DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI

Cybersecure tools, technologies and services relying on AI

Status
open for submission
Programme
Digital Europe Programme (DIGITAL)
Action type
DIGITAL JU Simple Grants
Opens
1 Sep 2026
Deadline
14 Jan 2027
Fetched
5 Sep 2026, 00:32 UTC
Plain-language summary

Funding for AI-powered cybersecurity tools and services to support Cyber Hubs, CSIRTs, and NIS authorities in Europe.

This call supports the development and deployment of AI-based cybersecurity technologies for national and cross-border Cyber Hubs and authorities. It aims to enhance threat detection, incident response, and secure AI solutions compliant with EU legislation. Projects should focus on trustworthy, robust AI tools that improve cybersecurity operations and collaboration.

Likely relevant for

  • Cybersecurity technology developers
  • AI and machine learning researchers
  • National and cross-border Cyber Hubs
  • CSIRTs and NIS authorities
  • Cybersecurity service providers
  • SMEs in cybersecurity and AI

Project signals

Development of AI-powered cybersecurity solutionsFocus on threat detection, vulnerability management, incident responseCompliance with GDPR, AI Act, and cybersecurity certificationCollaboration with national authorities and Cyber Hubs

What it funds

  • Development and deployment of AI-based cybersecurity tools and services
  • Enhancement of Cyber Threat Intelligence (CTI) creation and analysis
  • Automation of cybersecurity processes and incident response
  • Secure AI solutions compliant with EU legislation and standards
  • Tools for vulnerability detection, malware mitigation, and self-healing recovery
  • Support for cybersecurity certification and standardisation of AI technologies

Expected outcomes

  • AI-powered cybersecurity tools available to Cyber Hubs, CSIRTs, and NIS authorities
  • Improved information sharing and collaboration among cybersecurity stakeholders
  • Enhanced detection and mitigation of cyber threats using AI
  • Secure and trustworthy AI solutions mitigating risks of misuse
  • Contribution to EU cybersecurity certification and standardisation efforts

Who can apply / participate

  • Private companies
  • Research organizations
  • Public bodies
  • Consortia including Cyber Hubs and tool providers
  • Consortia encouraged, including Cyber Hubs and AI tool providers
  • Links with High-Performance Computing stakeholders recommended
  • Applicants from EU Member States and associated countries as per call document
  • Must comply with eligibility conditions in call document section 6
  • Proposals must align with NIS 2 directive and national strategies where applicable
  • Exact eligible countries and consortium size must be verified in call document

Must check before shortlisting

  • Eligibility criteria in call document section 6
  • Consortium composition and funding rules
  • Specific budget and grant size per action
  • Compliance with EU legislation on AI and data protection

Money

Total budget of approximately €15 million for this action in 2026, with individual grants ranging from €3 million to €5 million.

  • Total budget for DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI action — 15000000EUR
    Budget planned for 2026
  • Minimum grant per project — 3000000EUR
    Minimum funding per grant
  • Maximum grant per project — 5000000EUR
    Maximum funding per grant

Application notes

  • Single-stage submission model.
  • Proposal page limits and layout as per call document section 5 and application form Part B.
  • Eligibility conditions detailed in call document section 6.
  • Financial and operational capacity requirements in call document section 7.
  • Evaluation and award criteria in call document sections 8 and 9.
  • Legal and financial setup described in call document section 10.
  • Prepare proposal according to call document and application form templates.
  • Submit proposal via the Funding & Tenders Portal by the deadline.
  • Contact National Cybersecurity Coordination Centres or ECCC Applicants Direct Contact Centre for support.
  • Check eligibility and consortium requirements carefully.
  • Ensure compliance with EU legislation on AI, GDPR, and cybersecurity.
  • Verify budget and grant size limits before applying.

Derived from official EU Funding portal source · updated 1 Sep 2026, 11:20 UTC. Use this as a shortlisting aid; the official call text remains authoritative.

Official source text

Fine print from the EU source record. Expand when you need the original wording.

