What the Kit Consulting Cybersecurity category is

Most of the SMEs I work with don't have a "tools" security problem: they have a judgement problem. They've bought an antivirus, maybe a firewall, they've turned on backups… and yet no one can answer the key question: "are we actually protected, and where are we weakest?" That honest snapshot of risk is exactly what Kit Consulting's Cybersecurity category funded.

Kit Consulting is a public programme run by Red.es, under Component 13 of the Recovery, Transformation and Resilience Plan (PRTR) and financed with NextGenerationEU funds. Its logic differs from that of the Kit Digital programme: Kit Digital pays for implementing solutions (including a cybersecurity one), while Kit Consulting pays for the expert advisory that decides what to do and how. If you're looking for the overview of the programme, you'll find it in my guide to what Kit Consulting is.

Within the programme, cybersecurity was one of the categories with the most demand, and for good reason: the number of incidents affecting Spanish SMEs keeps growing, and many don't recover well from a serious attack. It's worth clarifying that this article describes the advisory category as a whole. If what interests you is specifically preparing an ISO 27001 certification with Kit Consulting, I cover that in detail in cybersecurity and ISO 27001 with Kit Consulting; here I focus on the general scope, the deliverables and the advisor's profile.

What does Kit Consulting's cybersecurity advisory cover?

The programme structured cybersecurity into three sub-levels, designed to support the company according to its starting point. The sensible approach was to start with the basic level before jumping to the advanced ones.

Basic cybersecurity. This is the entry point. The advisor helps develop a basic cybersecurity plan tailored to the SME's specific needs: identifying the important assets, assessing the main risks and proposing essential protection measures. For a company starting from zero, this level already represents a huge leap in control.

Advanced cybersecurity. For companies with more maturity, it goes deeper into areas such as incident management, business continuity, supplier security or more demanding technical measures. It usually requires having completed the basic level first.

Certification preparation. Aimed at SMEs that want to formally prove their security to clients or in tenders. It prepares the ground for certifications such as ISO 27001 or the Esquema Nacional de Seguridad, leaving documentation and processes ready to face the audit.

Deliverables: what do you take home?

What sets a real advisory apart from a chat is the tangible deliverable. In the cybersecurity category, this is what an SME should expect to receive at the end. I've summarised it in the table below, which also works as a checklist for evaluating any security consulting proposal:

DeliverableWhat it includesWhat it's for
Security diagnosisAsset inventory, risk analysis and detected vulnerabilitiesKnowing where you're genuinely weak
Cybersecurity planTechnical and organisational measures prioritised by riskHaving a roadmap, not a list of fears
Policies and proceduresRules of use, passwords, backups and incident responseMaking sure the team knows how to act
Continuity planHow to keep operating after a serious incidentNot being paralysed after an attack
Certification preparationDocumentation and processes ready for ISO 27001 or the ENSProving your security to clients

Notice an important nuance: the advisory doesn't implement the technical measures, it plans them. Installing the firewall, rolling out two-factor authentication or contracting cloud backups is execution, and for that another route (such as Kit Digital) fits better. Kit Consulting gives you the blueprint; building the house comes after.

How much did the cybersecurity voucher fund?

Kit Consulting worked with a voucher whose total amount depended on the size of the company, and each individual service had a cap of €6,000. These were the three segments:

SegmentCompany sizeTotal voucher amountServices (€6,000/service cap)
Segment A10 to fewer than 50 employees€12,000Up to 2 services
Segment B50 to fewer than 100 employees€18,000Up to 3 services
Segment C100 to fewer than 250 employees€24,000Up to 4 services

In practice, an SME could dedicate one of its services to cybersecurity and combine another, for example, with the AI or processes category. The grant was awarded on a non-competitive basis, on a first-come, first-served basis until funds ran out.

Does it help prepare for ISO 27001 or the ENS?

Yes, and it's one of the most sensible uses of the advanced level and the certification-preparation level. An SME wanting to bid for public contracts or work with large clients usually needs to demonstrate its security, and the two usual references are ISO 27001 (the international information security management standard) and the Esquema Nacional de Seguridad (mandatory for the public sector and, de facto, for its suppliers).

The advisory doesn't hand you the certification itself — that's granted by an accredited body after an audit — but it leaves the road prepared: the risk analysis, the policies, the procedures and the documentation the audit will ask for. It's the difference between arriving at certification with your homework done or starting from zero. I cover the specific ISO 27001 angle in this companion article, and if you're interested in the security master plan as a broader framework, I cover that in security master plan.

What type of SME does it make sense for?

