ECCC Dual-Use Cybersecurity Funding 2027: From Civilian-Defence Cooperation to Deployment

The DUALUSE topic funds working prototypes, market-ready products and operational infrastructure with credible civilian and defence use. The fit test, the technology domains, the evidence of maturity, the KPIs and why dual-use funding is not an export classification.

October 07, 2026 14 min read

Analyst reading a printed report at a desk Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. DUALUSE at a Glance
  4. The Dual-Use Fit Test
  5. Capability Domains in Scope
  6. Deployment Contexts
  7. A Civilian-Defence Operating Model
  8. Maturity and Validation Evidence
  9. Security, Data and Supply-Chain Controls
  10. Dual-Use Funding Is Not Export Classification
  11. Expected Outcomes and Evidence
  12. Mandatory KPI Contract
  13. A Practical Work-Package Model
  14. Funding and Cost Model
  15. How Evaluators Will Read the Proposal
  16. Eligibility, Security and Application Package
  17. Readiness Checklist
  18. Frequently Asked Questions
  19. Conclusion
  20. Guides in the ECCC 2027 Series
  21. Official Sources

Applies to: civilian cybersecurity and law-enforcement stakeholders, defence ministries and agencies, industrial companies, SMEs, startups, research partners and operators considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-DUALUSE.

DUALUSE provides a €10 million envelope for concrete cybersecurity cooperation between civilian and defence communities. The expected EU contribution is €3-5 million per project, the funding rate is 50%, and the indicative duration is 36 months. Proposals are due by 14 January 2027 at 17:00 CET. The topic is deployment-oriented: it calls for working prototypes, market-ready products or operational infrastructure with credible relevance in both civilian and defence contexts, not a generic research concept or a product described as dual-use without users and validation from both spheres (official call document).

In Brief

  • Dual-use fit comes from a shared civilian-defence operational need and demonstrable use in both contexts.
  • The topic covers working prototypes, market-ready products and operational infrastructures; it does not specify a numeric technology-readiness level.
  • Example domains include quantum-safe cryptography, Zero Trust, AI-driven detection, cyber ranges and digital twins, and advanced SOAR.
  • Deployment contexts include critical infrastructure, secure communications, hybrid-threat management, SOC/CSIRT extensions and digital-forensics or public-safety use cases.
  • A multinational consortium is not mandatory, but cross-country composition can strengthen impact.
  • The mandatory KPIs measure participating civilian and defence stakeholders and documented dual-use use cases, scenarios or good practices.
  • Article 12(5) security restrictions make establishment, ownership, control, data location and subcontracting material design constraints.
  • The call's dual-use label does not itself decide export-control, classified-information or procurement obligations; those require separate assessment.

Scope and Source Boundary

This guide explains topic fit, capability areas, maturity evidence, cooperation models, expected outcomes, funding mechanics and security constraints. It does not classify a product under export-control law, authorize access to classified information, determine procurement eligibility or replace the official call and live Funding & Tenders record.

The legal basis cited by the call is Article 6(1)(f) of the Digital Europe Programme Regulation and Article 5(3)(g) of the ECCC Regulation. The objective is operational cooperation and spillover between civilian cybersecurity and cyber-defence ecosystems.

DUALUSE at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-DUALUSE
Topic budget €10 million
Type of action Simple Grant
Funding rate 50%
Expected EU contribution €3-5 million per project
Indicative duration 36 months
Multinational consortium Not mandatory; positive for impact
Equipment-cost treatment Depreciation and full cost for listed equipment
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The €3-5 million range is an expected contribution, not an automatic award or absolute ceiling. A different amount may be considered when duly justified, and the awarded grant may be lower than requested. Availability of the call budget remains subject to final adoption of the relevant 2025-2027 Work Programme amendment.

The Dual-Use Fit Test

A credible project should answer six questions with evidence.

Question Strong evidence
Is the problem shared? Specific civilian and defence missions face a materially similar cyber or hybrid threat
Is the capability truly reusable? One core architecture supports both contexts with documented adaptations
Are both user communities involved? Named civilian and defence stakeholders own requirements, pilots and acceptance
Is the result mature enough? Working prototype, market-ready product or operational infrastructure exists or is credibly delivered
Can it interoperate? Interfaces, standards, integration constraints and cross-sector workflows are defined
Can it be governed securely? Classification, ownership, control, supply chain, data and exploitation rules are workable

Merely claiming that a civilian tool “could also be used by defence” is weak. The proposal needs a common operational problem, distinct user requirements, representative environments and acceptance evidence from both spheres.

