🏛 EU_PORTAL · 📍 EU
€5,000,000
Sep 1, 2026
Jan 14, 2027
Digital Europe Programme
Strengthening EU cybersecurity capacities & capabilities in line with legislative requirements
Expected Outcome:
One or more of the following should be covered:
Objective:
The objective of this topic is to support the European ecosystem to strengthen its cybersecurity capacities and to support the implementation of the regulatory framework in line with the Cyber Resilience Act (CRA), NIS 2 Directive, GDPR, DORA, Cybersecurity Act, specific requirements of the AI Act, etc. in a homogeneous approach. Additionally, and in alignment with the Digital education plan, which emphasises the development of digital skills crucial for the modern economy, and in support of initiatives like the Cybersecurity Skills Academy, activities related to cybersecurity challenges should also be promoted. These initiatives aim to address the skills shortage in cybersecurity and develop a workforce capable of meeting regulatory and operational demands. By providing practical training, attracting young professionals, and encouraging diversity within the field, these efforts are vital to Europe’s ability to respond to evolving cyber threats and to comply with new legislation. Additionally, these activities foster equal opportunities and raise cybersecurity awareness among future generations, contributing to Europe’s broader strategic goals in the digital domain.
The implementation of EU cybersecurity legislation needs to be supported to achieve a higher level of cybersecurity in the EU, especially in a constantly changing threat landscape. Cybersecurity maturity levels are different depending on each sector. This means that efforts and investments are needed to ensure and continuously improve cyber security in both the public and private sectors. Such efforts and investments are crucial in each Member State and therefore require increased focus and joint efforts at European level. Empowerment and self-assessment tools can be the most effective.
All the above efforts should consider that data security and protection must be promoted during the design and development of ICT products and services.
Scope:
EU cybersecurity legislation brings new responsibilities and imposes obligations on key stakeholders, ICT systems, Operational Technology and IoT manufacturers. For instance, the cost of obtaining a cybersecurity certification for an ICT or digital product, service or process is often an insuperable barrier for EU start-ups and SMEs.
Support must be provided for the implementation of these obligations. The activities under this action require various types of support, including financial and organisational. Applications should address at least one of the eligible pieces of cybersecurity legislation but can also address more.
The focus will also be on fostering cross-border collaboration and promoting diversity within the cybersecurity workforce, encouraging participation from women and other underrepresented groups. In conjunction with initiatives like the Cybersecurity Skills Academy, these activities will contribute to building capacity, raising awareness, and supporting the uptake of the aforementioned regulatory framework. By integrating these challenges into a broader capacity-building framework, they will ensure that stakeholders across sectors are equipped to address evolving cybersecurity threats and comply with the new legislative landscape.
Aligned with the goals of the Digital Education Action Plan which focuses on enhancing digital skills across Europe, activities related to cybersecurity challenges will play a crucial role in developing the next generation of cybersecurity professionals. These challenges will provide hands-on experience for young professionals and students, helping to close the cybersecurity skills gap and ensuring they are well-prepared to meet the demands of new legislative requirements.
The assessment of products and services is an essential step in the EU cybersecurity certification process. As cybersecurity threats are rapidly evolving and attacks are becoming more sophisticated, it is important to find a way to address these challenges. In addition, the EU needs to cope with the continuous growth of information systems (in terms of size and complexity) and the significant expansion of the digital space by enabling fast but secure replication of assessments. Furthermore, it is a great opportunity for the EU to develop interoperable solutions that will increase its competitiveness. In doing so, the Union can rely on a large and dynamic number of players who have already developed high-quality offerings.
The certification process is also very formal in terms of the documentation that is later used as proof for issuing the certificate. There is currently no platform to help proponents overcome the challenges posed by the use of many different and complex documents by all parties.
This action involves building capacity of national cybersecurity certification authorities to undertake market surveillance and supervise conformity assessment bodies and conformity assessments of essential requirements for cybersecurity products, services and processes. It should ensure the mutual recognition across Member States.
Furthermore, the action is also about building up capabilities of conformity assessment bodies and certification laboratories to meet the requirements of the Cyber Security Act and the Cyber Resilience Act, as regards verifying declarations of conformity from suppliers and vendors.
The action involves also the development of supporting tools for certification and evaluation processes, including a ‘Certification and Evaluation as a Service’ software platform to assist conformity assessment as well as support in creating national or cross-regional expert hubs to assist with these processes. Its development should involve relevant stakeholders such as CBs, CABs, and client representatives.
The ‘Certification and Evaluation as a Service platform’ could facilitate and streamline the management of all documentation used in the certification process. It could also help to speed up the information exchange between the bodies taking part in the process. The platform could help to harmonise and standardise the documentation and tools to be used across Europe.
The main areas considered under the scope of this action could include:
In addition to providing supports for national cybersecurity certification authorities, conformity assessment bodies and national accreditation bodies with certification, the implementation of the NIS 2 Directive will continue in the coming years. In particular, competent authorities will need to build up capacity in audit and compliance to ensure that essential and important entities are meeting their responsibilities. Training and awareness raising activities along with trust and confidence building activities to facilitate information sharing and knowledge building should be provided.
Overall, this action is intended to increase collaboration between national authorities, supporting or supplementing the structures under the NIS Directive that need to comply with CRA (e.g. Software Bill of Materials, CRA Single Reporting Platform contributions and open prototypes, CVD processes or security advisory automation, like the CSAF), as well as between national authorities and stakeholders, especially SMEs, to raise cybersecurity maturity levels through the development and implementation of common methodologies to enable the deployment of cybersecurity processes and the uptake of products and services by entities.
This action involves the creation and deployment of common tools for regulation and enforcement, including targeted security audits and incident notifications to national competent authorities to facilitate information exchange.
Under information exchange, the action can also include:
In addition, this topic promotes security and privacy ‘by design’ in existing and emerging technologies, applications and hardware, including IoT, Operational Technology, Identity and e-government systems, by supporting and/or funding research and innovation opportunities. Privacy-enhancing technologies aim to minimise the risks to the privacy of data subjects. Implementing security and privacy features in emerging technologies, applications and hardware from the outset – in the design and implementation phase [1] – ensures that potential vulnerabilities and risks are recognised and addressed early in the development process. In addition, to be in line with data protection regulations, this approach can be more cost effective and would reduce the likelihood of security and personal data breaches.
Consortia should consider including at least one representative of each of the following categories to reflect the whole value chain: privacy-enhancing technology researchers, privacy-enhancing technology providers, developers of ICT products and services integrating privacy-enhancing technologies, and ICT product and services user organisations.
[1] Data Protection Engineering, ENISA, 2022, available at: https://www.enisa.europa.eu/publications/data protection-engineering.
described in section 5 of the call document.
Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.
described in section 6 of the call document.
described in section 6 of the call document.
described in section 7 of the call document.
described section 8 of the call document and the Online Manual.
described in section 9 of the call document.
described in section 4 of the call document.
described in section 10 of the call document.
Application form templates
Standard application form (DEP) — the application form specific to this call is available in the Submission System
Model Grant Agreements (MGA)
Digital Europe Cybersecurity Work Programme 2025-2027
EU Financial Regulation 2024/2509
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
For guidance and support related to this call, we recommend that you first contact the National Cybersecurity Coordination Centres (NCC) in your country, where available. The Network of NCCs includes one national centre from each of the 27 EU Member States plus Iceland and Norway. You may also address your questions to the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu
Funding & Tenders Portal FAQ – Submission of proposals.
IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc.
Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and evaluation to reporting on your ongoing project. Valid for all 2021-2027 programmes.