From my experience supporting companies in Castilla y León and the Canary Islands, the cybersecurity advisory fits especially well when:

You handle sensitive data. Customer data, financial information, industrial property... The more valuable what you hold, the more attractive a target you are for an attacker, and the more you need a serious plan.

You depend on your systems to operate. If an attack that knocks out your systems for days would jeopardise your revenue, the investment in prevention pays for itself.

You have clients that demand guarantees. More and more contracts — public and private — ask you to demonstrate security measures. A good plan opens commercial doors, not just protects you.

You've never done a formal diagnosis. If your security is based on "whatever we happened to buy", it's very likely there are gaps that only an orderly analysis will bring to light.

Who provides this advisory?

Only a digital advisor adhered to the programme, registered in Red.es's official catalogue and with accredited technical solvency for the cybersecurity category. Not just any provider would do: the programme required the advisor's formal registration and the signing of a service-provision agreement with the SME.

For cybersecurity, look for a profile that understands both the technical side (risks, controls, regulation) and the operational reality of an SME. A textbook security plan, copied from a large company, is usually unworkable — and therefore useless — in a twenty-person organisation. Proportionality is key: protecting yourself from what genuinely threatens you, without driving up costs with controls you don't need. If you want to see how this translates into services and real-world costs outside the programme, I cover it in cybersecurity consulting for companies.

Common cybersecurity mistakes among SMEs

A good advisory helps you avoid the pitfalls I see most often. These are the usual ones:

Thinking "we're too small for anyone to attack us". It's exactly the opposite: attackers automate and go after the weakest link, which is usually the SME with few defences. Size doesn't protect you.

Trusting everything to a single tool. An antivirus is not a security plan. Without policies, training and verified backups, the tool alone leaves huge gaps.

Not testing backups. Having backups no one has ever restored is having a false sense of security. The backup that's never tested is the one that fails on the day of the incident.

Forgetting the team. Most incidents come in through a human click: a phishing email, a reused password. Without training people, even the best technology falls short.

Ignoring suppliers. Many attacks come in through third parties with access to your systems. A good plan also looks at the security of your supply chain.

Basic, advanced or certification: which level fits you?

One of the most common doubts is which of the three sub-levels to choose. The answer depends on your starting maturity, and it's worth thinking it through carefully because, within a limited voucher, every service counts. This is the logic I apply when guiding an SME:

If you've never done anything formal in security, start with the basic level. It gives you the diagnosis and the plan that bring order to the initial chaos, and it often uncovers risks the company didn't even suspect. Skipping this step to go straight to advanced usually backfires, because you'd be building on foundations you don't understand.

If you already have the basics covered — backups, antivirus, some policy — and want to go deeper into incident management, continuity or supplier security, the advanced level is your spot. It assumes a more mature starting point.

If your goal is commercial — proving your security to win contracts or satisfy a big client — certification preparation is the way. But be careful: it only makes sense if you're genuinely going for the certification; otherwise you'll be left with documentation you won't use.

In companies with more than one service available in their voucher, a common and sensible combination was basic + advanced, or basic + certification preparation, chaining the whole journey within a single call.

Kit Consulting and Kit Digital in cybersecurity: they complement each other

One point that causes confusion: both Kit Consulting and Kit Digital touch cybersecurity, but they do different things and, used well, complement each other. Kit Consulting gives you the advisory: the diagnosis, the plan and the policies, in other words the "what to do and why". Kit Digital, in turn, funds the implementation of specific cybersecurity solutions — such as advanced antivirus or device protection — in other words the "do it".

The ideal sequence, when both programmes were open, was to use the advisory to decide what you needed and the implementation to put it in place. I compare both programmes in depth in Kit Digital versus Kit Consulting, worth reading if you're still unsure which fits each need.

Current status of Kit Consulting and remaining funds

To avoid setting false expectations: Kit Consulting's ordinary application period ended on 31 March 2025 and the call for applications appears as closed on the Acelera Pyme site. SMEs with a granted voucher are in the execution and justification phase.

The 2026 development is Orden TDF/38/2026, de 26 de enero (BOE-A-2026-2069), which amended the programme's regulatory basis to allow redistributing remaining funds and attending to applications previously excluded for lack of budget. That said, the order itself has not yet set deadlines or a specific procedure, so the rigorous way to describe it is as a "remaining-funds route", not a confirmed reopening. I keep this updated in the state of Kit Consulting in 2026.

My recommendation is simple: cybersecurity doesn't wait for grants. If your company has never done a serious diagnosis, do it — voucher or no voucher. And if the remaining-funds route does materialise, you'll already be ahead while others are still thinking about it. If you'd like an expert view proportionate to your case, I'd be glad to help you start with the diagnosis.