Strengthening EU cybersecurity capacities & capabilities in line with legislative requirements

Overview

Digital Europe Programme call DIGITAL-ECCC funds projects to strengthen EU cybersecurity capacities and support implementation of legislation such as the Cyber Resilience Act, NIS 2, GDPR, DORA and relevant AI Act requirements. The topic focuses on capacity building, certification and conformity assessment support, incident reporting and information sharing, SME-targeted compliance tools, training and privacy-enhancing technologies. The topic budget is €20,000,000 with indicative EU contributions per project of €3,000,000 to €5,000,000; opening date 01 September 2026 and deadline 14 January 2027 (17:00 Brussels time). Eligible applicants include public authorities, certification and conformity assessment bodies, SMEs, cybersecurity providers, research and academic organisations and other stakeholders able to deliver cross-border implementation support.

Partner Search

Find collaboration partners for this call

Your Profile
👤
Your country

What You Offer

Describe your expertise here...

You Are Looking For

Describe what you seek here...

Sign In

Highlights

What it funds

High-level scope

Grants to support implementation of EU cybersecurity legislation (Cyber Resilience Act, NIS2, Cybersecurity Act, GDPR, DORA, AI Act requirements etc.). Activities include development and deployment of guidelines, conformity assessment support (especially for SMEs), certification capacity building, 'Certification and Evaluation as a Service' platforms, reporting/incident platforms, market surveillance guidance, training and awareness (including youth and cross-border skills programmes), pilot CRA compliance projects, privacy-enhancing technology uptake and cross‑sector information‑sharing and incident-notification facilitation.

Funding and deadline:Multiple topic streams under DIGITAL-ECCC-2027-DEPLOY-CYBER-11 with indicative grant sizes per stream: €1.5M up to €5M depending on the specific topic. Opening date 01 September 2026; submission deadline 14 January 2027 17:00 Brussels time. Apply via the portal EU Funding & Tenders Portal 1.

  1. 1Who can apply: consortia of legal entities (public bodies, research organisations, industry, SMEs, conformity assessment bodies); check call doc for eligible countries and detailed eligibility conditions.
  2. 2Recommended participants to reflect the value chain: PET researchers/providers, ICT developers/integrators, user organisations, conformity assessment bodies, national authorities and market surveillance bodies.
  3. 3Activities must address at least one eligible piece of EU cybersecurity legislation; cross-border and SME‑facing proposals are prioritised.
Call strandIndicative grant (per project)
EULEG (legal/regulatory support)€3.0M to €5.0M
AI4SME (SME support)€3.0M to €5.0M
NCC (national coordination capacity)€2.0M to €3.0M
COORDPREP (preparedness & coordination)around €1.5M
REGCABH (regional/capacity hubs)around €2.5M

Project types:SIMPLE grants and SME Support Actions under the Digital Europe Programme. Proposals must follow the application templates and page limits in the call documents; financial and operational capacity checks apply.

Footnotes

  1. 1Full topic details, application templates and budget breakdowns are on the Funding & Tenders Portal topic page Topic page and in the Digital Europe Cybersecurity Work Programme.

Find a Consultant to Support You

Breakdown

Call identity and administrative facts

Call title:Strengthening European Cybersecurity Technologies, Capacities and Preparedness. Topic identifier: DIGITAL-ECCC. Programme: Digital Europe Programme (DIGITAL). Type of action: DIGITAL JU Simple Grants; Type of Model Grant Agreement: DIGITAL Action Grant Budget-Based (DIGITAL-AG). Submission opening date: 1 September 2026. Deadline: 14 January 2027, 17:00 Brussels time. Submission model: single-stage. Submission channel: EU Funding & Tenders Portal (electronic submission).

Call documents and templates:Applicants must use the standard Application Form (DEP) Part A (online forms) and Part B (PDF upload) available in the Submission System. Supporting templates and mandatory documents include: Call document, Application form templates (Part B), Ownership control declaration, DEP Model Grant Agreement (MGA), Digital Europe Cybersecurity Work Programme 2025-2027, EU Financial Regulation 2024/2509, Rules for Legal Entity Validation/LEAR appointment and Financial Capacity Assessment, EU Grants Annotated Model Grant Agreement, Funding & Tenders Portal Online Manual and Terms and Conditions. Proposal Part B page limit normally 70 pages; format requirements (A4, Arial >= 9pt, margins >=15 mm) apply and are enforced by the Portal.

