ECCC Cybersecurity Call 2027: Eligibility and Application Guide

A step-by-step check of the common rules of DIGITAL-ECCC-2027-DEPLOY-CYBER-11: legal eligibility, establishment and control restrictions, consortium design, financial and operational capacity, the application package and the 10/15 scoring threshold.

September 28, 2026 14 min read

Small business owner preparing a funding application Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. The Eligibility Chain at a Glance
  4. Gate 1: Confirm Topic Fit and Legal Eligibility
  5. Gate 2: Validate Establishment, Ownership and Control
  6. Gate 3: Design a Compliant Consortium
  7. Gate 4: Prove Capacity and Avoid Exclusion
  8. Gate 5: Assemble an Admissible Application
  9. Funding Model and Expected Contribution
  10. How Evaluation and Ranking Work
  11. Submission Sequence
  12. Application Timeline
  13. Pre-Submission Checklist
  14. Frequently Asked Questions
  15. Conclusion
  16. Guides in the ECCC 2027 Series
  17. Official Sources

Applies to: public and private organizations, SMEs, research bodies, cybersecurity providers, public authorities and consortium coordinators preparing a proposal under DIGITAL-ECCC-2027-DEPLOY-CYBER-11.

An admissible application to the 2027 ECCC cybersecurity call must match one of the seven topics, involve eligible legal entities established and controlled in the EU or eligible EEA countries, use the live Funding & Tenders templates, and be submitted electronically by 14 January 2027 at 17:00 CET. Part B is limited to 70 pages, ownership and control restrictions apply to every topic, and a proposal must score at least 3/5 on each evaluation criterion and 10/15 overall. Passing those thresholds does not guarantee funding (official call document).

In Brief

  • Eligibility is a chain of gates: topic fit, legal status, country of establishment, ownership and control, consortium composition, capacity, admissibility and timely submission.
  • Eligible applicants are generally public or private legal entities established in EU Member States or the EEA countries Norway, Iceland and Liechtenstein.
  • Security restrictions under Article 12(5) of the Digital Europe Programme Regulation apply to all seven topics and extend to associated partners, subcontractors and recipients of financial support.
  • A single applicant may submit where the chosen topic permits it; only REGCABH has an explicit common-section minimum of two independent applicants from two eligible countries.
  • Part A is completed online, Part B is uploaded as a PDF, and mandatory annexes must be placed in the correct Submission System slots.
  • Expected EU contributions range from €1.5 million to €5 million per project, depending on the topic, but the stated values are planning expectations rather than automatic awards or absolute caps.
  • Registration in the European Cybersecurity Competence Community is encouraged, not mandatory.

Scope and Source Boundary

This guide converts the common rules in sections 3-13 and Annexes 1-4 of the call document into an operational readiness sequence. It does not replace the topic description, the live Submission System, the Model Grant Agreement or a formal eligibility assessment.

The call is open from 1 September 2026 until 14 January 2027 at 17:00 CET and has an estimated total budget of €96 million. Budget availability remains subject to final adoption of the 2025-2027 Work Programme amendment. The granting authority may redistribute funds or leave part of the budget unawarded (ECCC call overview).

The Eligibility Chain at a Glance

Gate Question to resolve Evidence to prepare Failure consequence
Topic fit Does the project correspond wholly or partly to the selected topic? Scope-to-activity and outcome mapping Proposal is ineligible or scores poorly on Relevance
Legal eligibility Is each beneficiary an eligible legal entity in an eligible country? Participant Register data and legal-status documents Participant or proposal may be rejected
Ownership and control Is every relevant entity established and controlled from eligible countries? Ownership and control declarations and supporting records Security restriction failure
Consortium Does the composition satisfy topic rules and cover the required capabilities? Role matrix, mandates and consortium agreement plan Formal ineligibility or weak Implementation score
Capacity and exclusion Can applicants finance and deliver the action, and are they free from exclusion grounds? Financial records, team profiles, experience and declarations Replacement, safeguards or rejection
Admissibility Is the package complete, readable, within the page limit and in the correct portal slots? Part A, Part B and required annexes Inadmissibility or ignored excess pages
Evaluation Does the proposal meet individual and overall score thresholds? Traceable evidence for Relevance, Implementation and Impact Rejection below threshold or ranking below budget line

Match the project to one topic

The project must correspond wholly or at least partly to the topic under which it is submitted. Start with the intended operational outcome, then map each work package, deliverable and KPI to the official scope. Do not select a topic only because its budget or funding rate appears more attractive.

