Loading…
Strategic Analysis
A winning proposal under DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP must establish an operationally robust, cross-border preparedness framework that bridges standard cyber-range testing facilities with real-world critical infrastructure operators covered by the NIS 2 Directive and Cyber Solidarity Act. Success hinges on demonstrating concrete deployment of advanced penetration testing, supply chain vulnerability evaluations, and standardized Coordinated Vulnerability Disclosure (CVD) mechanisms that yield immediate, measurable resilience gains for essential entities.
TRL 6 → 8
Based on programme defaults
Development of penetration testing scenarios. The proposed scenarios may cover Networks, Applications, Virtualisation solutions, Cloud solutions, Industrial Control systems, and IoT.
Support for conducting testing of essential entities operating critical infrastructure for potential vulnerabilities.
Support for the deployment of digital tools and infrastructures supporting the execution of testing scenarios and for conducting exercises such as the development of standardised cyber-ranges or other testing facilities, able to mimic features of critical sectors (e.g. energy sector, transport sector, etc.) or others affected by NIS 2 to facilitate the execution of cyber-exercises, in particular within cross-border scenarios where relevant.
Evaluation and/or testing of cybersecurity capabilities of MS entities and MS sectors (including capabilities to prevent, detect and respond to incidents and stress test of the entire sectors), evaluation and compliance activities aimed at increasing maturity, e.g. on the basis of established maturity models and/or relevant evaluation and compliance schemes.
Evaluation and/or testing of cybersecurity capabilities of entities in scope (including for the evaluation and management of risks concerning the supply chain).
Consulting services, providing recommendations on how to improve infrastructure security and capabilities.
Threat Assessment process implementation and life cycle
Customised risk scenarios analysis.
Supply chain risk management within the risk assessment services.
Specific continuous risk monitoring such as attack surface monitoring, risk monitoring of assets and vulnerabilities.
Promote the adoption of national CVD Policies [1] and the EU Vulnerability Database.
Coordinate the disclosure of vulnerabilities and timely dissemination of security patches. Standardisation of the way information is shared between different stakeholders in the vulnerability handling process.
CVD applications that manage multiple sources of vulnerability information using open standards or technologies. (e.g. researchers, vendors, CSIRTs).
Raise awareness on the adoption of vulnerability management best practices.
Develop [2] comprehensive training programmes and workshops, including international ones, for cybersecurity professionals that will cover the latest trends in cyber threats, attack methodologies, and best practices for pre-threat management and prevention. Maturity checks, evaluation of cybersecurity capabilities.
Encourage the development of cybersecurity continuous learning activities [3] to keep up with all cybersecurity requirements driven by EU cybersecurity-related regulations and directives, including the NIS 2 Directive, CSA, CSoA, DORA, EECC, GDPR, CRA.
Enhanced cooperation, preparedness and cybersecurity resilience in the EU; preparedness support services.
Threat assessment and risk assessment services.
Risk monitoring services
Better compliance, coordinated vulnerability disclosure and monitoring
Improved skills, via exercises and training courses, organisation of events, workshops. Stakeholder consultations and white papers.
No expected impacts identified for this destination.
Cyber Solidarity Act
highThe Cyber Solidarity Act aims to strengthen operational capacities in the EU to detect, prepare for, and respond to significant and large-scale cybersecurity threats and incidents.
It establishes a European Cybersecurity Alert System and a Cybersecurity Emergency Mechanism supporting preparedness testing and incident response cooperation across Member States.
Evaluators expect proposals to align directly with the Cybersecurity Emergency Mechanism objectives, demonstrating robust coordinated preparedness testing methodologies, cross-border incident response exercises, and support for critical entities across the Union.
Directive (EU) 2022/2555 (NIS 2 Directive)
highThe NIS 2 Directive modernizes the EU legal framework to elevate cybersecurity resilience across essential and important entities covering critical infrastructure, supply chains, and incident reporting.
It mandates risk management measures, vulnerability handling, and strengthened supervision and enforcement across public and private sectors.
Evaluators expect actions to target sectors defined under NIS 2, integrating its security requirements and incident-reporting benchmarks into preparedness testing, audits, and operational resilience roadmaps.
