ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability

The EULEG topic funds shared capacity to implement EU cybersecurity law, from NIS 2 reporting to CRA testing and certification. What it pays for, what it does not, and how to build the evidence a proposal needs.

September 30, 2026 14 min read

Facade of a European institutional building in Brussels Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. EULEG at a Glance
  4. The Legal Frameworks in Scope
  5. What EULEG Is Designed to Fund
  6. What Is a Weak EULEG Fit
  7. Stakeholders and Consortium Design
  8. Funding and Cost Model
  9. Expected Outcomes and Evidence Model
  10. KPI Contract
  11. A Practical Work-Package Model
  12. How Evaluators Will Read the Proposal
  13. Eligibility, Security and Application Package
  14. Readiness Checklist
  15. Frequently Asked Questions
  16. Conclusion
  17. Guides in the ECCC 2027 Series
  18. Official Sources

Applies to: authorities, CSIRTs, SOCs, certification actors, industry, SMEs, startups, research organizations and cross-border partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG.

The EULEG topic provides a €20 million envelope for projects that turn EU cybersecurity legislation into shared operational capacity: implementation tools, reporting platforms, certification and market-surveillance support, audit capability, secure information exchange, privacy-enhancing technologies and skills programmes. The expected EU contribution is €3-5 million per project, the funding rate is 50%, and the indicative duration is 36 months. Proposals are due by 14 January 2027 at 17:00 CET and must address at least one relevant EU cybersecurity instrument. Routine compliance work for a single organization, without reusable ecosystem outcomes, is not the topic's central purpose (official call document).

In Brief

  • EULEG supports homogeneous implementation of the CRA, NIS 2, GDPR, DORA, the Cybersecurity Act, specific AI Act requirements and other relevant EU cybersecurity rules.
  • A proposal may address one or more instruments, but it needs a clear regulatory scope, target stakeholders and operational result.
  • Eligible directions include self-assessment tools, incident and vulnerability reporting, certification platforms, audit and authority capacity, secure information exchange, training, cross-border methods and privacy-enhancing technologies.
  • The topic is a Simple Grant with a 50% rate; applicants must plan credible co-financing for the remaining eligible costs.
  • A multi-country consortium is not mandatory, but the call states that it contributes positively to impact.
  • The topic's mandatory KPI counts stakeholders supported in understanding, preparing for or implementing EU cybersecurity obligations, divided into specified stakeholder categories.
  • Equipment is reimbursed through depreciation only under the topic-specific conditions.

Scope and Source Boundary

This guide explains how to translate the broad EULEG scope into a focused project concept, evidence model and work plan. It is not legal advice, does not determine compliance with any EU act and does not replace the live Funding & Tenders topic record, the official call document or the applicable legal texts.

EULEG is one of seven topics under DIGITAL-ECCC-2027-DEPLOY-CYBER-11. It targets implementation capacity rather than legislative interpretation alone: the proposal should enable stakeholders, authorities or ecosystems to apply requirements more consistently and effectively (ECCC call overview).

EULEG at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-EULEG
Topic budget €20 million
Type of action Simple Grant
Funding rate 50%
Expected EU contribution €3-5 million per project
Indicative duration 36 months
Consortium minimum None in the common composition rules
Multi-country composition Not mandatory; positive contribution to impact
Equipment-cost treatment Depreciation only
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The €3-5 million range is an expected contribution, not an automatic award or absolute cap. A different request can be considered when duly justified, and the grant awarded may be lower than the amount requested.

The call explicitly names several EU instruments. A proposal should identify the exact obligations, processes or authorities it supports rather than presenting a generic list of regulations.

Instrument Connection recognized by EULEG Official text
Cyber Resilience Act Product cybersecurity, conformity assessment, market surveillance, vulnerability handling and reporting support Regulation (EU) 2024/2847
NIS 2 Directive Capacity for competent authorities, CSIRTs and covered entities; audit, compliance, incident notification and information sharing Directive (EU) 2022/2555
GDPR Data protection, security and privacy-enhancing technology in ICT design and deployment Regulation (EU) 2016/679
DORA Included among the regulatory frameworks whose cybersecurity implementation capacity may be supported Regulation (EU) 2022/2554
Cybersecurity Act Cybersecurity certification, authorities, conformity-assessment bodies and laboratories Regulation (EU) 2019/881
AI Act Specific cybersecurity requirements and secure, privacy-aware technology design Regulation (EU) 2024/1689

The grant does not certify that a participant, product or service complies with these instruments. The project must define what capacity it builds, who validates the result and how the output supports the relevant implementation process.

