HORIZON-CL3-2026-02-CS-ECCC-01

Approaches and tools for security in software and hardware development and assessment

Status
open for submission
Programme
Horizon Europe (HORIZON)
Action type
HORIZON Research and Innovation Actions
Opens
3 Mar 2026
Deadline
15 Sep 2026
Fetched
15 Jul 2026, 07:18 UTC
Plain-language summary

Develop innovative tools and methods for securing software and hardware supply chains, focusing on trusted chips and secure software development.

This call seeks proposals to improve security in software and hardware development. It targets trusted chip architectures and secure software supply chains. Projects should address vulnerabilities, supply chain transparency, and security-by-design approaches.

Likely relevant for

  • Cybersecurity researchers
  • Hardware security developers
  • Software security engineers
  • AI-driven security testing experts
  • Supply chain security specialists

Project signals

Focus on hardware security architecturesDevelopment of secure software frameworksUse of AI for vulnerability detectionSecurity testing and certification methodologiesSupply chain transparency and traceability

What it funds

  • Development of secure hardware systems including tamper-resistant chips and secure microprocessors
  • Enhancement of supply chain transparency and security for hardware components
  • Security-by-design methodologies for hardware security assessment and lifecycle management
  • Tools for non-destructive authentication and physical analysis of integrated circuits
  • Development of self-healing firmware with AI-driven threat mitigation
  • Innovative tools for real-time software vulnerability detection and automatic patching
  • Secure software development lifecycle methodologies aligned with regulatory requirements
  • Formal verification and AI-assisted security testing approaches
  • Standardised methodologies for hardware security assessment and cybersecurity certification
  • Mitigation strategies for software supply chain cyber threats including provenance tracking and secure update distribution

Expected outcomes

  • Enhanced security frameworks for hardware and software supply chains
  • Secure and trusted chip architectures for next-generation systems
  • Integrated security-by-design approaches in software development
  • Advanced security testing methodologies including formal verification and AI-driven testing
  • Standardised hardware security assessment methodologies contributing to certification
  • Improved resilience against supply chain cyber threats
  • Development of self-healing and anomaly detection firmware for hardware security

Who can apply / participate

  • Legal entities established in EU Member States
  • Legal entities established in Horizon Europe Associated Countries
  • Participation limited to entities not controlled by non-eligible countries or entities
  • Consortium composition should ensure coverage of the selected main area of focus
  • Only entities from EU Member States and Associated Countries are eligible
  • Entities controlled by non-eligible countries are excluded
  • Participation limited to legal entities established in eligible countries
  • Entities controlled by non-eligible countries or entities are excluded to protect strategic interests
  • Specific consortium size requirements not stated
  • Details on SME participation incentives not specified

Must check before shortlisting

  • Eligibility limited to entities in EU Member States and Associated Countries
  • Restrictions on entities controlled by non-eligible countries
  • Potential involvement of classified or security sensitive information
  • Compliance with lump sum funding model and page limits

Money

Total budget of approximately €20 million for 2026. Expected grants: 5. Funding is provided as lump sums with minimum €3 million and maximum €4 million per grant.

  • Total budget for 2026 — 20000000EUR
    Approximate total budget for this topic in 2026
  • Minimum grant per project — 3000000EUR
    Minimum lump sum grant per awarded project
  • Maximum grant per project — 4000000EUR
    Maximum lump sum grant per awarded project

Application notes

  • Single-stage submission model. Proposals must comply with page limits and layout as per Horizon Europe General Annexes.
  • Proposal page limits and layout described in Annex A and Annex E of Horizon Europe Work Programme General Annexes
  • Eligible countries listed in Annex B of Horizon Europe Work Programme General Annexes
  • Participation restricted to entities established in Member States and Associated Countries not controlled by non-eligible countries
  • Use of lump sum funding model as per Decision of 7 July 2021
  • Some activities may involve classified or security sensitive information (EUCI and SEN)
  • Prepare proposal following the Application Form Part B layout
  • Ensure eligibility of participants according to Annex B
  • Submit proposal before the deadline via the Funding & Tenders Portal
  • Check security requirements if handling classified information
  • Use provided application form templates and follow evaluation criteria
  • Participation limited to entities established in eligible countries and not controlled by non-eligible countries
  • Proposals must select one main area of focus (hardware or software) but may address both
  • Security sensitive results may require compliance with EU classified information rules
  • Evaluation includes thresholds and ranking with guaranteed awards for top proposals in each focus area

Derived from official EU Funding portal source · updated 22 Jun 2026, 14:59 UTC. Use this as a shortlisting aid; the official call text remains authoritative.

Official source text

Fine print from the EU source record. Expand when you need the original wording.