Cybersecurity Act (CSA)
mediumThe Cybersecurity Act (Regulation (EU) 2019/881) establishes a permanent mandate for ENISA and creates a common EU-wide framework for cybersecurity certification of ICT products, services, and processes.
It aims to enhance trust and security in the digital single market by standardizing cybersecurity capabilities and evaluation criteria.
Evaluators look for alignment with ENISA guidance, integration of EU cybersecurity certification frameworks, and structured approaches to evaluating the security posture of digital products and infrastructures.
Digital Operational Resilience Act (DORA)
mediumDORA (Regulation (EU) 2022/2554) establishes uniform cybersecurity requirements for the financial sector, ensuring financial entities can withstand, respond to, and recover from ICT-related disruptions.
It mandates digital operational resilience testing, including advanced threat-led penetration testing (TLPT) and ICT third-party risk management.
Evaluators expect proposals involving financial entities to incorporate advanced operational resilience testing protocols and methodologies consistent with DORA requirements and TLPT frameworks.
General Data Protection Regulation (GDPR)
mediumGDPR sets strict guidelines for data privacy and protection, particularly for vulnerable populations such as children. It mandates transparency, consent, and security in data processing.
Proposals must demonstrate compliance with GDPR, especially when collecting and processing data from children and young adults. Evaluators will prioritize projects that incorporate privacy-by-design principles and ensure ethical data handling.
Cyber Resilience Act (CRA)
mediumThe Cyber Resilience Act introduces EU-wide common cybersecurity requirements for hardware and software products placed on the European market throughout their whole lifecycle.
It obliges manufacturers to ensure vulnerability management, security-by-design, and timely security updates for digital products.
Evaluators expect proposals to reflect CRA security-by-design baseline standards and lifecycle vulnerability handling practices when executing preparedness and penetration testing across digital systems.
European Cybersecurity Skills Framework (ECSF)
mediumDeveloped by ENISA, the European Cybersecurity Skills Framework outlines core profiles, competencies, and skills required by cybersecurity professionals.
It provides a common language to bridge the cybersecurity skills shortage, structure professional training, and standardize role profiles across the EU.
Evaluators expect preparedness training, capacity building, and testing exercises to align skill definitions and role expectations with recognized ECSF profiles and competencies.
European Electronic Communications Code (EECC)
lowThe EECC (Directive (EU) 2018/1972) updates the regulatory framework for telecommunications networks and services across the EU.
It includes requirements for telecom providers to take appropriate security measures to manage risks to the security of networks and services and report major security incidents.
Evaluators expect proposals touching electronic communications infrastructure to account for EECC security requirements and ensure robust network integrity and incident-reporting procedures during preparedness actions.
">
described in section 5 of the call document.
Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.
described in section 6 of the call document.
described in section 6 of the call document.
described in section 7 of the call document.
described section 8 of the call document and the Online Manual.
described in section 9 of the call document.
described in section 4 of the call document.
described in section 10 of the call document.
Application form templates
Standard application form (DEP) — the application form specific to this call is available in the Submission System
Model Grant Agreements (MGA)
Digital Europe Cybersecurity Work Programme 2025-2027
EU Financial Regulation 2024/2509
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
Evaluators will prioritize proposals that move beyond conceptual methodologies to deliver tangible, operational deployment of testing tools, standardized cyber ranges, and structured CVD workflows across cross-border critical sectors (e.g., energy, transport, health). They will closely assess direct engagement with essential entities, clear alignment with EU regulatory frameworks (NIS 2, CRA, DORA), and practical integration with national CSIRTs and the EU Vulnerability Database.
Everything the call asks for, seen from the call's point of view. Each line shows what answers it, and which partner carries it.