Objective, scope and expected outcomes

Objective:strengthen European cybersecurity capacities and support implementation and uptake of EU cybersecurity and related legislation in a harmonised way (Cyber Resilience Act CRA, NIS 2 Directive, GDPR, DORA, Cybersecurity Act, AI Act specific requirements, and related frameworks). Scope includes capacity building for national authorities and conformity assessment bodies, support to SMEs for conformity assessments and CRA compliance, development of tools and platforms for certification and evaluation (including Certification and Evaluation as a Service), reporting platforms (NIS2 incident reporting, CRA vulnerability reporting), training and exercises (including ECSF-based courses), cross-border collaboration, youth and non-formal education activities, benchmarking, fellowship and peer exchange programmes, market surveillance best practices, and promotion and commercialization of privacy-enhancing technologies. Expected outcomes include guidelines, standards and manuals; tools to reduce administrative burden (e.g. single entry incident reporting); secure communication channels and information-sharing frameworks; training materials and certification awareness campaigns; pilot projects using open-source tools for conformity assessment; and interoperable platforms to streamline certification documentation and data exchange.

Priority emphases:industry uptake with a focus on SMEs, cross-border and cross-sector collaboration, diversity and inclusion in skills development (encouraging participation of women and underrepresented groups), secure-by-design and privacy-by-design for ICT, OT and IoT systems, and alignment with the Digital Education Action Plan and Cybersecurity Skills Academy.

Who should apply and eligible applicant types

The action targets organisations able to operate across the cybersecurity value chain. Recommended participants to reflect the whole value chain include privacy-enhancing technology researchers, PET providers, developers of ICT products/services integrating PETs, ICT product and service user organisations, conformity assessment bodies (CABs), certification bodies (CBs), testing laboratories, national competent authorities, market surveillance authorities, National Coordination Centres (NCCs), training providers, SMEs/start‑ups, large enterprises, universities, research institutes, vocational and non-formal education providers (including organisations delivering high-school-level activities), NGOs, and public authorities. The call specifically supports applications where at least one representative per recommended category is included when relevant to the proposal.

Eligible applicant types (detailed):Startup, SME, large enterprise, university, research institute, certification body, conformity assessment body, national authority (competent authority, market surveillance body), public body, non-profit, vocational and school educators, training organisations, NCCs, NGO, public-private partnerships, laboratories, and other stakeholders in the cybersecurity and privacy-enhancing technology value chains.

Funding type, modalities and budget

Primary funding mechanism:grant (budget-based, action grant). The topics under DIGITAL-ECCC-2027-DEPLOY-CYBER-11 are implemented as DIGITAL JU Simple Grants and DIGITAL JU SME Support Actions with the DIGITAL Action Grant (DEP MGA) budget-based model. Funding is delivered as direct grant payments via the Funding & Tenders Portal in accordance with the DEP Model Grant Agreement and continuous/periodic reporting schedule.

  1. 1Funding form: Budget-based action grant (actual costs and permitted simplified forms where specified in Annex 2 / Annex 2a).
  2. 2Funding modalities: pre-financing, possible additional pre-financing, interim (where applicable) and final payment as per Data Sheet and DEP MGA payment schedule.
  3. 3Co-funding: not explicitly defined in the scraped topic text; applicants must consult the Call document and Annex 2 for funding rates and any co-funding rules. The DEP MGA and call documents specify eligibility and funding rates per budget category.

Indicative budget ranges per sub-topic:The call is split into multiple actions / sub-topics under the common umbrella DIGITAL-ECCC-2027-DEPLOY-CYBER-11. Indicative budgets and expected grant sizes (2026 budget year) per action are listed below and should be checked in the Portal for the final call text and ceilings:

Action codeIndicative programme contribution (EUR)Indicative number of grantsIndicative grant amount (per grant)
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME (SME Support Actions)20,000,00053,000,000 to 5,000,000
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP (Simple Grants)15,000,000around 10around 1,500,000
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI (Simple Grants)15,000,00043,000,000 to 5,000,000
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-DUALUSE (Simple Grants)10,000,00033,000,000 to 5,000,000
DIGITAL-ECCC (Simple Grants) — this topic20,000,00053,000,000 to 5,000,000
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC (Simple Grants)11,000,00042,000,000 to 3,000,000
DIGITAL-ECCC-2027-DEPLOY-CYBER-11-REGCABH (Simple Grants)5,000,0002around 2,500,000

