connects to regulatory supervision. The table focuses on that architecture, rather than repeating a legislative commencement timeline.

CountryOfficially documented institutional featurePotential advantageProblem requiring scrutiny
ItalyACN is the national NIS competent authority and single point of contact; CSIRT Italia performs incident-management functionsClear national reference pointWhether central capacity and sector expertise scale with the regulated population
GermanyBSI provides a common portal for NIS2 registration and incident reporting, including voluntary reports from entities outside scopeA shared administrative and reporting interfaceA functioning portal does not establish consistency or depth of supervision
FranceANSSI supports territorial, sectoral and ministerial CSIRTs; ReCyF provides recommended security measuresAssistance closer to local and sector-specific conditionsConsistent service quality and clarity about guidance versus enforceable requirements
AustriaNISG 2026 provides for a Federal Office for Cybersecurity under the Interior Ministry; USP services support registration and reportingA dedicated institutional structure with an established business interfaceStaffing, technical capability and workflows during the new system’s initial operation
NetherlandsNCSC manages the entity register and assistance; supervision is allocated by sectorSeparation between technical support and sector supervisionCoordination across authorities and avoidance of inconsistent information requests
SpainINCIBE-CERT’s official guidance describes governance, proportional controls and the interaction with DORAAccessible implementation guidance for affected organisationsGuidance must be distinguished from the final national allocation of enforceable powers
United KingdomNCSC provides technical guidance; the Cyber Security and Resilience Bill remained in parliamentary proceedings at the cutoffStrong technical guidance alongside legislative reformProposed obligations must not be presented as already enacted

Sources: Italy, Article 10 — ACN responsibilities and Article 15 — CSIRT Italia; Germany, BSI NIS2 portal information; France, ANSSI’s response-centre network, 8 January 2026; Austria, NIS2 implementation and USP services; Netherlands, NCSC–supervisor cooperation agreements, 7 October 2026; Spain, INCIBE-CERT NIS2 FAQs; UK Parliament, Bill stages. gazzettaufficiale.it

Several details sharpen the comparison.

The Netherlands has made coordination explicit. On 7 October 2026, NCSC and four supervisory authorities signed cooperation agreements covering information exchange, coordination of supervisory activity and mutual involvement. Further practical working arrangements were still to be developed, with evaluation after one year. This is evidence of institutional preparation, not yet evidence of successful implementation.

France separates preparation from binding status. ANSSI’s English NIS2 page identifies ReCyF as a working document, non-binding by default, and describes preregistration pending forthcoming national transposition. Its guidance is operationally useful, but that page cannot establish that every provision of the national framework is already enforceable.

The UK also requires a status distinction. Parliament’s record listed a Lords report stage for 26 October 2026, beyond this report’s cutoff. The reform should consequently be analysed as a bill at this point.

Sources: Dutch cooperation agreements, 7 October 2026; ANSSI’s NIS2 implementation page, retrieved 8 October 2026; UK parliamentary stages, retrieved 8 October 2026. NCSC

Cross-border dependence complicates national accountability

Italy’s Article 5 applies different jurisdictional rules to different categories. For specified digital providers—including cloud, data centres and managed services—the main establishment in the Union is central to jurisdiction. Public electronic communications follow a service-location rule, while public administration follows the state establishing it.

For relevant digital providers, the main-establishment test considers where cybersecurity risk-management decisions are predominantly taken, with further criteria where that location cannot be determined.

Source: Gazzetta Ufficiale, Legislative Decree 138/2024, Article 5 — jurisdiction and territoriality. gazzettaufficiale.it

Analytical implication. An Italian customer’s ability to recover may depend on a provider supervised elsewhere. Effective protection therefore requires cross-border cooperation and usable contractual arrangements. Domestic registration cannot by itself resolve dependence on foreign-controlled operational decisions.

DORA addresses part of this problem through European oversight of designated critical ICT providers. The European Supervisory Authorities published their designation list on 18 November 2025, moving the framework beyond a purely prospective mechanism.

Source: ESMA, designation of critical ICT third-party providers, 18 November 2025. esma.europa.eu

Nevertheless, a provider’s importance to an individual hospital, municipality or manufacturer can be substantial even when it is outside that financial-sector designation mechanism. Systemic oversight and organisation-specific dependency management answer different questions.

The implementation evidence: compliance demand exceeds delivery capacity

ENISA’s December 2025 investment findings provide a useful test of the assumption that legal obligations automatically produce resilience.

IndicatorReported valueWhat it establishes
Organisations identifying compliance as a main investment driver70%Regulation strongly influences investment decisions
Organisations reporting difficulty attracting cybersecurity professionals76%Recruitment constrains implementation
Organisations reporting difficulty retaining professionals71%Maintaining capability is also difficult
Respondents identifying patching as challenging50%Remediation remains a practical bottleneck
Respondents identifying business continuity as challenging49%Recovery obligations require substantial operational work
Respondents identifying supply-chain risk management as challenging37%Dependence is difficult to assess and control
Respondents citing supply-chain or third-party compromise as a future concern47%Organisations recognise a risk that outsourcing can intensify

Source: ENISA, What’s Driving Cybersecurity Investments and where lie the challenges?, 8 December 2025. Results concern surveyed organisations; questions permitting multiple selections are not mutually exclusive distributions. ENISA

The policy contradiction is clear. Regulation increases demand for expertise, assessment and remediation precisely where those capabilities are constrained. Outsourcing can alleviate a local shortage while increasing collective dependence on a limited provider base.

For Italy, the relevant comparison with France and the Netherlands is therefore how assistance and supervision reduce this implementation burden. For Germany and Austria, a common administrative interface is useful, but implementation quality still depends on technical capacity behind it. For Spain and the UK, accessible guidance can support preparation while legislative status and final powers remain separate questions.

Key judgments

  • Management accountability is economically meaningful only when leadership can resolve operational trade-offs. Training and approval should lead to decisions about service priorities, replacement, isolation and recovery.
  • Product security and organisational resilience remain complementary responsibilities. Neither supplier assurance nor product conformity establishes service continuity.
  • Institutional effectiveness depends on capacity and coordination. Centralisation and sector-based supervision each have strengths and failure modes.
  • The most consequential compliance gap is the distance between a documented control and a demonstrated result.

What would change the assessment

The assessment would strengthen with published evidence that supervision results in completed remediation, recovery tests meet service tolerances and assistance reaches organisations with limited internal capability.

It would weaken if registrations, notifications and expenditure rise while severe recovery failures persist, unsupported-system exceptions accumulate or supplier concentration remains poorly understood.

Open official record

The decisive missing comparison is a harmonised account of supervisory outcomes: inspections completed, material weaknesses identified, corrective actions closed and operational improvement demonstrated. The retrieved record does not support a defensible league table of the seven countries’ regulatory effectiveness.

Chapter 2 — Artificial intelligence, legacy systems and the distinction between attack activity and economic damage

Principal judgment. Artificial intelligence can accelerate offensive activity and defensive work, but the severity of economic harm remains strongly mediated by ordinary operational weaknesses: exposed systems, slow remediation, excessive privileges, unsupported technology and recovery arrangements that fail under pressure. Public policy should distinguish attack attempts, successful compromise, service interruption and economic loss. Treating those measures as interchangeable can misdirect investment and exaggerate—or conceal—national weakness.

The most useful current evidence combines threat observations, organisational surveys and regulated incident reporting. Each measures a different population. None should be converted into an all-purpose national cyber-risk score.

What the latest European threat evidence actually measures

ENISA’s Threat Landscape 2026, published on 22 September 2026, covers observations from 1 January to 31 December 2025. Its publication year must therefore be distinguished from the year of the underlying activity.

ObservationValueDenominator or interpretation
DDoS51.3%Incident types in ENISA’s analysed dataset
Unauthorised access39.5%Incident types in the same dataset
Unauthorised-access incidents with an identifiable intrusion vector5.2%A small subset of unauthorised-access observations
Vulnerability exploitation60.4%Only the subset with an identifiable intrusion vector
Misconfiguration or accidental exposure20.7%The same identifiable-vector subset
Phishing77.8%Identified social-engineering techniques; not all incidents

Source: ENISA, Threat Landscape 2026, overview and methodology, September 2026. enisa.europa.eu

The denominator is decisive. The finding that 60.4% of identified intrusion vectors involved vulnerabilities does not establish that vulnerabilities caused 60.4% of all European intrusions. Most unauthorised-access observations did not provide an identifiable vector.

This limits both causal attribution and year-to-year comparison. A change in the composition of disclosed cases can change the reported share without an equivalent change in the underlying threat.

ENISA also distinguishes frequency from consequence: ransomware remains particularly impactful in the short term, while public administration remains heavily targeted and geopolitical developments influence hacktivist activity.

Source: ENISA, How dependencies weaken digital resilience, 22 September 2026. ENISA

Analytical implication. A dataset dominated by visible availability attacks can be useful for understanding operational pressure without identifying the greatest source of economic loss. Public claims, readily observed outages and covert espionage have different visibility and disclosure patterns.

An attack counter is not a damage measure

MeasurementWhat it capturesWhat it cannot establish alone
Scanning or blocked connection attemptsExposure and attempted interactionSuccessful compromise
Security alertsEvents matching detection rulesDistinct attacks or confirmed incidents
Attacker claimsClaimed targeting or compromiseVerification, duration or damage
Confirmed incidentsEvents meeting a defined classificationComparable economic severity
Service downtimeLoss of availabilityPermanent loss of output or revenue
Records exposedConfidentiality impactRealised financial loss or subsequent misuse
Reported financial costsCosts recorded under a particular methodComplete social or economic harm
Insurance claimsCovered losses submitted to insurersUninsured losses or losses outside policy scope

This distinction matters directly to comparisons between Italy, the UK, France, Germany, Austria, Spain and the Netherlands. Reporting may be higher where detection, disclosure and supervisory coverage are stronger. Lower recorded activity can reflect fewer attacks, fewer detections, narrower thresholds or incomplete reporting.

Analytical judgment. A country can improve detection and become statistically “worse” on an incident-count measure while reducing economic harm. Conversely, a country can report fewer incidents while remaining exposed to a small number of severe failures.

AI: capability acceleration is credible; a universal loss multiplier is not established

In their 22 June 2026 joint statement, Five Eyes cybersecurity agencies warned that frontier AI was accelerating the speed, scale and sophistication of cyber threats and shrinking the interval between vulnerability discovery and exploitation. Their recommended response emphasised attack-surface reduction, faster patching, legacy-system treatment, stronger identity controls and rehearsed incident response.

This is an institutional threat assessment and call to action. It does not provide a measured percentage of European incidents caused by AI or a quantified multiplier for economic damage.

Source: NCSC, The AI shift in cyber risk: why leaders must act now, 22 June 2026. National Cyber Security Centre

The distinction prevents speculative forecasts from becoming apparent statistics.

AI-related mechanismPotential operational effectEvidence needed to quantify the effect
Faster reconnaissance and code analysisMore candidate weaknesses examinedValid findings and subsequent exploitation compared with a baseline
More persuasive social engineeringMore credible or localised deceptionCampaign conversion rates, with verified attribution
Assistance with exploit developmentReduced time or skill required for some tasksWorking exploitation under realistic conditions
Defensive analysis and triageFaster handling of alerts and investigationsDetection quality, false positives and time to containment
Automated remediation supportFaster preparation of fixesSuccessful deployment, regression rate and exposure reduction
Autonomous agents with system accessActions executed at greater speedPermission scope, error rates, reversibility and containment performance

These mechanisms should be evaluated separately. A model’s ability to explain a vulnerability does not establish its ability to compromise a real environment. Faster generation of phishing content does not establish successful fraud. Faster defensive triage does not establish that analysts can act on the result.

The policy problem is that offensive speed can increase before organisational change-management, procurement and maintenance processes adapt. AI may accelerate one side of the interaction while the defender remains constrained by operational approval and compatibility testing.

Agentic AI creates a second risk channel inside the organisation

AI is also part of the defended environment. Agents can interact with data, tools and production systems, creating exposure through excessive permissions, unintended actions and malicious instructions embedded in material they process.