This matrix lists everything the call asks for: outcomes, impacts, scope, the requirements buried in the call text, and policy alignment. Sign up free and GrantForge tracks each line against the concept you build.
| Requirement | Covered by | Carried | Status |
|---|---|---|---|
| Scope activities | |||
| SC1Development of penetration testing scenarios. The proposed scenarios may cover Networks, Applications, Virtualisation solutions, Cloud solutions, Industrial Control systems, and IoT. | · | · | Sign up to track |
| SC2Support for conducting testing of essential entities operating critical infrastructure for potential vulnerabilities. | · | · | Sign up to track |
| SC3Support for the deployment of digital tools and infrastructures supporting the execution of testing scenarios and for conducting exercises such as the development of standardised cyber-ranges or other testing facilities, able to mimic features of critical sectors (e.g. energy sector, transport sector, etc.) or others affected by NIS 2 to facilitate the execution of cyber-exercises, in particular within cross-border scenarios where relevant. | · | · | Sign up to track |
| SC4Evaluation and/or testing of cybersecurity capabilities of MS entities and MS sectors (including capabilities to prevent, detect and respond to incidents and stress test of the entire sectors), evaluation and compliance activities aimed at increasing maturity, e.g. on the basis of established maturity models and/or relevant evaluation and compliance schemes. | · | · | Sign up to track |
| SC5Evaluation and/or testing of cybersecurity capabilities of entities in scope (including for the evaluation and management of risks concerning the supply chain). | · | · | Sign up to track |
| SC6Consulting services, providing recommendations on how to improve infrastructure security and capabilities. | · | · | Sign up to track |
| SC7Threat Assessment process implementation and life cycle | · | · | Sign up to track |
| SC8Customised risk scenarios analysis. | · | · | Sign up to track |
| SC9Supply chain risk management within the risk assessment services. | · | · | Sign up to track |
| SC10Specific continuous risk monitoring such as attack surface monitoring, risk monitoring of assets and vulnerabilities. | · | · | Sign up to track |
| SC11Promote the adoption of national CVD Policies [1] and the EU Vulnerability Database. | · | · | Sign up to track |
| SC12Coordinate the disclosure of vulnerabilities and timely dissemination of security patches. Standardisation of the way information is shared between different stakeholders in the vulnerability handling process. | · | · | Sign up to track |
| SC13CVD applications that manage multiple sources of vulnerability information using open standards or technologies. (e.g. researchers, vendors, CSIRTs). | · | · | Sign up to track |
| SC14Raise awareness on the adoption of vulnerability management best practices. | · | · | Sign up to track |
| SC15Develop [2] comprehensive training programmes and workshops, including international ones, for cybersecurity professionals that will cover the latest trends in cyber threats, attack methodologies, and best practices for pre-threat management and prevention. Maturity checks, evaluation of cybersecurity capabilities. | · | · | Sign up to track |
| SC16Encourage the development of cybersecurity continuous learning activities [3] to keep up with all cybersecurity requirements driven by EU cybersecurity-related regulations and directives, including the NIS 2 Directive, CSA, CSoA, DORA, EECC, GDPR, CRA. | · | · | Sign up to track |
| Expected outcomes | |||
| EO1Enhanced cooperation, preparedness and cybersecurity resilience in the EU; preparedness support services. | · | · | Sign up to track |
| EO2Threat assessment and risk assessment services. | · | · | Sign up to track |
| EO3Risk monitoring services | · | · | Sign up to track |
| EO4Better compliance, coordinated vulnerability disclosure and monitoring | · | · | Sign up to track |
| EO5Improved skills, via exercises and training courses, organisation of events, workshops. Stakeholder consultations and white papers. | · | · | Sign up to track |
| Other requirements | |||
| REQ1Direct support for competent authorities, national CSIRTs, and National Cybersecurity AuthoritiesSupport will target the competent authorities in the Member States that play a central role in the implementation of the NIS 2 Directive, such as Computer Security Incident Response Teams (CSIRTs) and National Cybersecurity Authorities. | · | · | Sign up to track |
| REQ2Promotion and integration with the EU Vulnerability DatabaseActions must promote the adoption of national CVD Policies and integrate with the EU Vulnerability Database to coordinate vulnerability disclosure and patch dissemination. | · | · | Sign up to track |
| REQ3Multi-stakeholder vulnerability information sharing using open standards or technologiesStandardisation of how information is shared between different stakeholders in the vulnerability handling process and the use of CVD applications managing multiple vulnerability information sources (e.g. researchers, vendors, CSIRTs) via open standards or technologies. | · | · | Sign up to track |
| REQ4International training programmes and workshops for cybersecurity professionalsProposals are expected to develop comprehensive training programmes and workshops, including international ones, covering trends in cyber threats, attack methodologies, and best practices for pre-threat management and prevention. | · | · | Sign up to track |
| Expected impacts | |||
| No expected impacts in this call. | |||
| Underlying policies | |||
| POL1cyber solidarity actThe Cyber Solidarity Act aims to strengthen operational capacities in the EU to detect, prepare for, and respond to significant and large-scale cybersecurity threats and incidents. It establishes a European Cybersecurity Alert System and a Cybersecurity Emergency Mechanism supporting preparedness testing and incident response cooperation across Member States. | · | · | Sign up to track |
| POL2directive (eu) 2022/2555 (nis 2 directive)The NIS 2 Directive modernizes the EU legal framework to elevate cybersecurity resilience across essential and important entities covering critical infrastructure, supply chains, and incident reporting. It mandates risk management measures, vulnerability handling, and strengthened supervision and enforcement across public and private sectors. | · | · | Sign up to track |
The binding rules of this call. Items marked auto are verified by GrantForge from the call and the template. The others are yours to confirm.