Consortium, consortium requirement and project duration

Submission model is single-stage. The call allows for Simple Grants (which can be single beneficiary or multi‑beneficiary depending on the specific sub-topic). Some sub-topics under DIGITAL-JU-SIMPLE may accept single-beneficiary applications (mono-beneficiary) while others expect multi‑partner consortia; applicants must check the specific sub-topic conditions in the call document. For the EULEG sub-topic applicants should plan for strong cross‑sector and cross‑border partnerships; the call recommends (to reflect the whole value chain) inclusion of representatives from PET research, PET providers, ICT developers and user organisations. Typical project durations are defined in Part B (applicants must propose duration in months) and will be subject to eligibility and award criteria. The DEP application form Part B and Annexes require a detailed work plan and a management work package (WP1).

Consortium requirement:The call accommodates both single and consortium applicants depending on the sub-topic and the nature of the planned activities; however the call text explicitly recommends multi-stakeholder consortia to cover the whole value chain (research, providers, integrators, users and authorities) for many actions. Check the call and topic-specific conditions to confirm single vs consortium eligibility for the chosen action.

Geographic eligibility and beneficiary scope

Eligible countries are described in Section 6 of the Call document (applicants must consult the call document for the definitive list). The call materials and supporting pages explicitly reference the Network of NCCs which includes one NCC for each of the 27 EU Member States plus Iceland and Norway, indicating that Iceland and Norway (EEA) are engaged in the network and are recognised stakeholders. In practice, Digital Europe Programme typically accepts applicants from EU Member States and certain associated countries (EEA/Associated) — consult the call document for the exact list of eligible countries and any country-specific restrictions.

Mentioned countries / regions:Explicitly mentioned: EU Member States (general), Iceland, Norway. Regionally: European Union (EU) and EEA via the NCC network. For the formal list of eligible countries consult section 6 of the Call document.

Target sectors, technologies and project maturity

Target sectors and thematic areas:Cybersecurity (capacity building, certification, conformity assessment), ICT (hardware and software products with digital elements), Operational Technology (OT), Internet of Things (IoT), privacy-enhancing technologies (PET), artificial intelligence (AI) for cybersecurity, standardisation and certification infrastructure, education and skills development (including non-formal education and high-school engagement), market surveillance, data protection and privacy, vulnerability disclosure processes, and cyber threat intelligence (CTI) sharing platforms.

Technology and science focus areas:Key technology topics called out include: conformity assessment tooling for CRA compliance, Certification and Evaluation as a Service platforms, open-source libraries and toolkits for conformity testing, security- and privacy-enhancing technologies (PETs), Software Bill of Materials (SBOM) and Software Supply Chain aspects, CSAF / CVD automation, secure communication channels and CTI information-sharing platforms, interoperable certification documentation tooling, and AI-enabled cyber tools. The action promotes secure-by-design and privacy-by-design integration in product lifecycles.

Project stage / expected maturity:Expected maturity: activities range from development, piloting, validation and demonstration (Certification-as-a-Service prototypes, reporting platforms, conformity assessment methods) to capacity building, training, market surveillance setup and commercialization support. Proposals should demonstrate readiness to implement the planned deployment, piloting and cross-border collaboration activities and the capacity to produce operational deliverables (tools, platforms, training curricula).

Application process, evaluation and reporting

Application type:open single-stage call via the EU Funding & Tenders Portal. Applicants must register organisations and persons in the Portal, prepare Part A (online) and Part B (PDF Part B technical description) using the DEP Application Form templates. The Portal enforces admissibility rules (Part B page limit, layout) and validates mandatory declarations. Evaluation and award follow the processes described in the Call Document (sections 8-9). Continuous reporting and delivery of standardised deliverables use the Portal Continuous Reporting tool. Periodic reporting and financial statements follow DEP MGA rules (continuous reporting, prefinancing, periodic reports, CFS thresholds as per Data Sheet).

