Digital EuropeDIGITAL JU Simple Grants

Strengthening EU cybersecurity capacities & capabilities in line with legislative requirements

Deadline14 January 2027
Total budget€20M
Grant size€3M–€5M
Expected grants5
Opens1 September 2026
Deadline modelsingle-stage
Call IDDIGITAL-ECCC-2027-DEPLOY-CYBER-11

What this call funds

Expected Outcome

One or more of the following should be covered:

  • Implementation of guidelines, standardised processes, or manuals – in the EU or multiple EU MS – concerning the most challenging issues, supporting specific stakeholders and sectors addressed by cybersecurity legislation.
  • Develop and implement tools, raise awareness and encourage and facilitate industry uptake, with a focus on SMEs, of conformity assessments of essential cybersecurity requirements for products with digital elements (hardware and software) under the CRA.
  • Support for mechanisms reducing the administrative burden for entities, like single entry point for incident notification.
  • Establish secure communication channels allowing for cooperation and information sharing initiatives.
  • Support the organisation of regular meetings/workshops to identify good practices within specific sectors or emerging areas and facilitate collaborative efforts between different sectors.
  • Support the development of training courses, on the basis of the ECSF and exercises that promote capacity building and internal awareness.
  • Contribution to CR standardisation: Training materials and training actions on cybersecurity certification for national authorities and conformity assessment bodies.
  • Fostering certification: Educational and supporting materials and an explanatory press campaign using interactive material such as ‘Do I comply with CRA?’. Information campaign through various channels such as conferences, meetings, etc. Website dedicated to the mandatory certification and conformity assessments of essential requirements.
  • Development of training programmes and materials, including tools for cross-country collaboration and exchange, aimed at enhancing participants’ skills and readiness for real-world threats. These programmes can also support non-formal education for high school students and teachers, enhancing digital literacy and cybersecurity awareness at early educational levels.
  • Creation of benchmarking and assessment programmes to evaluate and optimise the performance of participants in cybersecurity training programmes, ensuring continuous improvement and alignment with industry standards.
  • Implement peer exchange and fellowship programmes, aimed at fostering a connected, resilient community of cybersecurity professionals across Europe. These programmes will also include support for cross-border training initiatives and non formal education activities, ensuring that both students and educators can participate in hands-on cybersecurity learning experiences and contribute to long-term talent development.
  • Establishment of cross-border collaboration programmes to support the development of pan-European teams in cybersecurity competitions. These programmes will provide access to mentorship, advanced tools, and leadership training, ensuring European teams remain competitive on the global stage. Additionally, the programmes will foster the growth of a European cybersecurity leadership pipeline, enhancing Europe’s visibility and effectiveness in international cybersecurity challenges.
  • Support organisations, including SMEs, in assessing the robustness, applicability and relevance of security- and privacy-enhancing technologies to be integrated in the ICT products and services they develop.
  • Set-up pilot projects to test CRA compliance, use open-source software and libraries for conformity assessment and testing; develop assessment methodologies for the purpose of CRA compliance/requirements.
  • Develop best practices or guidelines for setting-up and operating market surveillance authorities in MSs; develop awareness of CRA requirements.
  • Support organisations, including SMEs, in commercialising privacy-enhancing technologies and demonstrate how they can address security and privacy risks from emerging technologies.
  • Facilitate cooperation between the producers of emerging technologies, the users of those technologies and regulators. Such cooperation would make it possible to identify which requirements can be met by which privacy-enhancing technology, in which use cases, to what extent they could facilitate compliance or reduce the cost thereof, and how to engineer it in practice, during the early phases of design and development of ICT products and services.
  • Strengthen cooperation in the whole privacy-enhancing technology value chain, including between researchers, providers, integrators and users, and GDPR national authorities/European supervisors.

Objective

The objective of this topic is to support the European ecosystem to strengthen its cybersecurity capacities and to support the implementation of the regulatory framework in line with the Cyber Resilience Act (CRA), NIS 2 Directive, GDPR, DORA, Cybersecurity Act, specific requirements of the AI Act, etc. in a homogeneous approach. Additionally, and in alignment with the Digital education plan, which emphasises the development of digital skills crucial for the modern economy, and in support of initiatives like the Cybersecurity Skills Academy, activities related to cybersecurity challenges should also be promoted. These initiatives aim to address the skills shortage in cybersecurity and develop a workforce capable of meeting regulatory and operational demands. By providing practical training, attracting young professionals, and encouraging diversity within the field, these efforts are vital to Europe’s ability to respond to evolving cyber threats and to comply with new legislation. Additionally, these activities foster equal opportunities and raise cybersecurity awareness among future generations, contributing to Europe’s broader strategic goals in the digital domain.

