Detalji natječaja:

Strengthening EU cybersecurity capacities & capabilities in line with legislative requirements (Digital Europe programme)

Objective of the call

The objective of this action is to strengthen the European cybersecurity ecosystem and support the effective and homogeneous implementation of EU cybersecurity legislation, including:

  • Cyber Resilience Act (CRA)
  • NIS 2 Directive
  • GDPR
  • DORA
  • Cybersecurity Act
  • Specific requirements under the AI Act

The action also aligns with the Digital Education Action Plan and the Cybersecurity Skills Academy, aiming to reduce the cybersecurity skills gap, promote diversity and strengthen Europe’s digital resilience.

It supports both regulatory compliance and operational maturity across public and private sectors, ensuring higher cybersecurity levels across Member States.

Scope of activities

Projects must support the implementation of one or more pieces of EU cybersecurity legislation and contribute to increasing cybersecurity maturity across sectors.

Activities may include:

1. Regulatory compliance support

  • Development of practical guidelines, manuals and standardised processes to support compliance with CRA, NIS 2, Cybersecurity Act, DORA, GDPR and AI Act requirements
  • Development of user-friendly compliance tools for SMEs, including self-assessment tools
  • Tools enabling conformity assessment of products with digital elements under the CRA
  • Support for Software Bill of Materials (SBOM) implementation
  • Development of NIS 2 incident reporting platforms
  • Development of CRA vulnerability single reporting platforms
  • Establishment of single entry points for incident notification

2. Certification and conformity assessment capacity building

  • Capacity building for national cybersecurity certification authorities
  • Support to conformity assessment bodies and certification laboratories
  • Development of a “Certification and Evaluation as a Service” platform
  • Harmonisation and digitalisation of certification documentation
  • Development of common methodologies for cross-border recognition
  • Support for market surveillance authorities

The action should streamline documentation processes, facilitate mutual recognition and accelerate secure assessment replication across Member States.

3. Skills development and workforce capacity

  • Development of cybersecurity training programmes aligned with the European Cybersecurity Skills Framework (ECSF)
  • Hands-on training, exercises and cybersecurity challenges
  • Cross-border exchange, fellowship and peer-learning programmes
  • Non-formal education initiatives targeting students and teachers
  • Diversity and equal opportunity programmes
  • Support for pan-European teams participating in international cybersecurity competitions

Training programmes should enhance regulatory understanding, audit readiness and operational capabilities.

4. Information sharing and cooperation

  • Creation of secure communication channels
  • Federated national platforms for cyber threat intelligence (CTI)
  • Vertical (sector-specific) information-sharing platforms
  • EU-level cross-border collaboration mechanisms
  • Support for structured cooperation between authorities and stakeholders
  • Development of common methodologies to improve cybersecurity maturity

5. Privacy-enhancing and security-by-design technologies

Projects should promote privacy and security by design in ICT products, IoT, Operational Technology, identity systems and e-government systems.

Activities may include:

  • Support for commercialisation of privacy-enhancing technologies (PETs)
  • Pilot projects testing CRA compliance
  • Development of open-source conformity assessment tools
  • Development of assessment methodologies for CRA compliance
  • Cooperation frameworks between researchers, providers, integrators and regulators
  • Support for early integration of privacy-enhancing technologies during design and development

Consortia should include representatives from across the value chain:

  • Privacy-enhancing technology researchers
  • Technology providers
  • ICT product developers
  • User organisations
  • Regulatory and supervisory authorities

Expected Deliverables:

One or more of the following should be covered:

• Implementation of guidelines, standardised processes, or manuals – in the EU or multiple EU MS – concerning the most challenging issues, supporting specific stakeholders and sectors addressed by cybersecurity legislation.

• Develop and implement tools, raise awareness and encourage and facilitate industry uptake, with a focus on SMEs, of conformity assessments of essential cybersecurity requirements for products with digital elements (hardware and software) under the CRA.