Application form structure and templates (overview):Application Form (DEP) consists of: Part A — administrative data entered online (general information, participants, budget summary, declarations). Part B — technical description (narrative, up to normally 70 pages) uploaded as PDF; Part B includes sections: Project summary; 1 Relevance (objectives, policy synergies); 2 Implementation (maturity, implementation plan, project management, risk management); 3 Impact (expected outcomes, dissemination and communication); 4 Work plan, work packages, activities, resources and timing (detailed WPs, staff effort, subcontracting, purchases, budget justification); 5 Other (ethics, security); 6 Declarations. Annexes: Detailed budget table or calculator (when required), CVs, list of previous projects, supporting documents. Ownership control declaration must be filled and uploaded by participants as required.

  1. 1Part A key fields: proposal title (max 200 characters), duration in months, abstract, declarations including compliance and exclusion grounds, legal and financial data for participants.
  2. 2Part B required sections: cover page, project summary, Relevance, Implementation, Impact, Work plan (with WP1 management), Staff effort and budget tables, Ethics and Security self-assessments.
  3. 3Mandatory annexes: ownership control declaration (assembled by coordinator), model grant agreement conditions, DEP MGA and call-specific annexes. Supporting documents may be requested after selection (financial capacity, legal status).

Evaluation stages, selection and success indicators

Submission and evaluation is single-stage:applicants submit a complete proposal which will be evaluated against the award criteria published in the Call document. The Portal and call document specify scoring thresholds, evaluation criteria and indicative timeline for evaluation and grant agreement preparation (check section 4 of the call document and the Online Manual for details). The call includes links to a continuous reporting tool and templates for deliverables.

Number of application stages:1 (single-stage submission and evaluation).

Success rates:Not specified in the scraped content. Success rates depend on competition, quality of proposals and available budget; applicants should consult the call-specific evaluation criteria and budget overview to estimate competitiveness. The call lists an indicative number of grants per sub-topic which can be used to gauge acceptances.

Financial, legal and operational requirements

Applicants must satisfy admissibility and eligibility conditions (page limits, forms, eligible countries, legal statuses) and demonstrate financial and operational capacity per section 7 of the Call document. Exclusion and due diligence rules, ownership and control declarations, and LEAR/Participant Register data requirements apply. DEP MGA contains detailed rules on eligible costs, reporting, certificates, recoveries, audits, record-keeping, confidentiality and publicity obligations, data protection, ethics, and security.

Co-funding requirement:The scraped call text does not explicitly state a mandatory co-funding percentage for this topic. Funding rate specifics and any co-funding obligations (if applicable) are set out in Annex 2 and in the call conditions; applicants must consult the Call document and Annex 2 in the Submission System to confirm the funding rate and whether co-funding (own contribution) is required.

Nature of support to beneficiaries

Beneficiaries will receive financial support (grant funding) and non-financial services. Non-financial support expected under projects includes training programmes, workshops, exercises, peer exchange and fellowship programmes, cross-border collaboration facilitation, access to expert hubs, development and deployment of shared platforms and tools, awareness and information campaigns, and support to commercialization and uptake of privacy-enhancing technologies. The action explicitly lists both monetary and organisational/technical services.

Important implementation topics and technical deliverables applicants should include

Suggested deliverables and activities to propose (non-exhaustive and aligned to call expectations): implementation guidelines and standardised processes/manuals; CRA conformity assessment toolkits and pilot tests; Certification and Evaluation as a Service platform prototypes and operational pilots; NIS 2 / CRA reporting platform prototypes (incident and vulnerability reporting); training curricula and ECSF-aligned exercise plans; educational resources for SMEs and high-school non-formal education; benchmarking and assessment frameworks for training effectiveness; peer exchange, fellowship and mentorship programmes; market surveillance best-practice guidelines and operational support for national authorities; open-source libraries for conformity testing; vulnerability disclosure and CVD automation tooling; cross-border CTI information-sharing frameworks; awareness campaigns (Do I comply with CRA? interactive materials) and dedicated websites for certification guidance.

  1. 1Operational platforms: Certification and Evaluation as a Service, incident/vulnerability reporting platforms, CTI sharing platforms.
  2. 2Training and skills: ECSF-based courses, cross-country exchange tools, benchmarking and evaluation frameworks, youth engagement and onboarding tracks.
  3. 3Standards and processes: guidelines for market surveillance authorities, conformity assessment methodologies, documentation harmonisation.
  4. 4Awareness and uptake: informational and press campaigns, SME-targeted user-friendly compliance checks, support for PET commercialisation.

