ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers

The AI4SME topic funds AI-enabled cybersecurity tools and services that European SMEs actually adopt. Budget, the 75% SME funding rate, eligible activity paths, KPIs and what evaluators will look for.

September 29, 2026 14 min read

Consultant and company owner reviewing a document together Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. AI4SME at a Glance
  4. What AI4SME Is Designed to Fund
  5. Capabilities the Toolkit Can Cover
  6. Cybersecure and Trustworthy AI Requirements
  7. Who Can Participate and How to Build the Partnership
  8. Funding Mechanics and Co-Financing
  9. Expected Outcomes and Proof of Adoption
  10. KPI Contract
  11. A Practical Work-Package Model
  12. How Evaluators Will Read the Proposal
  13. Eligibility, Documents and Timeline
  14. Readiness Checklist
  15. Frequently Asked Questions
  16. Conclusion
  17. Guides in the ECCC 2027 Series
  18. Official Sources

Applies to: European SMEs, startups, cybersecurity and AI providers, research organizations, public-sector bodies, NIS 2 entities and consortium partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME.

The AI4SME topic provides a €20 million envelope to develop, adapt, validate and deploy user-friendly AI-powered cybersecurity solutions for European SMEs. The expected EU contribution is €3-5 million per project. The funding rate is 50%, increased to 75% for SME eligible costs, and the indicative project duration is 36 months. Proposals must be submitted by 14 January 2027 at 17:00 CET and must show credible SME adoption, operational validation and measurable cybersecurity outcomes, not only an AI concept or research prototype (official call document).

In Brief

  • AI4SME is an SME Support Action designed to move market-ready or adaptable AI-powered cybersecurity capabilities into practical SME use.
  • A proposal must include at least one official activity path: adoption where AI cyber tools are not yet used, development of an SME-oriented toolkit, or an incident-reporting interface supported by AI assistants.
  • The topic covers risk assessment, infrastructure scanning, vulnerability and threat alerts, incident prediction, response, notification, recovery support and secure information exchange.
  • The 75% rate applies to eligible costs of SMEs; it is not a blanket 75% rate for every consortium participant or every budget item.
  • Two topic KPIs form the baseline: SMEs or other entities benefiting, and AI-powered infrastructures, tools or services developed, adapted, tested and validated for SME use.
  • Trustworthy AI, human oversight, robustness, personal-data protection and security of the AI solution are part of the expected design, not optional presentation language.
  • The common Digital Europe ownership, control and eligible-country restrictions apply to every participant role.

Scope and Source Boundary

This guide explains the AI4SME topic's objectives, eligible activity patterns, funding mechanics and evidence expectations. It does not determine whether a specific organization or project is eligible and does not replace the live Funding & Tenders topic record, the official call document or the templates generated by the Submission System.

The topic sits within the seven-topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11 call. Its purpose is to strengthen the cyber resilience of European SMEs by increasing the uptake and dissemination of innovative AI-powered cybersecurity solutions, including results originating from EU-supported research projects where relevant (ECCC call overview).

AI4SME at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-AI4SME
Topic budget €20 million
Type of action SME Support Action
Funding rate 50%; 75% for SMEs
Expected EU contribution €3-5 million per project
Indicative duration 36 months
Consortium minimum None in the common composition rules
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The expected contribution range is not an automatic award or absolute cap. A different amount can be considered when duly justified, and the awarded grant may be lower than the amount requested.

What AI4SME Is Designed to Fund

Market uptake and operational deployment

The topic starts from a practical problem: many SMEs lack the resources to assess cyber risk, build a strategy and implement suitable protections. AI4SME therefore combines product development or adaptation with validation and deployment. A credible proposal should explain who will use the solution, what operational process changes, how adoption barriers are reduced and how the result will be validated in realistic SME environments.

Pure research without a route to use is a weak fit. So is a generic AI feature without a defined cybersecurity workflow, target users, integration model or measurable resilience outcome.

Three eligible activity paths

The official scope requires activities to include at least one of the following paths.