What EULEG Is Designed to Fund

Implementation support and self-assessment

The call supports practical guidelines and user-friendly tools that help stakeholders, especially SMEs, understand and implement relevant requirements. A useful concept moves beyond static explanations by connecting obligations to evidence, workflows, decisions, responsible roles and measurable improvement.

Examples include common methodologies, maturity or readiness assessments, open-standard mappings, structured evidence models and tools that reduce administrative burden. The project's value should be reusable across organizations, sectors or Member States.

Reporting and information exchange

The scope includes NIS 2 incident-reporting platforms, CRA vulnerability-reporting support, single entry points, secure communication channels and information-sharing mechanisms. It also permits national platforms that federate cyber threat intelligence actors and competent authorities, vertical exchanges within sectors and collaboration between countries.

A reporting project should define jurisdiction, data fields, validation, confidentiality, routing, acknowledgement, escalation and integration with existing authorities. A new interface without a governance and operating model is insufficient.

Certification and conformity-assessment capacity

EULEG can strengthen national cybersecurity certification authorities, market-surveillance and notifying authorities, conformity-assessment bodies and certification laboratories. It can also support tools for certification and evaluation, including a proposed "Certification and Evaluation as a Service" platform that manages documentation and accelerates information exchange.

The official scope emphasizes interoperability, harmonized documentation, mutual recognition and the ability to scale assessments securely. Relevant projects should involve the authorities, assessment bodies, laboratories, vendors and user representatives needed to test the process end to end.

CRA testing, vulnerability handling and product support

The topic covers pilots and methodologies for CRA implementation, including open-source tools or libraries for conformity assessment and testing. It also refers to Software Bills of Materials, coordinated vulnerability disclosure, contributions to CRA reporting structures and security-advisory automation such as the Common Security Advisory Framework.

This does not mean that any product test is automatically in scope. The proposal should create transferable methods, shared tools, authority capacity or demonstrable uptake across a defined stakeholder group.

Skills, diversity and cross-border collaboration

The call supports practical training, exercises, benchmarking, peer exchange, fellowships and cybersecurity challenges. It emphasizes young professionals, students, educators, women and other underrepresented groups, together with cross-country exchange and leadership development.

Training should be connected to regulatory and operational demands. The European Cybersecurity Skills Framework can help define roles and learning outcomes, but the proposal still needs participant targets, assessment methods and evidence of acquired capability.

Security and privacy by design

Projects may support security- and privacy-enhancing technologies in ICT products, services, IoT, Operational Technology, identity and e-government systems. The call links early design choices to lower vulnerability and personal-data risk and cites ENISA's Data Protection Engineering work.

For this direction, consortia should consider representing the full value chain: privacy-enhancing-technology researchers, technology providers, ICT developers or integrators and user organizations. This is a topic recommendation, not the formal common-section minimum consortium rule.

What Is a Weak EULEG Fit

The call has broad scope, but breadth does not make every compliance expense fundable. A proposal is likely to be weak when it centers on:

  • routine policy writing or a one-off gap assessment for one beneficiary;
  • paying for an isolated certification without creating shared methods or capacity;
  • a generic training calendar without regulatory outcomes or skills measurement;
  • another reporting portal with no authority integration, governance or adoption plan;
  • a legal summary that does not produce operational tools, processes or validated support;
  • a technology prototype whose connection to a named legal implementation problem is asserted but not demonstrated.

This distinction is an inference from the official objectives and expected outcomes. Final eligibility depends on the call text and evaluation.

Stakeholders and Consortium Design

The target audience is deliberately broad: industry, SMEs, startups, NIS 2 stakeholders, competent authorities, national and sectoral CSIRTs, SOCs, Operators of Essential Services, digital service providers, ISACs, certification bodies and other actors involved in relevant EU cybersecurity legislation.