Eligibility and proposal preparation tips

Tips based on the call materials and DEP rules:ensure organisation and partner information is fully registered in the Participant Register and LEAR data is current; prepare Ownership control declaration and be ready to upload supporting legal/financial documents if requested; follow Part B page and layout rules strictly; include a strong consortium that covers policy, technical, educational, market surveillance and SME outreach roles where relevant; detail WP1 (management) and risk mitigation; justify procurement and subcontracting practices and ensure best value for money; plan for record-keeping and auditability (time records for personnel, invoices, procurement procedures); align deliverables to the call Expected Outcomes and to the Digital Europe Cybersecurity Work Programme; consult National Cybersecurity Coordination Centres (NCCs) for guidance in the application phase.

Support and contact points:Contact the National Cybersecurity Coordination Centres (NCCs) in your country for guidance. The ECCC Applicants Direct Contact Centre can be reached at applicants@eccc.europa.eu. Use the Funding & Tenders Portal Online Manual and IT Helpdesk for submission and technical issues. Partner search functionality in the Portal is available to publish partner requests.

Application evaluation and award criteria (high level)

Evaluation procedures, award criteria, scoring and thresholds are described in sections 8 and 9 of the Call document and the Online Manual. Typical DEP evaluation criteria cover relevance (alignment with call objectives and policy), impact (expected EU-level benefits, sustainability, replicability), and implementation (methodology, management, resources, budget and cost-effectiveness, consortium capacity). Applicants must consult the Call document for precise scoring and threshold values.

Templates and form structure (detailed outline to assist applicants)

The Application Form (DEP) Part B template follows a compulsory structure. Below is an outline and guidance for what to include in each Part B section to match evaluator expectations and DEP formatting.

  1. 1Cover page and project summary: short clear title, acronym, coordinator contact; concise abstract aligned to call expected outcomes.
  2. 21 Relevance: define specific objectives, link to EU policy and the Digital Europe Cybersecurity priorities, target legislation addressed (CRA, NIS2, GDPR, DORA, Cybersecurity Act, AI Act), and identify targeted sectors/stakeholders/SMEs.
  3. 32 Implementation: maturity/readiness, detailed implementation plan, description of WPs, project management and governance structures, monitoring and quality assurance, risk register and mitigation measures, and demonstration/pilot plans.
  4. 43 Impact: expected outcomes (EU-level), KPIs and indicators, exploitation and sustainability plans, dissemination and communication strategy (visibility obligations), market uptake and SME adoption plans.
  5. 54 Work plan, WPs, activities, resources and timing: WP descriptions (WP1 management + technical WPs), tasks, milestones, deliverables (specify format, languages), staff effort, staff tables, subcontracting plan (if any, justify necessity), procurement and purchase costs justification (if >15% of personnel costs show details), equipment depreciation or full-cost option justification for listed equipment (if applicable), financial support to third parties arrangements (if requested), and Gantt/timetable.
  6. 65 Other: ethics self-assessment and security self-assessment (if applicable).
  7. 76 Declarations: double funding statements, prior EU funding declarations, and any special declarations.

Annexes:ownership control declaration (assembled by coordinator), CVs (annex 2 if required), detailed budget table/calculator where required (annex 1 for Lump Sum Grants or as called for), list of previous projects (if requested), and any additional required annexes noted in the call.

Risks, audits and legal/financial compliance

DEP MGA contains extensive rules on record-keeping (normally 5 years post project end unless otherwise indicated), checks/reviews/audits (granting authority, Commission, OLAF, ECA), certificates on financial statements (CFS) if thresholds are met, possible pre-financing guarantees, recovery mechanisms, joint and several liability options and consequences for non-compliance (rejection of costs, grant reduction, suspension, termination and administrative sanctions). Applicants should build robust financial management and procurement procedures and be ready for post-award audits and documentation requests.

Specific recommendations for technology and training proposals

Proposals addressing certification and conformity assessment should include:stakeholder mapping (CBs, CABs, labs, suppliers), pilot designs for CRA conformity testing (using open-source libraries where possible), documentation management workflows for certification, data exchange and interoperability specifications, privacy-preserving reporting mechanisms, and clear KPIs for time-to-certification and SME uptake. Training proposals should align curricula with ECSF and national authority needs, include evaluation/benchmarking schemes, accessibility and diversity plans, cross-border exchange mechanics, and sustainability/scale-up plans (including potential integration with the Cybersecurity Skills Academy).

