Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics

The ECCC opened a €96 million Digital Europe call across seven cybersecurity topics, with a single-stage deadline of 14 January 2027 at 17:00 CET. How the topics compare, who can apply and how proposals are scored.

September 27, 2026 12 min read

Facade of a European institutional building in Brussels Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. Call at a Glance
  4. Seven Topics Compared
  5. How to Choose the Right Topic
  6. Common Eligibility and Security Boundary
  7. What a Complete Application Must Address
  8. How Proposals Are Evaluated
  9. Application Timeline
  10. Readiness Checklist
  11. Frequently Asked Questions
  12. Conclusion
  13. Guides in the ECCC 2027 Series
  14. Official Sources

Applies to: cybersecurity vendors, SMEs, startups, public authorities, research organizations, National Coordination Centres and potential European consortium partners assessing DIGITAL-ECCC-2027-DEPLOY-CYBER-11.

The European Cybersecurity Competence Centre (ECCC) has opened a €96 million Digital Europe call covering seven cybersecurity topics: secure AI, AI-powered protection for SMEs, coordinated preparedness, regional cable hubs, the NCC Network, implementation of EU cybersecurity legislation and dual-use technologies. Applications must be submitted through the Funding & Tenders Portal by 14 January 2027 at 17:00 CET. The correct call identifier is DIGITAL-ECCC-2027-DEPLOY-CYBER-11 (ECCC call page, official call document).

In Brief

  • The call opened on 1 September 2026 and uses a single-stage application process.
  • Its estimated €96 million budget is divided among seven topics with allocations from €5 million to €20 million.
  • Topic budget, expected EU contribution per project and funding rate are different values and must not be conflated.
  • Funding rates range from 50% to 75% for SMEs under AI4SME; REGCABH uses an exceptional 70% co-funding rate.
  • Eligible beneficiaries and affiliated entities must generally be legal entities established in an EU Member State or an eligible EEA country and must satisfy the call's ownership and control restrictions.
  • Only REGCABH sets a formal minimum consortium composition in the common eligibility section, although other topics target specific public bodies, NCCs or stakeholder profiles.
  • Proposals are evaluated on Relevance, Implementation and Impact and must reach at least 3/5 for each criterion and 10/15 overall.

Scope and Source Boundary

This overview helps potential applicants select the most relevant topic and understand the common call structure. It does not determine eligibility for a specific organization, replace the topic conditions or promise that a project will be funded.

The authoritative sources are the live Funding & Tenders topic record and the official ECCC call document, including its annexes. ACN's announcement is used for the Italian NCC-IT context and summary only (ACN announcement, Funding & Tenders call search).

Call at a Glance

Item Official value
Call identifier DIGITAL-ECCC-2027-DEPLOY-CYBER-11
Programme Digital Europe Programme
Granting authority European Cybersecurity Competence Centre and Network (ECCC)
Estimated total budget €96 million
Opening date 1 September 2026
Submission deadline 14 January 2027, 17:00 CET
Submission model Single-stage, electronic submission only
Indicative evaluation February-March 2027
Indicative result information April 2027
Indicative grant signature October 2027
Part B maximum length 70 pages

The call document states that budget availability depends on final adoption of the 2025-2027 Work Programme amendment. ECCC may also leave funds unawarded or redistribute them between priorities depending on the proposals received and evaluation results. Applicants should therefore treat each topic allocation as an available envelope, not a guaranteed award amount (official call document).

Which call identifier is correct?

The official document record, downloadable PDF headers and topic identifiers use DIGITAL-ECCC-2027-DEPLOY-CYBER-11. One visible link label on the ECCC overview page refers to 2026, but applicants should use the 2027 identifier confirmed by the call document and Funding & Tenders query (ECCC document record).

Seven Topics Compared

Topic Topic budget Funding rate Expected EU contribution per project Best initial fit
CYBER-11-CYBERAI €15 million 50% €3-5 million Providers and operators developing secure AI capabilities for cyber operations, Cyber Hubs, CSIRTs and NIS stakeholders
CYBER-11-AI4SME €20 million 50%; 75% for SMEs €3-5 million SMEs and solution providers deploying user-friendly AI-powered cybersecurity tools for European SMEs
CYBER-11-COORDPREP €15 million 50% Expected €1.5 million Designated public cybersecurity bodies coordinating tests and preparedness actions, with supporting partners
CYBER-11-REGCABH €5 million 70% Expected €2.5 million Competent public authorities from countries sharing an EU sea basin and partners supporting cable resilience
CYBER-11-NCC €11 million 50% €2-3 million Recognized National Coordination Centres and consortium partners strengthening the NCC community and SME support
CYBER-11-EULEG €20 million 50% €3-5 million Industry, authorities and cybersecurity actors building capacities aligned with EU cybersecurity legislation
CYBER-11-DUALUSE €10 million 50% €3-5 million Civilian and defence cybersecurity stakeholders developing operational dual-use technologies

The expected contribution ranges are planning benchmarks, not absolute limits. The call permits different requested amounts where the variance is duly justified. Applicants must still demonstrate that the requested budget is proportionate to the action, activities and expected impact (official call document).

