ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing

The COORDPREP topic funds coordinated preparedness testing and wider preparedness services, led by designated public cybersecurity bodies with private partners in support. The two tracks, the testing method, the KPIs and the evidence to plan.

October 02, 2026 14 min read

Operations room during incident handling, with a manager on the phone Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. COORDPREP at a Glance
  4. Choose the Correct Preparedness Track
  5. Part 1: Common Scenarios for Four Critical Contexts
  6. The Three-Phase Testing Method
  7. Part 2: Broader Preparedness Services
  8. Public Leadership and Partner Roles
  9. Safe Testing and Evidence Governance
  10. Expected Outcomes and KPI Contract
  11. A Practical Work-Package Model
  12. Funding, Evaluation and Security Conditions
  13. Application Package and Timeline
  14. Readiness Checklist
  15. Frequently Asked Questions
  16. Conclusion
  17. Guides in the ECCC 2027 Series
  18. Official Sources

Applies to: designated public cybersecurity bodies, competent authorities, CSIRTs, national SOCs or Cyber Hubs, critical-sector operators and specialist partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP.

COORDPREP finances Member State cyber-preparedness actions through two routes: coordinated testing for selected high-criticality sectors and other preparedness actions across NIS 2 critical sectors. The topic has a €15 million budget, expects an EU contribution of about €1.5 million per project, applies a 50% funding rate and has an indicative duration of 24 months. Proposals are due by 14 January 2027 at 17:00 CET. The action is targeted at public bodies designated or entrusted by a Member State with cybersecurity responsibilities; relevant public and private partners may support delivery (official call document).

In Brief

  • Part 1 covers coordinated preparedness testing in electricity, rail, ports and public administration using the common risk scenarios in Annex 3.
  • A Part 1 proposal must include at least the relevant baseline, low-stress scenario; medium- and high-stress layers may be added and adapted to the national context.
  • Part 2 supports broader preparedness in sectors from Annexes I and II of NIS 2, including risk monitoring, supply-chain assessment, coordinated vulnerability disclosure, exercises and training.
  • Public cybersecurity bodies are the target applicants; private testing, technology and training providers can participate as implementation partners but do not replace the competent public authority.
  • The mandatory topic KPI is the number of essential and important entities supported through coordinated testing or other preparedness actions.
  • Article 12(5) security restrictions and ownership-and-control declarations apply to every participation role.
  • COORDPREP is operational funding: proposals need authorized test environments, safe execution controls, measurable remediation and evidence that results will improve preparedness.

Scope and Source Boundary

This guide explains the two official action tracks, target stakeholders, test method, expected outcomes, funding mechanics and evidence needed for a credible proposal. It does not determine the eligibility of a specific applicant, entity or activity and does not replace the live Funding & Tenders record, the official call document or applicable procurement and cybersecurity law.

The topic implements preparedness actions under the Cybersecurity Emergency Mechanism established by the Cyber Solidarity Act. Its purpose is to complement, not duplicate, national and Union work and to help Member States improve protection and resilience for critical installations and infrastructures (ECCC call overview).

COORDPREP at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP
Topic budget €15 million
Type of action Simple Grant
Funding rate 50%
Expected EU contribution €1.5 million per project
Indicative duration 24 months
Consortium minimum None in the common composition rules
Equipment-cost treatment Depreciation and full cost for listed equipment
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The expected contribution is a planning value, not an automatic award or fixed ceiling. A different requested amount may be considered if it is duly justified, and the awarded grant may be lower than the amount requested.

Choose the Correct Preparedness Track

The first design decision is whether the project addresses Part 1, Part 2 or a coherent combination of both.