The NCSC’s 20 August 2026 advice links greater autonomy to greater potential impact and explicitly warns against treating built-in model safeguards as sufficient protection. It calls for proportionate additional safeguards, observability, monitoring and response arrangements. The publication identifies its advice as interim, ahead of formal guidance.

Source: NCSC, Managing the cyber risk of agentic AI, 20 August 2026. National Cyber Security Centre

Deployment choiceRisk mechanismPractical control objective
Agent can read sensitive informationDisclosure through outputs or connected toolsLimit accessible data and destinations
Agent can modify production systemsUnintended changes become service incidentsRestrict changes and preserve rollback
Agent can authorise transactionsFraud or error receives execution capabilitySeparate recommendation from authorisation
Agent processes external documentsUntrusted content influences actionsKeep external content from acquiring authority
Several agents share powerful credentialsA local failure crosses task boundariesSeparate identities and permissions
Logs record outputs but not actionsInvestigators cannot reconstruct decisionsRecord tool use, authorisations and system changes

These are analytical control objectives. Their importance depends on the actual deployment rather than the “AI” label.

European financial authorities have also moved this issue into supervisory practice. On 31 July 2026, EBA, EIOPA and ESMA called for consistent, risk-based supervision of ICT risks from frontier AI models, with attention to governance, prevention, detection, management and critical-provider oversight under DORA.

Source: ESMA, joint supervisory statement on frontier AI risks, 31 July 2026. esma.europa.eu

The European and UK positions converge on an operational principle: AI risk belongs inside established governance, access management and resilience arrangements. Purchasing an AI security tool cannot substitute for those arrangements.

Legacy systems: age, support and recoverability must be separated

“Legacy” can describe unsupported software, obsolete architecture, scarce expertise or a system that is difficult to change without disrupting service. These conditions overlap but are not identical.

An old system with maintained support, constrained access and tested recovery can present a different risk from a newer application with excessive privileges and undocumented dependencies.

Legacy conditionEconomic riskDecision required
Unsupported softwareVulnerabilities may have no supported fixReplacement or tightly bounded continued operation
Specialist knowledge has disappearedRecovery depends on unavailable expertiseDocumentation, knowledge transfer or migration
Integration is poorly documentedChange can interrupt dependent servicesDependency discovery and staged transition
Patching requires downtimeSecurity improvement competes with continuityPlanned maintenance and interim controls
Hardware is difficult to replaceFailure extends restoration timeSpares, alternative capacity or redesign
Recovery cannot be demonstratedBackups may not restore the full serviceEnd-to-end recovery testing

The strongest official quantitative example in the retrieved record concerns the UK public sector. It is useful as evidence of the problem, but it must not be treated as a European average.

UK official measureValueDate and scope
Identified government legacy IT systemsAt least 228March 2024 inventory reported by NAO in January 2025
Legacy systems rated red for likelihood and impact of risk63 of 228 — 28%Subset of that inventory
Independently assessed critical IT systems showing fundamental control gaps58 systems assessed2024 GovAssure evidence
Government technology estate estimated to be legacy28%Estimate cited in the January 2026 Government Cyber Action Plan

Sources: NAO, Government cyber resilience, January 2025; UK Government, Government Cyber Action Plan, January 2026. nao.org.uk

The two 28% figures have different denominators. One concerns the risk rating of identified legacy systems; the other concerns the estimated legacy share of the technology estate. Combining them would create a false measurement.

NAO also found that the legacy assessments were insufficiently detailed and that those systems had not been included in GovAssure. Consequently, the government lacked a detailed assessment of their cybersecurity exposure and how effectively it had been managed.

Comparative limitation. The retrieved official sources do not provide equivalent, consistently defined inventories for Italy, France, Germany, Austria, Spain and the Netherlands. The UK’s greater visibility into weaknesses cannot establish that its legacy exposure is greater than theirs.

Remediation capacity is the measurable bottleneck

ENISA’s NIS Investments 2025 survey covered 1,080 professionals representing organisations across all 27 EU member states. The sample was predominantly large enterprises: 83% large organisations and 17% SMEs. It therefore offers evidence about the surveyed high-criticality sectors, rather than a representative census of European businesses.

Implementation measureReported resultInterpretation
Organisations without a cybersecurity assessment in the preceding 12 months30%Significant gaps in checking security posture
SMEs without such an assessment63%Particularly limited assessment capacity in the SME sample
Organisations taking a month or longer to apply critical patches63%Exposure can persist beyond rapid exploitation cycles
Organisations taking more than three months28%A substantial long-delay group
SMEs taking more than three months51%Remediation constraints are more pronounced in the SME sample

Source: ENISA, NIS Investments 2025 — main report, methodology and patching findings. enisa.europa.eu

These findings identify a practical mechanism through which AI could worsen exposure: faster offensive work interacting with a remediation process that already takes weeks or months.

They do not establish that every delayed patch is managerial neglect. Industrial and healthcare environments can require compatibility testing and carefully controlled maintenance. The appropriate response is to distinguish unavoidable delay from unmanaged delay, and require interim protection where replacement or patching cannot occur immediately.

ENISA’s NIS360 2026 assessment illustrates the sector problem in healthcare: moderate maturity coexists with heterogeneous organisations, resource constraints, asset-tracking weaknesses, legacy infrastructure and uneven incident readiness. It also identifies limitations in sector-specific supervisory expertise.

Source: ENISA, NIS360 2026 — health-sector assessment, May 2026. enisa.europa.eu

DORA evidence: incident frequency and economic harm diverge

The European Supervisory Authorities’ first report on major ICT-related incidents in 2025 provides an important counterweight to attack-count narratives.

DORA observationReported result
Major ICT-related incidents reported3,383
Incidents per financial entity subject to DORA0.18 on average
Incidents with cross-border impactAround one third
Incidents attributable to third-party failure29%
Incidents reporting no direct or indirect costsAlmost 40%
Incidents reporting costs below €1,000Around 10%
Incidents leaving the cost field unfilled15%

The report warns that some cost reporting may be incorrect because staff time allocated to incident handling should count. It also acknowledges divergent reporting practices. The apparently low costs therefore require qualification.

A further inconsistency appears in its transaction-impact text: 32% with no affected transactions plus 26% affecting fewer than 1,000 transactions equals 58%, although the passage describes “two thirds”. The discrepancy is left unresolved here.

Source: EBA, EIOPA and ESMA, 2025 report on major ICT-related incidents, June 2026, especially sections 3.3–3.5. esma.europa.eu

Analytical judgment. This evidence supports two conclusions simultaneously. Incident frequency does not establish equivalent economic damage; incomplete cost recording does not establish that damage is negligible.

The dataset also concerns ICT incidents, including non-malicious failures. Describing all 3,383 as cyberattacks would misstate its coverage.

Economic damage requires a consistent accounting boundary

A credible loss assessment should identify whose loss is measured, when it is measured and which costs are included. Otherwise, incident totals can mix firm expenditure, customer losses and social harm.

Damage categoryAppropriate measurementMain accounting trap
Immediate responseInvestigation, containment and attributable labourExcluding internal staff costs
Technical restorationRebuild, recovery, validation and replacementCounting planned upgrades entirely as incident losses
Business interruptionIrrecoverable output or contribution lostTreating every delayed transaction as permanently lost revenue
Customer consequencesCompensation, fraud and additional recovery costsOmitting losses outside the affected organisation
Contractual and legal consequencesLiabilities and costs within a stated boundaryCombining contingent and realised amounts
Information lossObservable consequences of stolen or corrupted informationAssigning speculative values to every exposed record
Public-service harmCancelled services, backlogs and reduced accessAssuming cash expenditure captures the entire impact
Financial recoveryInsurance and other recoveries reported separatelyMixing gross loss with net retained loss

This is an analytical accounting framework, rather than a new estimate of European losses.

For Italy, the policy consequence is that successful cybersecurity investment should be assessed through restored service capability and reduced exposure. Spending can increase because an organisation is improving, because it has suffered a severe failure or because obligations have expanded. The expenditure figure alone does not distinguish these explanations.

The same discipline is necessary when assessing France’s local assistance network, German or Austrian implementation systems, Dutch sector supervision or UK resilience reform. Comparable outputs require consistent definitions of disruption and loss.

The defence paradox: containment can interrupt the business it protects

Isolation, credential revocation and shutdown can prevent escalation while immediately reducing service availability. A sound plan therefore identifies which interruption is tolerable, who can authorise it and how essential operations continue.

The NCSC’s 20 April 2026 severe-threat guidance explicitly distinguishes ordinary assurance from readiness for severe disruption. It calls for mapping critical IT and operational technology, planning degraded operations and rehearsing isolation and rebuilds. An organisation meeting normal Cyber Assessment Framework expectations may still need to reconsider its response under severe threat.

Source: NCSC, Preparing for severe cyber threat: why leaders must act now, 20 April 2026. National Cyber Security Centre

Decision under pressureBenefitOperational costPreparation needed
Isolate a compromised environmentLimit propagationApplications become unavailableMinimum-service arrangements
Revoke privileged accessRestrict attacker controlAdministrators and suppliers may lose accessTrusted recovery access
Suspend transactionsPrevent fraud or corruptionDelays and backlogReconciliation and restart sequence
Rebuild rather than repairIncrease confidence in system integrityLonger restorationReproducible configurations and clean dependencies
Disconnect a supplierReduce external exposureShared service interruptionAlternative provision or degraded operation

The contradiction is not a reason to avoid containment. It is a reason to make the decision before the incident. A plan that leaves every disruptive action to improvised approval can lose its value precisely when speed matters most.

A more useful performance dashboard for Italy and its peers

A comparative framework should preserve both activity and impact measures, without collapsing them into one number.

DimensionUseful indicatorWhy it matters
ExposureCritical assets with an accountable owner and known support statusIdentifies unmanaged dependencies
RemediationCritical exposed vulnerabilities remaining beyond the agreed treatment periodMeasures persistent risk
Privilege controlCritical administrative access subject to strong authentication and reviewTests containment of identity compromise
RecoveryEssential services restored within approved tolerances during exercisesMeasures demonstrated capability
Supplier dependenceCritical functions concentrated in shared providers or infrastructureIdentifies common failure points
Incident consequenceService interruption and irrecoverable output by severitySeparates volume from harm
Cost qualityReports including attributable labour and distinct gross/net lossesImproves economic comparability
AI deploymentAutonomous systems with bounded permissions and reconstructable actionsConnects capability to control
Supervisory outcomeMaterial findings closed and retestedMeasures change following intervention

These are proposed analytical indicators. The current record does not provide a harmonised dataset covering all seven countries.

Publishing them would make policy evaluation more demanding and more useful. A rising incident count alongside faster containment and lower service interruption could indicate improvement. Falling counts alongside longer outages or unresolved critical vulnerabilities could indicate deterioration.

Key judgments

  • AI acceleration is a credible operational concern; a universal numerical multiplier for European economic damage is not established by the retrieved official evidence.
  • Legacy risk is a combination of support, exposure, expertise and recoverability. System age alone is an inadequate prioritisation rule.
  • Attack activity, confirmed compromise and economic loss require separate measures. Their relationship depends on detection, containment and recovery.
  • European evidence identifies remediation and assessment gaps, particularly among surveyed SMEs. Those gaps provide a concrete mechanism through which faster threats can become more damaging.
  • A low reported cost can reflect effective containment or incomplete accounting. The DORA findings require both possibilities to remain visible.
  • For Italy, the most useful policy test is demonstrated service resilience under realistic conditions.

What would change the assessment

The assessment would strengthen if AI-assisted defence measurably reduces exposure and containment time, legacy exceptions receive funded treatment plans and recovery exercises demonstrate continuity despite provider or identity failure.

It would weaken if autonomous systems gain broad production access without effective boundaries, critical patch delays persist, recovery remains untested or economic reporting continues to omit substantial categories of cost.

Open official record

The principal unresolved questions are the share of verified incidents materially enabled by AI, comparable national inventories of unsupported critical systems, consistently measured incident losses and the demonstrated ability of shared providers to support simultaneous customer recovery.

