Summary
- The Dutch Mijn Cyberweerbare Zaak programme opens on 7 September with a €1 million budget.
- Eligible businesses can claim 50% of qualifying implementation costs, capped at €1,250 per applicant.
- Supported measures include MFA, backups, password managers, patch management, network security, risk assessment, and awareness training.
The Netherlands is reopening a €1 million subsidy programme designed to move small businesses from cybersecurity guidance towards funded implementation of basic resilience measures.
The country’s National Cyber Security Centre said applications for the 2026 Mijn Cyberweerbare Zaak programme will open on 7 September and remain available until 30 November, subject to the available budget.
Qualifying businesses can receive support covering 50% of the cost of purchasing or implementing eligible cybersecurity measures, up to a maximum subsidy of €1,250 for each applicant. Funding will be allocated in order of application until the €1 million budget is exhausted.
The programme is aimed at sole traders and small businesses with no more than 50 employees and annual turnover of no more than €10 million.
Eligible measures include secure network and Wi-Fi access, password managers, two-factor and multifactor authentication, automated patch-management tools or services, antivirus software, backup implementation and testing, risk assessment, and cyber-awareness training.
The individual grants are modest, particularly compared with the cost of a major technology or security programme. The design instead targets practical controls that can remain difficult for smaller organisations to prioritise when technology budgets, specialist skills, and management time are limited.
That makes the scheme a different policy instrument from regulation. Rather than imposing another compliance obligation, the Dutch government is using a targeted subsidy to offset some of the immediate cost of security measures that are already widely recognised as basic risk controls.
The choice of eligible measures also gives an indication of where policymakers believe relatively small investments can reduce exposure. MFA can limit the usefulness of stolen passwords, tested backups improve recovery options, and systematic patch management reduces the period during which known vulnerabilities remain exploitable.
The scheme does not guarantee that a funded business becomes secure, nor does a single control resolve broader weaknesses in architecture, supplier management, or incident response. Its value is instead in reducing the financial barrier to implementing controls that many very small companies might otherwise postpone.
The Netherlands says the programme attracted significant interest in 2025, leading to its return this year. Businesses that previously received support for a particular cyber-resilience measure cannot apply again for the same measure, which encourages repeat applicants to extend their controls rather than subsidise the same purchase twice.
Applications also apply only to qualifying measures purchased or implemented from the opening date. Costs incurred before 7 September are excluded.
The programme comes as European cybersecurity policy increasingly extends beyond large regulated operators. Small businesses can sit deep inside supply chains serving larger enterprises and public bodies, while their size often limits the specialist security resources available to them.
Funding basic implementation will not resolve that structural imbalance on its own, but it provides a measurable intervention: €1 million directed towards specific controls, with defined eligibility and a maximum contribution per business. The eventual take-up will show whether cost-sharing at this scale is sufficient to turn guidance into action across the smallest part of the Dutch business market.




