Skip to content
All guides

// Guides

M.I.D. Digital Security: Applying for Cybersecurity Grants for SMEs in NRW

Small and medium-sized enterprises in North Rhine-Westphalia are increasingly targeted by automated ransomware attacks, credential stuffing, and phishing campaigns. Under the state funding program "Mittelstand Innovativ & Digital" (M.I.D.) – Digital Security module, the state of NRW subsidizes external security audits, penetration testing, and IT protection concepts with up to €15,000 in non-repayable grants (subsidy rate up to 80% for small businesses). Understanding the formal requirements and applying prior to signing contracts drastically lowers cybersecurity expenditure.

Updated: 2026-10-02

Immediate steps

  1. 1Verify SME eligibility and operational establishment in NRW: Eligible applicants are SMEs (fewer than 250 employees, annual turnover under €50M) with a registered office or permanent establishment in North Rhine-Westphalia.
  2. 2Define testing scope and cybersecurity requirements: Specify whether testing covers external network exposure, web application penetration testing, API auditing, or holistic IT security architecture.
  3. 3Obtain a qualified technical proposal from an external security provider: The offer must clearly detail methodological milestones, daily consultant rates, and precise testing deliverables.
  4. 4Submit funding application via the official M.I.D. portal: Applications are submitted electronically through the state project management agency (PtJ / Land NRW) before commissioning work.
  5. 5Await grant approval notice before starting any work: The cybersecurity provider can only be contracted after the formal grant notice (Zuwendungsbescheid) is officially issued.
  6. 6Execute testing, file proof of completion, and receive grant payout: Upon completion of the technical audit, the final report, invoice, and payment confirmations are submitted for reimbursement.

What not to do

  • Never sign vendor contracts or commence services prior to grant approval — early commitment permanently disqualifies the grant.
  • Do not submit generic hardware purchases or standard software licenses without qualified consulting and analytical services.
  • Do not miss implementation deadlines or project execution windows (typically 6 to 9 months).
  • Do not rely on verbal assurances — only the formal written grant notification establishes legal certainty.

// SKOPION SECURITY ADVISORY

When professional help makes sense

SKOPION supports organizations across Mönchengladbach, Düsseldorf, Cologne, and the wider NRW region in structuring grant-eligible penetration testing and security audits. We deliver standards-compliant service specifications meeting M.I.D. requirements and execute rigorous security assessments under BSI and OWASP methodologies.

Common questions

What is the subsidy rate under the M.I.D. Digital Security program?
Small and micro enterprises (under 50 staff) receive up to 80% of eligible advisory and testing costs as a grant, while medium-sized enterprises (up to 249 staff) receive up to 50%, capped at €15,000.
Are penetration tests and vulnerability assessments by SKOPION eligible for funding?
Yes. The M.I.D. Digital Security program explicitly covers professional consulting, security assessments, and penetration testing to identify and remediate vulnerabilities in IT systems.
What does the prohibition of early commencement mean?
You must not award contracts or start testing before receiving the official grant approval notice. Any services commissioned beforehand are strictly ineligible for reimbursement.
How long does the application review process take?
Grant authorities typically review complete applications within 4 to 8 weeks. We recommend submitting your application well ahead of planned testing windows.

Sources