Success factors and competitive advantage

Competitive proposals will:address at least one relevant piece of EU cybersecurity legislation with clear implementation impact; demonstrate pan-European and cross-sector reach; include strong involvement of national authorities or NCCs where relevant; provide a viable platform/technical prototype with an exploitation and sustainability plan; commit to SME-targeted support measures and clear methods to reduce certification barriers; present measurable training outcomes and plans to attract diverse talent; and document procurement and governance policies aligned with DEP MGA rules to ensure auditability and value-for-money.

Footnote reference:This topic highlights privacy-enhancing technologies and secure-by-design approaches; applicants may reference Data Protection Engineering (ENISA, 2022) for relevant principles and practices 1.

Summary: what this opportunity is about and how to explain it

This Digital Europe Programme call topic funds projects that will materially strengthen EU cybersecurity capacities and help implement multiple pieces of EU cybersecurity and related legislation (such as the Cyber Resilience Act, NIS 2, GDPR, DORA and aspects of the AI Act). It supports technical, organisational and educational activities: building certification and conformity assessment capabilities, creating platforms and tools (for certification, incident and vulnerability reporting, and information sharing), piloting CRA compliance processes, training public authorities and conformity assessment bodies, running skills and youth programmes, fostering cross-border collaboration, and promoting PETs and secure-by-design engineering. The call is open via the Funding & Tenders Portal with single-stage submission; it offers sizeable grants per sub-topic (multi-million euro brackets). Applicants should prepare a DEP-format proposal (Part A online + Part B PDF) conforming to the DEP MGA requirements, assemble required declarations and annexes, and demonstrate technical readiness, consortium capacity, clear impact on regulatory uptake and SME support, and robust financial and procurement controls. For country eligibility and precise funding rates, Annex 2 of the call and section 6 of the Call document must be consulted before submission.

Footnotes

  1. 1Data Protection Engineering, ENISA, 2022. Reference cited in the topic: enisa.europa.eu

Short Summary

Impact

Enable harmonised, operational implementation of EU cybersecurity legislation (CRA, NIS2, GDPR, DORA, Cybersecurity Act and relevant AI Act requirements) by building certification capacity, streamlining reporting and information sharing, and increasing SME regulatory readiness across Member States.

Applicant

Teams with combined capabilities in policy implementation, conformity assessment and certification, technical development (platforms/tools for certification, reporting and CTI sharing), training and capacity building, and SME outreach including privacy-enhancing technology expertise.

Developments

Deployment of certification and conformity-assessment tooling and platforms (e.g., Certification & Evaluation as a Service), NIS2/CRA reporting solutions, market-surveillance guidance, training curricula and exercises, PET uptake and pilot CRA compliance projects.

Applicant Type

profit SMEs/startups, researchers, large corporations, government organizations.

Consortium

Designed primarily for multi‑stakeholder consortia with cross‑border and cross‑sector partners (though some sub‑topics may accept single beneficiaries—multi‑partner proposals are strongly encouraged).

Funding Amount

Indicative EU contribution per project:€3,000,000 to €5,000,000 (topic budget €20,000,000; funding rate ~50% for Simple Grants).

Countries

EU Member States (all 27) and certain associated/EEA countries explicitly referenced such as Iceland and Norway due to NCC network participation and cross‑border cooperation requirements.

Industry

Digital Europe Programme targeting the cybersecurity policy/sector (implementation of Cyber Resilience Act, NIS2, Cybersecurity Act and related regulatory frameworks).

