Filter Search for grants
Call Navigation
Call key data
Coordinated preparedness testing and other preparedness actions
Funding Program
Digital Europe
Call number
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP
deadlines
Opening
01.09.2026
Deadline
14.01.2027 17:00
Funding rate
50%
Call budget
€ 15,000,000.00
Estimated EU contribution per project
€1,500,000.00
Link to the call
Link to the submission
Call content
short description
This action covers two actions from the Cyber Solidarity Act, dedicated to the Cybersecurity Emergency Mechanism, namely (1) coordinated preparedness testing of entities operating in sectors of high criticality across the Union and (2) other preparedness actions for entities operating in sectors of high criticality and other critical sectors.
Call objectives
These actions aim to complement and not duplicate efforts by Member States and those at Union level to increase the level of protection and resilience to cyber threats, in particular for critical industrial installations and infrastructures, by assisting Member States in their efforts to improve their preparedness for cyber threats and incidents by providing them with knowledge and expertise.
Proposals should contribute to achieving at least one of the following objectives:
- (part 1) Coordinated preparedness testing of entities operating in sectors of high criticality across the Union (including penetration testing and threat assessment) considering ICT as well as Operational Technology/Industrial Control Systems.
- (part 2) Other preparedness actions for entities operating in sectors of high criticality and other critical sectors (i.e. vulnerability monitoring, exercises and training courses).
For details on the actions related to (part 1) and (part 2) covered under the current call for proposals, please consult the Call document accordingly.
read more
Expected effects and impacts
[Part 1 Coordinated preparedness testing]
The provision of preparedness support services shall include the activities listed below, for entities in the sector or sub-sector as identified by the Commission in accordance with the Cyber Solidarity Act, from the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555 and specified in the call for proposal document for each of the calls under this topic:
Support for testing for potential vulnerabilities:
- Development of penetration testing scenarios. The proposed scenarios may cover Networks, Applications, Virtualisation solutions, Cloud solutions, Industrial Control systems, and IoT.
- Support for conducting testing of essential entities operating critical infrastructure for potential vulnerabilities.
- Support for the deployment of digital tools and infrastructures supporting the execution of testing scenarios and for conducting exercises such as the development of standardised cyber-ranges or other testing facilities, able to mimic features of critical sectors (e.g. energy sector, transport sector, etc.) or others affected by NIS 2 to facilitate the execution of cyber-exercises, in particular within cross-border scenarios where relevant.
- Evaluation and/or testing of cybersecurity capabilities of MS entities and MS sectors (including capabilities to prevent, detect and respond to incidents and stress test of the entire sectors), evaluation and compliance activities aimed at increasing maturity, e.g. on the basis of established maturity models and/or relevant evaluation and compliance schemes.
- Evaluation and/or testing of cybersecurity capabilities of entities in scope (including for the evaluation and management of risks concerning the supply chain).
- Consulting services, providing recommendations on how to improve infrastructure security and capabilities.
Support for threat assessment and risk assessment, such as:
- Threat Assessment process implementation and life cycle
- Customised risk scenarios analysis.
The support will target the competent authorities in the Member States, which play a central role in the implementation of the NIS2 Directive, such as Computer Security Incident Response Teams (CSIRTs) and National Cybersecurity Authorities.
[Part 2 other preparedness actions]
For the second part, in addition to the services already listed for Part 1 (support for testing for potential vulnerabilities and support for threat assessment and risk management), the provision of preparedness support services included below addresses entities operating in highly critical and other critical sectors as referred to in Annex I and II of the NIS 2 Directive.
Support for threat assessment and risk assessment:
- Supply chain risk management within the risk assessment services.
Risk monitoring service:
- Specific continuous risk monitoring such as attack surface monitoring, risk monitoring of assets and vulnerabilities.
Support coordinated vulnerability disclosure and management:
- Promote the adoption of national CVD Policies and the EU Vulnerability Database.
- Coordinate the disclosure of vulnerabilities and timely dissemination of security patches. Standardisation of the way information is shared between different stakeholders in the vulnerability handling process.
- CVD applications that manage multiple sources of vulnerability information using open standards or technologies. (e.g. researchers, vendors, CSIRTs).
- Raise awareness on the adoption of vulnerability management best practices.
Dedicated exercises and training courses:
- Develop comprehensive training programmes and workshops, including international ones, for cybersecurity professionals that will cover the latest trends in cyber threats, attack methodologies, and best practices for pre-threat management and prevention. Maturity checks, evaluation of cybersecurity capabilities.
- Encourage the development of cybersecurity continuous learning activities to keep up with all cybersecurity requirements driven by EU cybersecurity-related regulations and directives, including the NIS 2 Directive, CSA, CSoA, DORA, EECC, GDPR, CRA.
The support will target the competent authorities in the Member States, which play a central role in the implementation of the NIS2 Directive, Computer Security Incident Response Teams (CSIRTs) including sectorial CSIRTs, Security Operation Centres (SOC)/Cyber Hubs, highly critical and other critical sectors, industry stakeholders (including Information Sharing and Analysis Centres- ISACs) and any other actors within the scope of the NIS 2 Directive, DORA, CSA, etc.
Support may be provided, among others, for the on boarding to the CEF Cybersecurity Core Service Platforms of public and private organisations which are working on the implementation of the NIS 2 Directive and are potential users of the CEF Cybersecurity Core Service Platforms.