How to Choose the Right Topic

The starting point should be the project's primary outcome, not the applicant's preferred technology.

Choose CYBERAI when the core outcome is secure AI for cyber operations

CYBERAI supports development and deployment of AI-based cybersecurity systems and tools for areas such as threat and vulnerability detection, cyber threat intelligence, incident response, self-healing, data analysis and secure information sharing. It also covers the security, robustness and trustworthiness of AI itself and links to the AI Act, GDPR, intellectual-property requirements and cybersecurity certification.

The action is designed for technology providers, Cyber Hubs, CSIRTs, research organizations, public bodies, NIS 2 entities and other cybersecurity stakeholders. A proposal needs more than a generic AI feature: it should connect technical development, secure deployment, measurable operational outcomes and the needs of the target cyber ecosystem (ECCC call page).

Choose AI4SME when the core outcome is usable cybersecurity capacity for SMEs

AI4SME targets the market uptake and dissemination of cybersecure AI-powered solutions for European SMEs. Its scope includes risk management, vulnerability and threat detection, incident response and notification, recovery support and user-friendly delivery models such as SaaS toolkits.

This is an SME Support Action with a 50% funding rate and an increased 75% rate for SMEs. A strong concept should show how SMEs will adopt and use the solution, how it addresses real organizational constraints, and how development or adaptation will be validated in relevant conditions.

Choose COORDPREP when a competent public body leads preparedness activity

COORDPREP covers coordinated preparedness testing and other preparedness actions under the Cybersecurity Emergency Mechanism. Targeted applicants are public bodies designated or entrusted by Member States with cybersecurity responsibilities, including competent authorities and CSIRTs. Other public or private partners may participate to support implementation.

The topic is not a general penetration-testing grant for any vendor. The proposal must fit the public-authority-led preparedness model and the detailed sector or action track described in the call. Its indicative duration is 24 months, compared with 36 months for the other six topics.

Choose REGCABH when the project concerns regional undersea cable resilience

REGCABH supports Regional Cable Hubs for threat detection and analysis, near-real-time situational awareness, incident reporting and information sharing around undersea cable infrastructure.

It is the only topic with an explicit minimum consortium in the common eligibility section: at least two independent applicants from two eligible countries, including competent public authorities from at least two Member States concerned by the relevant sea basin. Its 70% rate reflects the call's stated geopolitical importance of the activity.

Choose NCC when the action strengthens National Coordination Centres and their communities

NCC targets National Coordination Centres recognized as capable of managing funds under the ECCC framework, together with public and private entities participating in consortium with NCCs. The topic supports cybersecurity community development, deployment of innovative solutions and assistance to SMEs and startups.

This topic permits Financial Support to Third Parties. The call sets a maximum of €100,000 per third party, with awards above €60,000 allowed where the nature of the action makes them necessary. Applicants must design transparent, open and European-dimension support calls that satisfy the detailed conditions in the official document.

Choose EULEG when the core outcome is capacity to implement EU cybersecurity law

EULEG supports capacities and capabilities linked to requirements under the Cyber Resilience Act, NIS 2 Directive, GDPR, DORA, Cybersecurity Act, AI Act and other relevant EU rules. Its target audience includes industry, SMEs, startups, competent authorities, CSIRTs, SOCs and stakeholders concerned with cybersecurity certification.

The topic should not be read as funding ordinary compliance documentation without wider deployment value. A credible proposal must connect legal requirements to scalable capabilities, services, tools, operational support or ecosystem outcomes described in the topic.

Choose DUALUSE when the result serves civilian and defence cybersecurity needs

DUALUSE aims to improve operational cooperation between civilian and defence spheres through working prototypes, market-ready products and operational infrastructures. Target stakeholders include industrial actors, defence and interior ministries, agencies, SMEs, startups and other relevant civilian or defence cybersecurity actors.

A multinational consortium is not mandatory, but the call states that it can contribute positively to impact. Proposals must also address the heightened security and control requirements that apply across the call.

Common Eligibility and Security Boundary

At common-rule level, beneficiaries and affiliated entities must be legal entities established in:

  • EU Member States, including overseas countries and territories;
  • EEA countries: Norway, Iceland and Liechtenstein.

All seven topics are subject to security restrictions under Article 12(5) of the Digital Europe Programme Regulation. Participation in any capacity, including as beneficiary, affiliated entity, associated partner, subcontractor or recipient of financial support, is limited to entities established in and controlled from eligible countries under the detailed rules. Activities and subcontracted work must take place in eligible countries. Ownership and control declarations are required, subject to the exceptions and procedures in the call document (official call document).

Except for REGCABH, the common eligibility section lists no minimum consortium composition. This does not make every applicant suitable for every topic: targeted-stakeholder rules still matter, particularly for COORDPREP and NCC.

What a Complete Application Must Address

Applications are electronic only. The submission package includes:

  • Part A, completed online, with participant and summarized budget information;
  • Part B, containing the technical description and limited to 70 pages;
  • mandatory ownership and control declarations, including where required for associated partners and subcontractors;
  • any other forms generated or requested by the live Submission System.

