Official call identifier: DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP
Objective of the call
The call supports two actions under the Cyber Solidarity Act’s Cybersecurity Emergency Mechanism: coordinated preparedness testing of entities operating in sectors of high criticality, and other preparedness actions for entities operating in sectors of high criticality and other critical sectors.
The objective is to complement Member State and EU-level efforts to strengthen protection and resilience against cyber threats, particularly for critical industrial installations and infrastructure, by providing knowledge and expertise that improve preparedness for cyber threats and incidents.
Projects must contribute to at least one of the following:
- Part 1 – Coordinated preparedness testing: testing of entities operating in sectors of high criticality, including penetration testing and threat assessment covering ICT as well as Operational Technology/Industrial Control Systems.
- Part 2 – Other preparedness actions: vulnerability monitoring, exercises, training courses and other preparedness activities for highly critical and other critical sectors.
Scope of activities
Part 1 – Coordinated preparedness testing
Part 1 focuses on coordinated preparedness testing in three sectors and sub-sectors identified for this call:
- Energy: electricity
- Transport: rail and water/ports
- Public administration
Proposals under Part 1 must use the common risk scenarios developed for the call and include at least the baseline risk scenario. Applicants may adapt these scenarios to national circumstances and may also include higher-intensity scenarios.
Activities may include:
- Development and implementation of penetration testing based on the defined risk scenarios
- Testing essential entities operating critical infrastructure for potential vulnerabilities
- Deployment of digital tools and infrastructure supporting testing scenarios
- Development and use of standardised cyber ranges and other testing facilities
- Cross-border cyber exercises where relevant
- Evaluation and testing of cybersecurity capabilities to prevent, detect and respond to incidents
- Sector-wide cyber resilience stress testing
- Evaluation and management of supply-chain cybersecurity risks
- Security audits and vulnerability scanning
- Consulting and recommendations to improve infrastructure security and cybersecurity capabilities
- Threat-assessment processes and lifecycle implementation
- Customised risk-scenario analysis
The coordinated testing process should include a Systemic Risk Analysis Phase, a Testing Phase, and a Gap Analysis Phase, leading to identified gaps, recommendations and an action plan for remediation.
Part 2 – Other preparedness actions
Part 2 addresses entities operating in highly critical and other critical sectors referred to in Annexes I and II of the NIS 2 Directive, particularly sectors not selected for coordinated preparedness testing under Part 1.
Activities may include:
- Threat and risk assessment
- Supply-chain risk management
- Continuous risk monitoring, including attack-surface monitoring and monitoring of assets and vulnerabilities
- Coordinated vulnerability disclosure and management
- Promotion of national Coordinated Vulnerability Disclosure policies and the EU Vulnerability Database
- Coordination of vulnerability disclosure and timely dissemination of security patches
- Development of applications managing vulnerability information from multiple sources using open standards or technologies
- Awareness raising on vulnerability-management best practices
- Training programmes and workshops for cybersecurity professionals
- Cybersecurity exercises and continuous learning activities
- Activities supporting compliance with cybersecurity requirements arising from EU legislation and directives, including NIS 2, the Cybersecurity Act, Cyber Solidarity Act, DORA, EECC, GDPR and the Cyber Resilience Act.
Eligible applicants
• Innovative SMEs, startups and enterprises aiming to scale and strengthen competitiveness
• Public-sector organisations driving transformation and societal impact
• Research and academic institutions commercialising knowledge
• Non-profit organisations delivering purpose-driven innovation
• Organisations based in EU Member States, EFTA/EEA countries, or Associated Countries as defined in the Horizon Europe General Annexes
• Consortia must include at least the minimum number of independent legal entities from different eligible countries, as specified in the call conditions
For this specific call, eligible beneficiaries and affiliated entities must be legal entities established in EU Member States, including overseas countries and territories, or EEA countries (Norway, Iceland and Liechtenstein). Participation in any capacity is restricted to entities established in and controlled from eligible countries due to the security restrictions applying under Article 12(5) of the Digital Europe Programme Regulation.
For both Part 1 and Part 2, the action primarily targets public bodies designated or entrusted by the relevant Member State with cybersecurity responsibilities, including cybersecurity competent authorities and CSIRTs designated under the NIS 2 Directive. Other relevant public or private partners may participate in the consortium to support implementation. No minimum consortium composition requirement is specified for this topic.
Specific consortium we are looking for:
- Public body designated or entrusted by a Member State with cybersecurity responsibilities, including a competent cybersecurity authority or CSIRT
- Cybersecurity testing and penetration-testing expertise capable of supporting vulnerability assessments, security audits and cyber resilience stress testing
- Threat and risk-assessment expertise covering ICT, Operational Technology and Industrial Control Systems
- Cyber-range and testing infrastructure providers capable of supporting realistic preparedness exercises and testing scenarios
- Vulnerability and risk-monitoring specialists supporting attack-surface, asset and vulnerability monitoring
- Coordinated vulnerability disclosure expertise supporting vulnerability management and information exchange
- Cybersecurity training and exercise providers capable of delivering training programmes, workshops and continuous learning activities
- Other relevant public or private partners supporting the implementation of national preparedness activities
Eligible costs
Eligible costs may include:
- Personnel costs
- Subcontracting costs
- Travel and subsistence
- Equipment
- Other goods, works and services
- Internally invoiced goods and services
- Indirect costs calculated at 7% of eligible direct costs
- Equipment costs based on depreciation, with full-cost reimbursement possible for listed equipment under the conditions of the call
Funding conditions
Type of action:
DIGITAL JU Simple Grants
Funding rate:
50% funding rate
EU indicative budget:
Around EUR 15,000,000
Expected EU contribution:
€1,5 million per project
Project duration:
Indicatively 24 months
Deadline for submission
14 January 2027