The action may also support industry, with a particular focus on start-ups and SMEs, to seize the industrial and market uptake opportunities created by the Cyber Resilience Act and may support the implementation of the NIS 2 Directive.
read more
Expected results
The types of deliverables are presented in two parts.
The first part covers:
- Enhanced cooperation, preparedness and cybersecurity resilience in the EU; preparedness support services.
- Threat assessment and risk assessment services.
The second part covers:
- Risk monitoring services
- Better compliance, coordinated vulnerability disclosure and monitoring
- Improved skills, via exercises and training courses, organisation of events, workshops. Stakeholder consultations and white papers.
Eligibility Criteria
Regions / countries for funding
eligible entities
Education and training institution, Non-Profit Organisation (NPO) / Non-Governmental Organisation (NGO), Other, Private institution, incl. private company (private for profit), Public Body (national, regional and local; incl. EGTCs), Research Institution incl. University, Small and medium-sized enterprise (SME)
Mandatory partnership
No
Project Partnership
In order to be eligible, the applicants (beneficiaries and affiliated entities) must:
- be legal entities (public or private bodies)
- be established in one of the eligible countries, i.e.:
- EU Member States (including overseas countries and territories (OCTs))
- EEA countries (Norway, Iceland, Liechtenstein)
Although proposals may be submitted by a single applicant where permitted, applicants are encouraged to form consortia where appropriate, as collaboration between complementary entities can strengthen the implementation and expected impact of the action.
Natural persons — Natural persons are NOT eligible (with the exception of self-employed persons, i.e. sole traders, where the company does not have legal personality separate from that of the natural person).
International organisations — International organisations are NOT eligible, unless they are International organisations of European Interest within the meaning of Article 2 of the Digital Europe Regulation (i.e. international organisations the majority of whose members are Member States or whose headquarters are in a Member State).
Entities without legal personality — Entities which do not have legal personality under their national law may exceptionally participate, provided that their representatives have the capacity to undertake legal obligations on their behalf, and offer guarantees for the protection of the EU financial interests equivalent to that offered by legal persons.
EU bodies — EU bodies (with the exception of the European Commission Joint Research Centre) can NOT be part of the consortium.
Associations and interest groupings — Entities composed of members may participate as ‘sole beneficiaries’ or ‘beneficiaries without legal personality’. Please note that if the action will be implemented by the members, they should also participate (either as beneficiaries or as affiliated entities, otherwise their costs will NOT be eligible).
Countries currently negotia agreementting associations — Beneficiaries from countries with ongoing negotiations for participating in the programme (see list of participating countries above) may participate in the call and can sign grants if the negotiations are concluded before grant signature and if the association covers the call (i.e. is retroactive and covers both the part of the programme and the year when the call was launched).
EU restrictive measures — Special rules apply for entities subject to EU restrictive measures under Article 29 of the Treaty on the European Union (TEU) and Article 215 of the Treaty on the Functioning of the EU (TFEU). Such entities are not eligible to participate in any capacity, including as beneficiaries, affiliated entities, associated partners, subcontractors or recipients of financial support to third parties (if any).
EU conditionality measures — Special rules apply for entities subject to measures adopted on the basis of EU Regulation 2020/2092. Such entities are not eligible to participate in any funded role (beneficiaries, affiliated entities, subcontractors, recipients of financial support to third parties, etc). Currently such measures are in place for Hungarian public interest trusts established under the Hungarian Act IX of 2021 or any entity they maintain (see Council Implementing Decision (EU) 2022/2506, as of 16 December 2022).
Additional information
Topics
Relevance for EU Macro-Region
EUSAIR - EU Strategy for the Adriatic and Ionian Region, EUSALP - EU Strategy for the Alpine Space, EUSBSR - EU Strategy for the Baltic Sea Region, EUSDR - EU Strategy for the Danube Region
UN Sustainable Development Goals (UN-SDGs)
project duration
24 months
Additional Information
Proposals must be submitted electronically via the Funding & Tenders Portal Electronic Submission System (accessible via the Topic page in the Calls for proposals section.) Paper submissions are NOT possible.
Proposals (including annexes and supporting documents) must be submitted using the forms provided inside the Submission System (NOT the documents available on the Topic page — they are only for information).
Proposals must be complete and contain all the requested information and all required annexes and supporting documents:
- Application Form Part A — contains administrative information about the participants (future coordinator, beneficiaries and affiliated entities) and the summarised budget for the project (to be filled in directly online)
- Application Form Part B — contains the technical description of the project (template to be downloaded from the Portal Submission System, completed, assembled and re-uploaded)
- mandatory annexes and supporting documents (templates to be downloaded from the Portal Submission System, completed, assembled and re-uploaded):
- ownership control declarations including for associated partners and subcontractors
- Additional non-mandatory documen:
- In addition, applicants are encouraged to apply for membership to the Cybersecurity Competence Community through the National (NCCs) and attach proof of the request to the application. Registration to the Cyber Community is not mandatory but encouraged for those entities that would like to be further engaged with the ECCC and NCC community.
Proposals are limited to maximum 70 pages (Part B).
Call documents
Call Document DIGITAL-ECCC-2027-DEPLOY-CYBER-11Call Document DIGITAL-ECCC-2027-DEPLOY-CYBER-11(996kB)
Contact
applicants@eccc.europa.eu
Website
Digital Europe NCPs
Website