Activity path What the call expects Evidence a proposal should provide
Adoption Uptake of AI-powered cybersecurity tools in organizations where adoption has not yet occurred SME baseline, onboarding method, deployment targets and before/after measures
SME toolkit Development of user-friendly AI tools that automate core cybersecurity processes Architecture, functions, integration points, validation plan and usability evidence
Incident interface An SME interface for reporting incidents, receiving reaction instructions and finding response support, potentially through AI assistants Workflow to competent support, human oversight, escalation rules and recovery guidance

A proposal may combine all three paths, but breadth is useful only when the work packages remain deliverable and the KPI model can prove actual use.

Capabilities the Toolkit Can Cover

The call describes a SaaS toolkit tailored to SME needs and identifies several functions that can be developed or integrated.

Capability Practical purpose Evidence to define
Cyber-risk assessment Assess risk, recommend mitigations and identify response options Risk method, inputs, scoring logic and accountable reviewer
Infrastructure scanning Use authorized infrastructure data to assess exposure Authorization model, asset scope, scan controls and data handling
Vulnerability and threat alerts Issue relevant alerts from risk and technical information Detection sources, prioritization, false-positive handling and response SLA
Incident prediction and response Anticipate patterns and support containment or recovery Model limits, escalation logic, human approval and outcome measures
Incident notification Help SMEs report incidents and connect with a Cyber Hub or other support channel Routing criteria, required data, jurisdiction mapping and audit trail
Training and onboarding Help employees use AI-enabled security capabilities correctly Personas, learning objectives, completion and effectiveness measures

The official scope references ENISA's Interoperable EU Risk Management Framework for risk-management context. A proposal should not claim interoperability merely because it uses a shared vocabulary; it should identify the data model, mappings, interfaces and validation evidence that make interoperability testable.

Cybersecure and Trustworthy AI Requirements

AI4SME is not only about applying AI to cybersecurity. The AI-enabled solution must itself be secure and trustworthy. The call highlights poisoning and evasion attacks, human oversight, robustness and the protection of personal data.

A defensible solution design should address:

  • the AI model or service boundary and the data used for training, adaptation and inference;
  • access control, tenant isolation and secure handling of SME telemetry;
  • resistance to manipulation, prompt injection, poisoning, evasion and unsafe automation where applicable;
  • human review for material risk decisions, notifications and response actions;
  • logging, traceability, performance monitoring and model-change governance;
  • false positives, false negatives, confidence thresholds and fail-safe behavior;
  • privacy, data minimization, retention and lawful processing;
  • secure integration with scanners, ticketing, SOC, CSIRT or Cyber Hub workflows.

Trustworthiness must be connected to test cases and acceptance criteria. Statements such as "human in the loop" or "privacy by design" are not sufficient unless the proposal explains who performs the control, when it occurs and what evidence is retained.

Who Can Participate and How to Build the Partnership

The topic names SMEs, startups, research and academia, the public sector, NIS 2 entities, other industry actors and providers of AI-assisted functionality as targeted stakeholders. The common rules impose no minimum consortium composition for AI4SME, so a single applicant may submit where all conditions are met.

In practice, the delivery model may require complementary roles:

Role Contribution to the action
SME users or pilot groups Define constraints, supply use cases, validate usability and measure adoption
Cybersecurity provider Provide risk, detection, incident-response or recovery capability
AI or technology provider Develop or adapt models, interfaces, automation and monitoring
Research organization Support validation methodology, testing and evidence quality
Public, NIS 2 or ecosystem actor Support sector alignment, dissemination and connection to competent-response structures

Partner count should follow the work, not an assumption that larger consortia score better. Each participant needs a distinct operational responsibility, budget rationale and evidence contribution. When more than one beneficiary participates, a consortium agreement is required.

Funding Mechanics and Co-Financing

The 50% and 75% rates must be applied carefully. The topic uses a 50% funding rate, with 75% applying to SMEs under the SME Support Action model. A mixed consortium should calculate the rate and co-financing burden by participant and eligible cost rather than applying one headline percentage to the entire project.