• Support for mechanisms reducing the administrative burden for entities, like single entry point for incident notification.

• Establish secure communication channels allowing for cooperation and information sharing initiatives.

• Support the organisation of regular meetings/workshops to identify good practices within specific sectors or emerging areas and facilitate collaborative efforts between different sectors.

• Support the development of training courses, on the basis of the ECSF and exercises that promote capacity building and internal awareness.

• Contribution to CR standardisation: Training materials and training actions on cybersecurity certification for national authorities and conformity assessment bodies.

• Fostering certification: Educational and supporting materials and an explanatory press campaign using interactive material such as ‘Do I comply with CRA?’. Information campaign through various channels such as conferences, meetings, etc. Website dedicated to the mandatory certification and conformity assessments of essential requirements.

• Development of training programmes and materials, including tools for cross-country collaboration and exchange, aimed at enhancing participants’ skills and readiness for real-world threats. These programmes can also support non-formal education for high school students and teachers, enhancing digital literacy and cybersecurity awareness at early educational levels.

• Creation of benchmarking and assessment programmes to evaluate and optimise the performance of participants in cybersecurity training programmes, ensuring continuous improvement and alignment with industry standards.

• Implement peer exchange and fellowship programmes, aimed at fostering a connected, resilient community of cybersecurity professionals across Europe. These programmes will also include support for cross-border training initiatives and non formal education activities, ensuring that both students and educators can participate in hands-on cybersecurity learning experiences and contribute to long-term talent development.

• Establishment of cross-border collaboration programmes to support the development of pan-European teams in cybersecurity competitions. These programmes will provide access to mentorship, advanced tools, and leadership training, ensuring European teams remain competitive on the global stage. Additionally, the programmes will foster the growth of a European cybersecurity leadership pipeline, enhancing Europe’s visibility and effectiveness in international cybersecurity challenges.

• Support organisations, including SMEs, in assessing the robustness, applicability and relevance of security- and privacy-enhancing technologies to be integrated in the ICT products and services they develop.

• Set-up pilot projects to test CRA compliance, use open-source software and libraries for conformity assessment and testing; develop assessment methodologies for the purpose of CRA compliance/requirements.

• Develop best practices or guidelines for setting-up and operating market surveillance authorities in MSs; develop awareness of CRA requirements.

• Support organisations, including SMEs, in commercialising privacy-enhancing technologies and demonstrate how they can address security and privacy risks from emerging technologies.

• Facilitate cooperation between the producers of emerging technologies, the users of those technologies and regulators. Such cooperation would make it possible to identify which requirements can be met by which privacy-enhancing technology, in which use cases, to what extent they could facilitate compliance or reduce the cost 66 thereof, and how to engineer it in practice, during the early phases of design and development of ICT products and services.

• Strengthen cooperation in the whole privacy-enhancing technology value chain, including between researchers, providers, integrators and users, and GDPR national authorities/European supervisors.

Eligible applicants

  • Innovative SMEs, startups and enterprises aiming to scale and strengthen competitiveness 
  • Public-sector organisations driving transformation and societal impact 
  • Research and academic institutions commercialising knowledge 
  • Non-profit organisations delivering purpose-driven innovation 
  • Organisations based in EU Member States, EFTA/EEA, or Associated Countries (more info on eligible countries will be published soon)
  • Minimum 3 independent partners from 3 eligible countries

Funding conditions

Type of action: 
Simple grant 

Funding rate: 
50%

Indicative budget 
€32 million 

Deadline for submission

Q1 2027

U najavi
Veličina poduzeća: SMEs, Startups, Public-sector organisations, Enterprises, Research, Academia
Objavljuje: European Health and Digital Executive Agency
Područje: Cybersecurity
Vrsta natječaja: Simple grant
Visina sufinanciranja: 50%
Datum objave: Q4 2026
Rok za predaju: Q1 2027

Trebate li našu pomoć prilikom pridobivanja sredstava?

Kontaktirajte nas