Ciberseguridad

Cybersecurity with public funding

Spanish SMEs have had public programmes to fund their digital protection, although the two national ones, Kit Digital and Activa Ciberseguridad, now have their calls closed. Summum Sistemas checks which call fits each case, prepares the application when a window is open and carries out the technical measures so that nothing is left unprotected.

ProgrammesKit Digital and Activa Ciberseguridad: calls closed
FundingNextGenEU · PRTR · INCIBE funds
ScopeSMEs and micro-enterprises · Castilla y León · Canarias

70 % of cyber attacks in Spain hit SMEs, according to INCIBE data. The reason is straightforward: SMEs hold valuable assets — customer records, payment data, intellectual property — but have historically under-invested in protecting them. The average cost of an incident for a company with fewer than 50 employees exceeds 35,000 euros in recovery, lost productive time and reputational damage. Against that risk, public programmes have funded security tools and services that were previously out of reach for businesses without a dedicated IT department.

The Activa Ciberseguridad programme, managed by EOI with INCIBE's collaboration under the Recovery Plan (PRTR), offered each qualifying SME in-kind advisory support: a cybersecurity diagnosis and audit, a cybersecurity plan and an awareness workshop. Its 2023-2025 call is closed to applications (EOI). Kit Digital funded the deployment of concrete solutions — managed firewalls, threat detection, encrypted backup, identity management — with vouchers of up to 6,000 euros for companies with 3 to 9 employees and up to 12,000 euros for those with 10 to 49. Its calls have closed (Acelera Pyme): Order TDF/39/2026 only amends articles 4, 6.3 and 28.8 of the regulatory bases and does not open any new application window. If you already have a voucher granted, what remains is to use it before it expires.

These funding lines are accompanied by the NIS2 regulatory framework: the European directive, still pending transposition in Spain (the draft Law on Cybersecurity Coordination and Governance has not been published), provides that companies in essential and important sectors implement minimum security measures, risk management, incident notification and personal accountability at board level. Although the final Spanish law has not yet been published, the European Commission has already launched infringement proceedings against non-transposing Member States, so waiting is not a viable strategy. Summum Sistemas structures the technical roadmap so that every subsidised investment also serves to comply with NIS2 when the law comes into force. For the governance and regulatory compliance analysis of NIS2, we coordinate with the Summum Consultoría team, which owns that domain within the group.

The Cybersecurity with public funding process.

The process · four stages
01

Diagnosis and eligibility

We audit the current security posture (asset inventory, exposure, existing controls) and verify which calls are open and which ones the company qualifies for based on its CNAE code, size and autonomous community. We deliver a gap report with prioritisation by real risk.

02

Application and processing

We prepare the technical and administrative documentation required by each programme (descriptive report, action plan, certificates). We guide the company through the electronic submission and follow up the file until the grant award decision.

03

Technical deployment

We deploy the solutions covered by the grant: EDR/XDR on endpoints, next-generation firewalls, centralised identity management (MFA, SSO) and encrypted backups on sovereign cloud — all integrated with existing ERP and CRM systems.

04

Training, justification and maintenance

We train staff on the new tools and secure habits (phishing awareness, password hygiene, device management). We prepare the financial and technical justification report for the granting body and establish an annual maintenance and review plan to keep protection up to date.

What is included

What Cybersecurity with public funding includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Cybersecurity diagnosis

    Technical analysis of the perimeter, endpoints, internal network, access management and backups. Gap report prioritised by impact and ease of remediation.

  • Grant application

    Identification of open calls that fit the project, drafting of the technical report and processing before the body running the call. Kit Digital and Activa Ciberseguridad no longer accept applications.

  • Endpoint and network protection

    Deployment of EDR/XDR, NGFW firewalls, network segmentation, DNS filtering and Zero Trust access control. Integration with existing Microsoft 365 or Google Workspace environments.

  • Identity and access management

    Implementation of multi-factor authentication (MFA), single sign-on (SSO) and least-privilege access policies. Reduces the attack surface against credential theft.

  • Encrypted backup and recovery

    Encrypted backup solution on sovereign EU cloud, with documented periodic restoration tests. Ensures business continuity against ransomware or hardware failure.

  • Justification and final audit

    Preparation of all justification documentation (invoices, deployment evidence, technical reports) to close the grant file and, where applicable, to support the granting body's audit.

Frequently asked questions about Cybersecurity with public funding.

Were Activa Ciberseguridad and Kit Digital compatible?

Yes. They were independent programmes with different funding sources: the first offered a free diagnosis and cybersecurity plan, and the second funds the deployment of specific solutions. Combining them was common, because the Activa Ciberseguridad diagnosis showed which solutions to invest the Kit Digital voucher in. Today both calls are closed.

How much does Kit Digital cover for cybersecurity?

The Kit Digital Cybersecurity category is paid at €125 per device (Order TDF/435/2024, table in article 18.2): up to €250 in Segment III (0–2 employees, 2 devices), €1,125 in Segment II (3–9 employees, 9 devices) and €6,000 in Segment I (10–49 employees, 48 devices), within an overall voucher of €3,000, €6,000 and €12,000 respectively. The calls of the Kit Digital programme have closed (Acelera Pyme). Order TDF/39/2026 only amends articles 4, 6.3 and 28.8 of the regulatory bases and does not open any new application window.

Does the NIS2 directive apply to my SME even though it has not yet been transposed in Spain?

Until it is transposed, NIS2 creates no direct obligations for your company; it serves as a reference for what the law will require and for what many customers already ask for in their contracts, especially if you operate in an essential or important sector (energy, transport, health, digital infrastructure, managed service providers, among others). The draft Law on Cybersecurity Coordination and Governance has still not been published, and the European Commission has already launched infringement proceedings. Waiting for the Spanish law to act is the highest-risk scenario.

What is the difference between a managed SOC and Kit Digital solutions?

For small and micro-enterprises (segments I to III), Kit Digital funds the deployment of tools (licences, configuration, commissioning), not an ongoing monitoring service; the Managed Cybersecurity Service category, with EDR and MDR, was created by Order TDF/435/2024 only for medium-sized companies (segments IV and V). A managed SOC is a different service: it watches the alerts those tools generate 24×7 and responds to incidents. They are complementary — tools detect, the SOC acts — but each one is contracted separately.

Can Summum Sistemas support a company in the Canary Islands?

Yes. We have an office in Las Palmas and have been supporting SMEs in Castilla y León and the Canary Islands since 2017. Grant processing can be carried out remotely for any company in Spain; technical deployment is supported by the local team when the service requires it.