The call contains seven topics: CYBERAI, AI4SME, COORDPREP, REGCABH, NCC, EULEG and DUALUSE. Each has different targeted stakeholders and specific conditions even though the common eligibility rules are shared.

Identify eligible legal entities

Beneficiaries and affiliated entities must generally:

  • be public or private legal entities;
  • be established in an EU Member State, including overseas countries and territories, or in Norway, Iceland or Liechtenstein;
  • register in the Participant Register before submission;
  • complete legal validation through the Central Validation Service when requested.

Natural persons are not eligible, except self-employed persons or sole traders where the business has no legal personality separate from the individual. International organizations are eligible only when they qualify as international organizations of European interest under the Digital Europe Regulation. EU bodies cannot join a consortium except for the European Commission's Joint Research Centre.

Entities without legal personality may participate only exceptionally when their representatives can assume legal obligations and provide equivalent protection for EU financial interests. Associations acting as sole beneficiaries must ensure that members implementing the action also participate in an eligible role so that their costs can be recognized (official call document).

Gate 2: Validate Establishment, Ownership and Control

All seven topics activate the call's security restrictions. This is not a check limited to the coordinator or beneficiaries.

Role Establishment and control boundary Application implication
Beneficiary or affiliated entity Must be established in and controlled from eligible countries Register the entity and prepare the required declarations
Associated partner Same security boundary applies Include ownership and control documentation where required
Subcontractor Same security boundary; work must occur in eligible countries Screen ownership before procurement and preserve evidence
Recipient of financial support Same boundary applies when third-party support is used Build eligibility and ownership checks into the support process

Project activities, including subcontracted work, must take place in eligible countries. The Grant Agreement may also impose restrictions on intellectual-property transfers, result exploitation and exclusive licensing. EEA countries benefit from a status equivalent to Member States for these security restrictions.

Ownership and control declarations are part of the proposal package, including for associated partners and subcontractors. The call document exempts entities validated as public bodies from the general all-entities declaration requirement. Applicants should still verify the exact declaration slots generated by the live Submission System.

Projects involving EU classified information face additional security scrutiny. Depending on the activity, facility and personnel clearances may be required before grant signature, and information classified TRES SECRET UE/EU TOP SECRET cannot be funded under the call.

Gate 3: Design a Compliant Consortium

The common rules set no minimum consortium composition for CYBERAI, AI4SME, COORDPREP, NCC, EULEG or DUALUSE. A single applicant can therefore submit where the topic's stakeholder and activity conditions permit it. This is not a recommendation to work alone: evaluators still assess whether the applicant or consortium has the combined capacity to deliver the work.

REGCABH is the exception. It requires:

  • at least two independent applicants that are beneficiaries, not affiliated entities;
  • applicants from two different eligible countries;
  • competent public authorities from at least two Member States concerned by the relevant sea basin.

When a project has more than one beneficiary, a consortium agreement is required. Before drafting, define the coordinator, beneficiaries, affiliated entities, associated partners and subcontractors, then connect each role to tasks, budget, decision rights, security checks and ownership of results.

Gate 4: Prove Capacity and Avoid Exclusion

Financial capacity

Applicants must have stable and sufficient resources to implement the action and finance their share. The check normally covers all beneficiaries, except public bodies, international organizations and applicants requesting no more than €60,000 individually. It may also be extended to affiliated entities.

During grant preparation, the Participant Register may request profit-and-loss statements, balance sheets, a business plan or an external audit report. If capacity is insufficient, the granting authority may require additional information, guarantees, staged prefinancing, enhanced financial responsibility, replacement of an applicant or rejection.

Operational capacity

Applicants must demonstrate suitable know-how, qualifications, staff and technical resources, including experience with projects of comparable nature and scale. This assessment is integrated into the Implementation criterion and relies primarily on:

  • profiles and experience of staff responsible for management and delivery;
  • descriptions of consortium participants and their complementary roles;
  • additional supporting evidence requested during evaluation or grant preparation.