4 key insights you must internalise before writing. Each is grounded in the call text and tells you what evaluators will actually look for. Share these with your consortium before drafting.
Evaluators are explicitly instructed to prioritize proposals that deliver tangible, operational deployment of testing tools and standardized cyber ranges. Proposals focusing merely on conceptual methodologies or theoretical frameworks will be penalized. You must demonstrate concrete execution across cross-border critical sectors such as energy, transport, or health.
Source: Evaluation criteria (pre-award)
Your consortium or stakeholder network must include direct participation from essential entities (critical infrastructure operators) and national CSIRTs. The evaluation explicitly assesses this direct engagement and the practical integration of your workflows with national CSIRTs and the EU Vulnerability Database.
Source: Evaluation criteria (pre-award)
Success in this call requires clear, demonstrable alignment with specific EU regulatory frameworks. Evaluators will closely assess how your preparedness testing, supply chain evaluations, and continuous learning activities integrate the requirements of the NIS 2 Directive, Cyber Resilience Act (CRA), and DORA.
Source: Underlying policies
Beyond penetration testing, the scope mandates the operationalization of Coordinated Vulnerability Disclosure (CVD) mechanisms. Proposals must include the deployment of CVD applications using open standards and ensure practical integration with the EU Vulnerability Database to facilitate timely security patch dissemination.
Source: Scope / Expected Outcomes
Talk to the Grant Coach to build your concept. There is no set order: start wherever your project starts. The sections below mirror what the conversation produces, and your coverage tracks the progress. You can refine everything once your project workspace is created.
The problems this call frames, and who they affect. Your concept and plan address them.
Critical infrastructure operators lack access to standardized, high-fidelity cyber-range environments that accurately simulate sector-specific (ICS/SCADA, IoT, Cloud) interdependencies across national borders.
Essential entities face systemic exposure to third-party digital component vulnerabilities without systematic continuous monitoring tools or standardized risk assessment schemes.
Inconsistent adoption of Coordinated Vulnerability Disclosure (CVD) mechanisms across Member States delays critical patch deployment and weakens integration with the EU Vulnerability Database.
Operators of essential services and critical infrastructures (energy grids, transport hubs, healthcare networks) requiring technical vulnerability testing, continuous risk monitoring, and compliance evaluation.
Member State cybersecurity authorities and computer security incident response teams facilitating coordinated vulnerability disclosure and sectoral stress-testing.
Hardware, software, and industrial automation providers whose component vulnerabilities directly impact downstream critical infrastructure resilience.
European businesses and citizens who rely on uninterrupted, secure vital services such as electricity, public transit, and emergency healthcare.
The long-term impacts your project should drive, and the policies they serve.
Substantial decrease in security incidents and breach vulnerabilities across critical infrastructure through structured testing and threat assessment protocols.
Uplift in operational cybersecurity skill proficiencies and preparedness exercise readiness among critical sector personnel mapped to the European Cybersecurity Skills Framework.
Harmonized uptake of CVD policies and continuous attack surface monitoring across Member States ensuring continuity of vital societal functions.