The implementation of EU cybersecurity legislation needs to be supported to achieve a higher level of cybersecurity in the EU, especially in a constantly changing threat landscape. Cybersecurity maturity levels are different depending on each sector. This means that efforts and investments are needed to ensure and continuously improve cyber security in both the public and private sectors. Such efforts and investments are crucial in each Member State and therefore require increased focus and joint efforts at European level. Empowerment and self-assessment tools can be the most effective.

All the above efforts should consider that data security and protection must be promoted during the design and development of ICT products and services.

Scope

EU cybersecurity legislation brings new responsibilities and imposes obligations on key stakeholders, ICT systems, Operational Technology and IoT manufacturers. For instance, the cost of obtaining a cybersecurity certification for an ICT or digital product, service or process is often an insuperable barrier for EU start-ups and SMEs.

Support must be provided for the implementation of these obligations. The activities under this action require various types of support, including financial and organisational. Applications should address at least one of the eligible pieces of cybersecurity legislation but can also address more.

The focus will also be on fostering cross-border collaboration and promoting diversity within the cybersecurity workforce, encouraging participation from women and other underrepresented groups. In conjunction with initiatives like the Cybersecurity Skills Academy, these activities will contribute to building capacity, raising awareness, and supporting the uptake of the aforementioned regulatory framework. By integrating these challenges into a broader capacity-building framework, they will ensure that stakeholders across sectors are equipped to address evolving cybersecurity threats and comply with the new legislative landscape.

Aligned with the goals of the Digital Education Action Plan which focuses on enhancing digital skills across Europe, activities related to cybersecurity challenges will play a crucial role in developing the next generation of cybersecurity professionals. These challenges will provide hands-on experience for young professionals and students, helping to close the cybersecurity skills gap and ensuring they are well-prepared to meet the demands of new legislative requirements.

The assessment of products and services is an essential step in the EU cybersecurity certification process. As cybersecurity threats are rapidly evolving and attacks are becoming more sophisticated, it is important to find a way to address these challenges. In addition, the EU needs to cope with the continuous growth of information systems (in terms of size and complexity) and the significant expansion of the digital space by enabling fast but secure replication of assessments. Furthermore, it is a great opportunity for the EU to develop interoperable solutions that will increase its competitiveness. In doing so, the Union can rely on a large and dynamic number of players who have already developed high-quality offerings.

The certification process is also very formal in terms of the documentation that is later used as proof for issuing the certificate. There is currently no platform to help proponents overcome the challenges posed by the use of many different and complex documents by all parties.

This action involves building capacity of national cybersecurity certification authorities to undertake market surveillance and supervise conformity assessment bodies and conformity assessments of essential requirements for cybersecurity products, services and processes. It should ensure the mutual recognition across Member States.

Furthermore, the action is also about building up capabilities of conformity assessment bodies and certification laboratories to meet the requirements of the Cyber Security Act and the Cyber Resilience Act, as regards verifying declarations of conformity from suppliers and vendors.

The action involves also the development of supporting tools for certification and evaluation processes, including a ‘Certification and Evaluation as a Service’ software platform to assist conformity assessment as well as support in creating national or cross-regional expert hubs to assist with these processes. Its development should involve relevant stakeholders such as CBs, CABs, and client representatives.

The ‘Certification and Evaluation as a Service platform’ could facilitate and streamline the management of all documentation used in the certification process. It could also help to speed up the information exchange between the bodies taking part in the process. The platform could help to harmonise and standardise the documentation and tools to be used across Europe.

The main areas considered under the scope of this action could include:

  • The implementation of EU legislation in cybersecurity to be supported to achieve a higher cybersecurity level in Europe.
  • Provide support to SMEs aiming to enhance cybersecurity resilience with a particular focus on legal requirements deriving from EU legislation such as NIS 2, Cyber Resilience Act, Cybersecurity Act, etc., including practical guidelines and user-friendly tools allowing the company to check whether its solutions are compliant with the requirements of the new legislation considering open standards.
  • Develop reporting platforms for NIS 2 (e.g. incident reporting platform) and CRA (e.g. vulnerability single reporting platform).
  • Establish short-term and long-term actions to prepare professionals to properly implement the requirements of new EU regulations in entities covered by those regulations.
  • Develop programmes to promote diversity and equal opportunities for all young Europeans, providing tailored onboarding programmes for youth. These programmes will offer resources and easy access to educational content, ensuring that participants from various backgrounds can engage with cybersecurity training. By supporting non formal education and offering participation opportunities, such as cybersecurity challenges, these efforts will help equip the next generation with the skills needed to thrive in the sector.
  • Creation and development of cooperation initiatives in cross-border and cross-sector contexts. Encourage collaboration between national and regional authorities to enhance cyber resilience and raise cybersecurity maturity levels through development and implementation of common methodologies.
  • The design and evaluation of platforms for training programmes and tools for cross country exchange will support these efforts. Additionally, benchmarking and assessment programmes will help optimise performance, enhancing participants’ skills. These initiatives, including training materials, with cybersecurity challenges as one example, will also include peer exchange and fellowship opportunities, fostering a connected community of cybersecurity professionals. By encouraging cross-border collaboration and ongoing engagement, these programmes aim to strengthen Europe’s cybersecurity workforce and support long-term talent development.
  • Support the development of cross-border collaboration programmes, enabling pan European teams to participate in international cybersecurity competitions, enhancing visibility and competitiveness on the global stage. These initiatives will provide teams with access to advanced tools, mentorship, and leadership training, fostering the growth of a European cybersecurity talent pipeline. By promoting excellence, skills development, and leadership, this support will ensure that Europe’s top talent remains competitive, well-prepared, and collaborative in facing global cybersecurity challenges.