Exclusion and integrity

Organizations subject to EU exclusion decisions, restrictive measures or applicable conditionality measures cannot participate in prohibited roles. Other exclusion grounds include insolvency, serious tax or social-security breaches, grave professional misconduct, fraud, corruption, money laundering and material failures under previous EU contracts. Applicants can also be rejected for misrepresentation, missing required information or an unremedied conflict created by prior involvement in preparing the call.

Gate 5: Assemble an Admissible Application

Use only the forms generated inside the Funding & Tenders Submission System. Files displayed on the public topic page are informational and may not be the submission templates.

Package component Required content Control point
Part A Participant data, roles and summarized project budget Complete directly online and reconcile with Part B
Part B Technical description of the action Download the mandatory Word template, complete it and upload it as PDF
Mandatory annexes Ownership and control declarations, including relevant associated partners and subcontractors Use the current portal templates and correct upload slots
Optional evidence Proof of an application to join the Cybersecurity Competence Community Include only if the membership request has actually been submitted through an NCC

Part B is limited to 70 pages. Evaluators will disregard excess pages. The call does not list a detailed budget calculator, core-team CVs, last-year activity reports or previous-project lists as mandatory annexes, but the live portal remains decisive if its generated package changes.

The coordinator must confirm its mandate to act for all applicants and confirm that the application is correct, complete and compliant with EU funding conditions. Before grant signature, each beneficiary and affiliated entity must reconfirm through a declaration of honour. All uploaded documents must be readable, accessible and printable.

Funding Model and Expected Contribution

Topic Expected EU contribution per project Funding rate
CYBERAI €3-5 million 50%
AI4SME €3-5 million 50%; 75% for SMEs
COORDPREP €1.5 million 50%
REGCABH €2.5 million 70%
NCC €2-3 million 50%
EULEG €3-5 million 50%
DUALUSE €3-5 million 50%

The call permits a different requested amount when it is duly justified, and the awarded grant may be lower than the request. Funding is provided through a budget-based mixed actual-cost grant: only eligible costs actually incurred can be reimbursed, with the specified unit-cost and flat-rate elements. Indirect costs use a 7% flat rate on eligible direct-cost categories, subject to the exclusions in the call.

The grant cannot generate a profit. A proposal therefore needs a credible co-financing model, cost ownership by partner, cash-flow assumptions and a budget that traces directly to work packages and deliverables.

How Evaluation and Ranking Work

Formal admissibility and eligibility checks come first. Eligible proposals are then assessed for operational capacity and scored separately within each topic.

Criterion Core evidence Pass threshold
Relevance Direct topic alignment, policy contribution and European or national synergies 3/5
Implementation Project maturity, sound plan, efficient resources and delivery capacity 3/5
Impact Expected outcomes, dissemination, competitiveness and societal benefit 3/5
Overall Combined score 10/15

A proposal must pass all three individual thresholds and the overall threshold. It is then considered for funding within the available budget; it does not acquire an entitlement to a grant.

For tied proposals, priority first favors themes not already covered by higher-ranked projects, then the higher Relevance score, followed by Impact. The evaluation panel may subsequently consider portfolio synergies and geographical or thematic balance. Even an invitation to grant preparation is not a funding commitment because legal-entity, financial-capacity and exclusion checks still remain.

Submission Sequence

  1. Select the topic and document how each work package fits its official activities and outcomes.
  2. Create EU Login accounts and register every required organization in the Participant Register.
  3. Obtain the 9-digit PIC and start legal validation early.
  4. Classify every participant role and verify country, ownership, control and security constraints.
  5. Confirm consortium composition and prepare a consortium agreement when more than one beneficiary participates.
  6. Build the work plan, deliverables, milestones, KPIs and partner budgets from the topic text.
  7. Complete Part A online and reconcile its participants and summarized budget with Part B.
  8. Complete Part B in the live template, keep it within 70 pages and upload it as PDF.
  9. Upload each declaration and annex in the correct category, then run a completeness and readability review.
  10. Submit before 14 January 2027 at 17:00 CET and verify receipt of the confirmation email.

