Coordinated preparedness testing and other preparedness actions
EU DIGITAL JU grant for coordinated cybersecurity preparedness testing and actions in critical sectors to enhance resilience and risk management.
This call funds projects that improve cybersecurity preparedness for critical sectors in the EU. It supports coordinated testing, risk assessment, vulnerability monitoring, and training. The goal is to strengthen resilience against cyber threats across member states.
Likely relevant for
- Cybersecurity service providers
- National cybersecurity authorities
- Critical infrastructure operators
- Cybersecurity training organizations
- SMEs in cybersecurity sector
Project signals
What it funds
- Coordinated preparedness testing for high criticality sectors including penetration testing and threat assessment
- Support services for vulnerability testing and risk assessment
- Development and deployment of digital tools for cyber exercises and testing
- Evaluation of cybersecurity capabilities and compliance activities
- Risk monitoring services including supply chain risk management
- Coordinated vulnerability disclosure and management
- Cybersecurity exercises, training courses, and workshops
- Support for onboarding to EU Cybersecurity Core Service Platforms
Expected outcomes
- Enhanced cooperation and cybersecurity resilience in the EU
- Improved threat and risk assessment capabilities
- Better compliance and coordinated vulnerability management
- Improved skills and capacity through training and exercises
- Increased maturity and preparedness of critical sectors and entities
Who can apply / participate
- Public authorities
- Private companies
- Research organizations
- Cybersecurity service providers
- Training organizations
- Check call document for consortium composition rules
- Eligible countries as per call document section 6
- Entities operating in sectors of high criticality and other critical sectors as defined by NIS2 Directive Annexes I and II
- Competent authorities such as CSIRTs, National Cybersecurity Authorities
- Industry stakeholders including ISACs
- Start-ups and SMEs in cybersecurity
- Exact eligibility conditions and consortium requirements must be verified in call document
Must check before shortlisting
- Eligibility criteria per call document section 6
- Specific sector focus per call annexes
- Consortium requirements and funding conditions
Money
Total budget of approximately €15 million for this action in 2026. Individual grants expected around €1.5 million each.
- Total budget for DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP action — 15000000EURBudget for 2026
- Minimum grant per project — 1500000EURFixed minimum contribution
- Maximum grant per project — 1500000EURFixed maximum contribution
Application notes
- Single-stage submission model.
- Proposal page limits and layout as per call document section 5 and application form Part B
- Eligibility conditions detailed in call document section 6
- Financial and operational capacity requirements in call document section 7
- Evaluation and award criteria in call document section 9
- Legal and financial setup described in call document section 10
- Prepare proposal according to call document and application form templates
- Submit proposal via the Funding & Tenders Portal before deadline
- Contact National Cybersecurity Coordination Centres for guidance
- Use provided online manuals and helpdesk for submission support
- Check detailed eligibility and admissibility conditions in call document
- Ensure compliance with sector and geographic eligibility
- Verify consortium composition and funding rules before applying
Derived from official EU Funding portal source · updated 1 Sep 2026, 11:20 UTC. Use this as a shortlisting aid; the official call text remains authoritative.
Official source text
Fine print from the EU source record. Expand when you need the original wording.
