Book an Appointment
Funding · State of NRW · NRW.BANK

A 50% grant for your IT security

Under its “Digital Security” track, the North Rhine-Westphalia programme “Mittelstand Innovativ & Digital (MID)” funds measures that strengthen your cyber resilience — from penetration tests, incident response plans and awareness training to baseline IT protection including hardware and software. The state covers 50% of eligible costs, up to €15,000. We guide you from the expression of interest to the final proof of use.

€15,000maximum grant
50%of eligible costs
3combinable focus areas
Lottery procedure — open year-round16 slots drawn per monthRegister your interest anytime in the NRW.BANK customer portal; slots are drawn monthly, usually on the first working day. If your entry is drawn, you have 28 days to submit the application — so prepare your quote and documents now.

What is MID-Digitale Sicherheit?

“Mittelstand Innovativ & Digital (MID)” is a funding programme run by NRW’s Ministry of Economic Affairs (MWIKE); since 1 January 2026 the granting authority is NRW.BANK (previously Projektträger Jülich). The Digital Security track subsidises measures that measurably increase your company’s digital security — across three freely combinable focus areas: analysing the current state (A), employee awareness and training (B), and baseline IT protection through software and hardware (C).

Unlike purely consulting-oriented schemes, this track also funds penetration tests, remediation of identified vulnerabilities, incident response plans, training and even protective software including installation — with licences and maintenance covered for up to twelve months. The grant is pro-rata funding: 50% of eligible costs, with a minimum grant of €4,000 and a maximum of €15,000, paid as a non-repayable subsidy.

Looking to digitalise processes instead? See the sister programme MID-Digitale Prozesse

The three focus areas in detail

Each focus area is eligible on its own and freely combinable — every block here is directly linkable (anchor link).

A · Current-state analysis

Pentest, vulnerabilities & IR plan

Focus area A funds the honest outside view: where does your IT security really stand? The services the directive names are exactly our daily business — from penetration testing to a tested emergency response plan.

  • Penetration tests of infrastructure, web applications and cloud — with a prioritised remediation report instead of a raw findings list
  • IT infrastructure analysis: attack surface, configurations, permissions, backup and patch levels
  • Support in remediating identified vulnerabilities — eligible within the same project
  • Incident simulations (tabletop exercises) with management and IT — including lessons learned
  • Creation and testing of emergency and recovery plans, aligned with your critical processes
B · Human factor

Awareness & training

Most successful attacks start with people. Focus area B funds awareness and qualification of your employees — from awareness campaigns to the formal training of the person who will own IT security internally.

  • Security awareness training for all employees — hands-on and tailored to your attack surface
  • Phishing simulations and awareness campaigns as a measurable part of the training measure
  • Targeted sessions for exposed groups: management, assistants, finance, IT
  • Organisational anchoring of IT security: roles, reporting paths, everyday rules of conduct
  • Qualification as IT security officer — a course with a recognised final examination (e.g. IHK, TÜV, DEKRA), optionally via a second contractor admitted for training measures
C · Baseline IT protection

Protective software & hardware

What makes this track special: technology itself is eligible. Focus area C subsidises the initial procurement and installation of baseline protection — we advise vendor-neutrally on what fits your environment and support a secure rollout.

  • Vendor-neutral selection: requirements, market overview and a documented decision for your environment
  • Antivirus, anti-ransomware and patch-management solutions — including initial installation and configuration
  • Firewall and backup solutions: procurement, hardening and restore testing
  • Licences and maintenance are eligible for up to twelve months — software updates included
  • Important: software subject to a BSI warning under Section 13 BSIG is excluded from funding — we factor this into the selection

All three focus areas are freely combinable — the grant covers 50% of costs, with a minimum of €4,000 and a maximum of €15,000. In the free funding check we tailor the package to your starting point.

Book a free funding check

Security services we deliver under this programme

Each service as a funded project — with its own service page. Directly linkable (anchor).

Penetration testing

Infrastructure, web apps and cloud under controlled attack — with a prioritised action plan and fundable remediation support.

Learn more

IT security audit

Systematic analysis of attack surface, configurations and processes — the documented current state from focus area A.

Learn more

Emergency planning & BCM

Emergency and recovery plans, tabletop exercises and incident simulations — tested, not just documented.

Learn more

Security awareness

Awareness training and phishing simulations that measurably lower click rates — as a funded training measure.

Learn more

Training & qualification

From employee awareness to qualifying your future IT security officer with a recognised examination.

Learn more

Baseline protection & operations

EDR, firewall, backup: vendor-neutral selection, funded initial procurement — and Managed Detection & Response afterwards if you wish.

Learn more

The 50% model: the state pays half

The grant is pro-rata funding — predictable, but with your own share and upfront payment. Here is how the maths works.

50% pro-rata funding

The grant covers 50% of eligible costs. The assessment basis is the quotes at the time of application — your own share remains fully predictable.

€4,000 to €15,000 grant

The minimum grant is €4,000 — equivalent to at least €8,000 of project volume. The ceiling is €15,000 at €30,000 of eligible volume; higher spending is allowed, funding stops at the cap.

Reimbursement after completion

The programme works on a cost-reimbursement basis: you pay upfront, and the grant is paid out in one sum after project completion, settled invoices and the proof of use.

Technology is eligible too

Unlike purely consulting-oriented programmes, focus area C also covers software and hardware — including installation, plus licences and maintenance for up to twelve months.

