Filter Search for grants
Call Navigation
Call key data
Strengthening EU cybersecurity capacities & capabilities in line with legislative requirements
Funding Program
Digital Europe
Call number
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG
deadlines
Opening
01.09.2026
Deadline
14.01.2027 17:00
Funding rate
50%
Call budget
€ 20,000,000.00
Estimated EU contribution per project
between € 3,000,000.00 and € 5,000,000.00
Link to the call
Link to the submission
Call content
short description
EU cybersecurity legislation brings new responsibilities and imposes obligations on key stakeholders, ICT systems, Operational Technology and IoT manufacturers. For instance, the cost of obtaining a cybersecurity certification for an ICT or digital product, service or process is often an insuperable barrier for EU start-ups and SMEs. Support must be provided for the implementation of these obligations. The activities under this action require various types of support, including financial and organisational. Applications should address at least one of the eligible pieces of cybersecurity legislation but can also address more.
Call objectives
The objective of this topic is to support the European ecosystem to strengthen its cybersecurity capacities and to support the implementation of the regulatory framework in line with the Cyber Resilience Act (CRA), NIS 2 Directive, GDPR, DORA, Cybersecurity Act, specific requirements of the AI Act, etc. in a homogeneous approach. Additionally, and in alignment with the Digital education plan, which emphasises the development of digital skills crucial for the modern economy, and in support of initiatives like the Cybersecurity Skills Academy, activities related to cybersecurity challenges should also be promoted. These initiatives aim to address the skills shortage in cybersecurity and develop a workforce capable of meeting regulatory and operational demands. By providing practical training, attracting young professionals, and encouraging diversity within the field, these efforts are vital to Europe’s ability to respond to evolving cyber threats and to comply with new legislation. Additionally, these activities foster equal opportunities and raise cybersecurity awareness among future generations, contributing to Europe’s broader strategic goals in the digital domain.
The implementation of EU cybersecurity legislation needs to be supported to achieve a higher level of cybersecurity in the EU, especially in a constantly changing threat landscape. Cybersecurity maturity levels are different depending on each sector. This means that efforts and investments are needed to ensure and continuously improve cyber security in both the public and private sectors. Such efforts and investments are crucial in each Member State and therefore require increased focus and joint efforts at European level. Empowerment and self-assessment tools can be the most effective.
All the above efforts should consider that data security and protection must be promoted during the design and development of ICT products and services.
read more
Expected effects and impacts
The focus will also be on fostering cross-border collaboration and promoting diversity within the cybersecurity workforce, encouraging participation from women and other underrepresented groups. In conjunction with initiatives like the Cybersecurity Skills Academy, these activities will contribute to building capacity, raising awareness, and supporting the uptake of the aforementioned regulatory framework. By integrating these challenges into a broader capacity-building framework, they will ensure that stakeholders across sectors are equipped to address evolving cybersecurity threats and comply with the new legislative landscape.
Aligned with the goals of the Digital Education Action Plan which focuses on enhancing digital skills across Europe, activities related to cybersecurity challenges will play a crucial role in developing the next generation of cybersecurity professionals. These challenges will provide hands-on experience for young professionals and students, helping to close the cybersecurity skills gap and ensuring they are well-prepared to meet the demands of new legislative requirements.
The assessment of products and services is an essential step in the EU cybersecurity certification process. As cybersecurity threats are rapidly evolving and attacks are becoming more sophisticated, it is important to find a way to address these challenges. In addition, the EU needs to cope with the continuous growth of information systems (in terms of size and complexity) and the significant expansion of the digital space by enabling fast but secure replication of assessments. Furthermore, it is a great opportunity for the EU to develop interoperable solutions that will increase its competitiveness. In doing so, the Union can rely on a large and dynamic number of players who have already developed high-quality offerings.
The certification process is also very formal in terms of the documentation that is later used as proof for issuing the certificate. There is currently no platform to help proponents overcome the challenges posed by the use of many different and complex documents by all parties.
This action involves building capacity of national cybersecurity certification authorities to undertake market surveillance and supervise conformity assessment bodies and conformity assessments of essential requirements for cybersecurity products, services and processes. It should ensure the mutual recognition across Member States.
Furthermore, the action is also about building up capabilities of conformity assessment bodies and certification laboratories to meet the requirements of the Cyber Security Act and the Cyber Resilience Act, as regards verifying declarations of conformity from suppliers and vendors.
