What this call funds
Expected Outcome
- Support the adoption of market-ready innovative AI-powered cybersecurity solutions, including solutions developed in the framework of EU-supported research and innovation projects.
- Provide and deploy up to date AI-powered tools and services to organisations (in particular SMEs) to prepare, protect and respond to cybersecurity threats.
- Integrate AI technologies into cybersecurity processes to improve the security of ICT solutions, including providing innovative approaches to training employees to use AI solutions for cybersecurity.
- Deployment of cybersecure tools and technologies relying on trustworthy AI; AI driven cybersecurity tools; Integration of tools to protect and secure AI solutions.
Objective
To support the market uptake and dissemination of innovative AI-powered cybersecurity solutions (notably in SMEs, possibly using results stemming from Horizon Europe projects or similar) and improve knowledge and auditing of cybersecurity preparedness.
SMEs often lack the resources to assess cyber risks, develop cybersecurity strategies and implement solutions, leaving them vulnerable to cyberattacks. The resilience of organisations that fall into this category is key to the prosperity of the EU single market.
Cyber risk assessment and management can be significantly enhanced and simplified with the application of AI-based tools and solutions. However, this requires an understanding of the evolving technology landscape, of the benefits of technology integration and of deployment prioritisation. Faced with organisational and financial constraints, the SMEs may be missing the opportunity to fully harness AI-powered solutions to advance their cybersecurity and resilience.
Cybersecurity is the precondition for reliable, secure and resilient AI models and algorithms. Cybersecurity of AI is not just about protecting AI systems against threats such as poisoning and evasion attacks, as it also involves ensuring they have trustworthiness features such as human oversight and robustness – the ability to resist cyberattacks, as required by the EU’s AI Act for high-risk AI systems. The need for human oversight of AI has also been emphasised by experts. Also, the use of AI at the SME level supporting the integration of predictive algorithms can greatly support to a bottom-up approach when dealing with vulnerability detections, threat mitigation and more efficient coordinated incident response.
Scope
This action aims to increase the maturity of cyber risk management and improve the cyber resilience and ultimately foster a technologically advanced culture of cybersecurity for SMEs in the EU. Actions in this topic should develop and deploy AI-powered products, tools and services for European SMEs, also enabling the detection/discovery of attack patterns.
Proposals should cover the development or adaptation of the software/hardware and the validation of the solutions.
It foresees the automation of fundamental cybersecurity processes, in particular in small market organisations, through a SaaS toolkit tailored to the needs of SMEs. This toolkit should allow SMEs to improve the key aspects of their cybersecurity by providing user-friendly tools for risk management [1], threat detection, incident response and notification, to improve their cyber hygiene and mitigate potential threats while protecting personal data. The cyber toolkit should also provide cyber-incident prediction and response functions to improve SMEs’ resilience.
Activities should include at least one of the following:
- Uptake/adoption of AI-powered cybersecurity tools in organisations where this has not yet taken place.
- Development of user-friendly sets of tools (e.g. toolkit) based on AI to automate main cybersecurity processes in SMEs. Such a toolkit could provide automated functions such as: • A function that supports the assessment and management of an SME’s cybersecurity risks. This function should perform a risk assessment, provide recommendations for risk mitigation, and identify options.
- An interface to existing tools that support the analysis and assessment of the extent of an SME’s cyber risk based on information gathered from digital infrastructure scanning and data provided by authorised users.
- A function that issues alerts on relevant vulnerabilities and threats based on the information collected by the risk management function.
- A function that connects SMEs to a Cyber Hub to report an incident and assist with recovery if possible.
- SME user interface for incident reporting associated with the cyber toolkit. Users can report an incident, get instructions on how to react and obtain information on how to obtain support for the response, with the use of AI assistants.
[1] Interoperable EU Risk Management Framework, ENISA, 2023, available at: https://www.enisa.europa.eu/publications/interoperable-eu-risk-management-framework
Eligibility & conditions+
Conditions
1. Admissibility conditions: Proposal page limit and layout
described in section 5 of the call document.
Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.
2. Eligible countries
described in section 6 of the call document.
3. Other eligibility conditions
described in section 6 of the call document.
4. Financial and operational capacity and exclusion
described in section 7 of the call document.
5a. Evaluation and award: Submission and evaluation processes
described section 8 of the call document and the Online Manual.
5b. Evaluation and award: Award criteria, scoring and thresholds
described in section 9 of the call document.
5c. Evaluation and award: Indicative timeline for evaluation and grant agreement
described in section 4 of the call document.
6. Legal and financial set-up of the grants
described in section 10 of the call document.
Call document and annexes:
Call document
Application form templates
Standard application form (DEP) — the application form specific to this call is available in the Submission System
Ownership control declaration
Model Grant Agreements (MGA)
DEP MGA
Additional documents:
Digital Europe Cybersecurity Work Programme 2025-2027
DEP Regulation 2021/964
EU Financial Regulation 2024/2509
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
Funding & Tenders Portal Terms and Conditions
Funding & Tenders Portal Privacy Statement
Source: EU Funding & Tenders Portal · synced 2026-09-02