The grant is budget-based and reimburses eligible actual costs, together with the unit-cost and flat-rate elements defined by the call. Important planning points include:

  • expected EU contribution of €3-5 million per project;
  • indicative duration of 36 months;
  • indirect costs calculated at 7% of applicable eligible direct costs;
  • equipment reimbursement through depreciation and full cost for listed equipment under the conditions in section 10;
  • no-profit rule and possible reduction for non-compliance;
  • sufficient financial capacity and cash flow to fund each participant's share.

For example, a €4 million EU contribution does not mean a €4 million total project cost. The eligible-cost base depends on participant rates, cost categories and the approved budget. The financial model should therefore be built at partner and work-package level, then reconciled with Part A and the technical plan.

Expected Outcomes and Proof of Adoption

The call expects projects to support market-ready AI-powered solutions, deploy current tools and services, improve cybersecurity processes, help employees use AI for cybersecurity and protect AI solutions themselves.

Convert those outcomes into an evidence chain:

  1. Establish an SME baseline for maturity, risk exposure, current tooling and incident processes.
  2. Define target user groups and adoption barriers, including cost, skills, integration and trust.
  3. Deploy or adapt the solution in representative environments.
  4. Validate technical performance, usability, security and organizational integration.
  5. Measure operational change against the baseline.
  6. Document repeatability, support requirements and a route to wider market uptake.

Useful evidence can include the number and profile of onboarded SMEs, time to complete a risk assessment, alert precision, response time, percentage of recommended mitigations adopted, recovery milestones, user completion rates and validated integrations. Targets must be plausible and traceable to work packages, not selected only because they look ambitious.

KPI Contract

The call requires applicants to assess every topic-specific KPI. Applicable KPIs must be included with the information required by the common KPI template; a KPI considered not applicable needs a clear justification. All indicators must be measurable, verifiable and linked to activities, outcomes and deliverables.

KPI class Official indicator Proposal design implication
Baseline topic KPI Number of entities benefiting from project activities, especially SMEs Define what counts as a beneficiary and avoid counting unverified reach
Baseline topic KPI Number of AI-powered infrastructures, tools and services developed, adapted, tested and validated for SME use Separate development, test and validation states with acceptance evidence
Optional topic KPI Tools and services supporting reporting, recovery and information exchange with competent authorities Measure operational connections and completed workflows
Optional topic KPI AI-powered functions for incident prediction, response or notification Define deployed functions and performance criteria
Optional topic KPI Training, awareness or onboarding activities delivered to SMEs Measure participation, completion and changed capability

Projects may add justified KPIs. Additional indicators should close a real evidence gap, such as adoption quality, reduction in response time, successful mitigation or model robustness; they should not inflate the reporting burden without helping evaluation or delivery.

A Practical Work-Package Model

The following structure is a planning pattern, not a mandatory template from ECCC.

Work package Purpose Representative outputs
WP1 Governance and security Manage delivery, ethics, ownership-control obligations and risk Governance model, security plan, risk register
WP2 SME needs and baseline Segment users and establish measurable starting conditions Personas, maturity baseline, requirements and pilot protocol
WP3 Product adaptation Develop or adapt AI-enabled cyber capabilities Architecture, integrations, model controls and releases
WP4 Validation and pilots Test security, performance, usability and operational fit Test reports, pilot evidence and acceptance decisions
WP5 Adoption and support Onboard SMEs, train users and operate support workflows Deployment records, training, service procedures and recovery guidance
WP6 Dissemination and exploitation Build market uptake and sustainability beyond the grant Exploitation plan, dissemination evidence and scale-up model

Each work package should own deliverables and KPIs. The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables on relevant KPIs and project outputs.

How Evaluators Will Read the Proposal

Criterion AI4SME evidence to emphasize Pass threshold
Relevance Direct match to SME adoption, official activity paths, secure AI and topic outcomes 3/5
Implementation Mature architecture, credible pilots, roles, resources, security controls and measurable plan 3/5
Impact Number and quality of SME deployments, reusable capability, market uptake and societal benefit 3/5
Overall Combined score 10/15

For AI4SME, the award subcriteria concerning overcoming lack of market finance and environmental sustainability or European Green Deal effects are explicitly not applicable. The remaining criteria still require a coherent European impact and implementation case.

