Applies to: authorities, CSIRTs, SOCs, certification actors, industry, SMEs, startups, research organizations and cross-border partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG.
The EULEG topic provides a €20 million envelope for projects that turn EU cybersecurity legislation into shared operational capacity: implementation tools, reporting platforms, certification and market-surveillance support, audit capability, secure information exchange, privacy-enhancing technologies and skills programmes. The expected EU contribution is €3-5 million per project, the funding rate is 50%, and the indicative duration is 36 months. Proposals are due by 14 January 2027 at 17:00 CET and must address at least one relevant EU cybersecurity instrument. Routine compliance work for a single organization, without reusable ecosystem outcomes, is not the topic's central purpose (official call document).
In Brief
EULEGsupports homogeneous implementation of the CRA, NIS 2, GDPR, DORA, the Cybersecurity Act, specific AI Act requirements and other relevant EU cybersecurity rules.- A proposal may address one or more instruments, but it needs a clear regulatory scope, target stakeholders and operational result.
- Eligible directions include self-assessment tools, incident and vulnerability reporting, certification platforms, audit and authority capacity, secure information exchange, training, cross-border methods and privacy-enhancing technologies.
- The topic is a Simple Grant with a 50% rate; applicants must plan credible co-financing for the remaining eligible costs.
- A multi-country consortium is not mandatory, but the call states that it contributes positively to impact.
- The topic's mandatory KPI counts stakeholders supported in understanding, preparing for or implementing EU cybersecurity obligations, divided into specified stakeholder categories.
- Equipment is reimbursed through depreciation only under the topic-specific conditions.
Scope and Source Boundary
This guide explains how to translate the broad EULEG scope into a focused project concept, evidence model and work plan. It is not legal advice, does not determine compliance with any EU act and does not replace the live Funding & Tenders topic record, the official call document or the applicable legal texts.
EULEG is one of seven topics under DIGITAL-ECCC-2027-DEPLOY-CYBER-11. It targets implementation capacity rather than legislative interpretation alone: the proposal should enable stakeholders, authorities or ecosystems to apply requirements more consistently and effectively (ECCC call overview).
EULEG at a Glance
| Parameter | Official value |
|---|---|
| Topic | DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG |
| Topic budget | €20 million |
| Type of action | Simple Grant |
| Funding rate | 50% |
| Expected EU contribution | €3-5 million per project |
| Indicative duration | 36 months |
| Consortium minimum | None in the common composition rules |
| Multi-country composition | Not mandatory; positive contribution to impact |
| Equipment-cost treatment | Depreciation only |
| Part B limit | 70 pages |
| Submission deadline | 14 January 2027, 17:00 CET |
The €3-5 million range is an expected contribution, not an automatic award or absolute cap. A different request can be considered when duly justified, and the grant awarded may be lower than the amount requested.
The Legal Frameworks in Scope
The call explicitly names several EU instruments. A proposal should identify the exact obligations, processes or authorities it supports rather than presenting a generic list of regulations.
| Instrument | Connection recognized by EULEG | Official text |
|---|---|---|
| Cyber Resilience Act | Product cybersecurity, conformity assessment, market surveillance, vulnerability handling and reporting support | Regulation (EU) 2024/2847 |
| NIS 2 Directive | Capacity for competent authorities, CSIRTs and covered entities; audit, compliance, incident notification and information sharing | Directive (EU) 2022/2555 |
| GDPR | Data protection, security and privacy-enhancing technology in ICT design and deployment | Regulation (EU) 2016/679 |
| DORA | Included among the regulatory frameworks whose cybersecurity implementation capacity may be supported | Regulation (EU) 2022/2554 |
| Cybersecurity Act | Cybersecurity certification, authorities, conformity-assessment bodies and laboratories | Regulation (EU) 2019/881 |
| AI Act | Specific cybersecurity requirements and secure, privacy-aware technology design | Regulation (EU) 2024/1689 |
The grant does not certify that a participant, product or service complies with these instruments. The project must define what capacity it builds, who validates the result and how the output supports the relevant implementation process.
What EULEG Is Designed to Fund
Implementation support and self-assessment
The call supports practical guidelines and user-friendly tools that help stakeholders, especially SMEs, understand and implement relevant requirements. A useful concept moves beyond static explanations by connecting obligations to evidence, workflows, decisions, responsible roles and measurable improvement.
