Book an Appointment
Funding · State of NRW · NRW.BANK

Up to €15,000 in grants for your GRC digitalisation

The North Rhine-Westphalia programme “Mittelstand Innovativ & Digital (MID)” — sub-programme Digital Processes — funds external consulting for digitalising internal workflows: from NIS2, CRA, EU AI Act and ISO 27001 gap analyses to roadmap, software selection and VamiGRC implementation support. We know the process from NRW.BANK-funded projects and guide you from application to proof of use.

€15,000maximum grant
€500grant per consulting day
10–30eligible consulting days
Funding call 202607 Sep – 01 Dec 2026Call budget €1.415m · approvals in order of receipt (first come, first served) — prepare your quote and documents now, submit from 7 September.

What is MID-Digitale Prozesse?

“Mittelstand Innovativ & Digital (MID)” is a funding programme of the NRW Ministry of Economic Affairs (MWIKE); the granting authority is NRW.BANK. The Digital Processes sub-programme subsidises external consulting for analysing and optimising internal business and production processes. The directive is explicit: the grant is meant to cover the consulting share of a software introduction — analysing existing workflows, designing digital target processes and providing expert support during the system transition.

That is exactly what GRC digitalisation is: information security, risk and compliance processes are internal business processes — and moving them into a platform like VamiGRC is a textbook MID project. The consulting is funded, not the software: SMEs based in NRW receive up to €500 per consulting day for 10 to 30 days — up to €15,000 as a non-repayable grant (fixed-amount funding).

The four building blocks in detail

Each building block can be booked individually and combined freely — every block here is directly linkable (anchor link).

01 · As-is analysis

Gap analyses & workshops

Every MID project starts with an honest look at the status quo. In moderated workshops and structured interviews we capture your security and compliance processes, document them audit-proof and assess them against the requirements that apply to you — the solid basis for the target concept, your management system and the funding evidence.

  • Gap analyses against NIS2, CRA, the EU AI Act and ISO 27001 — individually or combined; on request also GDPR/ISO 27701, TISAX or the DORA requirements of your financial customers
  • Capturing and documenting the process landscape: roles, responsibilities, information flows, existing controls
  • Maturity assessment per requirement — with evidence instead of gut feeling
  • Workshop formats for management and business units, remote or on site
  • Result: documented as-is state plus gap register — at the same time your evidence for the directive’s success monitoring (target: at least 90 % of processes documented)
02 · Target concept

Roadmap & action plan

The gap register becomes a plan: we design your optimised, digital workflows and prioritise every measure by risk, effort and dependencies — up to compliance and certification readiness.

  • Digital target processes for your management system: risk management, incident and reporting workflows, supplier assessment, document control
  • Prioritised action plan with quick wins, milestones and clear ownership
  • Certification roadmap — for example for ISO 27001, including planning of internal audits and management reviews
  • Effort and resource estimate per measure — budgetable for management
  • Result: digital target concept plus roadmap (directive target: at least 80 %)
03 · Software selection

GRC platform selection

The directive explicitly funds support in selecting suitable systems. We translate your target processes into a requirements catalogue and guide you to a documented, defensible tool decision — vendor-neutral.

  • Requirements catalogue derived from the target processes: functional, technical, operations and data sovereignty
  • Market overview and shortlist of relevant GRC platforms — with VamiGRC as the AI-native reference in the comparison
  • Evaluation matrix, demo/PoC support and a documented selection decision
  • Specification sheet as the basis for implementation and contract design
  • Result: documented software selection or specification sheet (directive target: at least 60 %)
04 · Implementation support

VamiGRC implementation

The biggest building block: expert guidance during the rollout of your GRC platform. We build your management systems in VamiGRC — the entire implementation consulting is eligible, only the licence stays with you.