Topic description
Expected Outcome: The types of deliverables are presented in two parts. The first part covers: Enhanced cooperation, preparedness and cybersecurity resilience in the EU; preparedness support services. Threat assessment and risk assessment services. The second part covers: Risk monitoring services Better compliance, coordinated vulnerability disclosure and monitoring Improved skills, via exercises and training courses, organisation of events, workshops. Stakeholder consultations and white papers. Objective: This action covers two actions from the Cyber Solidarity Act, dedicated to the Cybersecurity Emergency Mechanism, namely (1) coordinated preparedness testing of entities operating in sectors of high criticality across the Union and (2) other preparedness actions for entities operating in sectors of high criticality and other critical sectors. Objectives These actions aim to complement and not duplicate efforts by Member States and those at Union level to increase the level of protection and resilience to cyber threats, in particular for critical industrial installations and infrastructures, by assisting Member States in their efforts to improve their preparedness for cyber threats and incidents by providing them with knowledge and expertise. Proposals should contribute to achieving at least one of the following objectives: (part 1) Coordinated preparedness testing of entities operating in sectors of high criticality across the Union (including penetration testing and threat assessment) considering ICT as well as Operational Technology/Industrial Control Systems. (part 2) Other preparedness actions for entities operating in sectors of high criticality and other critical sectors (i.e. vulnerability monitoring, exercises and training courses). For details on the actions related to (part 1) and (part 2) covered under the current call for proposals, please consult the Call document accordingly. Scope: [Part 1 Coordinated preparedness testing ] The provision of preparedness support services shall include the activities listed below, for entities in the sector or sub-sector as identified by the Commission in accordance with the Cyber Solidarity Act, from the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555 and specified in the call for proposal document for each of the calls under this topic: Support for testing for potential vulnerabilities: Development of penetration testing scenarios. The proposed scenarios may cover Networks, Applications, Virtualisation solutions, Cloud solutions, Industrial Control systems, and IoT. Support for conducting testing of essential entities operating critical infrastructure for potential vulnerabilities. Support for the deployment of digital tools and infrastructures supporting the execution of testing scenarios and for conducting exercises such as the development of standardised cyber-ranges or other testing facilities, able to mimic features of critical sectors (e.g. energy sector, transport sector, etc.) or others affected by NIS 2 to facilitate the execution of cyber-exercises, in particular within cross-border scenarios where relevant. Evaluation and/or testing of cybersecurity capabilities of MS entities and MS sectors (including capabilities to prevent, detect and respond to incidents and stress test of the entire sectors), evaluation and compliance activities aimed at increasing maturity, e.g. on the basis of established maturity models and/or relevant evaluation and compliance schemes. Evaluation and/or testing of cybersecurity capabilities of entities in scope (including for the evaluation and management of risks concerning the supply chain). Consulting services, providing recommendations on how to improve infrastructure security and capabilities. Support for threat assessment and risk assessment, such as: Threat Assessment process implementation and life cycle Customised risk scenarios analysis. The support will target the competent authorities in the Member States, which play a central role in the implementation of the NIS2 Directive, such as Computer Security Incident Response Teams (CSIRTs) and National Cybersecurity Authorities. [Part 2 other preparedness actions] For the second part, in addition to the services already listed for Part 1 (support for testing for potential vulnerabilities and support for threat assessment and risk management), the provision of preparedness support services included below addresses entities operating in highly critical and other critical sectors as referred to in Annex I and II of the NIS 2 Directive. Support for threat assessment and risk assessment : Supply chain risk management within the risk assessment services. Risk monitoring service: Specific continuous risk monitoring such as attack surface monitoring, risk monitoring of assets and vulnerabilities. Support coordinated vulnerability disclosure and management: Promote the adoption of national CVD Policies [1] and the EU Vulnerability Database. Coordinate the disclosure of vulnerabilities and timely dissemination of security patches. Standardisation of the way information is shared between different stakeholders in the vulnerability handling process. CVD applications that manage multiple sources of vulnerability information using open standards or technologies. (e.g. researchers, vendors, CSIRTs). Raise awareness on the adoption of vulnerability management best practices. Dedicated exercises and training courses: Develop [2] comprehensive training programmes and workshops, including international