Approaches and tools for security in software and hardware development and assessment
Develop innovative tools and methods for securing software and hardware supply chains, focusing on trusted chips and secure software development.
This call seeks proposals to improve security in software and hardware development. It targets trusted chip architectures and secure software supply chains. Projects should address vulnerabilities, supply chain transparency, and security-by-design approaches.
Likely relevant for
- Cybersecurity researchers
- Hardware security developers
- Software security engineers
- AI-driven security testing experts
- Supply chain security specialists
Project signals
What it funds
- Development of secure hardware systems including tamper-resistant chips and secure microprocessors
- Enhancement of supply chain transparency and security for hardware components
- Security-by-design methodologies for hardware security assessment and lifecycle management
- Tools for non-destructive authentication and physical analysis of integrated circuits
- Development of self-healing firmware with AI-driven threat mitigation
- Innovative tools for real-time software vulnerability detection and automatic patching
- Secure software development lifecycle methodologies aligned with regulatory requirements
- Formal verification and AI-assisted security testing approaches
- Standardised methodologies for hardware security assessment and cybersecurity certification
- Mitigation strategies for software supply chain cyber threats including provenance tracking and secure update distribution
Expected outcomes
- Enhanced security frameworks for hardware and software supply chains
- Secure and trusted chip architectures for next-generation systems
- Integrated security-by-design approaches in software development
- Advanced security testing methodologies including formal verification and AI-driven testing
- Standardised hardware security assessment methodologies contributing to certification
- Improved resilience against supply chain cyber threats
- Development of self-healing and anomaly detection firmware for hardware security
Who can apply / participate
- Legal entities established in EU Member States
- Legal entities established in Horizon Europe Associated Countries
- Participation limited to entities not controlled by non-eligible countries or entities
- Consortium composition should ensure coverage of the selected main area of focus
- Only entities from EU Member States and Associated Countries are eligible
- Entities controlled by non-eligible countries are excluded
- Participation limited to legal entities established in eligible countries
- Entities controlled by non-eligible countries or entities are excluded to protect strategic interests
- Specific consortium size requirements not stated
- Details on SME participation incentives not specified
Must check before shortlisting
- Eligibility limited to entities in EU Member States and Associated Countries
- Restrictions on entities controlled by non-eligible countries
- Potential involvement of classified or security sensitive information
- Compliance with lump sum funding model and page limits
Money
Total budget of approximately €20 million for 2026. Expected grants: 5. Funding is provided as lump sums with minimum €3 million and maximum €4 million per grant.
- Total budget for 2026 — 20000000EURApproximate total budget for this topic in 2026
- Minimum grant per project — 3000000EURMinimum lump sum grant per awarded project
- Maximum grant per project — 4000000EURMaximum lump sum grant per awarded project
Application notes
- Single-stage submission model. Proposals must comply with page limits and layout as per Horizon Europe General Annexes.
- Proposal page limits and layout described in Annex A and Annex E of Horizon Europe Work Programme General Annexes
- Eligible countries listed in Annex B of Horizon Europe Work Programme General Annexes
- Participation restricted to entities established in Member States and Associated Countries not controlled by non-eligible countries
- Use of lump sum funding model as per Decision of 7 July 2021
- Some activities may involve classified or security sensitive information (EUCI and SEN)
- Prepare proposal following the Application Form Part B layout
- Ensure eligibility of participants according to Annex B
- Submit proposal before the deadline via the Funding & Tenders Portal
- Check security requirements if handling classified information
- Use provided application form templates and follow evaluation criteria
- Participation limited to entities established in eligible countries and not controlled by non-eligible countries
- Proposals must select one main area of focus (hardware or software) but may address both
- Security sensitive results may require compliance with EU classified information rules
- Evaluation includes thresholds and ranking with guaranteed awards for top proposals in each focus area
Derived from official EU Funding portal source · updated 22 Jun 2026, 14:59 UTC. Use this as a shortlisting aid; the official call text remains authoritative.
Official source text
Fine print from the EU source record. Expand when you need the original wording.