Decision factor Part 1: coordinated testing Part 2: other preparedness actions
Primary scope Common, scenario-led testing across selected high-criticality sectors Wider preparedness support for NIS 2 high-criticality and other critical sectors
Sectors Electricity; rail; water transport focused on ports; public administration Sectors in NIS 2 Annexes I and II not selected for Part 1, plus broader eligible preparedness activity
Mandatory design anchor Relevant Annex 3 scenario, including at least the baseline level Defined risk, target sector and measurable preparedness need
Typical actions Penetration tests, vulnerability testing, security audits, exercises, resilience stress tests, threat and risk assessment Supply-chain risk assessment, attack-surface and vulnerability monitoring, CVD, exercises, workshops and training
Main evidence Test scope, authorization, scenario, safe execution, findings and remediation Service coverage, adoption, risk reduction, skills or process improvement and follow-up

A proposal should not label an ordinary penetration-test procurement as coordinated preparedness. Part 1 requires a common risk-scenario basis, a sector-specific national action and a path from testing to remediation and aggregated lessons learned.

Part 1: Common Scenarios for Four Critical Contexts

Annex 3 uses a baseline, medium and high stress structure. Each applicant may select relevant scenarios and adapt them to national needs, but the proposal must include at least the baseline scenario for the selected sector or subsector.

Sector or subsector Annex 3 baseline scenario Escalation focus
Electricity Supply-chain compromise affecting renewable-energy market platforms and grid stakeholders Ransomware, destructive attacks, grid stress and cross-border effects
Ports Ransomware affecting port IT systems OT/ICS disruption and coordinated multimodal disruption
Rail Ransomware affecting railway customer services Attacks on traffic-management IT/OT and combined cyber-physical disruption
Public administration DDoS, website defacement and phishing Supply-chain compromise, ransomware, espionage and destructive malware

The scenarios are not scripts to copy unchanged. Applicants may refine them for national maturity, interdependencies and sector conditions. The call encourages coverage of supply-chain failures, simultaneous incidents, system faults, human error, malicious acts and natural phenomena. This matters because preparedness is measured under realistic escalation, not only through isolated technical findings.

The Three-Phase Testing Method

The call sets out a common illustrative method for coordinated testing.

1. Systemic Risk Analysis

Identify stakeholders, define primary and secondary objectives, choose the evaluation type, design the test structure, refine the scenario and run pilots to confirm reliability and validity. Before testing begins, the proposal should establish system boundaries, critical services, dependencies, safety constraints, authorization and success criteria.

2. Testing

Testing may include vulnerability scanning, security audits, penetration testing, exercises and cyber-resilience stress tests. The chosen methods should cover ICT and, where relevant, operational technology or industrial control systems without putting essential services at unacceptable risk.

3. Gap Analysis and Remediation

Convert findings into gaps, recommendations and an action plan. Results should enter the tested entity's remediation plan and be sent to the relevant Member State authority for review. Lessons learned should be shared with the Commission in anonymized, aggregated form and may support follow-up work in the NIS Cooperation Group.

This final phase is decisive. A project that counts tests but cannot show ownership, deadlines, retesting and closure of critical findings has not demonstrated improved preparedness.

Part 2: Broader Preparedness Services

Part 2 extends beyond the four Part 1 contexts. It can reuse vulnerability testing and threat-assessment activities while supporting entities in the high-criticality and other critical sectors listed in NIS 2 Annexes I and II.

Eligible activity families include:

  • supply-chain risk management within risk-assessment services;
  • continuous attack-surface, asset, risk and vulnerability monitoring;
  • coordinated vulnerability disclosure policies and processes;
  • timely patch information and standardized exchange between researchers, vendors and CSIRTs;
  • applications that combine vulnerability information from multiple sources using open standards or technologies;
  • exercises, workshops and training for cybersecurity professionals;
  • continuous learning aligned with EU cybersecurity requirements.

Training should not be measured only by attendance. A strong design connects competencies to roles, uses the European Cybersecurity Skills Framework, tests learning and records whether organizations can perform the intended preparedness task after the intervention.

Public Leadership and Partner Roles

For both parts, the topic targets public bodies designated or entrusted by the relevant Member State with cybersecurity responsibilities, including NIS 2 competent authorities and CSIRTs. The call also refers to national sectoral CSIRTs, SOCs and Cyber Hubs in the operational support context.

