Back to blogSecurity

Mijn Cyberweerbare Zaak 2026: up to 1,250 euros in subsidy for your cyber resilience

uComply

Team uComply

Author

September 15, 2026

Published

Since Monday 7 September 2026, the Mijn Cyberweerbare Zaak (MCZ, "My Cyber-Resilient Business") subsidy scheme has reopened. Until 30 November 2026, self-employed professionals and small businesses can reclaim 50% of the cost of cyber resilience measures, up to a maximum of 1,250 euros, from RVO, the Netherlands Enterprise Agency. The 2026 budget is 1 million euros and applications are processed in order of receipt. Those who act quickly stand the best chance.

What is Mijn Cyberweerbare Zaak?

Mijn Cyberweerbare Zaak is a Dutch government subsidy for the smallest businesses in the Netherlands. Sole traders and SMEs rarely have their own IT department, yet they are just as much a target for phishing, ransomware and account takeovers. The scheme lowers the threshold for getting the basics in order: you choose measures from a personal action list, purchase them and receive half of the cost back.

The key figures for 2026 at a glance:

  • Application window: 7 September to 30 November 2026 inclusive.
  • Reimbursement: 50% of the cost of purchasing or implementing one or more measures, up to 1,250 euros per applicant.
  • Budget: 1 million euros, allocated in order of receipt until exhausted.
  • Target group: self-employed professionals and SMEs with up to 50 employees and a maximum annual turnover of 10 million euros, registered with the Dutch Chamber of Commerce (KvK).
  • Please note: according to the NCSC, the Dutch National Cyber Security Centre, measures purchased or paid for before 7 September 2026 are not eligible. The subsidy is intended for new steps, not for what you already had.

    Which measures are eligible?

    The subsidy is linked to the action list you receive from the CyberVeilig Check (Cyber Secure Check). That list contains practical measures relevant to almost every small business, for example:

  • Backups: an automatic, separate backup of your business data so ransomware cannot hold you hostage.
  • Multi-factor authentication (MFA): an extra security step alongside the password for email, accounting and cloud storage.
  • Password manager: unique, strong passwords without having to remember them.
  • Updates and patch management: software that stays current automatically so known vulnerabilities are closed.
  • Security awareness training: teaching staff to recognise phishing, often the weakest link.
  • Risk assessment: mapping which systems and data are most vulnerable.
  • The NCSC also lists categories such as secure network access and antivirus software. Exactly which measures qualify is determined by your own action list.

    Applying in three steps

    The application has deliberately been kept simple. You go through three steps:

    1.Complete the CyberVeilig Check on the NCSC website (formerly the Digital Trust Center). You answer a number of questions about your business and download your personal action list as a PDF. Keep this document, it is a mandatory piece of evidence.
    2.Purchase the measures on your action list that are eligible for the subsidy. Pay the invoices in full and keep both the invoice and the proof of payment.
    3.Submit the application to RVO with the action list, the invoices and the proof of payment. RVO decides within eight weeks; after approval, payment follows within two weeks.

    A practical tip: start with step 1 today. The check takes little time and immediately shows you what is still missing, even if you decide not to apply for the subsidy.

    Be quick

    The budget is limited. In the previous round in 2025 the money ran out quickly and the scheme closed before its official end date. In 2026 the same applies: applications are processed in order of receipt. If several applications arrive on the day the budget is reached, a draw decides which of them are still awarded. So do not wait until November for steps 2 and 3.

    From first measure to demonstrable control

    A subsidy is a good reason to get started. But switching on MFA or setting up a backup is a moment, while cyber resilience is a process. Once the basics are in place, a follow-up question soon arrives: can you show it?

    That question increasingly comes from outside. Since 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet, the national implementation of NIS2) has been in force. Organisations covered by that act must manage the risks in their supply chain. This means a medium-sized or large customer will ask its suppliers, including the small ones, which measures they have taken and how they keep track of them. The same applies to tenders, insurers and partners that are themselves ISO 27001 certified.

    Demonstrable control does not require a thick manual. It requires a light, ISO 27001-style structure:

  • a short risk assessment (which you already have from the CyberVeilig Check);
  • a list of measures with an owner and a status;
  • evidence that the measure works, such as a backup report or a training certificate;
  • a fixed moment to review everything.
  • The very evidence you collect for RVO forms the first file for this. It would be a shame to let it disappear into a mailbox after the application.

    How uComply helps

    The uComply SaaS entry option is designed for SMEs taking their first measures with the subsidy. You start without an installation project or technical requirements, pay per user per month and are operational within one working day. Choose a standard such as ISO 27001 or NEN 7510 and you immediately receive a content pack with controls, policies and procedures.

    You record the measures from your action list as controls with an owner and a status. You attach the invoices, the backup report and the training certificate as evidence to the relevant measure. Task management ensures the periodic check, such as testing the backup, is not forgotten. The gap analysis shows which requirements are still open, and the AI assistant helps you draft policies.

    When a customer or supply-chain partner later asks for substantiation, you show your compliance score and the implementation status per measure in the Flightdeck dashboard. And as you grow, all your data moves with you to your own Microsoft 365 environment.

    Summary

    Mijn Cyberweerbare Zaak 2026 reimburses up to 1,250 euros of your cyber resilience measures. Applications can be submitted to RVO from 7 September to 30 November, as long as the 1 million euro budget lasts. Complete the CyberVeilig Check today, purchase the measures and submit your evidence. And build the structure to maintain those measures and make them demonstrable at the same time.

    Curious how uComply keeps this manageable for a small business? Book a no-obligation demo or view the uComply SaaS pricing.

    Sources

  • RVO: Mijn Cyberweerbare Zaak (MCZ)
  • NCSC: Mijn Cyberweerbare Zaak subsidy scheme
  • NCSC: CyberVeilig Check for self-employed professionals and SMEs