The action involves also the development of supporting tools for certification and evaluation processes, including a ‘Certification and Evaluation as a Service’ software platform to assist conformity assessment as well as support in creating national or cross-regional expert hubs to assist with these processes. Its development should involve relevant stakeholders such as CBs, CABs, and client representatives.
The ‘Certification and Evaluation as a Service platform’ could facilitate and streamline the management of all documentation used in the certification process. It could also help to speed up the information exchange between the bodies taking part in the process. The platform could help to harmonise and standardise the documentation and tools to be used across Europe.
The main areas considered under the scope of this action could include:
- The implementation of EU legislation in cybersecurity to be supported to achieve a higher cybersecurity level in Europe.
- Provide support to SMEs aiming to enhance cybersecurity resilience with a particular focus on legal requirements deriving from EU legislation such as NIS 2, Cyber Resilience Act, Cybersecurity Act, etc., including practical guidelines and user-friendly tools allowing the company to check whether its solutions are compliant with the requirements of the new legislation considering open standards.
- Develop reporting platforms for NIS 2 (e.g. incident reporting platform) and CRA (e.g. vulnerability single reporting platform).
- Establish short-term and long-term actions to prepare professionals to properly implement the requirements of new EU regulations in entities covered by those regulations.
- Develop programmes to promote diversity and equal opportunities for all young Europeans, providing tailored onboarding programmes for youth. These programmes will offer resources and easy access to educational content, ensuring that participants from various backgrounds can engage with cybersecurity training. By supporting non formal education and offering participation opportunities, such as cybersecurity challenges, these efforts will help equip the next generation with the skills needed to thrive in the sector.
- Creation and development of cooperation initiatives in cross-border and cross-sector contexts. Encourage collaboration between national and regional authorities to enhance cyber resilience and raise cybersecurity maturity levels through development and implementation of common methodologies.
- The design and evaluation of platforms for training programmes and tools for cross country exchange will support these efforts. Additionally, benchmarking and assessment programmes will help optimise performance, enhancing participants’ skills. These initiatives, including training materials, with cybersecurity challenges as one example, will also include peer exchange and fellowship opportunities, fostering a connected community of cybersecurity professionals. By encouraging cross-border collaboration and ongoing engagement, these programmes aim to strengthen Europe’s cybersecurity workforce and support long-term talent development.
- Support the development of cross-border collaboration programmes, enabling pan European teams to participate in international cybersecurity competitions, enhancing visibility and competitiveness on the global stage. These initiatives will provide teams with access to advanced tools, mentorship, and leadership training, fostering the growth of a European cybersecurity talent pipeline. By promoting excellence, skills development, and leadership, this support will ensure that Europe’s top talent remains competitive, well-prepared, and collaborative in facing global cybersecurity challenges.
In addition to providing supports for national cybersecurity certification authorities, conformity assessment bodies and national accreditation bodies with certification, the implementation of the NIS 2 Directive will continue in the coming years. In particular, competent authorities will need to build up capacity in audit and compliance to ensure that essential and important entities are meeting their responsibilities. Training and awareness raising activities along with trust and confidence building activities to facilitate information sharing and knowledge building should be provided.
Overall, this action is intended to increase collaboration between national authorities, supporting or supplementing the structures under the NIS Directive that need to comply with CRA (e.g. Software Bill of Materials, CRA Single Reporting Platform contributions and open prototypes, CVD processes or security advisory automation, like the CSAF), as well as between national authorities and stakeholders, especially SMEs, to raise cybersecurity maturity levels through the development and implementation of common methodologies to enable the deployment of cybersecurity processes and the uptake of products and services by entities.
This action involves the creation and deployment of common tools for regulation and enforcement, including targeted security audits and incident notifications to national competent authorities to facilitate information exchange.
Under information exchange, the action can also include:
- At national level, federate national actors working on cyber threat intelligence and national competent authorities around a common platform. Including facilitating and centralising the notification process for NIS 2 entities.
- At vertical level within the EU, organise or support cyber threats intelligence (CTI) unclassified information sharing in confidence between stakeholders of the given vertical.
- At EU level, enabling and organising collaboration between countries and information sharing.
- Collaborate on and implement a framework of guidelines - in the EU or multiple EU MS - to ensure and continuously improve cybersecurity both within the public and private sectors through better protection of their data, a significant reduction of the risk of the most common cyberattacks, and an increase of cyber resilience in general.