Without those records, precise country rankings or AI-attributed loss totals would exceed the evidence.


Pillar II — Public investment and national policy comparisons

Assessment cutoff: 8 October 2026. Monetary amounts are nominal; programme budgets, grant awards, payments and observed results are distinguished throughout.

Chapter 3 — Italy: voucher design, territorial allocation, accessibility and implementation risks

Principal judgment. Italy’s voucher can finance substantial technological upgrades, but its allocation mechanism does not establish that the most exposed or least capable firms will receive support first. The decisive implementation questions concern financing before reimbursement, administrative readiness, the distribution of expenditure between cloud adoption and cybersecurity, and whether funded systems remain effective after the subsidy ends.

The funding envelope is larger than the amount necessarily available for grants

The programme has a €150 million envelope, with €71,065,813.34 reserved for expenditure plans in eight specified southern regions. That reservation represents 47.38% of the headline envelope, calculated from the published amounts. The remainder is unreserved funding; describing it as an exclusive allocation to central and northern Italy would misstate the instrument. Sostegno alla domanda di servizi di cloud computing e cyber security — MIMIT — programme page. mimit.gov.it

Funding componentPublished amount or calculated valueCorrect interpretation
Overall programme envelope€150,000,000Programme resources, rather than expenditure already delivered
Territorial reservation€71,065,813.34Reserved for plans in Abruzzo, Basilicata, Calabria, Campania, Molise, Puglia, Sardinia and Sicily
Reservation as a proportion of the envelope47.38%Calculated territorial floor within this instrument
Unreserved remainder€78,934,186.66Not an exclusive central/northern quota
Maximum permitted technical and administrative charges€3,750,000Calculated from the legal ceiling of 2.5%
Resources remaining if that ceiling were fully used€146,250,000Conditional calculation, not a published final grant allocation

The founding decree permits technical and administrative costs, including checks, to be charged to the programme within a 2.5% ceiling. Consequently, €150 million should not automatically be presented as the amount ultimately transferred to beneficiaries. Decreto ministeriale 18 luglio 2025 — MIMIT — July 2025, Article 3. mimit.gov.it

The territorial reservation protects resources against unrestricted national competition, but money reserved geographically is not equivalent to money absorbed effectively. A region can have a protected allocation while its firms encounter difficulties preparing applications, obtaining eligible quotations or financing projects. Assessing territorial success therefore requires separate measures of applications, approvals, implementation and payments.

The relevant denominator also matters. A large regional award total could reflect the number of eligible firms, greater supplier activity or larger average projects. It would not, by itself, demonstrate that the regional capability gap had narrowed.

The subsidy becomes less generous above €40,000

The contribution covers 50% of eligible expenditure, subject to a €20,000 ceiling and a €4,000 minimum expenditure plan. The ceiling is reached at €40,000: spending beyond that point increases the beneficiary’s contribution without increasing the grant. Sostegno alla domanda di servizi di cloud computing e cyber security — MIMIT — programme page. mimit.gov.it

Eligible project expenditureCalculated grantBeneficiary’s eligible-cost contributionEffective subsidy
€4,000€2,000€2,00050%
€10,000€5,000€5,00050%
€20,000€10,000€10,00050%
€40,000€20,000€20,00050%
€60,000€20,000€40,00033.33%
€100,000€20,000€80,00020%

Calculated from the programme’s contribution rate and ceiling. The beneficiary column excludes ineligible costs and any applicable tax treatment.

This structure supports bounded projects more strongly than comprehensive transformations. A firm requiring several interdependent changes can face an incentive to limit the funded package to €40,000, postpone complementary work or fund it separately. That is a plausible behavioural effect of the ceiling, rather than an observed outcome: implementation data would be needed to establish whether project values cluster around that threshold.

For evaluation, project size should therefore be examined alongside the completeness of the resulting system. A smaller, fully configured intervention may outperform a larger collection of disconnected purchases.

Accessibility depends on legal form and connectivity, not merely business size

MIMIT’s updated clarification introduces distinctions that materially affect access. Individual professionals can qualify, whereas associated professional practices are excluded. Each legal entity can submit an application, while the relevant de minimis assessment remains sensitive to the wider undertaking. The connectivity threshold refers to nominal or maximum download speed; mobile-network connections are excluded, although qualifying fixed wireless and satellite connections are accepted. Sostegno domanda servizi di cloud computing e cyber security: Risposte alle domande frequenti — MIMIT — updated October 2026. Risposte alle domande frequenti (FAQ)

Access distinctionPolicy consequence
Individual professional versus associated practiceSimilar activities can receive different treatment because of organisational form
Application per legal entity versus aid assessment across an undertakingCorporate organisation affects application opportunities without removing State-aid constraints
Nominal connection speed versus demonstrated service qualityThe threshold verifies contractual eligibility rather than actual reliability
Eligible fixed connection versus excluded mobile connectionFirms using mobile connectivity face a categorical barrier even where performance is adequate

These distinctions expose a tension between administrative classifications and economic vulnerability. A professional practice does not necessarily face lower cyber risk because several professionals operate jointly. Likewise, a nominal connection speed does not establish reliable cloud access, resilience during an outage or effective recovery capability.

The connectivity rule is especially relevant to territorial policy. A geographically reserved budget cannot fully compensate for an eligibility barrier affecting firms with particular connectivity arrangements. The distributional question is therefore broader than whether the reserved funds are spent: it includes which firms remain outside the applicant population.

A chronological procedure rewards readiness

Applications can be prepared from 20 October 2026 at noon and submitted from 10 November 2026 at noon until 20 January 2027 at noon. Thus, at this assessment cutoff, the beneficiary application window has not opened. Decreto direttoriale 4 agosto 2026: Voucher cloud cybersecurity, termini e modalità di presentazione delle domande — MIMIT — August 2026. mimit.gov.it

The chronological procedure creates a foreseeable advantage for applicants that already have advice, supplier quotations and administrative documentation. This does not establish improper allocation. It means that application readiness is part of the selection mechanism, while the procedure does not rank projects principally by their expected reduction of economic exposure.

Administrative stageOperative requirementImplementation implication
AssessmentNormally within 60 days, with permitted interruptions or extensionsThe deadline is not an unconditional payment promise
Direct purchasesExpenditure and payment within 12 months of award communicationExecution must fit the grant calendar
SubscriptionContract signed within 30 days of award communicationSupplier and contract choices must be ready promptly
Subscription notificationWithin 60 days of award communicationA separate compliance deadline follows contracting
First payment requestAt least three months after award communicationThe award does not immediately resolve liquidity needs
First instalmentAt least 50% of the expenditure plan already paidBeneficiaries must bridge part of the financing
Final settlementSecond instalment, or a single request after completionDocumentary closure affects cash recovery

Source: Decreto direttoriale 4 agosto 2026 — MIMIT — August 2026, Articles 4–7. mimit.gov.it

The grant reduces eventual eligible cost, but it does not remove the need for working capital. Firms with limited liquidity can struggle to reach the expenditure threshold required for reimbursement. Consequently, the nominally equal contribution rate may produce unequal practical access.

A useful implementation response would be targeted assistance with application preparation and project financing, accompanied by reporting on withdrawals after award. Withdrawals would help distinguish weak demand from projects that were approved but could not be executed.

Purchasing technology and building capability remain different funding decisions

The eligible categories include business cloud applications alongside dedicated security technologies. The founding instrument therefore supports digital adoption as well as protection. An accounting or customer-management migration can improve operations, but the amount spent on it cannot automatically be counted as equivalent cybersecurity expenditure. Decreto ministeriale 18 luglio 2025 — MIMIT — July 2025, Article 5. mimit.gov.it

The October FAQ also excludes training and purely theoretical assessments without implementation. It distinguishes an eligible learning platform from the excluded educational content delivered through it. Risposte alle domande frequenti — MIMIT — updated October 2026. Risposte alle domande frequenti (FAQ)

This produces a substantive policy contradiction: the instrument can subsidise the infrastructure used to deliver knowledge while excluding the knowledge itself. The administrative boundary is understandable as a way to constrain expenditure, but it leaves beneficiaries responsible for acquiring skills that may determine whether the purchased systems are used correctly.

The appropriate evaluation should therefore follow the chain from procurement to operational use:

Evaluation questionEvidence neededWhat an invoice cannot establish
Was the purchase additional?Baseline inventory and investment plansWhether the firm would have bought it anyway
Was it configured correctly?Acceptance records and technical checksWhether default or ineffective settings remain
Is responsibility assigned?Named operator and maintenance arrangementsWhether anyone owns the ongoing task
Can operations recover?Documented restoration testWhether a backup is usable
Does protection persist?Follow-up checks after subsidy expiryWhether subscriptions and controls remain active
Did territorial capability improve?Comparable regional resultsWhether allocation translated into sustained capability

These are proposed evaluation requirements, not reported programme results.

Key judgments

Italy’s main implementation risk is a gap between formally eligible purchases and sustained operational capability. Territorial protection improves the distribution of available resources, but its effectiveness depends on the ability of firms to apply, finance and complete projects.

What would change the assessment

Evidence of strong participation among small and administratively inexperienced firms, low post-award withdrawal, independently verified implementation and continued operation after support expires would strengthen the assessment.

Open official record

The consequential missing results are regional applications and rejection reasons, grant commitments versus payments, expenditure by product category, applicant size and legal form, project completion, and post-support performance. Before the application window opens, these cannot be presented as realised outcomes.

Chapter 4 — The United Kingdom, France and Germany: assurance, sovereignty and regulatory execution

Principal judgment. The three countries illustrate different ways to turn public policy into business behaviour. The United Kingdom uses recognised assurance and procurement demand; France combines diagnostic support with requirements for sensitive public-sector cloud use; Germany combines standardised advice with geographically differentiated financial assistance. Each addresses a particular obstacle, but none of these mechanisms alone establishes economy-wide resilience.

The United Kingdom: assurance has commercial value, but coverage remains uneven

The UK’s procurement policy makes cybersecurity assurance relevant to access to public contracts. PPN 014 requires proportionate application, accepts equivalent controls and warns against blanket certification requirements that unnecessarily deter smaller suppliers. It also states that Cyber Essentials does not assure the specific products or services being supplied. PPN 014: Cyber essentials scheme — Cabinet Office — February 2025. GOV.UK

The economic mechanism is important. Procurement can create a recurring commercial reason to maintain controls: assurance becomes relevant to revenue and customer access rather than depending entirely on a temporary grant. However, this mechanism is strongest where buyers request it. Businesses outside those supply chains may experience a much weaker incentive.

The official management information records 61,430 certificates issued between July 2025 and June 2026, including 15,185 Cyber Essentials Plus certificates. Issuances include renewals and should not be treated as a count of distinct newly protected businesses. Cyber Essentials management information — UK Government — September 2026. GOV.UK

UK assurance indicatorValuePeriod and interpretation
Cyber Essentials certificate issuances46,245July 2025–June 2026
Cyber Essentials Plus issuances15,185Same period
Combined issuances61,430Includes renewal activity
Plus share of issuances24.72%Calculated; not the share of all UK firms independently audited
Businesses reporting Cyber Essentials certification5%2025/2026 survey
Small businesses reporting certification12%Survey size category
Large businesses reporting certification35%Survey size category

Survey source: Cyber security breaches survey 2025/2026 — UK Government — 2026. GOV.UK

The evidence points to a mature assurance mechanism with uneven penetration. Certificate activity and economy-wide coverage measure different things: a substantial renewal market can coexist with limited participation across the business population. The size gradient also suggests that procurement incentives and implementation capacity should be assessed together.

The relevant policy question is whether smaller firms lack awareness, face implementation costs, see insufficient commercial benefit or encounter several of these barriers simultaneously. Certificate totals cannot resolve that question.

Free assessment does not mean free implementation

The NCSC’s funded Cyber Essentials programme is now closed. Its design included practical assistance and certification, but did not finance additional hardware or software required to meet the standard. Funded Cyber Essentials Programme — NCSC — current programme notice. National Cyber Security Centre

This exposes a difference from Italy’s purchase subsidy. Removing the cost of advice and assessment can help a firm identify deficiencies without enabling it to finance the corrections. Conversely, subsidising products can enable purchases without guaranteeing an independent check of the resulting configuration.