Examples include common methodologies, maturity or readiness assessments, open-standard mappings, structured evidence models and tools that reduce administrative burden. The project's value should be reusable across organizations, sectors or Member States.
Reporting and information exchange
The scope includes NIS 2 incident-reporting platforms, CRA vulnerability-reporting support, single entry points, secure communication channels and information-sharing mechanisms. It also permits national platforms that federate cyber threat intelligence actors and competent authorities, vertical exchanges within sectors and collaboration between countries.
A reporting project should define jurisdiction, data fields, validation, confidentiality, routing, acknowledgement, escalation and integration with existing authorities. A new interface without a governance and operating model is insufficient.
Certification and conformity-assessment capacity
EULEG can strengthen national cybersecurity certification authorities, market-surveillance and notifying authorities, conformity-assessment bodies and certification laboratories. It can also support tools for certification and evaluation, including a proposed "Certification and Evaluation as a Service" platform that manages documentation and accelerates information exchange.
The official scope emphasizes interoperability, harmonized documentation, mutual recognition and the ability to scale assessments securely. Relevant projects should involve the authorities, assessment bodies, laboratories, vendors and user representatives needed to test the process end to end.
CRA testing, vulnerability handling and product support
The topic covers pilots and methodologies for CRA implementation, including open-source tools or libraries for conformity assessment and testing. It also refers to Software Bills of Materials, coordinated vulnerability disclosure, contributions to CRA reporting structures and security-advisory automation such as the Common Security Advisory Framework.
This does not mean that any product test is automatically in scope. The proposal should create transferable methods, shared tools, authority capacity or demonstrable uptake across a defined stakeholder group.
Skills, diversity and cross-border collaboration
The call supports practical training, exercises, benchmarking, peer exchange, fellowships and cybersecurity challenges. It emphasizes young professionals, students, educators, women and other underrepresented groups, together with cross-country exchange and leadership development.
Training should be connected to regulatory and operational demands. The European Cybersecurity Skills Framework can help define roles and learning outcomes, but the proposal still needs participant targets, assessment methods and evidence of acquired capability.
Security and privacy by design
Projects may support security- and privacy-enhancing technologies in ICT products, services, IoT, Operational Technology, identity and e-government systems. The call links early design choices to lower vulnerability and personal-data risk and cites ENISA's Data Protection Engineering work.
For this direction, consortia should consider representing the full value chain: privacy-enhancing-technology researchers, technology providers, ICT developers or integrators and user organizations. This is a topic recommendation, not the formal common-section minimum consortium rule.
What Is a Weak EULEG Fit
The call has broad scope, but breadth does not make every compliance expense fundable. A proposal is likely to be weak when it centers on:
- routine policy writing or a one-off gap assessment for one beneficiary;
- paying for an isolated certification without creating shared methods or capacity;
- a generic training calendar without regulatory outcomes or skills measurement;
- another reporting portal with no authority integration, governance or adoption plan;
- a legal summary that does not produce operational tools, processes or validated support;
- a technology prototype whose connection to a named legal implementation problem is asserted but not demonstrated.
This distinction is an inference from the official objectives and expected outcomes. Final eligibility depends on the call text and evaluation.
Stakeholders and Consortium Design
The target audience is deliberately broad: industry, SMEs, startups, NIS 2 stakeholders, competent authorities, national and sectoral CSIRTs, SOCs, Operators of Essential Services, digital service providers, ISACs, certification bodies and other actors involved in relevant EU cybersecurity legislation.
| Project direction | Core participant roles to consider |
|---|---|
| NIS 2 implementation | Competent authority, CSIRT or SOC, covered entities, audit or technical specialists and sector representatives |
| CRA product support | Manufacturers, SMEs, market-surveillance or notifying authorities, testing or conformity-assessment actors and vulnerability specialists |
| Certification platform | Certification authority, accreditation or assessment bodies, laboratories, vendors and client representatives |
| Information sharing | Authority, CSIRT, ISAC or sector hub, participating entities, platform operator and governance owner |
| Privacy-enhancing technology | Researchers, providers, ICT integrators or developers, users and relevant data-protection stakeholders |
| Skills programme | Employers, training providers, academia, public bodies and target learner communities |
A multi-country consortium is not mandatory, but cross-border composition can strengthen the Impact case. Partner geography alone does not create impact: the proposal should show shared methods, interoperable outputs, replicated pilots, twinning or adoption in multiple Member States.
