Many business owners know their digital security could use some improvement. But it keeps getting pushed back, because something else always feels more urgent, and it costs money you’d rather spend elsewhere. As of today, 7 September 2026, that argument is a lot weaker: the Dutch subsidy scheme Mijn Cyberweerbare Zaak (MCZ) is open again. The government pays half of your cybersecurity measures, up to EUR 1,250 per business. The budget is limited, and it’s first come, first served.
What the scheme involves
Mijn Cyberweerbare Zaak is run by RVO, the Netherlands Enterprise Agency, on behalf of the Ministry of Economic Affairs. The scheme reimburses 50% of the cost of purchasing and implementing one or more basic measures, up to a maximum of EUR 1,250 per applicant. For 2026, a total of EUR 1 million is available.
Applications are open from 7 September 2026, 9:00 until 30 November 2026, 17:00. They are processed in order of receipt until the budget runs out. In previous years that happened quickly, so waiting until November is not a good idea.
Who this is for
The scheme is for freelancers and SMEs with at most 50 employees and an annual turnover of at most EUR 10 million, registered with the Dutch Chamber of Commerce (KVK). It’s particularly relevant for smaller businesses in wholesale, manufacturing, and transport. These companies work with many links in the chain, from suppliers to transport partners, but rarely have an IT department of their own. Security then tends to be something that gets squeezed in.
Important: you have to submit the application yourself, using eHerkenning level 2+. An IT provider is no longer allowed to apply on your behalf. What your IT partner can do: help you decide which measures deliver the most, carry them out, and make sure the invoice is usable for the application.
What you can use the subsidy for
The scheme covers eight categories of measures:
- Risk assessment. A scan or baseline measurement that shows where you’re vulnerable, such as our MIRA risk baseline.
- Cyber awareness training for your employees. Most incidents don’t start with technology, but with someone clicking the wrong link.
- Two-factor authentication (MFA). The measure with the biggest effect for the least effort.
- Backups. So you can simply carry on after a ransomware attack or a human error.
- Patch management. Keeping software and systems up to date.
- Antivirus software.
- Password managers.
- Secure network access and Wi-Fi.
Not eligible: websites, web shops, payment systems, and cloud workplaces. Measures you already received MCZ subsidy for in a previous year can’t be submitted again. And the measure must have been purchased after 7 September 2026, so it doesn’t work retroactively.
How to approach this practically
- Start with the free CyberVeilig Check from the NCSC. This is an online questionnaire that results in an advisory report with an action list. Download that report as a PDF, because without this advice your application will be rejected.
- Choose the measures that matter for your business. Not every measure delivers equal value. A good conversation with your IT partner helps determine where you’ll get the most benefit, and which combination gets the most out of the EUR 1,250.
- Have the measures carried out and keep the evidence. You’ll need the itemised invoice and the bank statement showing the payment.
- Submit the application yourself via the RVO portal. With eHerkenning level 2+ and an authorisation for RVO services. If you don’t have that yet, arrange it right away, as it takes a few days.
- Be timely. The EUR 1 million budget is for the whole country. First come, first served.
This subsidy isn’t a reason to only now take cybersecurity seriously, but it is a good occasion to act on something that’s been on the agenda for a while. And with half the costs reimbursed, the sums suddenly look a lot better.
A few questions we’re often asked
Do I need to apply myself, or can my IT partner do it for me?
You have to apply yourself. As of this year, the scheme deliberately separates the supplier from the applicant. Your IT partner can help you choose the measures, carry them out, and make sure the invoice is suitable for the application.
How much subsidy can I get?
50% of the costs, up to a maximum of EUR 1,250 per business. If you spend EUR 2,500 on a risk assessment and an awareness training, for example, you get EUR 1,250 back.
I already work in the cloud with Microsoft 365. Can I still apply for something?
The cloud workplace itself is excluded, but the measures around it are not. Think of properly setting up two-factor authentication, a backup of your Microsoft 365 environment, a risk assessment with MIRA, or training for your employees.
What if the budget runs out before I’ve applied?
Then you can still fund the planned measures yourself, in phases if needed. So don’t make your plan entirely dependent on the subsidy, but see it as an acceleration of something you wanted to do anyway.
Want to know which measures would benefit your business most, or need help preparing your application? We’re happy to think it through with you.