Passing the thresholds does not guarantee funding. Proposals are ranked within the topic budget, and legal, financial and security checks continue during grant preparation.

Eligibility, Documents and Timeline

Beneficiaries and affiliated entities must be eligible legal entities established in EU Member States or in Norway, Iceland or Liechtenstein. Participation in any capacity is limited by the call's establishment and ownership-control rules, and project activities, including subcontracted work, must take place in eligible countries.

The application package includes online Part A, a technical Part B limited to 70 pages, and required ownership-control declarations, including for relevant associated partners and subcontractors. Submission is exclusively electronic through the Funding & Tenders Portal.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Confirm that SME adoption and deployment, not generic AI research, is the project's primary outcome.
  2. Select at least one official activity path and map every work package to it.
  3. Define the SME segment, baseline, adoption barriers, pilot environments and validation method.
  4. Document secure and trustworthy AI controls, human oversight, privacy and model limitations.
  5. Assign consortium roles around measurable delivery rather than organization count.
  6. Calculate the 50% or 75% rate correctly for each participant and build a credible co-financing model.
  7. Include the two baseline topic KPIs and justify the treatment of every optional or non-applicable indicator.
  8. Connect deliverables, milestones, KPIs, budget and expected outcomes without contradictions.
  9. Complete ownership and control checks for every relevant entity and subcontractor.
  10. Use the live portal templates, keep Part B within 70 pages and submit before the absolute deadline.

Frequently Asked Questions

Is AI4SME only for SMEs?

No. SMEs are the primary beneficiaries of the capabilities and receive the higher rate on their eligible costs, but targeted stakeholders also include startups, research and academia, public-sector bodies, NIS 2 entities, industry actors and AI-function providers.

Does every consortium partner receive 75% funding?

No. The topic rate is 50%, with 75% for SMEs. A consortium must apply the correct rate to each participant and eligible-cost position under the call and Grant Agreement.

Must the project build a new product from scratch?

No. The scope permits development or adaptation and explicitly supports market uptake of innovative, market-ready solutions, including relevant results from EU-supported research projects. Validation and deployment remain essential.

Is a SaaS toolkit mandatory?

The call foresees a toolkit tailored to SMEs and requires at least one of the listed activity paths. A proposal must show how its chosen path satisfies the official scope; it should not assume that merely labeling a service "SaaS" establishes compliance.

Is an AI chatbot for incident reporting enough?

Not by itself. An incident interface should connect reporting, reaction guidance and access to response support. The proposal also needs secure data handling, human oversight, escalation logic, validation and measurable outcomes.

Is a consortium mandatory?

The common rules set no minimum consortium for AI4SME, and a single applicant may submit where permitted. The applicant must still demonstrate all technical, operational, financial and adoption capabilities needed for the action.

Does reaching 10/15 guarantee an award?

No. The proposal must score at least 3/5 on every criterion, reach 10/15 overall, rank within the available budget and pass subsequent legal, financial and security checks.

Conclusion

AI4SME is strongest for projects that can turn secure AI-enabled cybersecurity into verified SME practice. The proposal must connect a real SME constraint to a usable tool or service, deploy it in representative environments, prove trustworthy operation and measure adoption and resilience outcomes.

We can help you structure SME cyber-risk baselines, evidence ownership and measurable validation plans, starting from the Cyber Check-up and with the support of a virtual CISO. Final scope, eligibility, cost and submission decisions must remain anchored to the official call document and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 28, 2026

ECCC Cybersecurity Call 2027: Eligibility and Application Guide

A step-by-step check of the common rules of DIGITAL-ECCC-2027-DEPLOY-CYBER-11: legal eligibility, establishment and control restrictions, consortium …

September 27, 2026

Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics

The ECCC opened a €96 million Digital Europe call across seven cybersecurity topics, with a single-stage deadline of 14 January 2027 at 17:00 CET. Ho…

February 20, 2026

SECURE First Open Call 2026: What mSMEs Need to Submit Before 29 March 2026

The SECURE First Open Call (28 Jan - 29 Mar 2026) offers up to EUR 30,000 per project at 50% co-financing to help mSMEs achieve Cyber Resilience Act …