Funding and Cost Model
EULEG is a Simple Grant with a 50% funding rate. Each beneficiary must therefore plan its co-financing, financial capacity and cash flow. The expected EU contribution is €3-5 million per project, with an indicative 36-month duration.
The grant is budget-based and reimburses eligible actual costs with the unit-cost and flat-rate elements defined by the call. Relevant planning rules include:
- indirect costs at 7% of applicable eligible direct costs;
- equipment costs reimbursed through depreciation only for this topic;
- no-profit rule and possible grant reduction for non-compliance;
- work and subcontracting limited to eligible countries under the security restrictions;
- a consortium agreement when more than one beneficiary participates.
The financial model should trace every cost to a work package, deliverable and expected outcome. A large platform budget without adoption, governance and validation evidence will not become credible simply because it falls within the expected contribution range.
Expected Outcomes and Evidence Model
The official outcome list is extensive. A focused proposal should select a coherent subset and show a complete evidence chain.
| Outcome family | Representative result | Evidence to plan |
|---|---|---|
| Guidance and common process | Standardized method, manual or sector implementation framework | Authority or stakeholder validation, adoption sites and revision governance |
| Compliance-enabling tool | Self-assessment, reporting, monitoring or automation capability | Functional tests, user validation, process completion and reduced burden |
| Certification capacity | Platform, laboratory method, authority support or harmonized documentation | End-to-end assessment pilots, interoperability and stakeholder acceptance |
| NIS 2 capacity | Audit, incident notification, cooperation or information-sharing process | Exercises, completed workflows, response metrics and participating entities |
| Skills development | Training, challenge, benchmarking, fellowship or peer exchange | Learner profiles, assessed outcomes, role mapping and post-training application |
| Privacy-enhancing technology | Validated technology integration or commercialization support | Use-case fit, security/privacy testing, developer and user evidence |
Avoid counting publication or attendance as the final impact when the topic expects capability. The strongest measures distinguish reach, active use, completed implementation and sustained outcome.
KPI Contract
The mandatory topic KPI is the number of stakeholders supported in understanding, preparing for or implementing relevant EU cybersecurity legislation. Reporting must distinguish:
- SMEs and startups;
- competent authorities and CSIRTs;
- market-surveillance and notifying authorities;
- national cybersecurity certification authorities;
- conformity-assessment bodies and certification laboratories;
- other entities subject to or supporting implementation.
The call also lists optional indicators covering deployed incident-handling solutions, cooperation and training activities, Member State twinning, CRA vulnerability tools, compliance automation, SME use of open or low-cost tools, authority-support tools, uptake of CRA-compliant products, NIS 2 implementation tools and certification support.
For every applicable KPI, define the baseline, target, unit, data source, collection frequency and owner. If an indicator is not applicable because the related activity or outcome is outside the proposal, state that explicitly and justify it. Additional KPIs are permitted when measurable and connected to deliverables.
A Practical Work-Package Model
The following is a planning pattern, not a mandatory ECCC template.
| Work package | Purpose | Representative outputs |
|---|---|---|
| WP1 Regulatory scope and governance | Define legal perimeter, stakeholders, ethics, security and decision rights | Scope matrix, governance model and risk register |
| WP2 Common methodology | Translate requirements into shared workflows and evidence | Method, taxonomy, data model and assessment criteria |
| WP3 Tool or platform delivery | Build or adapt the operational capability | Architecture, integrations, releases and security controls |
| WP4 Pilots and validation | Test across sectors, roles or countries | Pilot reports, authority review, interoperability and acceptance evidence |
| WP5 Capacity and skills | Prepare users, professionals and authorities | Training, exercises, role pathways and assessed outcomes |
| WP6 Uptake and sustainability | Expand use and maintain results after funding | Adoption plan, operating model, exploitation and maintenance responsibilities |
The common rules require a dissemination and exploitation deliverable within the first six months and yearly deliverables on relevant KPIs and project outputs. Topic-specific milestones should demonstrate progress from methodology to usable capability and validated adoption.
How Evaluators Will Read the Proposal
| Criterion | EULEG evidence to emphasize | Pass threshold |
|---|---|---|
| Relevance | Named legal implementation problem, eligible activity, target stakeholders and European added value | 3/5 |
| Implementation | Mature method, credible partners, secure architecture, pilots, resources and governance | 3/5 |
| Impact | Stakeholders supported, reusable capacity, cross-border uptake and measurable burden or maturity improvement | 3/5 |
| Overall | Combined score | 10/15 |
Three standard award subcriteria are explicitly not applicable to EULEG: reinforcement of the EU digital technology supply chain, overcoming lack of market finance, and environmental sustainability or European Green Deal effects. The remaining criteria still require a strong implementation and impact case.