Applicants must use the templates inside the Funding & Tenders submission system. Documents displayed on topic pages are for information and may not be the submission templates. Membership in the Cybersecurity Competence Community is encouraged but not mandatory; applicants may attach proof that they requested membership through their National Coordination Centre.

How Proposals Are Evaluated

Eligible and admissible proposals are scored on three criteria:

Criterion What evaluators examine Minimum
Relevance Alignment with the topic, policy objectives, European and national synergies, and applicable supply-chain or financing considerations 3/5
Implementation Project maturity, implementation plan, use of resources and applicant or consortium capacity 3/5
Impact Delivery of expected outcomes, dissemination, competitiveness and societal benefits, plus applicable sustainability considerations 3/5
Overall Combined score 10/15

Passing the thresholds does not guarantee funding. Proposals are ranked within available budgets, and the evaluation process also uses prioritization rules for ties, thematic coverage and portfolio balance (official call document).

Application Timeline

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Proposal submission deadline
February-March 2027 Indicative evaluation period
April 2027 Indicative information on results
October 2027 Indicative grant-agreement signature

Applicants should work backward from the submission deadline. Ownership checks, partner validation, Participant Register records, scope-to-topic alignment, work-package design, KPI definitions and internal budget approval all need to be completed before the final portal upload.

Readiness Checklist

  1. Confirm the primary project outcome and select one topic whose scope directly supports it.
  2. Distinguish the topic's total allocation, expected contribution per project and reimbursement rate.
  3. Validate establishment, ownership and control requirements for every planned participant and subcontractor.
  4. Check whether the topic requires a particular public authority, NCC relationship or consortium structure.
  5. Map every work package to official activities, expected outcomes, deliverables and applicable KPIs.
  6. Build measurable evidence for maturity, implementation capacity and European impact.
  7. Prepare the co-financing model and confirm that applicants have sufficient resources for their share.
  8. Complete Participant Register and organizational validation tasks early.
  9. Use the live Funding & Tenders templates and keep Part B within 70 pages.
  10. Complete a final eligibility, security, factual-consistency and portal-readiness review before submission.

Frequently Asked Questions

What is the total budget of the call?

The estimated budget is €96 million across seven topics. Availability remains subject to final adoption of the 2025-2027 Work Programme amendment, and the granting authority may redistribute or leave funds unawarded.

When is the submission deadline?

Proposals must be submitted electronically by 14 January 2027 at 17:00 CET through the Funding & Tenders Portal.

Does a topic budget equal the grant available to one project?

No. The topic budget is the total envelope. The call separately provides expected EU contribution ranges per project and a reimbursement rate.

Can one organization apply alone?

The common eligibility section states that there is no minimum consortium composition unless specified otherwise, and single applicants may submit where permitted. REGCABH requires at least two independent applicants from two eligible countries. Topic-specific stakeholder requirements still apply.

Which topic offers the highest funding rate?

AI4SME provides 50% funding and 75% for SMEs. REGCABH provides 70% co-funding. The other five topics use a 50% rate.

Are organizations outside the EU eligible?

The call permits eligible legal entities established in EU Member States and the EEA countries Norway, Iceland and Liechtenstein, subject to the detailed security, ownership and control rules.

Is passing the 10/15 threshold enough to receive funding?

No. A proposal must pass individual and overall thresholds, but awards also depend on ranking, available budget, legal checks and grant preparation.

Conclusion

DIGITAL-ECCC-2027-DEPLOY-CYBER-11 is not one generic cybersecurity grant. It is a portfolio of seven actions with different audiences, funding rates, consortium boundaries and expected outcomes. The strongest starting decision is to select the topic whose intended operational result matches the project, then build eligibility, security, work packages, KPIs and budget around the official text.

For organizations weighing an application, a useful first step is a documented picture of their security posture: the Cyber Check-up returns one as a report, and our Virtual CISO service can help you map capabilities, regulatory requirements, operational evidence and partner responsibilities into a structured project concept. Final eligibility and submission decisions must remain grounded in the official call document and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

  • ECCC Cybersecurity Call 2027: Eligibility and Application Guide
  • ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers
  • ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability
  • ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations
  • ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing
  • ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 20, 2026

SECURE First Open Call 2026: What mSMEs Need to Submit Before 29 March 2026

The SECURE First Open Call (28 Jan - 29 Mar 2026) offers up to EUR 30,000 per project at 50% co-financing to help mSMEs achieve Cyber Resilience Act …

September 27, 2026

NIS Reinforced Security Measures: ACN Opens the Consultation

On 18 September 2026 ACN opened a sector consultation on reinforced NIS security measures, meant to supplement and replace the baseline measures. The…

September 27, 2026

NIS Supply Chain Security: What ACN's FAQs MSB.13 to MSB.19 Clarify

On 24 July 2026 ACN published seven FAQs on NIS supply chain security. The four-phase process, the five minimum criteria for supply risk, why not eve…