Additional Web Data

This topic is a Digital Europe Programme call under Strengthening European Cybersecurity Technologies, Capacities and Preparedness, and it is designed to help the European ecosystem implement key cybersecurity legislation in a more consistent way, especially the Cyber Resilience Act, NIS 2, GDPR, DORA, the Cybersecurity Act and selected AI Act requirements.[1][3] The topic combines capacity building, compliance support, certification, reporting, information sharing, training and privacy enhancing technologies, with a strong focus on SMEs and cross border cooperation.[1]

Official topic page:Funding and Tenders Portal topic page

What the funding is about

The call supports practical implementation of EU cybersecurity legislation by funding tools, methodologies, training, awareness actions and coordination mechanisms that make compliance easier for organisations and authorities.[1] It is especially aimed at reducing the burden on SMEs, strengthening certification and conformity assessment, improving incident reporting and information exchange, and supporting secure by design approaches in emerging digital technologies.[1]

  • Develop guidelines, standardised processes and manuals for difficult cybersecurity implementation issues across one or more Member States.[1]
  • Create tools and awareness actions that help SMEs understand and meet Cyber Resilience Act conformity assessment requirements.[1]
  • Reduce administrative burden through mechanisms such as a single entry point for incident notification and related reporting tools.[1]
  • Establish secure communication channels and information sharing initiatives across sectors and across borders.[1]
  • Support training courses, exercises, benchmarking, peer exchange, fellowships and competitions to build cybersecurity skills and diversity.[1]
  • Develop certification support, including materials for national authorities, conformity assessment bodies and certification laboratories.[1]
  • Run pilot projects, open source based testing and assessment methodologies for CRA compliance and market surveillance practices.[1]
  • Promote privacy enhancing technologies and secure and privacy by design solutions across ICT products and services.[1]

Who can apply

The formal eligibility rules are set out in section 6 of the call document, but the topic is clearly aimed at organisations that can deliver implementation support, regulatory capacity building, certification related work, training or coordination actions across the cybersecurity ecosystem.[1] Public authorities, competent authorities, national cybersecurity coordination centres, conformity assessment bodies, certification laboratories, SMEs, cybersecurity providers, research and academic organisations and other relevant stakeholders are the types of actors repeatedly referenced in the topic description and related call summaries.[1][9]

  • Applications should address at least one eligible piece of cybersecurity legislation, although more than one may be covered.[1]
  • For privacy enhancing technology work, consortia should include at least one representative from each of the researcher, provider, integrator and user organisation categories.[1]
  • Cross border collaboration and diversity in the cybersecurity workforce, including participation by women and other underrepresented groups, is explicitly encouraged.[1]
  • The topic is intended to support organisations that can work with national and cross regional stakeholders, not isolated local actions.[1]

Budget, grant size and timing

ItemDetails
Topic codeDIGITAL-ECCC
Call titleStrengthening European Cybersecurity Technologies, Capacities and Preparedness
ProgrammeDigital Europe Programme
Action typeDIGITAL JU Simple Grants
Model grant agreementDIGITAL Action Grant Budget Based
Submission modelSingle stage
Opening date1 September 2026
Deadline14 January 2027 at 17:00 Brussels time
Topic budget€20,000,000[1]
Indicative EU contribution per project€3,000,000 to €5,000,000[1]
Funding rate50 percent for Simple Grants[1]
Indicative number of grantsAbout 5[13]

The broader call budget across all seven cybersecurity topics is €96,000,000, and this topic is one of the largest individual allocations within that package.[1][10] The topic page also indicates that the submission session is open and that proposals must be submitted electronically through the Funding and Tenders Portal.[1][5]

Conditions and requirements applicants should note

  1. 1Proposal page limits and layout are defined in Part B of the application form, while the main admissibility rules are in section 5 of the call document.[1]
  2. 2Eligible countries and other eligibility conditions are defined in section 6 of the call document.[1]
  3. 3Financial and operational capacity, together with exclusion rules, are defined in section 7 of the call document.[1]
  4. 4Submission and evaluation procedures are defined in section 8 of the call document and the Online Manual.[1]
  5. 5Award criteria, scoring and thresholds are defined in section 9 of the call document.[1]
  6. 6The indicative timeline for evaluation and grant agreement is defined in section 4 of the call document.[1]
  7. 7The legal and financial set up of the grant is defined in section 10 of the call document.[1]
  8. 8Support for applicants is available through national cybersecurity coordination centres where available, or through the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu.[1]

Practical assessment for applicants

This is a strong fit for consortia that can combine policy implementation, technical delivery and user adoption, especially where the proposal can demonstrate measurable impact on regulatory readiness, certification capacity, incident reporting, market surveillance, skills development or privacy enhancing technology uptake.[1] Proposals that show cross border usefulness, SME relevance, interoperability, and a clear route to operational deployment are likely to align best with the topic logic.[1]

Update Log

No updates recorded yet.