Project direction Core participant roles to consider
NIS 2 implementation Competent authority, CSIRT or SOC, covered entities, audit or technical specialists and sector representatives
CRA product support Manufacturers, SMEs, market-surveillance or notifying authorities, testing or conformity-assessment actors and vulnerability specialists
Certification platform Certification authority, accreditation or assessment bodies, laboratories, vendors and client representatives
Information sharing Authority, CSIRT, ISAC or sector hub, participating entities, platform operator and governance owner
Privacy-enhancing technology Researchers, providers, ICT integrators or developers, users and relevant data-protection stakeholders
Skills programme Employers, training providers, academia, public bodies and target learner communities

A multi-country consortium is not mandatory, but cross-border composition can strengthen the Impact case. Partner geography alone does not create impact: the proposal should show shared methods, interoperable outputs, replicated pilots, twinning or adoption in multiple Member States.

Funding and Cost Model

EULEG is a Simple Grant with a 50% funding rate. Each beneficiary must therefore plan its co-financing, financial capacity and cash flow. The expected EU contribution is €3-5 million per project, with an indicative 36-month duration.

The grant is budget-based and reimburses eligible actual costs with the unit-cost and flat-rate elements defined by the call. Relevant planning rules include:

  • indirect costs at 7% of applicable eligible direct costs;
  • equipment costs reimbursed through depreciation only for this topic;
  • no-profit rule and possible grant reduction for non-compliance;
  • work and subcontracting limited to eligible countries under the security restrictions;
  • a consortium agreement when more than one beneficiary participates.

The financial model should trace every cost to a work package, deliverable and expected outcome. A large platform budget without adoption, governance and validation evidence will not become credible simply because it falls within the expected contribution range.

Expected Outcomes and Evidence Model

The official outcome list is extensive. A focused proposal should select a coherent subset and show a complete evidence chain.

Outcome family Representative result Evidence to plan
Guidance and common process Standardized method, manual or sector implementation framework Authority or stakeholder validation, adoption sites and revision governance
Compliance-enabling tool Self-assessment, reporting, monitoring or automation capability Functional tests, user validation, process completion and reduced burden
Certification capacity Platform, laboratory method, authority support or harmonized documentation End-to-end assessment pilots, interoperability and stakeholder acceptance
NIS 2 capacity Audit, incident notification, cooperation or information-sharing process Exercises, completed workflows, response metrics and participating entities
Skills development Training, challenge, benchmarking, fellowship or peer exchange Learner profiles, assessed outcomes, role mapping and post-training application
Privacy-enhancing technology Validated technology integration or commercialization support Use-case fit, security/privacy testing, developer and user evidence

Avoid counting publication or attendance as the final impact when the topic expects capability. The strongest measures distinguish reach, active use, completed implementation and sustained outcome.

KPI Contract

The mandatory topic KPI is the number of stakeholders supported in understanding, preparing for or implementing relevant EU cybersecurity legislation. Reporting must distinguish:

  • SMEs and startups;
  • competent authorities and CSIRTs;
  • market-surveillance and notifying authorities;
  • national cybersecurity certification authorities;
  • conformity-assessment bodies and certification laboratories;
  • other entities subject to or supporting implementation.

The call also lists optional indicators covering deployed incident-handling solutions, cooperation and training activities, Member State twinning, CRA vulnerability tools, compliance automation, SME use of open or low-cost tools, authority-support tools, uptake of CRA-compliant products, NIS 2 implementation tools and certification support.

For every applicable KPI, define the baseline, target, unit, data source, collection frequency and owner. If an indicator is not applicable because the related activity or outcome is outside the proposal, state that explicitly and justify it. Additional KPIs are permitted when measurable and connected to deliverables.

A Practical Work-Package Model

The following is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Regulatory scope and governance Define legal perimeter, stakeholders, ethics, security and decision rights Scope matrix, governance model and risk register
WP2 Common methodology Translate requirements into shared workflows and evidence Method, taxonomy, data model and assessment criteria
WP3 Tool or platform delivery Build or adapt the operational capability Architecture, integrations, releases and security controls
WP4 Pilots and validation Test across sectors, roles or countries Pilot reports, authority review, interoperability and acceptance evidence
WP5 Capacity and skills Prepare users, professionals and authorities Training, exercises, role pathways and assessed outcomes
WP6 Uptake and sustainability Expand use and maintain results after funding Adoption plan, operating model, exploitation and maintenance responsibilities

The common rules require a dissemination and exploitation deliverable within the first six months and yearly deliverables on relevant KPIs and project outputs. Topic-specific milestones should demonstrate progress from methodology to usable capability and validated adoption.