Topic description
Expected Outcome: Proposals are expected to contribute to one or more of the following: Enhanced security frameworks for both hardware and software supply chains, building on root-of-trust architectures and secure lifecycle management; Secure and trusted chip architectures for next-generation computing and networking systems; Integrated security-by-design approaches in software development, aimed to be aligned with relevant regulatory requirements; Security testing methodologies, including formal verification approaches and AI-driven security testing methodologies; Standardised methodologies for hardware security assessment, also contributing to cybersecurity certification. Scope: The increasing complexity and globalisation of software and hardware supply chains introduce new vulnerabilities that cyber adversaries can exploit. Ensuring the security of both software and hardware components across the lifecycle of digital systems is paramount. This topic aims to develop innovative tools, methods, and processes to secure the entire ecosystem of software and hardware development. Proposals should explicitly select one main area of focus but can also address both: a. Secured hardware systems over trusted Chips The security of modern computing infrastructures relies heavily on the robustness of hardware components. This subtopic aims to develop robust security solutions for trusted hardware platforms, focusing on secured microprocessors, secure boot mechanisms, and cryptographic acceleration. Proposals are also expected to address the risks of hardware-based vulnerabilities and backdoors, ensuring the security of devices from edge to cloud, also taking into account emerging threats, including quantum where relevant. Synergies with existing EU initiatives on trusted hardware (e.g., CHIPS JU, EuroHPC) are encouraged. The topic is expected to: Develop new architectures for tamper-resistant chips and processors. Exploring novel designs for secure microprocessors, leveraging hardware-level security enhancements, and integrating cryptographic co-processors that may also support post-quantum cryptography (PQC), for enhanced protection against tampering and side-channel attacks. Enhance supply chain transparency for chip production and integration. Exploring innovative ways to improve traceability and accountability in chip manufacturing processes, including methods such as post-quantum secure hardware roots of trust, blockchain for tracking components, or certification mechanisms. Establish security-by-design methodologies for hardware security assessment. Advancing methodologies for systematic security testing of hardware components, including automated vulnerability analysis, verification frameworks, and integration of security assessment into chip design and lifecycle management. Develop methods and tools for an effective and efficient non-destructive authentication and physical analysis of integrated circuits and multi-chips modules (chiplets). Develop technical means for ensuring hardware supply chain security, and secure PQC implementations: hardware trojan and backdoor detection, hardware watermarking, relevant reverse engineering techniques, countermeasures also against new classes of hardware physical attacks. Develop self-healing firmware able to recover from cyber-attacks. Develop firmware able to leverage advanced anomaly detection, AI-driven threat mitigation and secure rollback mechanisms to automatically identify cyber-attacks, isolate compromised components restore the system to a trusted state while maintaining operational continuity. b. Software Supply Chain security The integrity of software supply chains is critical to mitigating cybersecurity threats such as supply chain attacks, dependency vulnerabilities, and compromised software components. This subtopic focuses on mitigating security risks in software supply chains, including secure code provenance, automated vulnerability detection, and secure software development lifecycle (SDLC) methodologies and tools, including those related to PQC security. Proposals should integrate formal verification approaches or AI-assisted security testing, leveraging upcoming European and International standards for supply chain security. The topic is expected to: Develop innovative tools for real-time software vulnerability detection and automatic patching. Advancing the state of automated detection techniques, incorporating dynamic analysis, AI-driven pattern recognition, predictive analytics to proactively identify security weaknesses before exploitation and self-healing mechanisms. Enhance secure software frameworks, including protection against the quantum threat. Exploring new methodologies for integrating security-by-design principles across development workflows, incorporating approaches such as automated security policy enforcement, modular security components, and improved dependency management. Improve resilience against supply chain cyber threats. Investigating novel mitigation strategies, including provenance tracking for software components and their analysis, secure update distribution mechanisms including protection from emerging quantum threats where relevant, enhanced anomaly detection, and multi-layer defence approaches to ensure integrity and trustworthiness.
Conditions and documents
General conditions
1. Admissibility Conditions: Proposal page limit and layout
2. Eligible Countries
described in Annex B of the Work Programme General Annexes.
A number of non-EU/non-Associated Countries that are not automatically eligible for funding have made specific provisions for making funding available for their participants in Horizon Europe projects. See the information in the Horizon Europe Programme Guide.
3. Other Eligible Conditions
In order to achieve the expected outcomes, and safeguard the Union’s strategic assets, interests, autonomy, and security, participation in this topic is limited to legal entities established in Member States and Associated Countries. In order to guarantee the protection of the strategic interests of the Union and its Member States, entities established in an eligible country listed above, but which are directly or indirectly controlled by a non-eligible country or by a non-eligible country entity, shall not participate in the action.
described in Annex B of the Work Programme General Annexes.
4. Financial and operational capacity and exclusion
described in Annex C of the Work Programme General Annexes.
5a. Evaluation and award: Award criteria, scoring and thresholds
To ensure a balanced portfolio covering a broad range of research areas, grants will be awarded to applications not only in order of ranking but at least also to the two highest ranked proposal addressing area a) as their main area of focus and the highest ranked proposal addressing area b) as its main area of focus, provided that the applications attain all thresholds.
are described in Annex D of the Work Programme General Annexes.