Topic description

Expected Outcome: Deployment of Artificial Intelligence and various AI-powered technologies as enablers for Cyber Hubs, CSIRTs, NCSCs, NIS SPOCs and others. Novel cybersecurity tools based on AI that have been developed, tested and validated in relevant conditions and made available to Cyber Hubs, CSIRTs, NCSCs, NIS SPOCs and others. Enhanced information sharing and collaboration amongst National and Cross-Border Cyber Hubs, CSIRTs, NCSCs, NIS SPOCs and others relevant stakeholders, supported by CTI produced by AI-powered tools. Tools for automation of cybersecurity processes such as the creation, analysis and processing of CTI, to enhance operations of the Cyber Hubs. Original European CTI feeds or services. Ensure that the most advanced and innovative secure AI solutions are developed and implemented for NIS sectors. Secure AI solutions and tools, complying with EU legislation. Promote the mitigation of risks associated with the misuse of AI by malicious actors, with a focus on AI ethics and secure deployment. Contribution to the standardisation and certification of cybersecure, trustworthy AI technologies. Objective: This topic addresses AI-based technologies (including GenAI) for national authorities and competent authorities, including National and Cross-Border Cyber Hubs, CSIRTs, public bodies and private entities from the NIS 2 directive, NCCs [1], etc. They play a key role in providing central operational capacity to European cybersecurity ecosystems. They may also provide primary input data for AI/ML-based cybersecurity tools and solutions, which can strengthen such authorities’ capacity to analyse, detect and prevent cyber threats and incidents, and to support the production of high-quality intelligence on cyber threats. In particular, the adoption of generative AI [2] could be a challenge and an opportunity for cybersecurity [3] processes and applications. These enabling technologies should allow for more effective creation and analysis of Cyber Threat Intelligence (CTI), automation of large-scale processes, as well as faster and scalable processing of CTI and identification of patterns that allow for rapid detection and decision making. The security of AI itself, especially for the systems in the learning phase, also needs to be addressed, including the misuse of AI by malicious actors. This includes carrying out risk assessments and mitigation of cybersecurity risks inherent to AI technologies, implementing supply chain security, etc., and complying with the AI Act, intellectual property legislation and the GDPR. In addition to being secure, the AI technologies being developed should perform well, and be robust and trustworthy. In particular, having trustworthy AI solutions will help in the deployment phase, where social acceptance is essential. [1] If applicable and in line with individual national strategies. [2] Cybersecurity in the age of generative AI, September 2023, available at: https://www.mckinsey.com/featured insights/themes/cybersecurity-in-the-age-of-generative-ai. [3] The Need For AI-Powered Cybersecurity to Tackle AI-Driven Cyberattacks, April 2024, available at: https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2024/the-need-for-ai-powered cybersecurity-to-tackle-ai-driven-cyberattacks. Scope: Actions in this topic should develop and deploy systems and tools for cybersecurity[1], based on AI technologies[2], addressing aspects such as threat detection, vulnerability detection, threat mitigation, incident recovery through self-healing, data analysis and data sharing. These activities must also comply with intellectual property rights (IPR) and the GDPR, depending on the type of information handled. The AI solutions proposed should also be cybersecure. Activities should include at least one of the following: Continuous detection of patterns and identification of anomalies that can potentially indicate emerging threats, recognising new attack vectors and enabling advanced detection in an evolving threat landscape, including in ICT or in Operational Technology infrastructures using open technologies. Creation of CTI based on novel threat detection capabilities Enhancing speed of incident response through real-time monitoring of networks to identify security incidents and generating alerts or triggering automated responses. Mitigating malware threats by analysing code behaviour, network traffic, and file characteristics, reducing the window of opportunity for attackers to exploit malware. Identification of vulnerabilities and support for management considering multiple sources of information. Cybersecure tools and solutions that provide risk-reduction in the crossover between AI, IoT and smart grids or other manufacturing chains. Support for recovery from incidents through self-healing capacities. Reducing the chances of attacks and pre-emptively identifying weaknesses through automated vulnerability scanning and penetration testing. Protecting business sensitive data through the analysis of access patterns and detection of abnormal behaviour. Enabling organisations to leverage and share CTI and other actionable information for analysis and insights without compromising data security and privacy, through anonymisation. Tools and solutions that provide product security or cybersecurity by design/default in line with CRA requirements. Tool and service providers are welcome to apply for this topic, also when in a consortium with Cyber Hubs. Links with stakeholders in the area of High-Performance Computing should be made where appropriate, as well as activities to foster networking with such stakeholders. In well justified cases, access requests to the EuroHPC high performance computing infrastructure could be granted. The systems, tools and services developed under this topic will be made available for licensing to National and/or Cross-Border Cyber Hubs platforms, CSIRTs, competent authorities, and other relevant authorities under favourable market conditions. These actions aim at providing AI-powered cybersecurity capabilities for National and/or Cross-Border Cyber Hubs and for national authorities encompassing Cyber Hubs, CSIRTs, which occupy a central role in ensuring the cybersecurity of national authorities, providers of critical infrastructures and essential services. These entities are tasked with monitoring, understanding and proactively managing cybersecurity threats. In light of their crucial operative role in ensuring cybersecurity in the Union, the nature of the technologies involved as well as the sensitivity of the information handled, Cyber Hubs must be protected against possible dependencies and vulnerabilities in cybersecurity to pre-empt foreign influence and control. Tools to protect and secure AI solutions in line with the EU legislative framework and considering integration of requirements for robustness, performance, trust and balanced AI autonomy. Contribute to the cybersecurity certification of AI-driven cybersecurity solutions and systems. The primary objective of cybersecurity certification for AI systems within the EU is twofold: to mitigate cybersecurity risks inherent in AI technologies and to demonstrate compliance with the EU’s comprehensive legislative framework, including the AI Act. By establishing a standardised, transparent, and rigorous certification process, the EU seeks to foster trust in AI technologies among users, developers, and regulators alike. [1] Multilayer Framework for Good Cybersecurity Practices for AI, ENISA, June 2023, available at: https://www.enisa.europa.eu/publications/multilayer-framework-for-good-cybersecurity-practices-for-ai. [2] Cybersecurity of AI and Standardisation, ENISA, March 2023, available at: https://www.enisa.europa.eu/publications/cybersecurity-of-ai-and-standardisation .