Documents

PDF documentPDF documentWord documentPDF documentPDF documentPDF documentPDF document

Discover with AI

Let our intelligent agent help you find the perfect funding opportunities tailored to your needs.

Try AI Agent →

EU Grant Database

Explore European funding opportunities in our comprehensive, up-to-date collection.

Browse Database →

Stay Informed

Get notified when grants change, deadlines approach, or new opportunities match your interests.

Configure Notifications →

Track Your Favorites

Follow grants you're interested in and keep them organized in one place. Get updates on changes and deadlines.

Use the Follow button above ↑

Coordinated preparedness testing and other preparedness actions

Call for ProposalOpen

Digital Europe Programme call DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP funds coordinated preparedness testing and other cyber preparedness actions for highly critical and other critical sectors under the Cyber Solidarity Act and the C...

January 14th, 2027

Standardisation

Call for ProposalOpen

The Standardisation topic (ISF-2026-TF2-AG-CYBER-STANDARD) under the Internal Security Fund supports standardisation activities to strengthen digital investigations and lawful access to digital evidence. The call opened on 15 September 2...

December 15th, 2026

Cybersecure tools, technologies and services relying on AI

Call for ProposalOpen

Digital Europe (ECCC) call DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI funds development, validation and deployment of AI-based cybersecurity tools and services for Cyber Hubs, CSIRTs, competent authorities and NIS2 entities. Opening 1 Sep...

January 14th, 2027

Enhancing the NCC Network

Call for ProposalOpen

This call under the Digital Europe Programme (Strengthening European Cybersecurity Technologies, Capacities and Preparedness) funds National Coordination Centres to strengthen national cybersecurity ecosystems, support SMEs, skills, mark...

January 14th, 2027

Strengthening cybersecurity capacities of European SMEs with cybersecure AI-powered solutions

Call for ProposalOpen

Call DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME under the Digital Europe Programme is open from 01 September 2026 to 14 January 2027 with an indicative budget of EUR 20,000,000 and an expected five grants. The action funds adoption, deploy...

January 14th, 2027

C5ISR and other space-related products

Call for ProposalOpen

This is a call for proposals under the European Defence Industry Programme (EDIP) Common Procurement Actions for joint procurement of C5ISR and other space-related defence capabilities, with actions to be completed by 31 December 2033. T...

February 16th, 2027

Research Support Framework for Situational Awareness on information integrity

Call for ProposalOpen

Research Support Framework for Situational Awareness on Information Integrity (DIGITAL-2026-BESTUSE-RSF-10-AWARENESS) is a Digital Europe call to establish a shared research infrastructure and tools to support advanced research and analy...

October 1st, 2026

Dual-use technologies

Call for ProposalOpen

Digital Europe Programme call DIGITAL-ECCC-2027-DEPLOY-CYBER-11 DUALUSE funds development, demonstration and deployment of dual-use cybersecurity technologies and operational infrastructures to strengthen cooperation between civilian and...

January 14th, 2027

Digital Investigations

Call for ProposalOpen

Call for proposals Internal Security Fund (ISF) Digital Investigations and Standardisation (ISF-2026-TF2-AG-CYBER-DIGITAL) to strengthen EU law enforcement and judicial capacity for cybercrime and digital investigations. Single-stage ele...

December 15th, 2026

Layered critical seabed infrastructure protection

Call for ProposalOpen

European Defence Fund call EDF-2026-LS-RA-SI-UWW-CSBI-STEP funds studies and design to develop a layered system-of-systems for protection of critical seabed infrastructure including cables and pipelines. The topic has a total budget of E...

September 29th, 2026

AI compute evaluation and deployment platform for EU infrastructure

Call for ProposalOpen

Call DIGITAL-JU-CHIPS-2026-AI-GFP under the Digital Europe Programme and Chips JU funds the establishment of a common EU evaluation platform for AI chips and racks and first pilot deployments of European AI compute systems validated for...

October 27th, 2026

Quantum secured tactical networks

Call for ProposalOpen

Quantum Secured Tactical Networks (EDF-2026-RA-CYBER-QSTN) is a European Defence Fund Research Actions call to design SDN-based quantum-secured tactical network architectures integrating QKD, post-quantum cryptography, PUFs, NFV, SDR and...

September 29th, 2026