Passing the thresholds does not guarantee an award. Proposals are ranked within the topic budget, and legal, financial, exclusion and security checks continue during grant preparation.
Eligibility, Security and Application Package
Beneficiaries and affiliated entities must generally be eligible legal entities established in EU Member States or in Norway, Iceland or Liechtenstein. Article 12(5) security restrictions apply to all participant roles: entities must be established in and controlled from eligible countries, and project activities, including subcontracted work, must take place there.
The application consists of online Part A, technical Part B limited to 70 pages, and the ownership and control declarations generated by the live Submission System. Registration in the European Cybersecurity Competence Community is encouraged but not mandatory.
| Date or period | Milestone |
|---|---|
| 1 September 2026 | Call opening |
| 14 January 2027, 17:00 CET | Submission deadline |
| February-March 2027 | Indicative evaluation |
| April 2027 | Indicative result notification |
| October 2027 | Indicative grant-agreement signature |
Readiness Checklist
- Select at least one named EU cybersecurity instrument and define the implementation problem precisely.
- Choose a coherent activity route instead of attempting to cover the entire EULEG scope.
- Identify the stakeholder whose capacity changes and the authority or process that validates the result.
- Distinguish routine organizational compliance from reusable ecosystem capacity.
- Design a consortium around the complete implementation value chain and justify any cross-border structure.
- Convert requirements into work packages, deliverables, pilots and measurable acceptance criteria.
- Include the mandatory stakeholder KPI with its required categories and define applicable optional indicators.
- Build a credible 50% co-financing plan and apply depreciation-only treatment to equipment.
- Complete ownership, control, country and subcontractor checks for every participant role.
- Use the live portal templates, keep Part B within 70 pages and submit before the deadline.
Frequently Asked Questions
Does EULEG fund a company's ordinary compliance programme?
The topic supports implementation capacity, tools, common methods, authority cooperation, skills and uptake. A proposal limited to one organization's ordinary policy drafting or gap assessment is unlikely to demonstrate the reusable European outcomes described by the call.
Must a project cover every law named in the topic?
No. Applications should address at least one eligible piece of EU cybersecurity legislation and may address more. A narrow, complete implementation path is stronger than an unconnected list of regulations.
Can EULEG support NIS 2 incident reporting?
Yes. The scope explicitly includes NIS 2 reporting platforms, incident notification, common authority tools and information-sharing capacity. The proposal still needs governance, integration, security, adoption and measurable outcomes.
Can it support CRA conformity assessment and certification?
Yes. The scope includes testing methods, conformity-assessment support, certification capacity, market surveillance, documentation platforms and tools that help stakeholders implement CRA requirements.
Is a multi-country consortium mandatory?
No. The call states that it is not mandatory but will contribute positively to impact. Cross-border partners should produce concrete replication, interoperability, twinning or shared-capacity results.
Is the funding rate higher for SMEs?
No topic-specific SME uplift is stated for EULEG. It is a Simple Grant with a 50% rate. Applicants must use the exact financial conditions generated for the call and Grant Agreement.
Does reaching 10/15 guarantee funding?
No. The proposal must also reach 3/5 for each criterion, rank within the available budget and pass subsequent legal, financial and security checks.
Conclusion
EULEG is designed for projects that make EU cybersecurity legislation operational at ecosystem scale. Strong proposals select a concrete implementation barrier, build a shared method or capability, validate it with the relevant authorities and users, and measure how many stakeholders can apply it effectively.
We can help you structure regulatory mappings, evidence models and audit workflows for NIS 2 and ISO/IEC 27001, with Cyber Console as the compliance platform. Final legal interpretation, eligibility, cost and submission decisions must remain anchored to the applicable legislation, official call document and live Funding & Tenders record.
Guides in the ECCC 2027 Series
- Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics
- ECCC Cybersecurity Call 2027: Eligibility and Application Guide
- ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers
- ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations
- ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing
- ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems
- ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security
- ECCC Dual-Use Cybersecurity Funding 2027: From Civilian-Defence Cooperation to Deployment