Capability Domains in Scope

The call lists examples rather than a closed catalogue.

Domain Shared operational value Evidence to plan
Quantum-safe cryptography Protect sensitive civilian and defence communications against future quantum threats Migration case, algorithms, performance, interoperability and crypto-agility
Zero Trust Architecture Reduce unauthorized access and lateral movement in critical environments Identity model, policy enforcement, segmentation, telemetry and degraded operation
AI-driven detection and response Detect anomalies, prioritize intelligence and support investigations Data rights, accuracy, robustness, human oversight, latency and adversarial tests
Cyber ranges and digital twins Simulate attacks on representative civilian and military systems Fidelity, scenarios, safety, repeatability, users and learning evidence
Advanced SOAR Coordinate and automate incident response across sectors Playbooks, authorization, integration, audit trail, rollback and response-time gains

Other cybersecurity domains are eligible where civilian and defence actors have a common interest in building working systems together. The proposal should still explain why the capability belongs under DUALUSE rather than a general cyber, AI or research topic.

Deployment Contexts

The call expects technologies to be demonstrated and deployed in operationally relevant contexts.

Critical Infrastructure Protection

Dual-use capabilities may protect undersea infrastructure, transport, communication networks, energy grids or healthcare systems against cyber and physical threats. Evidence should connect detection to an operator, authority and response workflow.

Secure Communications

Quantum-safe or other secure protocols may protect exchanges among civilian and defence stakeholders. Proposals should address key management, identity, interoperability, performance and transition from legacy systems.

Hybrid-Threat Management

Relevant scenarios include GPS jamming or spoofing, cable sabotage and ransomware combined with disinformation. A proposal should model linked physical, cyber and information effects rather than treating each threat independently.

SOC and CSIRT Extension

Civilian detection and situational-awareness functions can be extended for compatibility with military requirements. This requires defined data-release rules, classification boundaries, common formats and authority for automated or human response.

Public Safety and Digital Forensics

The topic also covers technologies addressing digital fraud, disinformation, identity theft, digital violence and evidence analysis across jurisdictions, including law-enforcement use. Legality, chain of custody, victim protection and proportionality must be designed into the operating model.

A Civilian-Defence Operating Model

The consortium should organize cooperation around shared capability rather than two parallel pilots.

Layer Civilian contribution Defence contribution Joint result
Requirements Critical services, NIS operations, law enforcement or market needs Mission assurance, defence networks and operational constraints Prioritized common and context-specific requirements
Data and intelligence Civilian telemetry, incidents and CTI Defence-relevant threat context and protected sources Governed, releasable datasets and exchange rules
Engineering Commercial technology, standards and scale Hardening, mission resilience and constrained-environment needs Reusable core with controlled adaptations
Validation Civilian operators, SOCs, CSIRTs or authorities Defence users, agencies or approved test environments Dual acceptance evidence and limitations
Deployment Market, public-service and critical-infrastructure pathways Defence adoption and secure operational integration Sustainable exploitation without uncontrolled transfer

On request from the ECCC, consortia must participate in clustering activities to define common actions and increase synergies between the two communities. Work plans should reserve qualified participation and controlled knowledge-sharing capacity for that obligation.

Maturity and Validation Evidence

The topic does not state a numeric Technology Readiness Level. Its wording nevertheless establishes a maturity boundary: the result must be a working prototype, market-ready product or operational infrastructure.

A proposal should define:

  1. the starting capability and known limitations;
  2. the target operational state at project end;
  3. representative civilian and defence environments;
  4. technical, security and operational acceptance criteria;
  5. test data, scenarios, baselines and comparison methods;
  6. interoperability and integration tests;
  7. red-team, resilience, failure and recovery tests;
  8. user acceptance and decision authority;
  9. deployment, maintenance, vulnerability-handling and support arrangements;
  10. evidence that the same core capability creates value in both contexts.

Demonstrations should test adverse conditions and operational constraints, not only ideal laboratory performance. For automated response, define human authorization, stop conditions, safe rollback and accountability.

Security, Data and Supply-Chain Controls

Civilian-defence collaboration can combine sensitive data, controlled environments and strategic technology dependencies. Security architecture must be part of the proposal, not a later work package.

