Applies to: designated public cybersecurity bodies, competent authorities, CSIRTs, national SOCs or Cyber Hubs, critical-sector operators and specialist partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP.
COORDPREP finances Member State cyber-preparedness actions through two routes: coordinated testing for selected high-criticality sectors and other preparedness actions across NIS 2 critical sectors. The topic has a €15 million budget, expects an EU contribution of about €1.5 million per project, applies a 50% funding rate and has an indicative duration of 24 months. Proposals are due by 14 January 2027 at 17:00 CET. The action is targeted at public bodies designated or entrusted by a Member State with cybersecurity responsibilities; relevant public and private partners may support delivery (official call document).
In Brief
- Part 1 covers coordinated preparedness testing in electricity, rail, ports and public administration using the common risk scenarios in Annex 3.
- A Part 1 proposal must include at least the relevant baseline, low-stress scenario; medium- and high-stress layers may be added and adapted to the national context.
- Part 2 supports broader preparedness in sectors from Annexes I and II of NIS 2, including risk monitoring, supply-chain assessment, coordinated vulnerability disclosure, exercises and training.
- Public cybersecurity bodies are the target applicants; private testing, technology and training providers can participate as implementation partners but do not replace the competent public authority.
- The mandatory topic KPI is the number of essential and important entities supported through coordinated testing or other preparedness actions.
- Article 12(5) security restrictions and ownership-and-control declarations apply to every participation role.
COORDPREPis operational funding: proposals need authorized test environments, safe execution controls, measurable remediation and evidence that results will improve preparedness.
Scope and Source Boundary
This guide explains the two official action tracks, target stakeholders, test method, expected outcomes, funding mechanics and evidence needed for a credible proposal. It does not determine the eligibility of a specific applicant, entity or activity and does not replace the live Funding & Tenders record, the official call document or applicable procurement and cybersecurity law.
The topic implements preparedness actions under the Cybersecurity Emergency Mechanism established by the Cyber Solidarity Act. Its purpose is to complement, not duplicate, national and Union work and to help Member States improve protection and resilience for critical installations and infrastructures (ECCC call overview).
COORDPREP at a Glance
| Parameter | Official value |
|---|---|
| Topic | DIGITAL-ECCC-2027-DEPLOY-CYBER-11-COORDPREP |
| Topic budget | €15 million |
| Type of action | Simple Grant |
| Funding rate | 50% |
| Expected EU contribution | €1.5 million per project |
| Indicative duration | 24 months |
| Consortium minimum | None in the common composition rules |
| Equipment-cost treatment | Depreciation and full cost for listed equipment |
| Part B limit | 70 pages |
| Submission deadline | 14 January 2027, 17:00 CET |
The expected contribution is a planning value, not an automatic award or fixed ceiling. A different requested amount may be considered if it is duly justified, and the awarded grant may be lower than the amount requested.
Choose the Correct Preparedness Track
The first design decision is whether the project addresses Part 1, Part 2 or a coherent combination of both.
| Decision factor | Part 1: coordinated testing | Part 2: other preparedness actions |
|---|---|---|
| Primary scope | Common, scenario-led testing across selected high-criticality sectors | Wider preparedness support for NIS 2 high-criticality and other critical sectors |
| Sectors | Electricity; rail; water transport focused on ports; public administration | Sectors in NIS 2 Annexes I and II not selected for Part 1, plus broader eligible preparedness activity |
| Mandatory design anchor | Relevant Annex 3 scenario, including at least the baseline level | Defined risk, target sector and measurable preparedness need |
| Typical actions | Penetration tests, vulnerability testing, security audits, exercises, resilience stress tests, threat and risk assessment | Supply-chain risk assessment, attack-surface and vulnerability monitoring, CVD, exercises, workshops and training |
| Main evidence | Test scope, authorization, scenario, safe execution, findings and remediation | Service coverage, adoption, risk reduction, skills or process improvement and follow-up |
A proposal should not label an ordinary penetration-test procurement as coordinated preparedness. Part 1 requires a common risk-scenario basis, a sector-specific national action and a path from testing to remediation and aggregated lessons learned.