In addition, this topic promotes security and privacy ‘by design’ in existing and emerging technologies, applications and hardware, including IoT, Operational Technology, Identity and e-government systems, by supporting and/or funding research and innovation opportunities. Privacy-enhancing technologies aim to minimise the risks to the privacy of data subjects. Implementing security and privacy features in emerging technologies, applications and hardware from the outset – in the design and implementation phase – ensures that potential vulnerabilities and risks are recognised and addressed early in the development process. In addition, to be in line with data protection regulations, this approach can be more cost effective and would reduce the likelihood of security and personal data breaches.
Consortia should consider including at least one representative of each of the following categories to reflect the whole value chain: privacy-enhancing technology researchers, privacy-enhancing technology providers, developers of ICT products and services integrating privacy-enhancing technologies, and ICT product and services user organisations.
read more
Expected results
One or more of the following should be covered:
- Implementation of guidelines, standardised processes, or manuals – in the EU or multiple EU MS – concerning the most challenging issues, supporting specific stakeholders and sectors addressed by cybersecurity legislation.
- Develop and implement tools, raise awareness and encourage and facilitate industry uptake, with a focus on SMEs, of conformity assessments of essential cybersecurity requirements for products with digital elements (hardware and software) under the CRA.
- Support for mechanisms reducing the administrative burden for entities, like single entry point for incident notification.
- Establish secure communication channels allowing for cooperation and information sharing initiatives.
- Support the organisation of regular meetings/workshops to identify good practices within specific sectors or emerging areas and facilitate collaborative efforts between different sectors.
- Support the development of training courses, on the basis of the ECSF and exercises that promote capacity building and internal awareness.
- Contribution to CR standardisation: Training materials and training actions on cybersecurity certification for national authorities and conformity assessment bodies.
- Fostering certification: Educational and supporting materials and an explanatory press campaign using interactive material such as ‘Do I comply with CRA?’. Information campaign through various channels such as conferences, meetings, etc. Website dedicated to the mandatory certification and conformity assessments of essential requirements.
- Development of training programmes and materials, including tools for cross-country collaboration and exchange, aimed at enhancing participants’ skills and readiness for real-world threats. These programmes can also support non-formal education for high school students and teachers, enhancing digital literacy and cybersecurity awareness at early educational levels.
- Creation of benchmarking and assessment programmes to evaluate and optimise the performance of participants in cybersecurity training programmes, ensuring continuous improvement and alignment with industry standards.
- Implement peer exchange and fellowship programmes, aimed at fostering a connected, resilient community of cybersecurity professionals across Europe. These programmes will also include support for cross-border training initiatives and non formal education activities, ensuring that both students and educators can participate in hands-on cybersecurity learning experiences and contribute to long-term talent development.
- Establishment of cross-border collaboration programmes to support the development of pan-European teams in cybersecurity competitions. These programmes will provide access to mentorship, advanced tools, and leadership training, ensuring European teams remain competitive on the global stage. Additionally, the programmes will foster the growth of a European cybersecurity leadership pipeline, enhancing Europe’s visibility and effectiveness in international cybersecurity challenges.
- Support organisations, including SMEs, in assessing the robustness, applicability and relevance of security- and privacy-enhancing technologies to be integrated in the ICT products and services they develop.
- Set-up pilot projects to test CRA compliance, use open-source software and libraries for conformity assessment and testing; develop assessment methodologies for the purpose of CRA compliance/requirements.
- Develop best practices or guidelines for setting-up and operating market surveillance authorities in MSs; develop awareness of CRA requirements.
- Support organisations, including SMEs, in commercialising privacy-enhancing technologies and demonstrate how they can address security and privacy risks from emerging technologies.
- Facilitate cooperation between the producers of emerging technologies, the users of those technologies and regulators. Such cooperation would make it possible to identify which requirements can be met by which privacy-enhancing technology, in which use cases, to what extent they could facilitate compliance or reduce the cost thereof, and how to engineer it in practice, during the early phases of design and development of ICT products and services.
- Strengthen cooperation in the whole privacy-enhancing technology value chain, including between researchers, providers, integrators and users, and GDPR national authorities/European supervisors.
read more
Eligibility Criteria
Regions / countries for funding
eligible entities
Education and training institution, Non-Profit Organisation (NPO) / Non-Governmental Organisation (NGO), Other, Private institution, incl. private company (private for profit), Public Body (national, regional and local; incl. EGTCs), Research Institution incl. University, Small and medium-sized enterprise (SME)
Mandatory partnership
No
Project Partnership
In order to be eligible, the applicants (beneficiaries and affiliated entities) must:
- be legal entities (public or private bodies)
- be established in one of the eligible countries, i.e.:
- EU Member States (including overseas countries and territories (OCTs))
- EEA countries (Norway, Iceland, Liechtenstein)
Although proposals may be submitted by a single applicant where permitted, applicants are encouraged to form consortia where appropriate, as collaboration between complementary entities can strengthen the implementation and expected impact of the action.