The two mechanisms are complementary. Their effectiveness depends on whether firms can move from diagnosis to implementation and from implementation to verification.

The Government Cyber Action Plan also announces more than £210 million for government cybersecurity. This is a public-sector programme, not a directly comparable SME voucher budget. Government Cyber Action Plan — UK Government — January 2026. GOV.UK

UK policy instrumentMain mechanismAppropriate performance measure
Procurement assuranceMakes controls relevant to contract accessSupplier participation, justified requirements and verified scope
Assisted certificationReduces advice and assessment barriersCorrections completed and firms subsequently certified
Central government investmentFinances public-sector executionCompleted milestones and tested public-service capability
Certificate renewalEncourages periodic reassessmentRetention and continuing compliance

The table identifies evaluation measures, rather than asserting that all are currently published.

France: diagnosing the problem is a distinct investment

France’s Diagnostic Cybersécurité provides an eight-day intervention, with a listed price of €8,800 excluding VAT and 50% support. Its output includes a diagnosis and prioritised recommendations. The remaining €4,400 is the firm’s contribution to the diagnostic service, rather than a comprehensive implementation budget. Diagnostic Cybersécurité — France Num — official programme guide. francenum.gouv.fr

The French diagnostic model confronts a problem that a catalogue subsidy can leave unresolved: firms may not know which purchase offers the highest value. An external review can improve sequencing and identify responsibilities before expenditure is committed.

Its limitation is equally clear. Recommendations do not finance themselves. A programme that produces high-quality plans can still leave firms unable to implement them.

Diagnostic-stage questionFrench model’s contributionRemaining implementation dependency
What is the baseline?Structured reviewAccurate disclosure and access
Which weaknesses matter most?Prioritised recommendationsManagement acceptance
What should be purchased or changed?Costed action planFinancing and procurement
Who must act?Organisational recommendationsStaff time and authority
Were the changes effective?A basis for later comparisonFollow-up verification

These are analytical implications of the diagnostic model, not measured programme outcomes.

Sovereignty requirements have a defined public-sector scope

The order of 12 August 2026 approves SecNumCloud version 3.2 for commercial cloud providers serving State administrations, State operators and public-interest groupings where particularly sensitive data are involved. Published on 14 August, it entered into force the following day. Its scope should not be expanded into a claim that every French SME must use a sovereign cloud. Arrêté du 12 août 2026 portant approbation du référentiel d’exigences relatif aux prestataires de services d’informatique en nuage — French Government — August 2026. Légifrance

The economic-security logic differs from a general purchase grant. Sensitive public-sector procurement can create demand for providers meeting a specified assurance framework. That may support investment in qualified services, but the resulting market should be evaluated through actual contracts, qualified capacity, interoperability and operating costs.

A sovereignty requirement can reduce particular dependencies while creating others. Concentration among qualifying suppliers, migration costs and the availability of specialised services remain relevant. These are implementation questions; neither a qualification label nor domestic ownership alone answers them.

France also opened a June–July 2026 call concerning the security of cybersecurity ecosystems, with notifications scheduled for September. The announcement establishes a selection process, not proof that funded sector capabilities were already operating at the cutoff. Appel à manifestation d’intérêt « Sécurité des écosystèmes de cybersécurité » — ANSSI — June 2026. ANSSI

Germany: standardised guidance reduces uncertainty, while funding access varies geographically

Germany’s Transferstelle Cybersicherheit im Mittelstand offers publicly funded initial support, including assessment and guidance. Its FAQ distinguishes these services from external commercial assistance that may incur charges. FAQ: Häufig gestellte Fragen zur Transferstelle Cybersicherheit im Mittelstand — programme operator — current FAQ. CYBERsicher

The CyberRisikoCheck associated with DIN SPEC 27076 provides a standardised assessment approach. It should not be represented as a certificate proving comprehensive regulatory compliance. DIN SPEC 27076 — DIN Media — May 2023. DIN Media

Standardisation can reduce the search problem facing a small firm: whom to consult, what questions to ask and how to compare recommendations. Nevertheless, a consistent diagnosis remains dependent on financing and execution afterward.

Bavaria illustrates the financial layer. Digitalbonus provides up to 50% support, with current ceilings of €7,500 for Standard and €30,000 for Plus projects with particular innovative content. These are Bavarian conditions, not national entitlements. Digitalbonus Bayern: Förderprogramm — Bavarian Ministry of Economic Affairs — current programme. digitalbonus.bayern

Bavarian provisionCurrent conditionConsequence
Geographic accessEligible establishment in BavariaComparable firms elsewhere cannot assume access
Standard ceiling€7,500Supports a smaller project than Italy’s maximum contribution
Plus ceiling€30,000Requires particular innovative content
Minimum eligible expenditure€4,000Excludes smaller interventions
Linked consultation and trainingUp to 50% of eligible expenditureAllows implementation-related capability expenditure
Application availabilityMonthly quotaReadiness and timing affect practical access

Sources: Digitalbonus funding provisions — Bavarian legislation portal — effective November 2025 and Häufig gestellte Fragen — Digitalbonus Bayern — current FAQ. Bürgerservice

The monthly quota creates a different timing problem from Italy’s national window. It spreads opportunities over successive months, but can still reward applicants ready at reopening. The inclusion of implementation-related training addresses a capability expenditure that Italy’s voucher excludes.

At federal level, a 2026 amendment suspended the 1 August project-outline submission round for transfer-oriented projects under the relevant IT-security funding programme. This concerns a funding round; it does not establish that existing advisory services ceased. Amendment to the IT-security funding guideline — Federal Ministry for Economic Affairs and Energy — published May 2026. bundesanzeiger.de

The comparison concerns mechanisms, not a spending league table

CountryMechanism examinedPrincipal strengthPrincipal unresolved problem
ItalySubsidised cloud and security purchasesReduces acquisition costAdditionality, financing and effective operation
United KingdomAssurance linked to procurementGives controls recurring commercial valueUneven coverage and implementation cost
FranceDiagnostics and sensitive public-cloud requirementsImproves prioritisation and defines assurance demandFinancing recommendations and supplying qualified capacity
GermanyStandardised advice and regional grantsReduces uncertainty and supports local implementationGeographic variation and continuity between funding rounds

This is an analytical comparison of the documented instruments. It is not a complete national expenditure inventory or a ranking of cyber performance.

Key judgments

The UK’s distinctive contribution is the use of procurement to sustain demand for assurance. France separates diagnostic investment from acquisition and uses sensitive public procurement to shape cloud supply. Germany demonstrates that free guidance can coexist with substantial regional differences in financial access.

What would change the assessment

The strongest evidence would connect these instruments to completed corrections: certification uptake among smaller firms, implementation of French diagnostic recommendations, performance and cost of qualified cloud procurement, and conversion of German advisory contacts into verified improvements.

Open official record

A comparable account remains incomplete without beneficiary-level outcomes, full implementation costs and consistent follow-up periods. Budget announcements and participation counts cannot substitute for those records.

Chapter 5 — Austria, Spain, the Netherlands, Finland and Ireland: implementation timing and alternative support models

Principal judgment. These countries offer useful alternatives to Italy’s acquisition model, particularly assessment before investment, support for inexpensive controls, advance payments and verification after implementation. Their programmes also show that a published funding offer may be closed, narrowly targeted or directed toward producers rather than ordinary business users.

Austria: diagnosis before implementation, with a lower subsidy rate

Austria’s KMU.DIGITAL framework provides €35 million for 2024–2026 across its digital and green strands. That is a broader transformation budget, not a cybersecurity-only appropriation. Cybersecurity is one of the supported themes. KMU.DIGITAL — Federal Ministry for Economy, Energy and Tourism — programme framework. bmwet.gv.at

The implementation rules provide 30% support, capped at €6,000, for eligible projects costing €2,000–€30,000 excluding VAT. A preceding supported consultation is normally required, subject to the specified exception mechanism. Richtlinie KMU.DIGITAL 4.0: Modul Umsetzung — Austrian federal ministry — programme guideline. Modul Umsetzung

Eligible implementation costCalculated Austrian contributionBeneficiary contributionEffective subsidy
€2,000€600€1,40030%
€10,000€3,000€7,00030%
€20,000€6,000€14,00030%
€30,000€6,000€24,00020%

Calculated from the implementation rate and ceiling; these examples do not establish current remaining budget or acceptance of a particular project.

The Austrian model can improve expenditure sequencing because advice generally precedes implementation. Its lower minimum project size also permits smaller interventions than Italy’s minimum plan. However, the lower contribution rate leaves a larger share to the beneficiary.

The two strands should not be treated as an automatic €12,000 entitlement for one project. Separate programme opportunities do not permit the same cost to be funded twice. The broader lesson is that accessible diagnosis and accessible implementation require separate design choices: linking them improves coherence, but insufficient financing can still interrupt the process.

Spain: a large delivery infrastructure does not mean an open application window

Spain’s Kit Digital illustrates the importance of distinguishing new applications from continuing programme delivery. The published calls closed on different dates: the earlier main calls in December 2024, the larger-company call in June 2025, and the remaining listed calls in October 2025. At the October 2026 cutoff, those listed application windows are closed. Convocatorias — Red.es, Kit Digital — current official call record. kitdigital

Published call groupingClosing dateInterpretation at 8 October 2026
Calls I and II31 December 2024Historical application rounds
Call V30 June 2025Historical application round
Calls III and IV31 October 2025Historical application rounds
Continuing delivery and evaluationSeparate from application deadlinesDoes not reopen closed calls

Kit Digital reports substantial administrative automation: 39 robots, 24,363,519 checks and 736,958 automatically processed files, representing 45% of files in the reported measure. Checks and files are administrative units, not counts of independently secured firms. Convocatorias — Red.es, Kit Digital — current official programme record. kitdigital

The useful comparison with Italy concerns administrative capacity. Automated checks can reduce repetitive processing and support delivery at scale. They can also reproduce classification errors consistently unless applicants have a workable correction process. Automation should therefore be assessed alongside rejection reasons, appeals, incomplete applications and processing times.

Red.es’s impact material reports an application-ease rating of 4.7 out of five and a processing rating of 3.7. These are programme-reported experience measures; they do not demonstrate a reduction in cyber incidents or losses. Evaluación de impacto — Red.es, Kit Digital — official evaluation page. kitdigital

Spanish measureWhat it helps establishWhat remains unproven
Automated checksAdministrative processing activityAccuracy and fair treatment
Automatically processed filesUse of delivery technologyUnique beneficiary reach
Application satisfactionRespondents’ experience of applyingTechnical quality of implementation
Processing satisfactionExperience of administrationLong-term business resilience
Funded digital solutionsAcquisition and programme deliveryCyber-specific additionality

Spain demonstrates why a broad digitalisation programme needs a separate cybersecurity evaluation. Aggregate digital adoption can include many services with different security implications. The evaluation must identify which controls were implemented and whether they remained operational.

The Netherlands: modest grants support controls that large purchase schemes can overlook

Mijn Cyberweerbare Zaak opened on 7 September 2026 and is scheduled to close on 30 November, subject to budget exhaustion. The 2026 envelope is €1 million, with 50% support capped at €1,250. Eligible categories include authentication, password management, patching, backup setup and testing, risk assessment and awareness training. Mijn Cyberweerbare Zaak in het kort — NCSC Netherlands — 2026 programme guidance. NCSC

This is a narrower security intervention than Italy’s cloud-and-cyber voucher. Its inclusion of awareness and assessment is significant: small expenditures on these activities can address organisational weaknesses without requiring a larger technology package.