Part 1: Common Scenarios for Four Critical Contexts
Annex 3 uses a baseline, medium and high stress structure. Each applicant may select relevant scenarios and adapt them to national needs, but the proposal must include at least the baseline scenario for the selected sector or subsector.
| Sector or subsector | Annex 3 baseline scenario | Escalation focus |
|---|---|---|
| Electricity | Supply-chain compromise affecting renewable-energy market platforms and grid stakeholders | Ransomware, destructive attacks, grid stress and cross-border effects |
| Ports | Ransomware affecting port IT systems | OT/ICS disruption and coordinated multimodal disruption |
| Rail | Ransomware affecting railway customer services | Attacks on traffic-management IT/OT and combined cyber-physical disruption |
| Public administration | DDoS, website defacement and phishing | Supply-chain compromise, ransomware, espionage and destructive malware |
The scenarios are not scripts to copy unchanged. Applicants may refine them for national maturity, interdependencies and sector conditions. The call encourages coverage of supply-chain failures, simultaneous incidents, system faults, human error, malicious acts and natural phenomena. This matters because preparedness is measured under realistic escalation, not only through isolated technical findings.
The Three-Phase Testing Method
The call sets out a common illustrative method for coordinated testing.
1. Systemic Risk Analysis
Identify stakeholders, define primary and secondary objectives, choose the evaluation type, design the test structure, refine the scenario and run pilots to confirm reliability and validity. Before testing begins, the proposal should establish system boundaries, critical services, dependencies, safety constraints, authorization and success criteria.
2. Testing
Testing may include vulnerability scanning, security audits, penetration testing, exercises and cyber-resilience stress tests. The chosen methods should cover ICT and, where relevant, operational technology or industrial control systems without putting essential services at unacceptable risk.
3. Gap Analysis and Remediation
Convert findings into gaps, recommendations and an action plan. Results should enter the tested entity's remediation plan and be sent to the relevant Member State authority for review. Lessons learned should be shared with the Commission in anonymized, aggregated form and may support follow-up work in the NIS Cooperation Group.
This final phase is decisive. A project that counts tests but cannot show ownership, deadlines, retesting and closure of critical findings has not demonstrated improved preparedness.
Part 2: Broader Preparedness Services
Part 2 extends beyond the four Part 1 contexts. It can reuse vulnerability testing and threat-assessment activities while supporting entities in the high-criticality and other critical sectors listed in NIS 2 Annexes I and II.
Eligible activity families include:
- supply-chain risk management within risk-assessment services;
- continuous attack-surface, asset, risk and vulnerability monitoring;
- coordinated vulnerability disclosure policies and processes;
- timely patch information and standardized exchange between researchers, vendors and CSIRTs;
- applications that combine vulnerability information from multiple sources using open standards or technologies;
- exercises, workshops and training for cybersecurity professionals;
- continuous learning aligned with EU cybersecurity requirements.
Training should not be measured only by attendance. A strong design connects competencies to roles, uses the European Cybersecurity Skills Framework, tests learning and records whether organizations can perform the intended preparedness task after the intervention.
Public Leadership and Partner Roles
For both parts, the topic targets public bodies designated or entrusted by the relevant Member State with cybersecurity responsibilities, including NIS 2 competent authorities and CSIRTs. The call also refers to national sectoral CSIRTs, SOCs and Cyber Hubs in the operational support context.
Relevant public or private partners may join to implement preparedness activities. A practical role model is:
| Role | Expected contribution |
|---|---|
| Designated public body | National mandate, sector selection, governance, authority liaison and result review |
| Sector authority or operator | Critical-service context, systems, dependencies, test windows and remediation ownership |
| CSIRT, SOC or Cyber Hub | Threat intelligence, monitoring, exercise control and incident-response integration |
| Testing provider | Authorized scanning, audit, penetration testing and technical evidence |
| Cyber-range or platform provider | Safe simulation environment, scenario tooling and repeatable exercises |
| Research or training partner | Methodology, evaluation, skills development and independent analysis |
There is no formal consortium minimum for this topic. That does not remove the stakeholder requirement: a proposal still needs the designated public-body mandate and access to representative entities or environments. Annex 3 also notes the Cyber Solidarity Act rule that grants for this support may be awarded only to beneficiaries that are contracting authorities or contracting entities. Applicant and partner roles should therefore be checked carefully against the live topic conditions.
