FactBox.

Boletín Oficial de Cantabria · 01 Sep 2026 · 2 vistas

SODERCAN opens second line of grants for corporate cybersecurity

Por FactBox Admin

SODERCAN, the Society for the Regional Development of Cantabria S.A., has opened a second line of grants for the year 2026 aimed at boosting investments in corporate cybersecurity, within the framework of the CIBERREG initiative of the RETECH program. The call is published in the Official Gazette of Cantabria number 168, dated September 1, 2026, through Resolution SOD/CB/25/26/2, of August 24, 2026, and is financed by the Recovery, Transformation and Resilience Plan (PRTR) with European Union NextGenerationEU funds.

The new line is added to the first call of 2026, approved by Resolution SOD/CB/25/26, of March 23, 2026, published in BOC number 62. Both are governed by the regulatory bases of Order IND/2/2025, of January 20, published in BOC number 17, and are framed within component 15, Investment 7 (C.15I7) of the PRTR, dedicated to digital connectivity, the promotion of cybersecurity, and the deployment of 5G.

Purpose and beneficiaries

The purpose of the call is to improve business productivity through projects that increase the level of cybersecurity of companies through the use of information and communication technologies (ICT). Eligible beneficiaries may be companies and self-employed workers, regardless of their legal form and size, that carry out a manufacturing industrial activity or industry support services in Cantabria.

  • They must be validly constituted and have a workplace in Cantabria.
  • A maximum of one application per interested person is permitted.
  • Companies and public entities are excluded.
  • Applicants must be up to date with their obligations to SODERCAN, the AEAT, the Cantabrian Tax Administration Agency, and the General Treasury of the Social Security.

Financing and eligible actions

Financing is established up to a maximum of 100,000 euros, charged to the multi-annual credit file 2024/IN/3 (2024/121) and budget item 12.06.461A.740.07 of the general budgets of the Government of Cantabria. The maximum intensity of the grant will be 50% of the eligible expenses, with a maximum aid of 20,000 euros per applicant, and projects must have an eligible budget exceeding 3,000 euros.

Eligible actions include, among others:

  • Convergence and integration of cyberattack protection systems in IT/OT environments and network segmentation.
  • Securing remote access and information, audits, and attack simulation.
  • Cybersecurity training for staff.
  • Diagnostics, risk and vulnerability analysis, and penetration testing.
  • Adoption of cybersecurity standards such as ISO 27001, IEC 62443, TISAX, or UNECE/R155.
  • Monitoring of perimeter security devices and new managed security services.

Deadline and submission

The application submission period extends from the day following the publication of the call summary in the BOC until 11:59 PM on October 2, 2026. Applications must be processed electronically through the SODERCAN grants manager, at the address ayudas.sodercan.es, using a digital signature or certificate.

The eligibility period for expenses spans from January 1, 2025, until the date of application submission, and all items must be fully invoiced, paid, and executed by that time. The grant will be awarded on a competitive basis, according to the chronological order of the applications and until the available credit is exhausted.

Impact for Cantabria

This second line reinforces the commitment of SODERCAN, a company attached to the Ministry of Industry, Employment, Innovation, and Trade of the Government of Cantabria, to the digital resilience of the regional business fabric. The CIBERREG project, developed together with the communities of Asturias, Castilla-La Mancha, Extremadura, Illes Balears, Canarias, Murcia, and Navarra, with the participation of INCIBE, seeks to turn cybersecurity into a lever for competitiveness and the attraction of high-value-added activity for Cantabrian SMEs.


Source: Official Gazette of Cantabria, no. 168, September 1, 2026, page 41755 (official reference: CVE-2026-6812, Resolution SOD/CB/25/26/2, of August 24, 2026).