Conditions and documents

Conditions

1. Admissibility conditions: Proposal page limit and layout

described in section 5 of the call document.

Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.

2. Eligible countries

described in section 6 of the call document.

3. Other eligibility conditions

described in section 6 of the call document.

4. Financial and operational capacity and exclusion

described in section 7 of the call document.

5a. Evaluation and award: Submission and evaluation processes

described section 8 of the call document and the Online Manual.

5b. Evaluation and award: Award criteria, scoring and thresholds

described in section 9 of the call document.

5c. Evaluation and award: Indicative timeline for evaluation and grant agreement

described in section 4 of the call document.

6. Legal and financial set-up of the grants

described in section 10 of the call document.

Support information

For guidance and support related to this call, we recommend that you first contact the National Cybersecurity Coordination Centres (NCC) in your country, where available. The Network of NCCs includes one national centre from each of the 27 EU Member States plus Iceland and Norway. You may also address your questions to the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu Funding & Tenders Portal FAQ – Submission of proposals . IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc. Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and evaluation to reporting on your ongoing project. Valid for all 2021-2027 programmes.

Raw budget overview
{
  "budgetYearsColumns": [
    "2026"
  ],
  "budgetTopicActionMap": {
    "115381": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-REGCABH - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 2,
        "minContribution": 2500000,
        "maxContribution": 2500000,
        "budgetYearMap": {
          "2026": "5000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115382": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 10,
        "minContribution": 1500000,
        "maxContribution": 1500000,
        "budgetYearMap": {
          "2026": "15000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115383": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-DUALUSE - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 3,
        "minContribution": 3000000,
        "maxContribution": 5000000,
        "budgetYearMap": {
          "2026": "10000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115384": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 5,
        "minContribution": 3000000,
        "maxContribution": 5000000,
        "budgetYearMap": {
          "2026": "20000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115385": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME - DIGITAL-JU-SME DIGITAL JU SME Support Actions",
        "expectedGrants": 5,
        "minContribution": 3000000,
        "maxContribution": 5000000,
        "budgetYearMap": {
          "2026": "20000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115386": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 4,
        "minContribution": 2000000,
        "maxContribution": 3000000,
        "budgetYearMap": {
          "2026": "11000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ],
    "115387": [
      {
        "action": "DIGITAL-ECCC-2027-DEPLOY-CYBER-11-CYBERAI - DIGITAL-JU-SIMPLE DIGITAL JU Simple Grants",
        "expectedGrants": 4,
        "minContribution": 3000000,
        "maxContribution": 5000000,
        "budgetYearMap": {
          "2026": "15000000"
        },
        "plannedOpeningDate": "2026-09-01",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2027-01-14"
        ]
      }
    ]
  }
}