Natural persons — Natural persons are NOT eligible (with the exception of self-employed persons, i.e. sole traders, where the company does not have legal personality separate from that of the natural person).
International organisations — International organisations are NOT eligible, unless they are International organisations of European Interest within the meaning of Article 2 of the Digital Europe Regulation (i.e. international organisations the majority of whose members are Member States or whose headquarters are in a Member State).
Entities without legal personality — Entities which do not have legal personality under their national law may exceptionally participate, provided that their representatives have the capacity to undertake legal obligations on their behalf, and offer guarantees for the protection of the EU financial interests equivalent to that offered by legal persons.
EU bodies — EU bodies (with the exception of the European Commission Joint Research Centre) can NOT be part of the consortium.
Associations and interest groupings — Entities composed of members may participate as ‘sole beneficiaries’ or ‘beneficiaries without legal personality’. Please note that if the action will be implemented by the members, they should also participate (either as beneficiaries or as affiliated entities, otherwise their costs will NOT be eligible).
Countries currently negotia agreementting associations — Beneficiaries from countries with ongoing negotiations for participating in the programme (see list of participating countries above) may participate in the call and can sign grants if the negotiations are concluded before grant signature and if the association covers the call (i.e. is retroactive and covers both the part of the programme and the year when the call was launched).
EU restrictive measures — Special rules apply for entities subject to EU restrictive measures under Article 29 of the Treaty on the European Union (TEU) and Article 215 of the Treaty on the Functioning of the EU (TFEU). Such entities are not eligible to participate in any capacity, including as beneficiaries, affiliated entities, associated partners, subcontractors or recipients of financial support to third parties (if any).
EU conditionality measures — Special rules apply for entities subject to measures adopted on the basis of EU Regulation 2020/2092. Such entities are not eligible to participate in any funded role (beneficiaries, affiliated entities, subcontractors, recipients of financial support to third parties, etc). Currently such measures are in place for Hungarian public interest trusts established under the Hungarian Act IX of 2021 or any entity they maintain (see Council Implementing Decision (EU) 2022/2506, as of 16 December 2022).
Additional information
Topics
Relevance for EU Macro-Region
EUSAIR - EU Strategy for the Adriatic and Ionian Region, EUSALP - EU Strategy for the Alpine Space, EUSBSR - EU Strategy for the Baltic Sea Region, EUSDR - EU Strategy for the Danube Region
UN Sustainable Development Goals (UN-SDGs)
project duration
36 months
Additional Information
Proposals must be submitted electronically via the Funding & Tenders Portal Electronic Submission System (accessible via the Topic page in the Calls for proposals section.) Paper submissions are NOT possible.
Proposals (including annexes and supporting documents) must be submitted using the forms provided inside the Submission System (NOT the documents available on the Topic page — they are only for information).
Proposals must be complete and contain all the requested information and all required annexes and supporting documents:
- Application Form Part A — contains administrative information about the participants (future coordinator, beneficiaries and affiliated entities) and the summarised budget for the project (to be filled in directly online)
- Application Form Part B — contains the technical description of the project (template to be downloaded from the Portal Submission System, completed, assembled and re-uploaded)
- mandatory annexes and supporting documents (templates to be downloaded from the Portal Submission System, completed, assembled and re-uploaded):
- ownership control declarations including for associated partners and subcontractors
- Additional non-mandatory documen:
- In addition, applicants are encouraged to apply for membership to the Cybersecurity Competence Community through the National (NCCs) and attach proof of the request to the application. Registration to the Cyber Community is not mandatory but encouraged for those entities that would like to be further engaged with the ECCC and NCC community.
Proposals are limited to maximum 70 pages (Part B).
Call documents
Call Document DIGITAL-ECCC-2027-DEPLOY-CYBER-11Call Document DIGITAL-ECCC-2027-DEPLOY-CYBER-11(996kB)
Contact
applicants@eccc.europa.eu
Website
Digital Europe NCPs
Website


