Detalji natječaja:

Coordinated preparedness testing and other preparedness actions (Digital Europe programme)

Official call identifier: DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP

Objective of the call

The call supports two actions under the Cyber Solidarity Act’s Cybersecurity Emergency Mechanism: coordinated preparedness testing of entities operating in sectors of high criticality, and other preparedness actions for entities operating in sectors of high criticality and other critical sectors.

The objective is to complement Member State and EU-level efforts to strengthen protection and resilience against cyber threats, particularly for critical industrial installations and infrastructure, by providing knowledge and expertise that improve preparedness for cyber threats and incidents.

Projects must contribute to at least one of the following:

  • Part 1 – Coordinated preparedness testing: testing of entities operating in sectors of high criticality, including penetration testing and threat assessment covering ICT as well as Operational Technology/Industrial Control Systems.
  • Part 2 – Other preparedness actions: vulnerability monitoring, exercises, training courses and other preparedness activities for highly critical and other critical sectors.

Scope of activities

Part 1 – Coordinated preparedness testing

Part 1 focuses on coordinated preparedness testing in three sectors and sub-sectors identified for this call:

  • Energy: electricity
  • Transport: rail and water/ports
  • Public administration

Proposals under Part 1 must use the common risk scenarios developed for the call and include at least the baseline risk scenario. Applicants may adapt these scenarios to national circumstances and may also include higher-intensity scenarios.

Activities may include:

  • Development and implementation of penetration testing based on the defined risk scenarios
  • Testing essential entities operating critical infrastructure for potential vulnerabilities
  • Deployment of digital tools and infrastructure supporting testing scenarios
  • Development and use of standardised cyber ranges and other testing facilities
  • Cross-border cyber exercises where relevant
  • Evaluation and testing of cybersecurity capabilities to prevent, detect and respond to incidents
  • Sector-wide cyber resilience stress testing
  • Evaluation and management of supply-chain cybersecurity risks
  • Security audits and vulnerability scanning
  • Consulting and recommendations to improve infrastructure security and cybersecurity capabilities
  • Threat-assessment processes and lifecycle implementation
  • Customised risk-scenario analysis

The coordinated testing process should include a Systemic Risk Analysis Phase, a Testing Phase, and a Gap Analysis Phase, leading to identified gaps, recommendations and an action plan for remediation.

Part 2 – Other preparedness actions

Part 2 addresses entities operating in highly critical and other critical sectors referred to in Annexes I and II of the NIS 2 Directive, particularly sectors not selected for coordinated preparedness testing under Part 1.

Activities may include:

  • Threat and risk assessment
  • Supply-chain risk management
  • Continuous risk monitoring, including attack-surface monitoring and monitoring of assets and vulnerabilities
  • Coordinated vulnerability disclosure and management
  • Promotion of national Coordinated Vulnerability Disclosure policies and the EU Vulnerability Database
  • Coordination of vulnerability disclosure and timely dissemination of security patches
  • Development of applications managing vulnerability information from multiple sources using open standards or technologies
  • Awareness raising on vulnerability-management best practices
  • Training programmes and workshops for cybersecurity professionals
  • Cybersecurity exercises and continuous learning activities
  • Activities supporting compliance with cybersecurity requirements arising from EU legislation and directives, including NIS 2, the Cybersecurity Act, Cyber Solidarity Act, DORA, EECC, GDPR and the Cyber Resilience Act.

Eligible applicants

• Innovative SMEs, startups and enterprises aiming to scale and strengthen competitiveness
• Public-sector organisations driving transformation and societal impact
• Research and academic institutions commercialising knowledge
• Non-profit organisations delivering purpose-driven innovation
• Organisations based in EU Member States, EFTA/EEA countries, or Associated Countries as defined in the Horizon Europe General Annexes
• Consortia must include at least the minimum number of independent legal entities from different eligible countries, as specified in the call conditions

For this specific call, eligible beneficiaries and affiliated entities must be legal entities established in EU Member States, including overseas countries and territories, or EEA countries (Norway, Iceland and Liechtenstein). Participation in any capacity is restricted to entities established in and controlled from eligible countries due to the security restrictions applying under Article 12(5) of the Digital Europe Programme Regulation.

For both Part 1 and Part 2, the action primarily targets public bodies designated or entrusted by the relevant Member State with cybersecurity responsibilities, including cybersecurity competent authorities and CSIRTs designated under the NIS 2 Directive. Other relevant public or private partners may participate in the consortium to support implementation. No minimum consortium composition requirement is specified for this topic.

Specific consortium we are looking for:

  • Public body designated or entrusted by a Member State with cybersecurity responsibilities, including a competent cybersecurity authority or CSIRT
  • Cybersecurity testing and penetration-testing expertise capable of supporting vulnerability assessments, security audits and cyber resilience stress testing
  • Threat and risk-assessment expertise covering ICT, Operational Technology and Industrial Control Systems
  • Cyber-range and testing infrastructure providers capable of supporting realistic preparedness exercises and testing scenarios
  • Vulnerability and risk-monitoring specialists supporting attack-surface, asset and vulnerability monitoring
  • Coordinated vulnerability disclosure expertise supporting vulnerability management and information exchange
  • Cybersecurity training and exercise providers capable of delivering training programmes, workshops and continuous learning activities
  • Other relevant public or private partners supporting the implementation of national preparedness activities

Eligible costs

Eligible costs may include:

  • Personnel costs
  • Subcontracting costs
  • Travel and subsistence
  • Equipment
  • Other goods, works and services
  • Internally invoiced goods and services
  • Indirect costs calculated at 7% of eligible direct costs
  • Equipment costs based on depreciation, with full-cost reimbursement possible for listed equipment under the conditions of the call

Funding conditions

Type of action: 
DIGITAL JU Simple Grants

Funding rate: 
50% funding rate

EU indicative budget: 
Around EUR 15,000,000 

Expected EU contribution: 
€1,5 million per project

Project duration: 
Indicatively 24 months

Deadline for submission

14 January 2027

Otvoren
Veličina poduzeća: SMEs, Startups, Public-sector organisations, Enterprises, Research, Academia
Objavljuje: European Cybersecurity Competence Centre
Područje: Cybersecurity, AI
Vrsta natječaja: DIGITAL JU Simple Grants
Visina sufinanciranja: Up to 50%
Datum objave: 1 September 2026
Rok za predaju: 14 January 2027

Trebate li našu pomoć prilikom pridobivanja sredstava?

Kontaktirajte nas