Worked example: a security package of penetration test, awareness training and firewall renewal with €20,000 of eligible costs yields a €10,000 grant. The implementation period is your choice: 3, 6, 9 or 12 months — plus around two months for the proof of use.

VAT is not eligible and is neutral for companies entitled to deduct input tax. No legal entitlement: NRW.BANK decides at its due discretion within available budget funds; the MID-Digitale Sicherheit directive (MBl. NRW. 2026 No. 12) applies as amended.

Who is eligible?

The key requirements and exclusions from the directive and FAQ — we check your eligibility free of charge in the first call.

SME under the EU definition

Micro and small enterprises (under 50 employees, max. €10m turnover or balance sheet) and medium-sized enterprises (under 250 employees, max. €50m turnover or €43m balance sheet).

Registered office in NRW

Decisive is the business address in the commercial register or trade registration. The contractor only needs a registered office in the EU — no certification is required.

Project not yet started

Only projects that have not yet started at the time of approval are funded — even a legally binding order counts as the start of the project.

A competent contractor

The contractor must prove relevant competence (professional or academic qualifications, or further training). Subcontracting and freelancers are not permitted; a maximum of two contractors — the second only for training measures.

Blocking period: once every two years

Each company may use this track only once within two years — affiliated and partner companies count towards this.

De-minimis headroom

The grant is a de-minimis aid under Regulation (EU) 2023/2831: a maximum of €300,000 in de-minimis aid per company within three years.

No double funding, no affiliation

No other public grants may be used for the same measure. Family relationships, identical management or shareholdings between client and contractor are excluded.

Excluded sectors & software

Hospitals, clinics and medical practices as well as agriculture and forestry (except processing/marketing) are not eligible. Software subject to a BSI warning under Section 13 BSIG is excluded from funding.

Six steps to your funded project

We know the process from funded projects — and prepare the quote, project description and evidence ready for submission.

01

Funding check & first call

Free and non-binding: we check SME status, exclusion criteria and de-minimis headroom, and tailor the security package across focus areas A, B and C.

02

Expression of interest in the portal

You register in the NRW.BANK customer portal and express your interest in the lottery — possible year-round, with no deadline and no documents.

03

Draw & application within 28 days

Slots are drawn monthly. If yours is drawn, the application is unlocked — you have 28 days. With our pre-prepared quote you submit immediately; if you are not drawn, you take part again the following month automatically.

04

Wait for approval

Only the grant notice allows you to commission and order — any legally binding order placed earlier puts the entire grant at risk.

05

Project implementation

3, 6, 9 or 12 months, depending on the chosen period: pentest, vulnerability remediation, training and baseline-protection rollout, documented in a structured way. You settle the invoices upfront.

06

Proof of use & payout

Project completion in the portal, final report, invoices and proof of payment — then the grant is reimbursed in one sum. We deliver all reports and evidence audit-proof.

Frequently asked questions

Answered at a glance — the NRW.BANK directive and FAQ remain authoritative.

Are penetration tests really eligible?

Yes — focus area A explicitly lists IT infrastructure analyses, penetration tests, remediation of identified vulnerabilities, incident simulations and the creation of emergency response plans. Exactly the work that gives you a reliable picture of your security posture is eligible — including the follow-up remediation.

How does the lottery procedure work?

In two stages: you express your interest in the NRW.BANK customer portal; every month — usually on the first working day — 16 slots are drawn. If your entry is drawn, the application is unlocked automatically and you have 28 days to submit. If not, you take part again the next month without re-registering. That is why it pays to have your quote and documents ready before the draw.

How much funding do we actually get?

50% of eligible costs, with a minimum grant of €4,000 and a maximum of €15,000. That means your project needs at least €8,000 of eligible volume; the cap is reached at €30,000 — higher spending is allowed, funding stops at €15,000. VAT is not eligible.

When is the money paid out?

After the project: the programme works on a cost-reimbursement basis. You commission after approval, pay the invoices yourself first, and submit the proof of use, final report, invoices and payment evidence after completion — then the grant is paid in one sum. Plan for this pre-financing.

Who may deliver the services?

A contractor with proven relevant competence (qualifications or further training) and a registered office in the EU; no specific certification is prescribed. Subcontracting and freelancers are not permitted, and there must be no personal or corporate affiliation. A maximum of two contractors is allowed — the second exclusively for training measures, such as the IT security officer course.

Can we combine this with MID-Digitale Prozesse?

The tracks are separate: each may be used once per company within two years, and the same measure may never be funded twice. A cleanly scoped security project and a separate process digitalisation project are therefore not mutually exclusive in principle — we check the right scoping and your de-minimis headroom in the funding check.

Are any sectors or products excluded?

Yes: hospitals, clinics and medical practices as well as agriculture and forestry businesses (except processing/marketing) are not eligible. In addition, software the BSI warns against under Section 13 BSIG is excluded — we take this into account from the start in the vendor-neutral selection under focus area C.

Funding check: is MID-Digitale Sicherheit right for you?

30 minutes, free of charge: we check eligibility, de-minimis headroom and the scoping across focus areas A, B and C — and prepare the quote and documents so you can submit right after the draw.

Note: this page is information provided by VamiSec GmbH and not a publication of NRW.BANK or the State of NRW. The funding decision rests with NRW.BANK as the granting authority; no legal entitlement.