5b. Evaluation and award: Submission and evaluation processes
are described in Annex F of the Work Programme General Annexes and the Online Manual.
5c. Evaluation and award: Indicative timeline for evaluation and grant agreement
described in Annex F of the Work Programme General Annexes.
6. Legal and financial set-up of the grants
Eligible costs will take the form of a lump sum as defined in the Decision of 7 July 2021 authorising the use of lump sum contributions under the Horizon Europe Programme – the Framework Programme for Research and Innovation (2021-2027) – and in actions under the Research and Training Programme of the European Atomic Energy Community (2021-2025) [[This decision is available on the Funding and Tenders Portal, in the reference documents section for Horizon Europe, under ‘Simplified costs decisions’ or through this link: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/horizon/guidance/ls-decision_he_en.pdf]].
described in Annex G of the Work Programme General Annexes.
Specific conditions
described in the [specific topic of the Work Programme]
Some activities resulting from this topic may involve using classified background and/or producing of security sensitive results (EUCI and SEN). Please refer to the related provisions in section B Security — EU classified and sensitive information of the General Annexes.
Application and evaluation forms and model grant agreement (MGA):
Application form templates — the application form specific to this call is available in the Submission System
Standard application form (HE RIA, IA)
Evaluation form templates — will be used with the necessary adaptations
Standard evaluation form (HE RIA, IA)
Guidance
Model Grant Agreements (MGA)
Call-specific instructions
Additional documents:
HE Main Work Programme 2026-2027 – 1. General Introduction
HE Main Work Programme 2026-2027 – 6. Civil Security for Society
HE Main Work Programme 2026-2027 – 15. General Annexes
Decision authorising the use of lump sum contributions under the Horizon Europe Programme
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
Support information
For guidance and support related to this call, we recommend that you first contact the National Cybersecurity Coordination Centres (NCC) in your country, where available. The Network of NCCs includes one national centre from each of the 27 EU Member States plus Iceland and Norway. You may also address your questions to the ECCC Applicants Direct Contact Centre at applicants@eccc.europa.eu . Online Manual is your guide on the procedures from proposal submission to managing your grant. Horizon Europe Programme Guide contains the detailed guidance to the structure, budget and political priorities of Horizon Europe. Funding & Tenders Portal FAQ – find the answers to most frequently asked questions on submission of proposals, evaluation and grant management. Research Enquiry Service – ask questions about any aspect of European research in general and the EU Research Framework Programmes in particular. National Contact Points (NCPs) – get guidance, practical information and assistance on participation in Horizon Europe. There are also NCPs in many non-EU and non-associated countries (‘third-countries’). Enterprise Europe Network – contact your EEN national contact for advice to businesses with special focus on SMEs. The support includes guidance on the EU research funding. IT Helpdesk – contact the Funding & Tenders Portal IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc. European IPR Helpdesk assists you on intellectual property issues. CEN-CENELEC Research Helpdesk and ETSI Research Helpdesk – the European Standards Organisations advise you how to tackle standardisation in your project proposal. The European Charter for Researchers and the Code of Conduct for their recruitment – consult the general principles and requirements specifying the roles, responsibilities and entitlements of researchers, employers and funders of researchers. Partner Search help you find a partner organisation for your proposal.
Raw budget overview
{
"budgetYearsColumns": [
"2026"
],
"budgetTopicActionMap": {
"113178": [
{
"action": "HORIZON-CL3-2026-02-CS-ECCC-01 - HORIZON-RIA HORIZON Research and Innovation Actions",
"expectedGrants": 5,
"minContribution": 3000000,
"maxContribution": 4000000,
"budgetYearMap": {
"2026": "20000000"
},
"plannedOpeningDate": "2026-03-03",
"deadlineModel": "single-stage",
"deadlineDates": [
"2026-09-15"
]
}
],
"113179": [
{
"action": "HORIZON-CL3-2026-02-CS-ECCC-03 - HORIZON-RIA HORIZON Research and Innovation Actions",
"expectedGrants": 4,
"minContribution": 2000000,
"maxContribution": 3000000,
"budgetYearMap": {
"2026": "15000000"
},
"plannedOpeningDate": "2026-03-03",
"deadlineModel": "single-stage",
"deadlineDates": [
"2026-09-15"
]
}
],
"113180": [
{
"action": "HORIZON-CL3-2026-02-CS-ECCC-02 - HORIZON-IA HORIZON Innovation Actions",
"expectedGrants": 5,
"minContribution": 3000000,
"maxContribution": 4000000,
"budgetYearMap": {
"2026": "21200000"
},
"plannedOpeningDate": "2026-03-03",
"deadlineModel": "single-stage",
"deadlineDates": [
"2026-09-15"
]
}
]
}
}