The detailed rules nevertheless create a financing constraint. Applicants must implement and pay for qualifying measures before applying. A CyberVeilig Check action list is mandatory; eligible expenditure starts at €400. General cloud-workplace subscriptions are excluded. Mijn Cyberweerbare Zaak — Netherlands Enterprise Agency, RVO — checked September 2026. RVO.nl

Dutch design featureAdvantageLimitation
€400 expenditure thresholdPermits inexpensive improvementsVery small measures still fall below the threshold
€1,250 maximum contributionSupports basic controlsInsufficient for a comprehensive transformation
Required action listConnects expenditure to identified needsCompletion does not independently validate the diagnosis
Training and risk assessment eligibleSupports human and organisational capabilityQuality must still be assessed
Payment before applicationProvides evidence of real expenditureTransfers financing and allocation uncertainty to the firm
Narrow security categoriesLimits diversion into general digitalisationExcludes broader migration needs

The Netherlands highlights a distinction between low administrative scale and low financial risk. A small grant can still require a firm to spend before it knows whether funds remain available. Conversely, a larger programme can reserve an award before expenditure while requiring more documentation.

The Dutch approach is particularly relevant to firms whose immediate deficiencies can be corrected cheaply. Its ceiling should be judged against that purpose, rather than against Italy’s maximum grant for a much broader project.

Finland: the current call funds producers, while an earlier call supported compliance implementation

Finland’s September 2026 call supports the commercialisation of innovative cybersecurity solutions. It has a €700,000 envelope and an application deadline of 4 November 2026. It is directed toward developing market-ready solutions, rather than providing a general purchase voucher to ordinary business users. Kansalliset rahoitustuet — Traficom — current national funding page. Traficom

The operative notice allows grants of €10,000–€100,000 covering up to 70% of eligible expenditure incurred in 2027. It provides 70% of the awarded grant after the positive decision and the remaining 30% after completion and accepted reporting. The aid intensity and payment schedule are separate percentages. Hakuilmoitus rahoitustuesta innovatiivisten kyberturvallisuusratkaisujen kaupallistamisen edistämiseen — Traficom — September 2026, pp. 2–3. kyberturvallisuuskeskus.fi

Finnish funding roundMain purposeContributionImplementation period
2025 roundImplementation of cybersecurity-law requirements by eligible organisationsUp to 50%2026
2026 roundCommercialisation of innovative cybersecurity solutionsUp to 70%2027

The distinction prevents a misleading comparison. Finland’s current contribution rate cannot be presented as a 70% subsidy available to any SME buying security software.

For a hypothetical €50,000 eligible development project receiving the maximum rate, the grant would be €35,000. The initial payment would then be €24,500—70% of the grant—with €10,500 retained for final settlement. The beneficiary would contribute at least €15,000. These are calculations illustrating the rules, not an actual award.

The advance materially changes financing needs relative to reimbursement schemes. It can help execute a selected project, while increasing the importance of selection quality, monitoring and recovery of funds where conditions are not fulfilled.

The Finnish official record contains a numerical revision that should remain visible

Traficom’s 3 February 2026 announcement reported 35 recipients and €1.65 million awarded under the 2025 round. Its current funding page records 36 recipients and €1.67 million. The opened records do not explain the difference. Liikenne- ja viestintävirasto myönsi rahoitustukea yhteensä 1,65 milj. euroa — Traficom — February 2026 and Kansalliset rahoitustuet — Traficom — current record. Kyberturvallisuuskeskus

2025-round indicatorOfficial value
Applications89
Funding requested€4.7 million
Announced round budget€2 million
February 2026 announcement35 recipients; €1.65 million
Current programme record36 recipients; €1.67 million
Current recipients divided by applications40.45%, calculated
Requested funding divided by round budget2.35 times, calculated

The fact that demand exceeded the budget while awards remained below it does not, by itself, establish administrative failure. Eligibility and minimum assessment thresholds can produce that combination. The decisive evidence would be the distribution of rejection reasons and the treatment of qualifying applications.

An evaluation of Finland’s earlier 2023–2024 support provides additional, qualified evidence. Traficom reports 50 beneficiaries, 44 survey responses and self-reported improvements, while only 40% had undertaken audits. Financial support provided by the National Coordination Centre improved the cybersecurity of companies — Traficom — February 2025. Traficom

This is stronger than a simple award count because it examines implementation, but it remains insufficient to attribute a precise reduction in losses to the subsidy. Respondent reports, audits and causal outcome measurement provide different levels of evidence.

Ireland: a coherent assessment-to-retest model, with a closed implementation grant

Ireland’s NCC-IE Cyber Security Improvement Grant has finished, and the official notice states that additional application rounds will not open. Its historical design required a prior Enterprise Ireland review, funded implementation and included post-implementation retesting. Contributions ranged from €20,000 to €60,000, with 20% beneficiary financing. NCC-IE Cyber Security Improvement Grant — NCSC Ireland — current closure notice. ncsc.gov.ie

Enterprise Ireland separately lists an 80% contribution toward a €3,000 cybersecurity review. That implies €2,400 support and a €600 company contribution; it should not be confused with a reopened implementation grant. Cyber Security Review Grant — Enterprise Ireland — current programme page. Enterprise Ireland

The Irish sequence addresses several failures discussed elsewhere: choosing an intervention without diagnosis, implementing recommendations without expert support, and accepting completion without retesting. Its limitation is continuity. A diagnostic service can remain available after the associated implementation funding ends.

Ireland also publishes unusually useful administrative results for the completed grant.

RoundApplicationsAwardsUnsuccessful applicationsCalculated award rateGrant agreements
October 2024232218.70%€61,644.80
January 202552312159.62%€1,085,228.82
June 202541172441.46%€596,639.60
Total116506643.10%€1,743,513.22

Source: Cyber Security Improvement Grant Report 2025, version 1.3 — NCSC Ireland — February 2026. Percentages are calculated from published counts. ncsc.gov.ie

The agreements represent 87.18% of the €2 million envelope, and the calculated average award is €34,870.26. These figures concern awards, not proof that every euro was paid or that a corresponding amount of economic damage was prevented.

The variation between rounds is material. It warrants investigation into eligibility, applicant preparation and procedural changes, but the figures alone do not identify which explanation predominates. Publishing refusal reasons by round would make that distinction possible.

Contribution rates conceal differences in access and purpose

Instrument examinedRateCeilingEligible expenditure needed to reach ceilingImportant qualification
Italy cloud/cyber voucher50%€20,000€40,000Broad acquisition programme
Austria implementation support30%€6,000€20,000Consultation normally precedes implementation
Bavaria Digitalbonus StandardUp to 50%€7,500€15,000 at maximum rateRegional eligibility
Netherlands MCZ50%€1,250€2,500Narrow basic-security measures
Finland 2026 callUp to 70%€100,000Approximately €142,857Commercialisation projects
Ireland completed improvement grant80%€60,000€75,000Closed implementation instrument

Thresholds are calculated from the documented rates and ceilings cited above. The instruments differ in eligibility, purpose, selection and availability; the table does not imply that every firm can access them.

A high contribution rate can coexist with restrictive eligibility, a large minimum project or a closed application window. A low ceiling can be well suited to inexpensive controls. The appropriate comparison therefore concerns the intervention each programme is designed to produce, together with the obstacles it leaves to the beneficiary.

Implementation timing is itself a policy variable

InstrumentPosition at the cutoffWhy timing matters
Italy voucherSubmission scheduled to begin in November 2026Programme design precedes beneficiary results
UK funded Cyber Essentials programmeClosedHistorical assistance cannot be offered as current access
French ecosystem callApplication period closedScheduled notifications do not prove deployed capability
Bavaria DigitalbonusProgramme through 2027, with monthly quotasAccess can vary within a continuing framework
Austria KMU.DIGITAL2024–2026 funding frameworkFramework duration does not guarantee remaining resources
Spain’s listed Kit Digital callsClosedContinuing delivery differs from new applications
Netherlands MCZ2026 window open, subject to exhaustionFirms spend before applying
Finland 2026 commercialisation callOpen; implementation in 2027Present applications finance future development
Ireland improvement grantFinished; no additional rounds announcedThe assessment-to-implementation funding chain has ended

Status derives from the adjacent official programme records. Austria’s entry describes its framework, rather than asserting verified remaining application capacity.

This timing comparison changes the interpretation of public investment. A budget can exist before firms can apply; awards can exist before projects are completed; expenditure can continue after applications close. Treating all three as simultaneous support overstates the assistance actually accessible at a given date.

Lessons for Italian execution

The comparative evidence supports five practical priorities.

PriorityDecision consequenceImplementation burden and risk
Connect purchases to a diagnosisReduces poorly prioritised expenditureAdditional assessment can delay small projects
Permit proportionate capability expenditureHelps firms operate funded systemsRequires clear boundaries and quality checks
Address financing before reimbursementImproves access for liquidity-constrained firmsAdvances require stronger monitoring
Verify operation after installationDistinguishes delivery from effectivenessFollow-up costs must be budgeted
Publish refusal, payment and completion dataReveals where the process failsReporting must protect sensitive information

These are analytical options drawn from the comparison, rather than assertions that one country has solved every implementation problem. They can be introduced proportionately: inexpensive projects need a lighter process than large, complex interventions.

Key judgments

Austria demonstrates the value of connecting advice and implementation. The Netherlands targets inexpensive organisational and technical controls. Finland’s current advance-payment model addresses financing for selected producers. Ireland’s completed programme connects diagnosis, implementation and retesting, while Spain demonstrates administrative delivery at scale.

For Italy, the central opportunity is to combine acquisition support with evidence that firms can finance, operate and retain the resulting capability. The central risk is judging success through allocated money and invoices before those later stages are observed.

What would change the assessment

Consistent evidence of verified improvements, participation by less-prepared firms, manageable financing burdens and retained capability after funding expires would strengthen confidence. High withdrawal, unresolved recommendations, weak follow-up or dependence on subscriptions that lapse after support would weaken it.

Open official record

The decisive comparative gap is a common set of implementation results: qualifying applicants, refusal reasons, grant commitments, actual payments, completion, independent verification and retention. Until those measures are available on compatible definitions and periods, a numerical ranking of national cybersecurity investment performance would exceed the evidence.


Pillar III — Structural contradictions and policy choices

Assessment cutoff: 8 October 2026. The outlook extends to 2031. Announced allocations, contractual commitments, payments and operational results remain separate measures.

Chapter 6 — Skills, procurement, cloud concentration, industrial dependencies and supply-chain exposure

Principal judgment. Europe’s central structural contradiction is that investment in digital protection can increase dependence on external operators without creating sufficient capacity to supervise them. Italy faces a particularly important execution challenge: widespread cloud adoption coexists with a relatively small ICT specialist workforce. Subsidised acquisition can improve protection, but its effectiveness depends on procurement competence, operational responsibility and the ability to recover when a supplier fails.

Italy’s adoption indicators and workforce indicators describe different capabilities

Eurostat records 10.45 million ICT specialists in EU employment in 2025, representing 5% of employed people. Italy’s share was 3.8%, compared with Finland’s 7.8%. These are ICT employment measures, not counts of cybersecurity professionals or direct measurements of defensive effectiveness. Number of ICT specialists in the EU continues to grow — Eurostat — May 2026. Eurostat

Workforce indicatorValueReference periodInterpretation
EU ICT specialist employment10.45 million2025Broad ICT workforce
EU ICT specialists as a share of employment5.0%2025Comparable employment denominator
Italy3.8%2025Below the EU employment share
Finland7.8%2025Larger relative ICT workforce
Italy–EU difference−1.2 percentage pointsCalculatedDoes not establish a corresponding cyber-performance gap
Women’s share of EU ICT specialist employment19.5%2025Indicates a narrow recruitment base

Against this workforce background, ISTAT reports that 68.1% of Italian enterprises with at least ten employees purchased intermediate or advanced cloud services in 2025. The figure was 67.7% among enterprises with 10–249 employees and 87% among larger firms. Imprese e ICT: Anno 2025 — ISTAT — December 2025, p. 2. istat.it

Italian cloud adoptionShare purchasing intermediate or advanced services
Enterprises with at least ten employees68.1%
Enterprises with 10–249 employees67.7%
Enterprises with at least 250 employees87.0%
Difference between the latter two groups19.3 percentage points, calculated

The statistical populations must remain explicit. These enterprise figures exclude businesses with fewer than ten employees, whereas public support can reach much smaller organisations. They also measure service acquisition, not whether customers understand access permissions, contractual responsibilities, recovery arrangements or supplier dependencies.