Topic description

Expected Outcome: Proposals are expected to contribute to one or more of the following: Enhanced security frameworks for both hardware and software supply chains, building on root-of-trust architectures and secure lifecycle management; Secure and trusted chip architectures for next-generation computing and networking systems; Integrated security-by-design approaches in software development, aimed to be aligned with relevant regulatory requirements; Security testing methodologies, including formal verification approaches and AI-driven security testing methodologies; Standardised methodologies for hardware security assessment, also contributing to cybersecurity certification. Scope: The increasing complexity and globalisation of software and hardware supply chains introduce new vulnerabilities that cyber adversaries can exploit. Ensuring the security of both software and hardware components across the lifecycle of digital systems is paramount. This topic aims to develop innovative tools, methods, and processes to secure the entire ecosystem of software and hardware development. Proposals should explicitly select one main area of focus but can also address both: a. Secured hardware systems over trusted Chips The security of modern computing infrastructures relies heavily on the robustness of hardware components. This subtopic aims to develop robust security solutions for trusted hardware platforms, focusing on secured microprocessors, secure boot mechanisms, and cryptographic acceleration. Proposals are also expected to address the risks of hardware-based vulnerabilities and backdoors, ensuring the security of devices from edge to cloud, also taking into account emerging threats, including quantum where relevant. Synergies with existing EU initiatives on trusted hardware (e.g., CHIPS JU, EuroHPC) are encouraged. The topic is expected to: Develop new architectures for tamper-resistant chips and processors. Exploring novel designs for secure microprocessors, leveraging hardware-level security enhancements, and integrating cryptographic co-processors that may also support post-quantum cryptography (PQC), for enhanced protection against tampering and side-channel attacks. Enhance supply chain transparency for chip production and integration. Exploring innovative ways to improve traceability and accountability in chip manufacturing processes, including methods such as post-quantum secure hardware roots of trust, blockchain for tracking components, or certification mechanisms. Establish security-by-design methodologies for hardware security assessment. Advancing methodologies for systematic security testing of hardware components, including automated vulnerability analysis, verification frameworks, and integration of security assessment into chip design and lifecycle management. Develop methods and tools for an effective and efficient non-destructive authentication and physical analysis of integrated circuits and multi-chips modules (chiplets). Develop technical means for ensuring hardware supply chain security, and secure PQC implementations: hardware trojan and backdoor detection, hardware watermarking, relevant reverse engineering techniques, countermeasures also against new classes of hardware physical attacks. Develop self-healing firmware able to recover from cyber-attacks. Develop firmware able to leverage advanced anomaly detection, AI-driven threat mitigation and secure rollback mechanisms to automatically identify cyber-attacks, isolate compromised components restore the system to a trusted state while maintaining operational continuity. b. Software Supply Chain security The integrity of software supply chains is critical to mitigating cybersecurity threats such as supply chain attacks, dependency vulnerabilities, and compromised software components. This subtopic focuses on mitigating security risks in software supply chains, including secure code provenance, automated vulnerability detection, and secure software development lifecycle (SDLC) methodologies and tools, including those related to PQC security. Proposals should integrate formal verification approaches or AI-assisted security testing, leveraging upcoming European and International standards for supply chain security. The topic is expected to: Develop innovative tools for real-time software vulnerability detection and automatic patching. Advancing the state of automated detection techniques, incorporating dynamic analysis, AI-driven pattern recognition, predictive analytics to proactively identify security weaknesses before exploitation and self-healing mechanisms. Enhance secure software frameworks, including protection against the quantum threat. Exploring new methodologies for integrating security-by-design principles across development workflows, incorporating approaches such as automated security policy enforcement, modular security components, and improved dependency management. Improve resilience against supply chain cyber threats. Investigating novel mitigation strategies, including provenance tracking for software components and their analysis, secure update distribution mechanisms including protection from emerging quantum threats where relevant, enhanced anomaly detection, and multi-layer defence approaches to ensure integrity and trustworthiness.

Conditions and documents

General conditions

1. Admissibility Conditions: Proposal page limit and layout

described in Annex A and Annex E of the Horizon Europe Work Programme General Annexes.

Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.

2. Eligible Countries

described in Annex B of the Work Programme General Annexes.

A number of non-EU/non-Associated Countries that are not automatically eligible for funding have made specific provisions for making funding available for their participants in Horizon Europe projects. See the information in the Horizon Europe Programme Guide.

3. Other Eligible Conditions

In order to achieve the expected outcomes, and safeguard the Union’s strategic assets, interests, autonomy, and security, participation in this topic is limited to legal entities established in Member States and Associated Countries. In order to guarantee the protection of the strategic interests of the Union and its Member States, entities established in an eligible country listed above, but which are directly or indirectly controlled by a non-eligible country or by a non-eligible country entity, shall not participate in the action.

described in Annex B of the Work Programme General Annexes.