In addition to providing supports for national cybersecurity certification authorities, conformity assessment bodies and national accreditation bodies with certification, the implementation of the NIS 2 Directive will continue in the coming years. In particular, competent authorities will need to build up capacity in audit and compliance to ensure that essential and important entities are meeting their responsibilities. Training and awareness raising activities along with trust and confidence building activities to facilitate information sharing and knowledge building should be provided.

Overall, this action is intended to increase collaboration between national authorities, supporting or supplementing the structures under the NIS Directive that need to comply with CRA (e.g. Software Bill of Materials, CRA Single Reporting Platform contributions and open prototypes, CVD processes or security advisory automation, like the CSAF), as well as between national authorities and stakeholders, especially SMEs, to raise cybersecurity maturity levels through the development and implementation of common methodologies to enable the deployment of cybersecurity processes and the uptake of products and services by entities.

This action involves the creation and deployment of common tools for regulation and enforcement, including targeted security audits and incident notifications to national competent authorities to facilitate information exchange.

Under information exchange, the action can also include:

  • At national level, federate national actors working on cyber threat intelligence and national competent authorities around a common platform. Including facilitating and centralising the notification process for NIS 2 entities.
  • At vertical level within the EU, organise or support cyber threats intelligence (CTI) unclassified information sharing in confidence between stakeholders of the given vertical.
  • At EU level, enabling and organising collaboration between countries and information sharing.
  • Collaborate on and implement a framework of guidelines - in the EU or multiple EU MS - to ensure and continuously improve cybersecurity both within the public and private sectors through better protection of their data, a significant reduction of the risk of the most common cyberattacks, and an increase of cyber resilience in general.

In addition, this topic promotes security and privacy ‘by design’ in existing and emerging technologies, applications and hardware, including IoT, Operational Technology, Identity and e-government systems, by supporting and/or funding research and innovation opportunities. Privacy-enhancing technologies aim to minimise the risks to the privacy of data subjects. Implementing security and privacy features in emerging technologies, applications and hardware from the outset – in the design and implementation phase [1] – ensures that potential vulnerabilities and risks are recognised and addressed early in the development process. In addition, to be in line with data protection regulations, this approach can be more cost effective and would reduce the likelihood of security and personal data breaches.

Consortia should consider including at least one representative of each of the following categories to reflect the whole value chain: privacy-enhancing technology researchers, privacy-enhancing technology providers, developers of ICT products and services integrating privacy-enhancing technologies, and ICT product and services user organisations.

[1] Data Protection Engineering, ENISA, 2022, available at: https://www.enisa.europa.eu/publications/data protection-engineering.

Eligibility & conditions+

Conditions

1. Admissibility conditions: Proposal page limit and layout

described in section 5 of the call document.

Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.

2. Eligible countries

described in section 6 of the call document.

3. Other eligibility conditions

described in section 6 of the call document.

4. Financial and operational capacity and exclusion

described in section 7 of the call document.

5a. Evaluation and award: Submission and evaluation processes

described section 8 of the call document and the Online Manual.

5b. Evaluation and award: Award criteria, scoring and thresholds

described in section 9 of the call document.

5c. Evaluation and award: Indicative timeline for evaluation and grant agreement

described in section 4 of the call document.

6. Legal and financial set-up of the grants

described in section 10 of the call document.

Call document and annexes:

Call document

Application form templates

Standard application form (DEP) — the application form specific to this call is available in the Submission System

Ownership control declaration

Model Grant Agreements (MGA)

DEP MGA

Additional documents:

Digital Europe Cybersecurity Work Programme 2025-2027

DEP Regulation 2021/964

EU Financial Regulation 2024/2509

Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment

EU Grants AGA — Annotated Model Grant Agreement

Funding & Tenders Portal Online Manual

Funding & Tenders Portal Terms and Conditions

Funding & Tenders Portal Privacy Statement

Source: EU Funding & Tenders Portal · synced 2026-09-02