The analytical implication is that adoption policy and capability policy should be assessed separately. Purchasing a service transfers some operational tasks to a provider, but the customer still needs enough competence to choose the service, configure its use and recognise failures. A workforce constraint can therefore remain consequential even when firms outsource most technical work.

The latest UK evidence shows that an established cyber market does not eliminate skills gaps

The UK’s September 2026 labour-market study estimates approximately 145,900 people in the cybersecurity workforce, an increase of 2%. It reports basic technical skills gaps in 57% of businesses, compared with 49% in the preceding study. Its estimates and survey measures should not be combined with Eurostat’s broader ICT employment series. Cyber security skills in the UK labour market 2026 — UK Government — September 2026. GOV.UK

UK indicatorLatest reported valueRelevant qualification
Estimated cybersecurity workforceApproximately 145,900Occupational estimate
Workforce growth2%Comparison with the previous year
Businesses with basic technical skills gaps57%Survey-defined gap
Previous study’s corresponding figure49%Eight-percentage-point increase
Cybersecurity graduates7,950Academic year 2023/2024
Change in cybersecurity apprenticeship enrolment−15%2023/2024 to 2024/2025

The apprenticeship figure comes from the full study. Cyber security skills in the UK labour market 2026 — UK Government — September 2026, summary. GOV.UK

The coexistence of more graduates, slower workforce growth and widespread basic gaps suggests several different policy problems. Graduate supply does not automatically produce experienced staff. Firms may need supervised entry routes, technical management, practical retraining or access to reliable shared services. An aggregate workforce target cannot identify which of these constraints prevents a particular business from operating securely.

For Italy, this evidence argues against treating the number of training participants as the sole skills outcome. A more useful measure is whether participants subsequently perform defined tasks successfully: administering access, restoring data, supervising a provider or executing an incident procedure.

Outsourcing concentrates scarce expertise, but also concentrates exposure

ENISA’s 2025 investment study surveyed 1,080 public and private organisations across the EU; 83% were large enterprises and 17% SMEs. It reports persistent difficulties attracting and retaining cybersecurity professionals. This sample supports analysis of critical-sector organisations, but it is not representative of every European microbusiness. What’s Driving Cybersecurity Investments and where lie the challenges? — ENISA — December 2025. ENISA

The report’s supplier findings expose a particularly important contradiction.

Supplier-related indicatorReported shareWhat it measures
Organisations implementing specific third-party or supply-chain controls90%Reported control adoption
Requiring supplier standards or certifications63%Assurance requirements
Supplier risk assessments or audits54%Assessment activity
Cybersecurity requirements in supplier contracts48%Contractual provisions
ICT service-management entities without cybersecurity testing in the preceding year43%Reported testing gap
ICT service-management entities taking over three months to patch critical systems45%Reported remediation delay

Source: NIS Investments 2025 — ENISA — December 2025, pp. 26–27. The service-management category includes managed service and managed security service providers. enisa.europa.eu

These measures are not mutually exclusive, and they do not prove that certifications are ineffective. They show that contractual assurance and operational maintenance are different activities.

A provider serving many customers can distribute expertise efficiently. The same arrangement can transmit a failure across those customers when they share administration, infrastructure or a vulnerable service. Procurement therefore needs to assess both the provider’s individual quality and the concentration created across the customer portfolio.

Cloud concentration must be measured at the correct market layer

The CMA’s final cloud investigation provides a useful official concentration measure: installed data-centre capacity in the UK and European Economic Area. Its published 2024 ranges place Microsoft at 40–50%, AWS at 20–30% and Google at 10–20%. These are capacity shares, not each country’s cloud revenue shares or the distribution of all cybersecurity expenditure. Cloud services market investigation: Final decision report — Competition and Markets Authority — July 2025, Table 3.4, p. 106. assets.publishing.service.gov.uk

ProviderPublished 2024 capacity rangeGeographic scope
Microsoft40–50%UK and EEA
AWS20–30%UK and EEA
Google10–20%UK and EEA
Oracle0–5%UK and EEA
CoreWeave0–5%UK and EEA
IBM0–5%UK and EEA

The CMA publishes ranges to protect confidential information. Their midpoints should not be presented as observed shares, and overlapping ranges should not be converted into a precise concentration index.

The relevant structural issue extends beyond the infrastructure invoice. A business can buy different applications from several vendors while those vendors rely on the same underlying cloud, identity system or managed operator. Apparent supplier diversity at the contractual level may therefore conceal common dependencies.

This distinction matters for public grants. A catalogue containing numerous vendors does not necessarily create infrastructure diversity. Evaluators need to identify the underlying operator where a funded service is critical to business continuity.

Procurement should disclose the dependencies that the customer cannot see

The NCSC’s cloud principles address matters including asset protection, supply-chain security, identity, administration and audit information. They provide a basis for asking what a provider secures and what remains the customer’s responsibility. The cloud security principles — National Cyber Security Centre — current guidance. National Cyber Security Centre

The following is a proposed procurement checklist, rather than a claim that every national programme already requires these disclosures.

DependencyInformation the buyer should obtainEvidence useful at acceptance
Underlying infrastructureOperator, service region and critical hosting dependenciesVerified service architecture
Identity and privileged accessWho can administer systems and how emergency access worksTested access and revocation procedure
SubcontractingMaterial subcontractors and notification of changesCurrent dependency register
Software maintenanceSupport period, update responsibility and escalation routeMaintenance schedule and supported versions
RecoveryData copies, restoration procedure and responsible partiesSuccessful restoration test
PortabilityExportable data, formats and configuration documentationSample export and usable documentation
Provider failureAssistance, alternative arrangements and termination provisionsExercised continuity procedure
Incident evidenceLog availability, retention and access conditionsSuccessful retrieval of required records

A small firm should not be expected to negotiate every clause independently. Public authorities and programme operators can supply standard schedules, while specialist advisers assess more complex services.

Standardisation nevertheless needs proportionality. Requiring an elaborate supply-chain inventory for a minor purchase can consume more resources than the intervention saves. Criticality should determine the depth of disclosure: an application supporting an essential process warrants a different assessment from a peripheral tool.

The Data Act reduces an exit charge, not every cost of leaving

From 12 January 2027, the Data Act prohibits switching charges for the switching process within its scope. However, the regulation distinguishes those charges from standard service fees and early termination penalties. It does not eliminate all expenditure on migration or redesign. Regulation (EU) 2023/2854, Data Act — European Parliament and Council — December 2023, Article 2(36), Article 29 and recital 89. EUR-Lex

Exit expenditureEffect of the switching-charge ruleRemaining procurement question
Provider-imposed charges for mandated switching operationsProhibited from the specified dateAre invoiced charges correctly classified?
Data egress forming part of switchingIncluded in the withdrawalIs the proposed movement a qualifying switching process?
Ordinary service feesDistinct from switching chargesWhen does the existing contract end?
Early termination penaltiesDistinct categoryAre they lawful and proportionate?
Customer’s migration assistance and redesignNot universally eliminatedWhat skills, testing and integration remain necessary?

The Commission also explains that switching involves contractual transparency, open interfaces and data export requirements. These measures address barriers, but they do not establish that every complex application can be moved immediately without operational disruption. Data Act explained — European Commission — current explanation. Shaping Europe’s digital future

The implication for grant design is precise: portability should be considered before purchase. A legal right to exit has limited practical value if the customer cannot reconstruct its workflow elsewhere.

Industrial autonomy requires control of functions, not a domestic address

The European supervisory authorities’ first DORA list designates 19 critical ICT third-party providers. It includes infrastructure, software and service companies, illustrating that financial-sector dependence reaches beyond the major cloud platforms. List of designated critical ICT third-party service providers — European Supervisory Authorities — November 2025. esma.europa.eu

Designation subjects providers to oversight aimed at their risk management and governance. It is not a certification that customers face no residual risk. The European Supervisory Authorities designate critical ICT third-party providers under DORA — European Supervisory Authorities — November 2025. esma.europa.eu

Industrial-policy objectiveMeaningful testInsufficient proxy
Control over sensitive operationsAdministrative authority, access arrangements and enforceable restrictionsRegistered office alone
Technological substitutabilityA functioning alternative for the relevant serviceA list of potential vendors
Domestic industrial contributionEngineering, maintenance and retained intellectual capabilityResale revenue alone
Continuity under supplier failureAvailable expertise, documentation and recoverable dataContractual reassurance without testing
Sustainable competitionBuyers can compare and change servicesA large catalogue containing common underlying dependencies

These are proposed analytical tests. They avoid assuming that domestic supply is always technically superior or that foreign supply is necessarily insecure.

A credible European industrial policy must distinguish areas where domestic capability is indispensable from areas where diversified international procurement is effective. Otherwise, autonomy requirements can produce expensive substitution without reducing the dependency that matters.

Key judgments

Italy’s workforce and adoption indicators make operational supervision a material policy concern. Outsourcing can improve access to expertise while creating common failure points. Procurement should therefore establish responsibilities, underlying dependencies and workable recovery before treating acquisition as completed capability.

What would change the assessment

Evidence of successful restoration, usable exports, effective supplier oversight and improved practical competence would strengthen confidence. Persistent common dependencies combined with weak customer visibility would weaken it.

Open official record

The consequential missing evidence concerns the underlying infrastructure of funded services, operational responsibility after installation, supplier concentration across beneficiaries, exit tests and the practical skills retained by customers.

Chapter 7 — The 2026–2031 outlook: funding continuity, enforcement and operational scenarios

Principal judgment. The next five years will be shaped by a transition from funding initial deployment to maintaining and supervising recurring services. Stronger rules can improve behaviour, but continuity depends on operating budgets and credible enforcement. The principal downside is a widening gap between formal compliance and the ability to sustain services during a shared-provider disruption.

The funding transition is already visible in the official record

The Commission’s annual RRF report, published on 7 October 2026, confirms that the completion deadline for milestones and targets passed on 31 August, and final payment requests were due by 30 September. Commission payments must conclude by 31 December 2026. These deadlines concern the Recovery and Resilience Facility; they should not be applied indiscriminately to other funding instruments. Recovery and Resilience Facility Annual Report 2026 — European Commission — October 2026. Reforms and Investments

RRF stageDeadlinePosition at the cutoff
Completion of milestones and targets31 August 2026Deadline passed
Final payment requests30 September 2026Deadline passed
Commission payments31 December 2026Assessment and payment period continues
Subsequent operation of funded capabilitiesDepends on operating arrangementsNot guaranteed by the completion deadline

The funding risk is therefore broader than incomplete procurement. Systems financed through temporary investment programmes may continue to require subscriptions, staff, exercises, maintenance and replacement. Completing an investment does not settle who finances those activities afterward.

This is particularly important where reported completion rests on installation. The future cost of keeping a service effective should be recorded before the investment is accepted, alongside the organisation responsible for paying it.

The ECCC envelope has been revised downward

The consolidated ECCC work programme adopted in July 2026 reduces its indicative 2025–2027 envelope from €390 million to €355 million, explaining that €35 million was reallocated to support AI Gigafactories. The reduction is 8.97%, calculated from those amounts. Digital Europe Cybersecurity Work Programme 2025–2027, Consolidated Amendment 3 — ECCC — adopted July 2026, p. 13. cybersecurity-centre.europa.eu

Updated indicative allocationAmount
New technologies, AI and post-quantum transition€139 million
Cyber Solidarity Act implementation and related capabilities€97 million
Additional actions improving EU resilience€110 million
Programme support, including evaluation and review€9 million
Total€355 million

The figures are indicative work-programme allocations, not expenditure already delivered. They cover ECCC-implemented actions within this programme, rather than all European cybersecurity funding.

The reallocation does not prove that European cybersecurity investment as a whole declined. It establishes a narrower and important point: an announced cyber envelope can change as competing digital priorities are financed. Long-term planning should therefore distinguish political ambition from protected programme resources.