4. Financial and operational capacity and exclusion

described in Annex C of the Work Programme General Annexes.

5a. Evaluation and award: Award criteria, scoring and thresholds

To ensure a balanced portfolio covering a broad range of research areas, grants will be awarded to applications not only in order of ranking but at least also to the two highest ranked proposal addressing area a) as their main area of focus and the highest ranked proposal addressing area b) as its main area of focus, provided that the applications attain all thresholds.

are described in Annex D of the Work Programme General Annexes.

5b. Evaluation and award: Submission and evaluation processes

are described in Annex F of the Work Programme General Annexes and the Online Manual.

5c. Evaluation and award: Indicative timeline for evaluation and grant agreement

described in Annex F of the Work Programme General Annexes.

6. Legal and financial set-up of the grants

Eligible costs will take the form of a lump sum as defined in the Decision of 7 July 2021 authorising the use of lump sum contributions under the Horizon Europe Programme – the Framework Programme for Research and Innovation (2021-2027) – and in actions under the Research and Training Programme of the European Atomic Energy Community (2021-2025) [[This decision is available on the Funding and Tenders Portal, in the reference documents section for Horizon Europe, under ‘Simplified costs decisions’ or through this link: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ls-decision_he_en.pdf]].

described in Annex G of the Work Programme General Annexes.

Specific conditions

described in the [specific topic of the Work Programme]

Some activities resulting from this topic may involve using classified background and/or producing of security sensitive results (EUCI and SEN). Please refer to the related provisions in section B Security — EU classified and sensitive information of the General Annexes.

Support information

For guidance and support related to this call, we recommend that you first contact the National Cybersecurity Coordination Centres (NCC) in your country, where available. The Network of NCCs includes one national centre from each of the 27 EU Member States plus Iceland and Norway. You may also address your questions to the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu . Online Manual is your guide on the procedures from proposal submission to managing your grant. Horizon Europe Programme Guide contains the detailed guidance to the structure, budget and political priorities of Horizon Europe. Funding & Tenders Portal FAQ – find the answers to most frequently asked questions on submission of proposals, evaluation and grant management. Research Enquiry Service – ask questions about any aspect of European research in general and the EU Research Framework Programmes in particular. National Contact Points (NCPs) – get guidance, practical information and assistance on participation in Horizon Europe. There are also NCPs in many non-EU and non-associated countries (‘third-countries’). Enterprise Europe Network – contact your EEN national contact for advice to businesses with special focus on SMEs. The support includes guidance on the EU research funding. IT Helpdesk – contact the Funding & Tenders Portal IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc. European IPR Helpdesk assists you on intellectual property issues. CEN-CENELEC Research Helpdesk and ETSI Research Helpdesk – the European Standards Organisations advise you how to tackle standardisation in your project proposal. The European Charter for Researchers and the Code of Conduct for their recruitment – consult the general principles and requirements specifying the roles, responsibilities and entitlements of researchers, employers and funders of researchers. Partner Search help you find a partner organisation for your proposal.

Raw budget overview
{
  "budgetYearsColumns": [
    "2026"
  ],
  "budgetTopicActionMap": {
    "113178": [
      {
        "action": "HORIZON-CL3-2026-02-CS-ECCC-01 - HORIZON-RIA HORIZON  Research and Innovation Actions",
        "expectedGrants": 5,
        "minContribution": 3000000,
        "maxContribution": 4000000,
        "budgetYearMap": {
          "2026": "20000000"
        },
        "plannedOpeningDate": "2026-03-03",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2026-09-15"
        ]
      }
    ],
    "113179": [
      {
        "action": "HORIZON-CL3-2026-02-CS-ECCC-03 - HORIZON-RIA HORIZON  Research and Innovation Actions",
        "expectedGrants": 4,
        "minContribution": 2000000,
        "maxContribution": 3000000,
        "budgetYearMap": {
          "2026": "15000000"
        },
        "plannedOpeningDate": "2026-03-03",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2026-09-15"
        ]
      }
    ],
    "113180": [
      {
        "action": "HORIZON-CL3-2026-02-CS-ECCC-02 - HORIZON-IA HORIZON Innovation Actions",
        "expectedGrants": 5,
        "minContribution": 3000000,
        "maxContribution": 4000000,
        "budgetYearMap": {
          "2026": "21200000"
        },
        "plannedOpeningDate": "2026-03-03",
        "deadlineModel": "single-stage",
        "deadlineDates": [
          "2026-09-15"
        ]
      }
    ]
  }
}