Safe Testing and Evidence Governance
Preparedness testing can touch production-like ICT, OT and public services. Governance should be designed before technical execution.
Define at least:
- written authorization, scope and rules of engagement for every tested entity;
- prohibited actions, stop conditions, safety observers and escalation contacts;
- test-data classification, secure evidence storage and need-to-know access;
- separation between simulation, staging and production activities;
- notification and incident-handling rules if a real compromise is discovered;
- coordinated disclosure, patching and retest procedures;
- anonymization and aggregation before lessons are shared outside the national context;
- remediation owners, priorities, deadlines and closure evidence.
For OT and critical infrastructure, availability and physical safety must shape the test method. A more aggressive scenario is not automatically a better test if it creates uncontrolled operational risk.
Expected Outcomes and KPI Contract
The expected outcomes differ by part but share a common result: measurable improvement in cooperation, preparedness and resilience.
| Outcome family | Evidence of completion |
|---|---|
| Preparedness testing | Authorized test records, scenario coverage, validated findings and remediation plans |
| Threat and risk assessment | Documented method, assessed entities, prioritized risks and accepted recommendations |
| Risk monitoring | Assets covered, monitoring period, alerts validated and response workflow used |
| Vulnerability disclosure | Intake and coordination process, affected parties, patch communication and closure metrics |
| Exercises and training | Scenarios delivered, roles exercised, capability gaps and post-exercise improvement |
| Cooperation | Authorities, CSIRTs and operators connected through repeatable workflows |
The mandatory topic KPI is the number of essential and important entities supported through coordinated preparedness testing or other preparedness actions.
Optional topic KPIs include the number of penetration tests, threat assessments or risk-scenario analyses, risk-monitoring services, discovered vulnerabilities and cross-border actions or exercises. Each applicable KPI needs a baseline, target, unit, evidence source, collection frequency and responsible partner. A non-applicable KPI must be identified and justified; additional indicators may be proposed where useful.
A Practical Work-Package Model
This is a planning pattern, not a mandatory ECCC template.
| Work package | Purpose | Representative outputs |
|---|---|---|
| WP1 Governance and authorization | Establish mandate, entities, security, data and test controls | Governance model, rules of engagement, risk register |
| WP2 Scenario and systemic-risk design | Select or refine scenarios and dependencies | Sector map, test objectives, pilot and acceptance criteria |
| WP3 Testing or preparedness delivery | Execute Part 1 tests or Part 2 services | Test records, monitoring services, exercises or training |
| WP4 Gap and remediation management | Turn observations into corrective action | Findings register, recommendations, action plans and retests |
| WP5 Measurement and lessons learned | Prove outcomes and share safe aggregate insight | KPI evidence, anonymized lessons and authority reporting |
| WP6 Sustainability and uptake | Continue capability after the grant | Operating model, service ownership and reuse plan |
The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables on relevant KPIs and project outputs.
Funding, Evaluation and Security Conditions
COORDPREP is a Simple Grant with a 50% funding rate. The grant uses eligible actual costs with defined unit-cost and flat-rate elements. Indirect costs use a 7% flat rate on applicable eligible direct costs, and the topic permits depreciation plus full cost for listed equipment.
Proposals are scored on Relevance, Implementation and Impact. Each criterion requires at least 3/5, and the overall threshold is 10/15. For this topic, two general subcriteria do not apply: overcoming lack of market finance and contribution to environmental sustainability or European Green Deal goals.
Article 12(5) security restrictions apply. Participation in any capacity is limited to entities established in and controlled from eligible countries, and activities, including subcontracted work, must take place there. Beneficiaries and affiliated entities must generally be established in an EU Member State or in Norway, Iceland or Liechtenstein. Ownership-and-control declarations are part of the application package, subject to the call's public-body exception and validation rules.