Address at least:

  • security classification and releasability between partners;
  • data provenance, purpose, minimization, retention and deletion;
  • identity, least privilege, segregation and privileged-access monitoring;
  • secure development, component inventory and vulnerability management;
  • supplier, cloud, model, library and hardware dependencies;
  • secure build, update and deployment channels;
  • incident notification and coordinated vulnerability disclosure;
  • intellectual-property ownership and access rights;
  • restrictions on subcontracting, transfer, licensing and exploitation;
  • continuity, recovery and exit plans for critical suppliers.

For AI systems, the call expressly requires ethical deployment aligned with the GDPR and AI Act. Proposals should cover data quality, bias, explainability, human oversight, adversarial robustness and misuse alongside detection performance.

Dual-Use Funding Is Not Export Classification

The term “dual-use” in this topic describes operational relevance to both civilian and defence cybersecurity. It does not automatically determine whether a product, software component or technical information is controlled under the EU Dual-Use Regulation.

Applicants should separately assess, where applicable:

  • export-control classification and authorization;
  • cybersecurity export restrictions and catch-all controls;
  • end users, end use, destinations and technology transfers;
  • access by consortium staff, associated partners and subcontractors;
  • classified-information and national-security rules;
  • defence procurement and security-of-supply requirements;
  • licensing, publication, open-source and exploitation plans.

The assessment should identify responsible experts and decision gates. Marketing language about dual use is not a substitute for a documented legal and security analysis.

Expected Outcomes and Evidence

The call identifies six outcome families.

Outcome family Evidence of completion
Secure data sharing Standardized encrypted exchange, tested identities, access controls and compliant workflows
Early warning Integrated monitoring, predictive analysis, verified alerts and response pathways
Collaborative training Joint scenarios, civilian and defence participation, competency assessment and lessons learned
Integrated detection Deployed AI, Zero Trust or digital-twin capability with cross-sector validation
Cross-sector standards Interoperability profile, contribution, implementation evidence and scalability
Stakeholder integration Active authorities, industry, SMEs and academia with sustained operating roles

The result should be more than a white paper. Standards and recommendations may support the action, but the topic's scope centers on concrete systems, products, tools, technologies and operational infrastructure.

Mandatory KPI Contract

The topic defines two mandatory indicators:

  1. Number of stakeholders from civilian and defence cybersecurity communities involved in project activities.
  2. Number of dual-use cybersecurity use cases, scenarios or good practices identified and documented.

Optional indicators cover industrial stakeholders involved in activities relevant to both sectors, publications and policy outputs, and common knowledge-transfer or best-practice actions.

For every KPI, define baseline, target, unit, counting rule, evidence source, collection frequency and responsible partner. The first KPI should distinguish active contributors from event attendees. The second should require a documented need, participating users, technical scope, validation result and reusable lesson for each counted case.

A Practical Work-Package Model

This is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Governance, legal and security Control ownership, classification, export, ethics, risks and decisions Governance model, security plan, legal gates and risk register
WP2 Joint requirements and architecture Translate civilian and defence missions into one capability Use cases, interfaces, threat model and acceptance criteria
WP3 Engineering and integration Build or adapt prototype, product or infrastructure Releases, integrations, component evidence and documentation
WP4 Dual validation Test in representative environments under adverse conditions Test records, user acceptance, limitations and remediation
WP5 Pilots and operational cooperation Deploy with both user communities Pilot operations, playbooks, exercises and measured benefit
WP6 Exploitation and scale Sustain market and institutional adoption securely Licensing, procurement, support, standards and scale-up plan

The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables covering relevant KPIs and project outputs. Dissemination must respect security, classification, intellectual-property and export constraints.

Funding and Cost Model

DUALUSE is a Simple Grant with a 50% funding rate. The expected EU contribution is €3-5 million per project, and the indicative duration is 36 months.

The budget-based mixed actual-cost grant uses the categories and controls defined in the call. Planning should account for:

  • indirect costs at 7% of applicable eligible direct costs;
  • depreciation and full cost for listed equipment;
  • co-financing and financial capacity for every beneficiary;
  • secure or classified-capable environments and qualified personnel;
  • duplicated or adapted civilian and defence test environments;
  • certification, standards, interoperability and assurance work;
  • integration, maintenance, vulnerability response and lifecycle support.