After the deadline, the Submission System closes. If no confirmation email arrives, the call document states that the proposal has not been submitted; a suspected system fault should be reported immediately through the Funding & Tenders IT Helpdesk with the proposal and available screenshots.

Application Timeline

Date or period Milestone
1 September 2026 Call opening and start of electronic submissions
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation period
April 2027 Indicative communication of results
October 2027 Indicative grant-agreement signature

Projects normally start after grant signature. A retroactive start may be approved only exceptionally, for duly justified reasons, and never before the proposal submission date. The indicative duration is 24 months for COORDPREP and 36 months for the other six topics, although justified alternatives are not excluded.

Pre-Submission Checklist

  • The selected topic matches the project's primary operational outcome.
  • Every entity has the correct role, legal status, PIC and validation plan.
  • Establishment, direct and indirect control, work location and subcontracting have been screened.
  • The consortium meets formal topic rules and collectively covers every work package.
  • Co-financing, financial capacity and cash flow are credible for each beneficiary.
  • Team profiles and participant descriptions demonstrate operational capacity.
  • Part A, Part B, partner roles, work packages, KPIs and budget are internally consistent.
  • Part B is within 70 pages and all files are readable, accessible and printable.
  • Ownership and control declarations are complete for every applicable role.
  • The final portal package has been reviewed and submitted early enough to resolve technical issues.

Frequently Asked Questions

Can an organization established outside the EU apply?

Eligible entities may be established in EU Member States or the EEA countries Norway, Iceland and Liechtenstein, subject to ownership, control and security rules. Other country-association scenarios should be checked against the live call text before relying on them.

Is a consortium mandatory?

Not under the common composition rules for six topics. REGCABH requires at least two independent beneficiaries from two eligible countries and competent authorities from at least two Member States concerned by the relevant sea basin. Topic-specific stakeholder conditions still apply everywhere.

Is Cybersecurity Competence Community membership mandatory?

No. Membership is encouraged but not required. An applicant may attach proof of a membership request submitted through its National Coordination Centre. Italian organizations can review the official role of NCC-IT.

Is the expected contribution a maximum grant amount?

No. It is the amount or range expected per project. A different request may be considered when duly justified, and the final award may be lower than the amount requested.

What happens if Part B exceeds 70 pages?

Evaluators disregard pages beyond the limit. Essential evidence must therefore remain inside the permitted section and page structure.

Does a 10/15 score guarantee funding?

No. The proposal must also pass each 3/5 criterion threshold, rank within the available topic budget and pass subsequent legal and financial checks.

Can the proposal be submitted by email or on paper?

No. Submission is exclusively electronic through the Funding & Tenders Portal Submission System.

Conclusion

The decisive question is not only whether an organization has a good cybersecurity idea. A fundable ECCC proposal must survive a linked sequence of topic, entity, control, consortium, capacity, document and evaluation gates. The safest approach is to resolve legal and security eligibility first, then build work packages, evidence and budget around the exact topic conditions.

Before drafting starts, our Virtual CISO service can help you map cybersecurity capabilities, regulatory requirements, evidence ownership and partner responsibilities; the Cyber Check-up gives you a documented starting point. Final eligibility and submission decisions must remain anchored to the official call document and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

  • Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics
  • ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers
  • ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability
  • ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations
  • ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing
  • ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems
  • ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security
  • ECCC Dual-Use Cybersecurity Funding 2027: From Civilian-Defence Cooperation to Deployment

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 27, 2026

Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics

The ECCC opened a €96 million Digital Europe call across seven cybersecurity topics, with a single-stage deadline of 14 January 2027 at 17:00 CET. Ho…

February 20, 2026

SECURE First Open Call 2026: What mSMEs Need to Submit Before 29 March 2026

The SECURE First Open Call (28 Jan - 29 Mar 2026) offers up to EUR 30,000 per project at 50% co-financing to help mSMEs achieve Cyber Resilience Act …

June 10, 2024

Aegister project funded under Campania Region grant

Aegister S.p.A. has received funding for a cybersecurity project aimed at high-risk SMEs. The project is currently in progress and focuses on develop…