Relevant public or private partners may join to implement preparedness activities. A practical role model is:

Role Expected contribution
Designated public body National mandate, sector selection, governance, authority liaison and result review
Sector authority or operator Critical-service context, systems, dependencies, test windows and remediation ownership
CSIRT, SOC or Cyber Hub Threat intelligence, monitoring, exercise control and incident-response integration
Testing provider Authorized scanning, audit, penetration testing and technical evidence
Cyber-range or platform provider Safe simulation environment, scenario tooling and repeatable exercises
Research or training partner Methodology, evaluation, skills development and independent analysis

There is no formal consortium minimum for this topic. That does not remove the stakeholder requirement: a proposal still needs the designated public-body mandate and access to representative entities or environments. Annex 3 also notes the Cyber Solidarity Act rule that grants for this support may be awarded only to beneficiaries that are contracting authorities or contracting entities. Applicant and partner roles should therefore be checked carefully against the live topic conditions.

Safe Testing and Evidence Governance

Preparedness testing can touch production-like ICT, OT and public services. Governance should be designed before technical execution.

Define at least:

  1. written authorization, scope and rules of engagement for every tested entity;
  2. prohibited actions, stop conditions, safety observers and escalation contacts;
  3. test-data classification, secure evidence storage and need-to-know access;
  4. separation between simulation, staging and production activities;
  5. notification and incident-handling rules if a real compromise is discovered;
  6. coordinated disclosure, patching and retest procedures;
  7. anonymization and aggregation before lessons are shared outside the national context;
  8. remediation owners, priorities, deadlines and closure evidence.

For OT and critical infrastructure, availability and physical safety must shape the test method. A more aggressive scenario is not automatically a better test if it creates uncontrolled operational risk.

Expected Outcomes and KPI Contract

The expected outcomes differ by part but share a common result: measurable improvement in cooperation, preparedness and resilience.

Outcome family Evidence of completion
Preparedness testing Authorized test records, scenario coverage, validated findings and remediation plans
Threat and risk assessment Documented method, assessed entities, prioritized risks and accepted recommendations
Risk monitoring Assets covered, monitoring period, alerts validated and response workflow used
Vulnerability disclosure Intake and coordination process, affected parties, patch communication and closure metrics
Exercises and training Scenarios delivered, roles exercised, capability gaps and post-exercise improvement
Cooperation Authorities, CSIRTs and operators connected through repeatable workflows

The mandatory topic KPI is the number of essential and important entities supported through coordinated preparedness testing or other preparedness actions.

Optional topic KPIs include the number of penetration tests, threat assessments or risk-scenario analyses, risk-monitoring services, discovered vulnerabilities and cross-border actions or exercises. Each applicable KPI needs a baseline, target, unit, evidence source, collection frequency and responsible partner. A non-applicable KPI must be identified and justified; additional indicators may be proposed where useful.

A Practical Work-Package Model

This is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Governance and authorization Establish mandate, entities, security, data and test controls Governance model, rules of engagement, risk register
WP2 Scenario and systemic-risk design Select or refine scenarios and dependencies Sector map, test objectives, pilot and acceptance criteria
WP3 Testing or preparedness delivery Execute Part 1 tests or Part 2 services Test records, monitoring services, exercises or training
WP4 Gap and remediation management Turn observations into corrective action Findings register, recommendations, action plans and retests
WP5 Measurement and lessons learned Prove outcomes and share safe aggregate insight KPI evidence, anonymized lessons and authority reporting
WP6 Sustainability and uptake Continue capability after the grant Operating model, service ownership and reuse plan

The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables on relevant KPIs and project outputs.

Funding, Evaluation and Security Conditions

COORDPREP is a Simple Grant with a 50% funding rate. The grant uses eligible actual costs with defined unit-cost and flat-rate elements. Indirect costs use a 7% flat rate on applicable eligible direct costs, and the topic permits depreciation plus full cost for listed equipment.

Proposals are scored on Relevance, Implementation and Impact. Each criterion requires at least 3/5, and the overall threshold is 10/15. For this topic, two general subcriteria do not apply: overcoming lack of market finance and contribution to environmental sustainability or European Green Deal goals.