ones, for cybersecurity professionals that will cover the latest trends in cyber threats, attack methodologies, and best practices for pre-threat management and prevention. Maturity checks, evaluation of cybersecurity capabilities. Encourage the development of cybersecurity continuous learning activities [3] to keep up with all cybersecurity requirements driven by EU cybersecurity-related regulations and directives, including the NIS 2 Directive, CSA, CSoA, DORA, EECC, GDPR, CRA. The support will target the competent authorities in the Member States, which play a central role in the implementation of the NIS2 Directive, Computer Security Incident Response Teams (CSIRTs) including sectorial CSIRTs, Security Operation Centres (SOC)/Cyber Hubs, highly critical and other critical sectors, industry stakeholders (including Information Sharing and Analysis Centres- ISACs) and any other actors within the scope of the NIS 2 Directive, DORA, CSA, etc. Support may be provided, among others, for the on boarding to the CEF Cybersecurity Core Service Platforms of public and private organisations which are working on the implementation of the NIS 2 Directive and are potential users of the CEF Cybersecurity Core Service Platforms. The action may also support industry, with a particular focus on start-ups and SMEs, to seize the industrial and market uptake opportunities created by the Cyber Resilience Act and may support the implementation of the NIS 2 Directive. [1] Coordinated Vulnerability Disclosure Policies in the EU, ENISA, 2022, available at: https://www.enisa.europa.eu/publications/coordinated-vulnerability-disclosure-policies-in-the-eu [2] Based on the European Cybersecurity Skills Framework (ECSF) [3] Based on ECSF: https://www.enisa.europa.eu/topics/education/european-cybersecurity-skills-framework
Conditions and documents
Conditions
1. Admissibility conditions: Proposal page limit and layout
described in section 5 of the call document.
Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.
2. Eligible countries
described in section 6 of the call document.
3. Other eligibility conditions
described in section 6 of the call document.
4. Financial and operational capacity and exclusion
described in section 7 of the call document.
5a. Evaluation and award: Submission and evaluation processes
described section 8 of the call document and the Online Manual.
5b. Evaluation and award: Award criteria, scoring and thresholds
described in section 9 of the call document.
5c. Evaluation and award: Indicative timeline for evaluation and grant agreement
described in section 4 of the call document.
6. Legal and financial set-up of the grants
described in section 10 of the call document.
Call document and annexes:
Application form templates
Standard application form (DEP) — the application form specific to this call is available in the Submission System
Model Grant Agreements (MGA)
Additional documents:
Digital Europe Cybersecurity Work Programme 2025-2027
EU Financial Regulation 2024/2509
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
Support information
For guidance and support related to this call, we recommend that you first contact the National Cybersecurity Coordination Centres (NCC) in your country, where available. The Network of NCCs includes one national centre from each of the 27 EU Member States plus Iceland and Norway. You may also address your questions to the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu Funding & Tenders Portal FAQ – Submission of proposals . IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc. Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and evaluation to reporting on your ongoing project. Valid for all 2021-2027 programmes.
Raw budget overview
{
"budgetYearsColumns": [
"2026"
],
"budgetTopicActionMap": {
"115381": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-REGCABH - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 2,
"minContribution": 2500000,
"maxContribution": 2500000,
"budgetYearMap": {
"2026": "5000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115382": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 10,
"minContribution": 1500000,
"maxContribution": 1500000,
"budgetYearMap": {
"2026": "15000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115383": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-DUALUSE - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 3,
"minContribution": 3000000,
"maxContribution": 5000000,
"budgetYearMap": {
"2026": "10000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115384": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 5,
"minContribution": 3000000,
"maxContribution": 5000000,
"budgetYearMap": {
"2026": "20000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115385": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME - DIGITAL-JU-SME DIGITAL JU SME Support Actions",
"expectedGrants": 5,
"minContribution": 3000000,
"maxContribution": 5000000,
"budgetYearMap": {
"2026": "20000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115386": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 4,
"minContribution": 2000000,
"maxContribution": 3000000,
"budgetYearMap": {
"2026": "11000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
],
"115387": [
{
"action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
"expectedGrants": 4,
"minContribution": 3000000,
"maxContribution": 5000000,
"budgetYearMap": {
"2026": "15000000"
},
"plannedOpeningDate": "2026-09-01",
"deadlineModel": "single-stage",
"deadlineDates": [
"2027-01-14"
]
}
]
}
}