Passing the scoring thresholds does not guarantee funding. Projects must rank within the available budget and pass legal, financial, exclusion, ownership and security checks.
Application Package and Timeline
Applications are submitted electronically through the Funding & Tenders Portal. Part A contains administrative and budget information; Part B contains the technical description and is limited to 70 pages. Applicants must use the forms available inside the submission system, not informational copies downloaded elsewhere.
| Date or period | Milestone |
|---|---|
| 1 September 2026 | Call opening |
| 14 January 2027, 17:00 CET | Submission deadline |
| February-March 2027 | Indicative evaluation |
| April 2027 | Indicative result notification |
| October 2027 | Indicative grant-agreement signature |
Readiness Checklist
- Confirm the designated public-body mandate and choose Part 1, Part 2 or a justified combination.
- For Part 1, select an Annex 3 sector and include at least its baseline scenario.
- Identify participating essential or important entities and obtain authorization for representative environments.
- Map ICT, OT, supply-chain and interdependency risks before selecting test methods.
- Define rules of engagement, safety limits, evidence handling and real-incident escalation.
- Connect every finding to remediation, ownership, retesting and closure evidence.
- Set the mandatory entity KPI and relevant optional indicators with auditable data sources.
- Allocate public, operator, CSIRT, testing, platform and training roles without gaps.
- Verify establishment, ownership, control, subcontracting and activity-location restrictions.
- Build the 50% co-financing plan and submit the live portal package before the deadline.
Frequently Asked Questions
Can a private cybersecurity company apply alone?
The common rules list no minimum consortium size, but the topic is expressly targeted at public bodies designated or entrusted by Member States with cybersecurity responsibilities. Private partners may support implementation. A private vendor should not assume that it can replace the designated public-body role; the proposed legal and consortium structure must be verified against the live call conditions.
Must every proposal address both Part 1 and Part 2?
No. Proposals should contribute to at least one objective. A combined proposal is credible only when the two parts share a coherent target, delivery model and evidence chain.
Can Part 1 test any NIS 2 sector?
No. Part 1 is limited to the selected contexts: electricity, rail, ports and public administration. Other Annex I and II sectors are addressed through Part 2 preparedness actions.
Is the baseline scenario optional?
No for Part 1. The proposal must include at least the relevant baseline, low-stress scenario. Applicants may also include medium- and high-stress scenarios and adapt them to national conditions.
Are penetration tests the only eligible activity?
No. The scope includes vulnerability testing, audits, exercises, resilience stress tests, threat and risk assessment, monitoring, coordinated vulnerability disclosure and training, depending on the selected part.
Is €1.5 million the maximum grant?
No. It is the expected EU contribution per project. A different amount may be considered when duly justified, and the final award may be lower than requested.
Does a passing score guarantee funding?
No. A proposal must pass each criterion and the overall threshold, rank within the available budget and satisfy subsequent legal, financial and security checks.
Conclusion
COORDPREP is for public-led projects that convert shared risk scenarios and practical preparedness services into safer testing, measurable gaps and completed remediation. The strongest proposals will align the correct track, competent authority, sector entities, delivery partners, safety controls, KPIs and follow-up from the beginning.
For operators taking part in the tests, our Virtual CISO service can help you structure assessments, remediation workflows and risk registers, and prepare your NIS 2 incident notification process. Final eligibility, procurement, legal, cost and submission decisions must remain anchored to the official call document, applicable law and the live Funding & Tenders record.
Guides in the ECCC 2027 Series
- Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics
- ECCC Cybersecurity Call 2027: Eligibility and Application Guide
- ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers
- ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability
- ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations
- ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems
- ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security
- ECCC Dual-Use Cybersecurity Funding 2027: From Civilian-Defence Cooperation to Deployment
Official Sources
- ECCC - Official call document, version 1.0
- ECCC - Call overview and COORDPREP summary
- EUR-Lex - Regulation (EU) 2025/38, Cyber Solidarity Act
- ENISA - European Cybersecurity Skills Framework
- ENISA - Coordinated Vulnerability Disclosure Policies in the EU
- European Commission - Funding & Tenders call search