INCIBE Cybersecurity Grants 2026 for SMEs: guide to funding

·

In 2026, the two main national routes for SME cybersecurity funding, the ACTIVA Ciberseguridad programme and the Kit Digital cybersecurity solution, have their calls closed. What remains are regional INCIBE-backed schemes, when a call is open, and INCIBE's free services such as the 017 hotline.

Computer security concept

Cybersecurity is no longer a luxury reserved for large corporations. Today, nearly 60% of Spanish SMEs (under 250 employees) have suffered some form of cyberattack in the past year, according to the Hiscox Cyber Readiness Report (2025) (a survey by a cyber-insurance provider). Public administrations have responded accordingly: in 2025 and 2026 several programmes have been set up specifically designed to help SMEs finance or subsidise their digital protection investments. The problem is that few businesses have a clear picture of which programmes exist, what they actually cover and how to access them without wasting time. This article explains it with real figures and verified sources.

What cybersecurity grants exist in 2026 for Spanish SMEs?

The four main public funding routes for cybersecurity in SMEs have been the ACTIVA Cybersecurity programme (free advisory service co-financed by European funds), the cybersecurity solution of the Kit Digital (economic voucher to contract certified solutions), regional programmes supported by INCIBE (calls such as CIBERREG in Cantabria) and INCIBE's own direct lines (the 017 helpline, training resources and free diagnostics). Today ACTIVA Cybersecurity and Kit Digital have their calls closed, so what is available are the regional calls that are open and INCIBE's free services.

ACTIVA Cybersecurity: specialist advisory at no direct cost

The ACTIVA Cybersecurity programme is part of the Ministry of Industry's Industria Conectada 4.0 strategy and is funded by the Recovery Plan (component 13). Its 2023-2025 call is closed to applications (EOI). It offered SMEs expert support over about four months to diagnose their cybersecurity situation and develop a personalised action plan.

The programme included at least 20 hours of specialist consultancy delivered by companies with proven experience in cybersecurity projects. On completion, the company received a Cybersecurity Plan with concrete measures prioritised according to the risk level identified. The company paid nothing directly: the service was provided in kind, financed by the Government through the School of Industrial Organisation (EOI), which manages the programme together with INCIBE.

With a total budget of more than 9 million euros and capacity to support thousands of SMEs across the national territory, it was one of the programmes with the widest coverage. It was aimed at SMEs in any sector, and registration was managed through the EOI platform.

What does the resulting Cybersecurity Plan cover?

The final deliverable of the programme is not generic. Consultants analyse the company's real technological infrastructure: operating systems, servers, remote connections, password management, backups, staff training and compliance with current regulations (ENS, GDPR, NIS2 where applicable). The action plan identifies critical vulnerabilities, proposes measures with estimated costs and prioritises the actions with the greatest immediate impact. For many SMEs, this diagnosis was the starting point for subsequently applying for the Kit Digital voucher and justifying the investment with sound criteria.

Kit Digital: the voucher for contracting cybersecurity solutions

The calls of the Kit Digital programme have closed (Acelera Pyme): Order TDF/39/2026 only amends articles 4, 6.3 and 28.8 of the regulatory bases and does not open any new application window. The Kit Digital is the SME digitalisation programme managed by Red.es under the Recovery, Transformation and Resilience Plan, financed by NextGenerationEU European funds. It includes a specific category called «Cybersecurity» that allows the financing of technical protection solutions: advanced antivirus, encrypted communications, password management, intrusion detection and cloud backups, among others.

Voucher amounts vary according to the company segment. The following table summarises the amounts set by Order TDF/435/2024 (table in article 18.2):

Segment Company size Total Kit Digital voucher Maximum amount for Cybersecurity (€125 per device)
Segment I 10 to 49 employees 12,000 € up to 6,000 €
Segment II 3 to 9 employees 6,000 € up to 1,125 €
Segment III 0 to 2 employees / self-employed 3,000 € up to 250 €
Segment IV 50 to 99 employees 25,000 € up to 12,375 €
Segment V 100 to 249 employees 29,000 € up to 29,000 €

Note: maximum amounts per category are set by Order TDF/435/2024, which amended the regulatory bases (Order ETD/1498/2021). The Cybersecurity category is paid at €125 per device, up to 2, 9, 48, 99 and 232 devices depending on the segment.

To access the Kit Digital voucher, the company had to register on Acelera pyme (acelerapyme.gob.es), complete the digital diagnostics test and select an Adhered Digitalising Agent. Once the voucher is granted, the agent delivers the service and handles the paperwork: the company does not advance the amount, because payment is made between Red.es and the agent after the service has been justified.

At Summum Sistemas we support our clients in subsidised cybersecurity projects, including those using Kit Digital vouchers already granted: from selecting the most suitable technical solution to coordinating with the digitalisation agent and follow-up afterwards.

Managed cybersecurity (EDR and MDR): for medium-sized companies only

Order TDF/435/2024 added the Managed Cybersecurity Service category for medium-sized companies (segments IV and V), with EDR (Endpoint Detection and Response) and MDR (Managed Detection and Response) solutions. These technologies go beyond traditional antivirus: they monitor device behaviour in real time, detect unknown threats through behavioural analysis and enable automated incident response. The amount is calculated per device: €200 per device, up to 99 devices in segment IV and 145 in segment V.