Article 12(5) security restrictions apply. Participation in any capacity is limited to entities established in and controlled from eligible countries, and activities, including subcontracted work, must take place there. Beneficiaries and affiliated entities must generally be established in an EU Member State or in Norway, Iceland or Liechtenstein. Ownership-and-control declarations are part of the application package, subject to the call's public-body exception and validation rules.

Passing the scoring thresholds does not guarantee funding. Projects must rank within the available budget and pass legal, financial, exclusion, ownership and security checks.

Application Package and Timeline

Applications are submitted electronically through the Funding & Tenders Portal. Part A contains administrative and budget information; Part B contains the technical description and is limited to 70 pages. Applicants must use the forms available inside the submission system, not informational copies downloaded elsewhere.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Confirm the designated public-body mandate and choose Part 1, Part 2 or a justified combination.
  2. For Part 1, select an Annex 3 sector and include at least its baseline scenario.
  3. Identify participating essential or important entities and obtain authorization for representative environments.
  4. Map ICT, OT, supply-chain and interdependency risks before selecting test methods.
  5. Define rules of engagement, safety limits, evidence handling and real-incident escalation.
  6. Connect every finding to remediation, ownership, retesting and closure evidence.
  7. Set the mandatory entity KPI and relevant optional indicators with auditable data sources.
  8. Allocate public, operator, CSIRT, testing, platform and training roles without gaps.
  9. Verify establishment, ownership, control, subcontracting and activity-location restrictions.
  10. Build the 50% co-financing plan and submit the live portal package before the deadline.

Frequently Asked Questions

Can a private cybersecurity company apply alone?

The common rules list no minimum consortium size, but the topic is expressly targeted at public bodies designated or entrusted by Member States with cybersecurity responsibilities. Private partners may support implementation. A private vendor should not assume that it can replace the designated public-body role; the proposed legal and consortium structure must be verified against the live call conditions.

Must every proposal address both Part 1 and Part 2?

No. Proposals should contribute to at least one objective. A combined proposal is credible only when the two parts share a coherent target, delivery model and evidence chain.

Can Part 1 test any NIS 2 sector?

No. Part 1 is limited to the selected contexts: electricity, rail, ports and public administration. Other Annex I and II sectors are addressed through Part 2 preparedness actions.

Is the baseline scenario optional?

No for Part 1. The proposal must include at least the relevant baseline, low-stress scenario. Applicants may also include medium- and high-stress scenarios and adapt them to national conditions.

Are penetration tests the only eligible activity?

No. The scope includes vulnerability testing, audits, exercises, resilience stress tests, threat and risk assessment, monitoring, coordinated vulnerability disclosure and training, depending on the selected part.

Is €1.5 million the maximum grant?

No. It is the expected EU contribution per project. A different amount may be considered when duly justified, and the final award may be lower than requested.

Does a passing score guarantee funding?

No. A proposal must pass each criterion and the overall threshold, rank within the available budget and satisfy subsequent legal, financial and security checks.

Conclusion

COORDPREP is for public-led projects that convert shared risk scenarios and practical preparedness services into safer testing, measurable gaps and completed remediation. The strongest proposals will align the correct track, competent authority, sector entities, delivery partners, safety controls, KPIs and follow-up from the beginning.

For operators taking part in the tests, our Virtual CISO service can help you structure assessments, remediation workflows and risk registers, and prepare your NIS 2 incident notification process. Final eligibility, procurement, legal, cost and submission decisions must remain anchored to the official call document, applicable law and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 30, 2026

ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability

The EULEG topic funds shared capacity to implement EU cybersecurity law, from NIS 2 reporting to CRA testing and certification. What it pays for, wha…

October 01, 2026

ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations

The CYBERAI topic funds secure, trustworthy AI for detection, threat intelligence, response and self-healing in European cyber operations. How it dif…

September 29, 2026

ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers

The AI4SME topic funds AI-enabled cybersecurity tools and services that European SMEs actually adopt. Budget, the 75% SME funding rate, eligible acti…