A new €96 million call bridges into 2027, but does not guarantee support to every SME

The September 2026 ECCC call provides an estimated €96 million across seven topics, with a deadline of 14 January 2027. It finances deployment and capacity projects; it is not a universal retail voucher. Strengthening European Cybersecurity Technologies, Capacities and Preparedness — ECCC — September 2026. cybersecurity-centre.europa.eu

TopicEstimated call allocationPrincipal policy function
Cybersecurity tools and services using AI€15 millionDevelopment and deployment
AI-powered cybersecurity solutions for SMEs€20 millionUptake and dissemination
Coordinated preparedness testing and other actions€15 millionExercises and preparedness
Regional cable hubs€5 millionInfrastructure awareness and coordination
National Coordination Centre network€11 millionEcosystem support
Capabilities supporting legislative requirements€20 millionImplementation support
Dual-use technologies€10 millionCivil–defence cooperation
Total€96 millionEstimated call budget

The call document gives indicative durations of 24 months for coordinated preparedness and 36 months for the other listed topics. Consequently, awards following the 2027 deadline can support work beyond the current budget-programming period. They do not establish uninterrupted assistance through 2031. Call document: DIGITAL-ECCC-2027-DEPLOY-CYBER-11 — ECCC — September 2026, pp. 46 and 56. cybersecurity-centre.europa.eu

The implementation question is how shared or intermediary projects reach ordinary firms. A funded platform can exist without substantial use; a successful pilot can remain difficult to procure; a technically strong service can require expertise unavailable to its intended customers. Beneficiary reach and sustained use should therefore be measured separately from project delivery.

Post-2027 funding remains a legislative and allocation question

The Commission’s 2028–2034 budget proposal provides a prospective framework for competitiveness, digital transition and security. The proposal should not be presented as a final cybersecurity appropriation or as guaranteed support for particular national programmes. EU budget 2028–2034 — European Commission — proposal presented July 2025. commission.europa.eu

Funding conditionConsequence for 2026–2031 planning
Existing grant agreementProvides defined project support, subject to its conditions
Open callOffers a competitive opportunity, not an assured award
Indicative work programmeEstablishes priorities that can be amended
Proposed future budgetSignals intent; adoption and detailed allocations remain decisive
National operating appropriationCan maintain capability beyond the initial project
Unfunded continuation planLeaves renewal and staffing exposed

This distinction is central to the outlook. A credible maintenance plan must identify an actual payer and budget mechanism. Assuming that the next European programme will cover recurring costs creates a dependency on decisions outside the beneficiary’s control.

Enforcement must change operational behaviour, not simply produce documentation

ENISA’s survey identifies regulatory compliance as the principal investment driver for 70% of respondents. This supports the judgment that enforcement expectations affect expenditure, while leaving open whether the resulting spending produces durable capability. What’s Driving Cybersecurity Investments and where lie the challenges? — ENISA — December 2025. ENISA

The useful enforcement sequence is to identify a material weakness, require correction, verify the change and monitor recurrence. Counting notices or penalties alone omits the central question: whether the service became more resilient.

Enforcement measureDecision-useful denominatorPotential misleading interpretation
Inspections completedRelevant entities and risk coverageMore inspections automatically mean better supervision
Corrective actions issuedMaterial weaknesses identifiedEvery instruction represents a completed correction
Actions closedActions independently verifiedAdministrative closure equals operational success
Repeat findingsPreviously inspected entitiesRecurring weaknesses disappear from aggregate totals
Time to correctionSeverity and operational constraintsFast closure is always preferable to durable remediation
Supplier-related findingsCritical service dependenciesEach legal entity is an independent risk unit

This is a proposed supervisory reporting framework. It would permit comparisons without assuming that authorities face identical populations or responsibilities.

The UK competition investigation is a concrete 2027 decision point

The CMA launched its strategic market status investigation into Microsoft’s business software ecosystem on 14 May 2026. Its published timetable identifies 13 February 2027 as the statutory deadline for issuing an SMS decision notice. An investigation is not a designation, and a designation would not itself prove that all competition concerns had been resolved. Microsoft’s business software ecosystem — Competition and Markets Authority — investigation opened May 2026. GOV.UK

This creates an observable policy branch. Measures affecting licensing, interoperability or customer choice could alter procurement conditions. Their practical value should be assessed through actual alternatives, contract terms and switching experience.

For EU buyers, the relevance is indirect. UK intervention does not automatically amend EU contracts, but developments in a shared software ecosystem may inform procurement and competition assessments elsewhere.

Public-sector implementation plans reveal different accountability mechanisms

France’s April 2026 roadmap provides for monthly interministerial monitoring. It also sets initial cryptographic inventory work for 2026–2027 and implementation objectives toward 2030. These are planned stages, not evidence that the transition has already been completed. Publication de la feuille de route des efforts prioritaires en matière de sécurité numérique de l’État 2026–2027 — ANSSI — April 2026. ANSSI

In an April parliamentary answer, the UK government identified initial institutional achievements and milestones due by April 2027. It stated that investment remained subject to business-case approval, without supplying the requested percentage committed in that answer. This does not establish the commitment position in October; it illustrates why milestone reporting and financial reporting must be read together. Government Cyber Action Plan: Written answer HL16287 — UK Parliament — April 2026. UK Parliament

The comparison concerns accountability rather than an unsupported ranking. France specifies a recurring coordination process; the UK exposes milestones to parliamentary scrutiny. Both still require evidence that corrections were delivered and funded.

Shared response capacity needs contracting evidence

ENISA describes a €36 million allocation supporting response and reporting under the EU Cybersecurity Reserve framework. A separate procurement notice seeks a framework involving three operators for services in nine Member States, with a maximum €18 million over four years. The notice remains marked “in progress.” EU Cybersecurity Reserve — ENISA — current programme description and Supporting ENISA for the provision of EU Cybersecurity Reserve services — ENISA — 2026 procurement notice. ENISA

The two amounts should not simply be added. A framework ceiling is also not guaranteed expenditure or proof that a specified number of experts can deploy immediately.

The operational test is availability under simultaneous demand: contractual response times, geographic coverage, specialist capacity and arrangements where several countries request assistance together. This is where pooled procurement can add value, but also where nominal capacity can exceed usable capacity.

Three operational pathways for 2026–2031

The following scenarios are analytical pathways. They can overlap across sectors and countries; no numerical probabilities are assigned.

PathwayMechanismObservable indicatorsPrincipal consequence
Capability consolidationFunding continues into maintenance; supervision verifies corrections; procurement supports recoveryRetained controls, successful exercises, fewer repeat findingsBetter continuity despite continuing incidents
Uneven complianceBetter-resourced firms maintain capability while smaller organisations struggle with recurring costsUnresolved actions, lapsed services, widening completion gapsPersistent exposure concentrated in weaker organisations
Common-provider disruptionA shared service failure affects multiple customers whose alternatives are incompleteCommon dependencies, failed exit tests, constrained response capacityCorrelated interruption across firms or sectors

The adverse pathway does not require a more sophisticated attacker. It can arise from a technical failure, a compromised administration service or an inability to restore a shared process. The distinguishing feature is correlated exposure.

Likewise, capability consolidation does not mean incidents disappear. It means organisations limit disruption, restore services and avoid repeating preventable failures.

The dated milestones and the analytical checkpoints

PeriodDocumentary milestone or analytical checkpointEvidence that matters
Late 2026RRF payment closure; continuing programme implementationCompleted capability and identified maintenance budgets
January 2027Data Act switching-charge prohibition; ECCC call deadlineContract compliance and subsequent awards
February 2027CMA statutory SMS decision deadlineActual decision and subsequent measures
2027–2028Proposed analytical checkpoint: first sustained-use assessmentsRetention, restoration and withdrawal results
From 2028Proposed next EU budget periodAdopted instruments and accessible allocations
2029–2030Proposed analytical checkpoint: mature operationRepeat findings, staffing continuity and exercised alternatives
2031Final horizon of this assessmentComparable retained capability and business-interruption evidence

The analytical checkpoints are recommendations for assessment, not official deadlines.

Key judgments

Funding continuity will determine whether initial improvements survive. The revised ECCC envelope demonstrates that allocations can change, while the open call demonstrates continuing investment opportunities. Enforcement will be most consequential where it verifies correction and recognises common dependencies.

What would change the assessment

Protected maintenance budgets, independently verified remediation and functioning alternatives would favour capability consolidation. Repeated funding interruptions, lapsed services and untested shared dependencies would favour the adverse pathways.

Open official record

The decisive records are post-2027 appropriations, operating commitments, completed corrective actions, Reserve contract awards and deployable capacity, and follow-up assessments of funded projects.

Chapter 8 — Policy options, measurable outcomes and final comparative assessment

Principal judgment. Italy should evaluate public cybersecurity support through retained operational capability, additional private investment and reduced business interruption. The strongest policy package combines proportionate diagnosis, implementation finance, practical skills, independent acceptance and recurring maintenance. European comparison provides design lessons, but the available record does not support a numerical ranking of national resilience.

Separate the objectives before allocating money

A programme can pursue several legitimate goals: helping firms acquire protection, supporting domestic suppliers, improving regulatory implementation or building shared response capacity. Problems arise when a measure designed for one objective is evaluated using another objective’s indicators.

ObjectiveAppropriate interventionPrimary outcomeMisleading substitute
Correct basic business weaknessesSmall, targeted implementation supportCritical controls functioningTotal software purchased
Improve management decisionsIndependent diagnosis and practical adviceRecommendations implementedReports produced
Strengthen industrial capabilityDevelopment, testing and market deploymentSustained customers and maintainable productsPrototype count alone
Reduce common dependenciesDependency mapping and continuity procurementTested alternativesNumber of contracting vendors
Improve public-service resilienceMaintenance and corrective programmesEssential functions restored within requirementsInvestment announced
Build response capacityContracted assistance and exercisesAvailable capacity under stressFramework ceiling

This separation should occur in programme design and reporting. Otherwise, a broad digitalisation budget can be described as cybersecurity spending, or an industrial development project can be judged by an incident-reduction outcome it was not designed to deliver.

A complete intervention should have distinct decision gates

The following is a proposed design for future support or complementary measures. It does not describe obligations already imposed on every Italian beneficiary.

GateRequired evidenceFunding decision
Establish the baselineExisting systems, critical processes and operational weaknessesConfirm the problem to be addressed
Define the interventionPrioritised changes and responsible operatorExclude unnecessary or incomplete purchases
Assess financingBeneficiary contribution and operating-cost planIdentify execution and continuation risk
Approve implementationEligible procurement and delivery planCommit support
Verify acceptancePractical tests and resolved defectsRecognise operational delivery
Assess retentionContinued operation after an appropriate intervalMeasure lasting value

The process should be lighter for inexpensive, standard interventions and deeper for complex or critical projects. Proportionality is essential: a small improvement should not require the documentation of a major infrastructure contract.

Acceptance also needs independence. Where the same supplier recommends, sells and declares the successful implementation of a solution, the programme should identify which evidence is independently checkable. This does not imply misconduct; it addresses an incentive conflict.

Policy options and their implementation trade-offs

OptionResponsible levelExpected effectBurden and time to effectReversibilityPrincipal risk
Standard diagnostic routeMinistry/programme operator, with technical inputImproves prioritisationModerate setup; usable within a programme cycleHighAssessments become a paperwork market
Capped advances for selected applicantsFunding authorityReduces financing barriersRequires controls and reconciliationModerateRecovery where projects fail
Implementation-related skills supportFunding authority and qualified providersImproves operation of funded systemsDelivery can begin alongside installationHighAttendance substitutes for competence
Independent acceptance samplingProgramme operatorDetects ineffective installationRequires testing capacityHighExcessive delay or supplier influence
Maintenance and renewal support tied to needBudget authority and programme operatorImproves retentionRequires recurring resourcesModeratePermanent subsidy of commercially viable services
Shared services for small organisationsRegional or sector bodiesDistributes scarce expertiseLonger setup and procurementModerateCreates a new concentration point
Portability and recovery schedulesProcurement authoritiesMakes exit and restoration more workableContract preparation plus testingHigh for future contractsFormal rights remain technically unusable
Supplier concentration monitoringNational and EU authoritiesIdentifies common dependenciesData collection and analysisHighIncomplete reporting obscures actual concentration

These are options, not expenditure commitments. Their feasibility depends on the applicable instrument, budget authority and procurement rules.