Every major cost should map to a shared use case, measurable output and acceptance criterion. Separate budgets for disconnected civilian and defence demonstrators weaken the cooperation rationale.

How Evaluators Will Read the Proposal

Criterion DUALUSE evidence to emphasize Pass threshold
Relevance Shared operational problem, concrete dual-use capability, correct maturity and EU policy alignment 3/5
Implementation Complementary partners, secure access, mature architecture, dual validation and credible resources 3/5
Impact Civilian and defence adoption, interoperability, scale, resilience and sustainable exploitation 3/5
Overall Combined score 10/15

For DUALUSE, three general award subcriteria are explicitly not applicable: reinforcement of the EU digital technology supply chain, overcoming lack of market finance and contribution to environmental sustainability or Green Deal goals. Passing the thresholds does not guarantee funding; ranking and later legal, financial and security checks still apply.

Eligibility, Security and Application Package

Target stakeholders include civilian cybersecurity and law-enforcement actors, defence ministries and agencies, industry, SMEs, startups and other relevant European civilian and defence organizations. A multi-country consortium is not mandatory, but it can improve impact where cross-border adoption and interoperability are credible.

Beneficiaries and affiliated entities must generally be legal entities established in EU Member States or Norway, Iceland or Liechtenstein. Article 12(5) restrictions limit participation in every capacity to entities established in and controlled from eligible countries. Activities and subcontracted work must also take place there.

The application consists of online Part A, technical Part B limited to 70 pages, and required ownership-and-control declarations. Submission is exclusively electronic through the Funding & Tenders Portal.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Define one concrete cyber or hybrid threat shared by civilian and defence users.
  2. Name participating users from both communities and document their operating roles.
  3. Show a working-prototype, market-ready or operational-infrastructure path without inventing a TRL requirement.
  4. Separate the reusable core from civilian- and defence-specific adaptations.
  5. Secure representative environments, data rights and acceptance authority.
  6. Define classification, ownership, control, supply-chain and subcontracting constraints.
  7. Assess export control, end use, licensing and technology transfer separately from call eligibility.
  8. Set both mandatory KPIs with evidence that measures active cooperation.
  9. Build a 50% co-financing plan tied to joint outputs and dual validation.
  10. Use the live portal templates and submit the complete package before the deadline.

Frequently Asked Questions

Does any product sold to both public and defence customers qualify?

No. The proposal needs a concrete shared cybersecurity need, working technology, involvement from both communities and operational evidence in both contexts.

Is a numeric TRL required?

The topic text does not specify one. It instead requires working prototypes, market-ready products or operational infrastructures, so the proposal must document its starting and target maturity directly.

Must the consortium include partners from several countries?

No. Multi-country composition is not mandatory, although the call states that it can contribute positively to impact.

Must every project include all five example technology domains?

No. The domains are examples, and other shared civilian-defence cybersecurity areas may fit. A focused, validated capability is stronger than an incoherent collection of technologies.

Does ECCC dual-use eligibility settle export-control classification?

No. Call fit and export-control status are different assessments. Applicable product, software, technology, destination, end-user and end-use rules must be reviewed separately.

Is €5 million the maximum grant?

The expected EU contribution is €3-5 million per project. Different amounts may be considered when duly justified, and the final award may be lower than requested.

Does reaching 10/15 guarantee funding?

No. The proposal must also reach 3/5 for each criterion, rank within the available budget and pass subsequent legal, financial, ownership and security checks.

Conclusion

CYBER-11-DUALUSE is designed for operational cooperation, not dual-use branding. A strong proposal starts from one shared threat, joins credible civilian and defence users, builds a mature common capability and validates it under the distinct constraints of both environments.

We can help you structure governance, risk, controls, evidence and supplier assurance through our Virtual CISO service; the Cyber Check-up gives each partner a first documented measure of its posture. Final eligibility, export-control, classified-information, procurement, cost and submission decisions must remain anchored to the official call, applicable law and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

October 06, 2026

ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security

The REGCABH topic funds Regional Cable Hubs that pool maritime, cyber and operator data to detect threats to undersea cables. The mandatory authority…

October 05, 2026

ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems

The NCC topic funds the operating capacity of National Coordination Centres and their communities, including financial support to third parties. Who …

October 02, 2026

ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing

The COORDPREP topic funds coordinated preparedness testing and wider preparedness services, led by designated public cybersecurity bodies with privat…