  • Building ISMS, AIMS, PIMS, BCMS and CSMS in VamiGRC — individually or as an integrated management system
  • Migration of existing content: risks, measures, assets, policies, evidence
  • Configuration of your workflows: incident and reporting flows, supplier assessment, audit management, reporting
  • Enabling your team along the newly introduced processes — process-related guidance, not a mere product training
  • Result: a productive system plus report evidence including impact statements (e.g. time savings, error reduction, process simplification)

All four building blocks can be combined freely — together, 10 to 30 consulting days are eligible. In the free funding check we tailor the package to your starting point.

Book a free funding check

The regulations & standards we cover with this funding

Each topic as a funded path from gap analysis to implementation — with its own topic page. Directly linkable (anchor).

NIS2

Scope, obligations and evidence under the NIS2 implementation act — from the gap to a running ISMS.

More on this topic

CRA (Cyber Resilience Act)

Products with digital elements: security-by-design, SBOM, vulnerability & reporting processes up to CE conformity.

More on this topic

EU AI Act

AI inventory, roles & risk classes, transparency obligations and an AIMS per ISO/IEC 42001.

More on this topic

ISO/IEC 27001

Building an ISMS to certification readiness: SoA, risk management, internal audits — audit-ready.

More on this topic

TISAX

Automotive information security: ISA maturity and assessment readiness incl. the ISA 2027 delta.

More on this topic

DORA (supply chain)

Ready to prove compliance to DORA-regulated financial customers: contracts, controls, trust center.

More on this topic

Data protection / GDPR

Demonstrable accountability: RoPA, TOMs, DPIA and a PIMS — optionally per ISO 27701.

More on this topic

BCM / business continuity

Business impact analysis, emergency concept and exercises per ISO 22301 / BSI 200-4 — as a BCMS.

More on this topic

The €0 model: consulting fully funded

The grant is a fixed amount per consulting day — not a percentage quota. That makes the maths predictable and your own contribution controllable.

Fixed amount instead of a quota

Up to €500 per consulting day (net) is subsidised. The assessment basis is the consultant’s quote at the time of application, stating the number of consulting days.

€0 own contribution for consulting

If your project uses up the eligible consulting days, the grant can fully cover the consulting costs — up to €15,000 with no own contribution for the consulting service.

Paid out in one sum

The grant is paid as a fixed amount in a single sum once the grant notice becomes final. Tip from the directive: waiving legal remedies in text form makes the notice final immediately — the payout arrives sooner.

Only the licence stays with you

Software, hardware and licence costs are not eligible. For a VamiGRC implementation, only the platform licence remains on your side — the entire implementation consulting is funded.

Example: the grant is up to €500 per funded consulting day — so 30 days means the full €15,000, which can fully cover the consulting. Software and licences are excluded. Funds must be used within the three-month implementation period plus five weeks for payments due.

VAT is not eligible and is neutral for companies entitled to input tax deduction. No legal entitlement: NRW.BANK decides at its due discretion within available budget funds; the MID-Digitale Prozesse directive (MBl. NRW. 2026 no. 211) applies as amended.

Who is eligible to apply?

The key requirements and exclusions from the directive — we check your eligibility free of charge in the first call.

SME under the EU definition

Micro and small enterprises (fewer than 50 employees, up to €10m turnover or balance sheet total) and medium-sized enterprises (fewer than 250 employees, up to €50m turnover or €43m balance sheet total).

Registered office in NRW

What counts is the business address in the commercial register or trade registration on the day of application. The consulting firm only needs a registered office in the EU — no certification required.

Project not yet started

The application must be submitted before any legally binding engagement. A valid quote covering at least ten consulting days must be attached — in German, amounts in euros, one contractor only.

Blocking period: once every two years

Each company can use the sub-programme only once within two years — ongoing and pending projects as well as linked and partner enterprises count towards this.

De minimis headroom

The grant is de minimis aid under Regulation (EU) 2023/2831: max. €300,000 of de minimis aid per company over three years; individual grants are published in the EU central register.

No double funding

No other public grants from state, federal or EU funds may be used for the same project — public loans and guarantees are exempt.