Regional programmes supported by INCIBE: the case of CIBERREG

In addition to national programmes, several autonomous communities have launched their own calls for support for business cybersecurity, many of them in technical collaboration with INCIBE. A relevant and recent example is CIBERREG in Cantabria, launched in 2026 by SODERCAN with a budget of 150,000 euros. This programme covers up to 50% of eligible expenditure on cybersecurity, with a maximum of 20,000 euros per project, for investments made from 1 January 2025.

Castilla y León also has grant lines for cybersecurity R&D projects, managed by the regional government, aimed at SMEs with their registered office in the region. Companies based in Valladolid, Burgos, Palencia or Aranda de Duero can combine these regional grants with a Kit Digital voucher already granted, provided the same expenditure is not subsidised twice (non-concurrence rule on the same concept).

The general pattern in these regional calls is to finance: acquisition of security hardware (firewalls, appliances), specialist software licences, external cybersecurity consultancy services and technical staff training. It is advisable to monitor the Official State Gazette (BOE) and regional bulletins (BOCYL in Castilla y León, BOC in Cantabria, etc.) to avoid missing application deadlines.

Free INCIBE resources: the 017 helpline and maturity diagnostics

Regardless of grants, INCIBE (National Cybersecurity Institute) makes available to SMEs and self-employed workers a set of highly practical free services:

Using these free resources before applying for a grant is a smart move: the prior diagnosis strengthens the technical justification of the application and helps to prioritise what to invest in, including when you already have a Kit Digital voucher granted.

How to combine the programmes to maximise impact

The optimal strategy for an SME starting from scratch in cybersecurity typically follows this sequence:

  1. Free diagnostics with the INCIBE test (the ACTIVA Cybersecurity programme has its call closed). Identifies real gaps.
  2. Action plan with clear priorities, derived from the diagnostics. This document serves as the basis for any subsequent grant application.
  3. Kit Digital voucher, only if you already have one granted: the calls have closed. With it, a digitalisation agent implements the chosen technical solution in the cybersecurity category.
  4. Complementary regional grants if there is an open call in the autonomous community (CIBERREG, JCYL lines, etc.) to finance additional hardware or consultancy.
  5. Ongoing team training through INCIBE resources and the offer of digitalisation agents, who typically include awareness sessions.

Summum Sistemas has been accompanying SMEs in technology and digitalisation projects since 2017, and we know Kit Digital from the inside: Grupo Summum has handled more than 2,000 files under the programme. If you want to know which grants apply to your specific company, the first step is a no-obligation situation analysis: request your cybersecurity diagnostics here.

Legal obligations that reinforce the need to act

Beyond grants, it is worth remembering that cybersecurity is not only a subsidised investment opportunity: in many cases it is a legal obligation. The GDPR (General Data Protection Regulation) requires every company that processes personal data to implement adequate technical and organisational measures to ensure its security. Non-compliance can result in fines of up to 4% of total annual global turnover or 20 million euros, whichever is greater.

Furthermore, the forthcoming transposition of the NIS2 Directive into Spanish law will expand the perimeter of entities obliged to have cybersecurity management systems in place, including suppliers in sectors such as energy, transport, food, critical manufacturing and digital services. For SMEs operating as suppliers to essential entities, NIS2 compliance will also be a business continuity requirement.

Frequently asked questions

Were Kit Digital and ACTIVA Cybersecurity compatible?

Yes, they were complementary programmes: ACTIVA Cybersecurity provided the diagnostics and action plan, and Kit Digital finances the technical implementation. There was no incompatibility, since the first was an in-kind consultancy service and the second a voucher for technology solutions. Today both calls are closed.

Are cybersecurity grants compatible with other regional subsidies?

Generally yes, as long as the same expenditure is not financed twice. The rule is that the total public aid for the same eligible expenditure must not exceed 100% of the actual cost. If a company receives a 50% regional subsidy for a firewall, it can top up with a Kit Digital voucher already granted to cover the remaining 50%, but cannot exceed the total cost of the good or service. Each call sets its own concurrence rules: it is essential to read the regulatory bases before applying.

What is a «digitalisation agent» and how do you choose one?

A digitalisation agent is a technology company that has passed Red.es' accreditation process to provide solutions within the Kit Digital. It can be a software company, a technology consultancy or a systems integrator. The official agent catalogue is available at acelerapyme.gob.es. The choice of agent is free; the most advisable approach is to select one with demonstrable experience in cybersecurity implementations and, if possible, with references in your sector or company size.

Does the INCIBE 017 helpline serve only individuals or also businesses?

The 017 helpline serves both individuals and businesses and self-employed workers. For businesses, it offers guidance during active security incidents (ransomware, phishing, unauthorised access), help reporting cybercrime and advice on preventive measures. The service is free and confidential. INCIBE also has an incident reporting form on its portal (incibe.es/reporte-amenaza-vulnerabilidad) for cases requiring more detailed technical follow-up.