The most immediate improvements concern evidence and standardisation: consistent baselines, clearer acceptance tests and comparable reporting. Larger structural changes—shared services or recurring support—require an operating model and durable financing.

Financial design should expose the full cost of operation

The acquisition price is only one part of the economic commitment. Evaluation should record recurring charges, staff time, maintenance, testing and eventual replacement or exit.

A simple illustrative case shows why grant percentages can obscure the longer-term burden.

Hypothetical five-year costAssumed amount
Initial implementation€20,000
Service and maintenance€6,000 annually
Five years of recurring expenditure€30,000
Total undiscounted expenditure€50,000
Hypothetical support covering half the initial implementation€10,000
Beneficiary’s remaining expenditure€40,000
Support as a share of five-year expenditure20%

Illustrative assumptions only; this is not an estimate of a national programme or market price. It excludes taxes, inflation, discounting and internal labour.

The policy implication is not that acquisition support lacks value. It is that a contribution described as “50%” can finance a much smaller share of the commitment required to maintain the capability.

Applicants should therefore identify how recurring costs will be financed. For public bodies, this requires coordination between investment approval and operating appropriations. For businesses, it requires an assessment of whether the service remains affordable after support ends.

Measure the beneficiary journey using separate denominators

Programme performance cannot be represented adequately by one beneficiary count. Applications, awards, payments and completed interventions describe different stages.

IndicatorProposed definitionWhy it matters
Application rateApplicants relative to an identified eligible populationMeasures reach
Approval rateApproved applications divided by complete applicationsIdentifies access and selection
Execution rateProjects started divided by awardsReveals financing or procurement failures
Completion rateAccepted projects divided by projects due for completionMeasures delivery
Payment rateGrants paid relative to amounts dueMeasures administrative settlement
Retention rateFunctioning interventions at follow-up divided by interventions assessedMeasures persistence
Recommendation completionVerified priority actions completed divided by priority actions dueConnects diagnosis to implementation
Repeat-defect ratePreviously corrected material defects recurring at follow-upTests durability

The denominator must be printed with the result. “Ninety per cent completed” can be misleading if it refers only to the projects that remained in the programme after withdrawals.

Missing follow-up should also remain visible. Organisations that close, withdraw or fail to respond should not silently disappear from the retention calculation. Their status may be relevant to the programme’s actual reach.

Operational measures should correspond to business functions

The following measures provide a practical evaluation framework. They are not universal statutory thresholds.

CapabilityProposed measurementVerification methodInterpretation risk
Access controlCritical accounts covered by the required controlsConfiguration review and sample testsCoverage can omit important accounts
Asset visibilityCritical assets identified and assigned an ownerInventory reconciliationA larger inventory can reflect better discovery
Vulnerability managementMaterial weaknesses corrected within approved deadlinesTechnical verificationSeverity and compensating measures matter
RecoveryCritical functions restored within business-defined requirementsRestoration exerciseA small test may not represent full recovery
Incident responseTime to execute agreed containment actionsExercise or incident reviewDetection time and exercise design affect comparability
Supplier continuityCritical external services with exercised arrangementsJoint testMultiple suppliers may share infrastructure
SkillsDefined tasks completed correctlyPractical assessmentAttendance and confidence are weaker proxies
PortabilityRequired data exported and used in an alternative environmentControlled migration testExport alone does not recreate the workflow

Business-defined requirements should be approved before testing. Moving the target after an exercise can convert a failed restoration into an apparent success.

Recovery should also be assessed at the level of the service. Restoring files is not sufficient if users cannot authenticate, interfaces do not work or staff lack the procedure required to resume operations.

Economic impact requires more than counting reported incidents

The appropriate economic measures include interruption duration, direct response costs, recovery expenditure and material effects on service delivery. They should distinguish observed expenditure from modelled consequences and avoid adding overlapping categories.

Economic measureUseful basisMain limitation
Business interruptionHours or days of affected critical operationsPartial disruption differs from complete shutdown
Direct response expenditureDocumented external and internal costsFirms record internal costs differently
Recovery expenditureRebuild, restoration and replacement costsCan overlap with response costs
Lost production or transactionsDocumented missed output, with recovery consideredDeferred activity is not always permanently lost
Customer effectsMeasured service delays or cancellationsAttribution may be difficult
Insurance recoveryClaims paid and retained lossCoverage differs and payments can lag
Public-service impactUnavailable functions and affected usersMonetary valuation may be inappropriate

A fall in incident reports is not sufficient evidence of programme success. Better detection can increase reporting, while fewer reports can reflect weaker visibility. Conversely, more incidents can coexist with lower interruption if response improves.

Evaluation should therefore examine several outcomes together, with incident type and severity preserved. A single national total can conceal improvements in common events and continuing exposure to rarer, more disruptive failures.

Establish additionality through a credible comparison

The central fiscal question is whether public support changes behaviour beyond what beneficiaries would otherwise have done.

A phased programme can provide an opportunity to compare similar eligible firms entering at different times. Where demand exceeds capacity, a transparent allocation method may also support stronger evaluation, subject to the programme’s legal design. Neither approach automatically produces a valid causal estimate: comparable groups, timing and follow-up remain necessary.

Evaluation approachWhat it can establishEssential condition
Before-and-after beneficiary assessmentChange within participating organisationsConsistent baseline and follow-up
Similar non-beneficiary comparisonWhether changes differ from wider trendsCredible comparability
Phased entry comparisonEffects before and after support becomes availableTiming is not driven by unmeasured risk
Independent technical sampleWhether interventions workRepresentative selection
Administrative-cost analysisCost of delivering each completed interventionConsistent cost accounting
Longitudinal follow-upWhether capability persistsWithdrawals and missing observations tracked

Before-and-after improvement alone does not establish additionality. Beneficiaries may have invested because of customer demands, regulation or a recent incident even without the grant.

This distinction affects policy choice. If support mainly reimburses investment already planned by well-prepared firms, its fiscal value differs from support that enables otherwise unaffordable corrections.

Procurement can strengthen competition while creating capability

The UK’s cloud intervention shows that competition policy and cybersecurity policy intersect through licensing, interoperability and customer choice. The CMA’s April 2026 statement records steps by providers to reduce barriers, while its subsequent investigation creates a further assessment process. Neither establishes that switching difficulties have disappeared. CMA announces package of actions on business software and cloud services — Competition and Markets Authority — April 2026. GOV.UK

For public procurement, competition should be evaluated through workable alternatives rather than bidder count alone. Specifications that unnecessarily reproduce one supplier’s architecture can narrow the market even where several resellers compete.

Conversely, mandatory diversification can increase complexity. The appropriate test is whether the additional provider creates usable continuity, improves negotiating conditions or reduces a material dependency. Purchasing a second service that staff cannot operate may increase cost without delivering those benefits.

Industrial-policy support should be conditional on maintainable deployment

The EU’s January 2026 cybersecurity package proposes a framework addressing ICT supply-chain risks and simplifying certification and compliance. Its proposed status must remain explicit; the announcement is not itself an enacted replacement regime. Cybersecurity Package: Questions & Answers — European Commission — January 2026. Shaping Europe’s digital future

A sound industrial assessment should examine more than origin or development expenditure.

Industrial outcomeEvidence to require
Deployable productWorking installation in the intended environment
Independent assuranceRelevant evaluation with defined scope
Maintenance capacitySupported versions, update process and sufficient technical staff
Commercial durabilityCustomers beyond the initial subsidised deployment
InteroperabilityDocumented interfaces and tested integration
Reduced critical dependencyFunctionally adequate substitute for the identified dependency
Retained European capabilityEngineering, support and control arrangements verified

Public support can reasonably finance early deployment, but continued assistance should require evidence that the product is usable and maintainable. Otherwise, industrial policy may sustain a succession of demonstrations without creating a supplier capable of supporting essential operations.

Country-specific priorities for the final assessment

The following priorities are analytical recommendations derived from the programme evidence in the preceding pillar. They do not rank countries or imply that the recommended changes have already been adopted.

CountryPriority for the next policy cycleEvidence that would demonstrate progressPrincipal trade-off
ItalyConnect acquisition to competence, acceptance and maintenanceRetained controls and participation by less-prepared firmsMore verification can increase administrative cost
United KingdomExtend practical capability beyond assurance-driven supply chainsSmaller firms implementing and maintaining required controlsBroader assistance requires sustained financing
FranceConnect diagnosis and sensitive-service requirements to executable investmentRecommendations completed and qualified services performing effectivelyStronger requirements can narrow available supply
GermanyMake advice-to-implementation access more consistentAdvisory users completing verified projects across jurisdictionsNational consistency must accommodate regional delivery
AustriaPreserve the connection between advice and executionPriority actions implemented and retainedAdditional assessment can slow small interventions
SpainSeparate cyber outcomes from broad digital deliveryCyber-specific controls and follow-up resultsGreater detail increases reporting demands
NetherlandsRetain low-cost access while addressing financing uncertaintySmall firms completing relevant improvementsEasier access requires robust but proportionate checks
FinlandLink producer support to sustained use and customer capabilityMaintained deployments and users operating solutions effectivelyInnovation support cannot substitute for general business assistance
IrelandMaintain a workable route from review to implementation and retestingDiagnosed weaknesses corrected despite the closed grantContinuity requires a successor financing mechanism

Programme sources: Italy — MIMIT; United Kingdom — NCSC; France — France Num; Germany — Transferstelle Cybersicherheit; Austria — BMWET; Spain — Red.es; Netherlands — RVO; Finland — Traficom; Ireland — NCSC. www.mimit.gov.it

A practical sequence for Italian policy

Proposed sequenceMain actionDecision enabled
During initial deliveryRecord baselines, critical functions and underlying suppliersEstablish what support is intended to change
At acceptanceVerify installation and selected operational testsDistinguish acquisition from capability
First follow-upAssess retention, recurring costs and withdrawalsIdentify continuation problems
Before further allocationAnalyse access, additionality and common dependenciesRedesign eligibility and delivery
Through 2031Maintain compatible outcome seriesAssess durable economic value

This sequence does not require postponing useful expenditure until an elaborate evaluation system exists. Essential data can be collected alongside delivery, with deeper testing applied to representative samples and higher-criticality projects.

The more consequential changes should depend on results. Expanding a programme is justified where it reaches constrained firms and produces retained capability. Where results show weak additionality or ineffective implementation, redesign should precede expansion.

Final comparative assessment

Italy’s principal weakness is the possibility that a broad purchase intervention will advance adoption faster than it advances the competence needed to supervise and maintain that adoption. The latest workforce and enterprise data make this a credible structural concern, but they do not establish that Italy suffers a precisely quantified resilience deficit relative to every comparator.

The European evidence supports a combined policy approach. Advice helps identify priorities; financing enables execution; practical skills sustain operation; independent tests establish whether the intervention works; procurement and competition measures reduce avoidable dependence. These functions require coordination, and their results should be assessed separately before being combined into an overall judgment.

The strongest claim supportable at the cutoff is therefore conditional: public investment can narrow Italy’s resilience gap if it finances and verifies continuing operational capability, while exposing the dependencies it creates. Allocated budgets, completed invoices, certificates and diagnostic reports are necessary evidence of activity, but none alone establishes that outcome.

Key judgments

The appropriate measure of success is a critical business or public function that remains protected, recoverable and affordable after initial support. Italy can improve its policy design by connecting purchase finance to those outcomes. European programmes provide useful components, while also revealing unresolved financing, access and dependency problems.

What would change the assessment

A consistent body of independently checked results showing additional investment, retained capability, shorter disruption and workable supplier alternatives would strengthen the positive judgment. Persistent expenditure without those results would support redesign rather than automatic continuation.

Open official record

The final comparative judgment remains constrained by the absence of compatible national data on retention, additionality, operational testing, interruption and common-provider exposure. Publishing those measures would permit a stronger assessment of value than a league table based on spending announcements.


Copyright of debuglies.com – Even partial reproduction of the contents is not permitted without prior authorization Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.