No ties to the consultant

Family relationships, identical management or shareholders, and cross-shareholdings between the applicant and the consulting firm are excluded.

Excluded sectors

Not eligible: hospitals, clinics, medical care centres, medical practices and sanatoriums, as well as agriculture, forestry, aquaculture and fisheries (except processing/marketing).

Six steps to your funded project

We know the process from NRW.BANK-funded projects — and prepare the quote, project description and evidence ready for submission.

01

Funding check & first call

Free and non-binding: we check SME status, exclusion criteria, de minimis headroom and the right project scope (10–30 consulting days).

02

Application-ready quote

You receive a valid quote stating the consulting days — in German, in euros, as the assessment basis for the grant.

03

Application in the online portal

From 7 September 2026 you apply digitally via the NRW.BANK funding portal; we supply the project description and documents. Important: before placing the order.

04

Approval & payout

NRW.BANK aims to approve within six weeks. With a waiver of legal remedies the notice becomes final immediately — the grant is paid in one sum.

05

Project delivery

Three months from the grant notice (payments up to five weeks after): gap analyses, roadmap, software selection and VamiGRC implementation support — documented throughout.

06

Proof of use

Final invoice, report with impact statements and monitoring form via the portal — we deliver the as-is analysis, target concept and specification sheet audit-proof.

Frequently asked questions about MID funding

Answered briefly — the directive and the NRW.BANK funding call are authoritative.

Are NIS2, CRA or ISO 27001 gap analyses really eligible?

Yes — as an as-is analysis within a digitalisation project. What matters is the framing: the project targets the digitalisation of your security and compliance processes and prepares the introduction of a software solution (e.g. VamiGRC). Measures that merely implement legal obligations are not eligible — we word the quote and project description accordingly.

Is the consulting really free for us?

The fixed-amount grant of up to €500 per consulting day can fully cover the consulting costs — reducing your own contribution for the consulting to as little as €0. What remains are statutory VAT (neutral for companies entitled to input tax deduction) and, if applicable, licence costs of software such as VamiGRC — software and licences are never eligible.

Who decides on the grant — and how fast?

The granting authority is NRW.BANK. It decides at its due discretion (no legal entitlement) in the order applications are received — first come, first served — and aims to approve within six weeks. The 2026 call runs from 7 September to 1 December 2026 with a budget of €1.415m; it may end early once the funds are committed.

Do we have to choose a certified consultant?

No. You choose the consulting firm freely; certification is not required, the registered office must be in the EU. Subcontracting is not permitted, and there must be no personal or corporate ties between you and the consultant. Exactly one contractor’s quote is eligible.

What happens after approval?

You have three months from the grant notice for delivery (payments up to five weeks after). The grant is paid as a fixed amount in one sum once the notice is final — immediately if you waive legal remedies. At the end you submit the final invoice, report and monitoring form.

What obligations come with the funding?

The report must evidence the impact (e.g. time savings, error reduction, process simplification); the authority may request underlying documents such as the as-is analysis, target concept or specification sheet on a sample basis — we produce all artefacts audit-proof. For your own PR about the project, the unmodified MID logo and the prescribed funding acknowledgement must be used.

We already use other funding — can we still use MID?

No other public grant may be used for the same project (no double funding); other projects are unaffected, and public loans and guarantees are exempt. In addition, the de minimis ceiling of €300,000 per three years applies across all de minimis aid — we check this in the funding check.

Official sources & application route

All figures per the programme page, FAQ and directive (MWIKE circular of 29 July 2026, MBl. NRW. 2026 no. 211, in force from 1 September 2026) — as of 12 August 2026.

Funding check: is your project MID-eligible?

30 minutes, free of charge: we check eligibility, de minimis headroom and project scope — and prepare the quote and application documents so you can submit on 7 September 2026.

Note: this page is information provided by VamiSec GmbH and not a publication of NRW.BANK or the State of NRW. The funding decision rests with NRW.BANK as the granting authority; no legal entitlement.