How Evaluators Will Read the Proposal

Criterion EULEG evidence to emphasize Pass threshold
Relevance Named legal implementation problem, eligible activity, target stakeholders and European added value 3/5
Implementation Mature method, credible partners, secure architecture, pilots, resources and governance 3/5
Impact Stakeholders supported, reusable capacity, cross-border uptake and measurable burden or maturity improvement 3/5
Overall Combined score 10/15

Three standard award subcriteria are explicitly not applicable to EULEG: reinforcement of the EU digital technology supply chain, overcoming lack of market finance, and environmental sustainability or European Green Deal effects. The remaining criteria still require a strong implementation and impact case.

Passing the thresholds does not guarantee an award. Proposals are ranked within the topic budget, and legal, financial, exclusion and security checks continue during grant preparation.

Eligibility, Security and Application Package

Beneficiaries and affiliated entities must generally be eligible legal entities established in EU Member States or in Norway, Iceland or Liechtenstein. Article 12(5) security restrictions apply to all participant roles: entities must be established in and controlled from eligible countries, and project activities, including subcontracted work, must take place there.

The application consists of online Part A, technical Part B limited to 70 pages, and the ownership and control declarations generated by the live Submission System. Registration in the European Cybersecurity Competence Community is encouraged but not mandatory.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Select at least one named EU cybersecurity instrument and define the implementation problem precisely.
  2. Choose a coherent activity route instead of attempting to cover the entire EULEG scope.
  3. Identify the stakeholder whose capacity changes and the authority or process that validates the result.
  4. Distinguish routine organizational compliance from reusable ecosystem capacity.
  5. Design a consortium around the complete implementation value chain and justify any cross-border structure.
  6. Convert requirements into work packages, deliverables, pilots and measurable acceptance criteria.
  7. Include the mandatory stakeholder KPI with its required categories and define applicable optional indicators.
  8. Build a credible 50% co-financing plan and apply depreciation-only treatment to equipment.
  9. Complete ownership, control, country and subcontractor checks for every participant role.
  10. Use the live portal templates, keep Part B within 70 pages and submit before the deadline.

Frequently Asked Questions

Does EULEG fund a company's ordinary compliance programme?

The topic supports implementation capacity, tools, common methods, authority cooperation, skills and uptake. A proposal limited to one organization's ordinary policy drafting or gap assessment is unlikely to demonstrate the reusable European outcomes described by the call.

Must a project cover every law named in the topic?

No. Applications should address at least one eligible piece of EU cybersecurity legislation and may address more. A narrow, complete implementation path is stronger than an unconnected list of regulations.

Can EULEG support NIS 2 incident reporting?

Yes. The scope explicitly includes NIS 2 reporting platforms, incident notification, common authority tools and information-sharing capacity. The proposal still needs governance, integration, security, adoption and measurable outcomes.

Can it support CRA conformity assessment and certification?

Yes. The scope includes testing methods, conformity-assessment support, certification capacity, market surveillance, documentation platforms and tools that help stakeholders implement CRA requirements.

Is a multi-country consortium mandatory?

No. The call states that it is not mandatory but will contribute positively to impact. Cross-border partners should produce concrete replication, interoperability, twinning or shared-capacity results.

Is the funding rate higher for SMEs?

No topic-specific SME uplift is stated for EULEG. It is a Simple Grant with a 50% rate. Applicants must use the exact financial conditions generated for the call and Grant Agreement.

Does reaching 10/15 guarantee funding?

No. The proposal must also reach 3/5 for each criterion, rank within the available budget and pass subsequent legal, financial and security checks.

Conclusion

EULEG is designed for projects that make EU cybersecurity legislation operational at ecosystem scale. Strong proposals select a concrete implementation barrier, build a shared method or capability, validate it with the relevant authorities and users, and measure how many stakeholders can apply it effectively.

We can help you structure regulatory mappings, evidence models and audit workflows for NIS 2 and ISO/IEC 27001, with Cyber Console as the compliance platform. Final legal interpretation, eligibility, cost and submission decisions must remain anchored to the applicable legislation, official call document and live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

Virtual CISO

An external CISO who leads your company's governance, risk and compliance work, without the cost of an in-house hire.

Learn more
Share this post:

Related news

October 01, 2026

ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations

The CYBERAI topic funds secure, trustworthy AI for detection, threat intelligence, response and self-healing in European cyber operations. How it dif…

September 29, 2026

ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers

The AI4SME topic funds AI-enabled cybersecurity tools and services that European SMEs actually adopt. Budget, the 75% SME funding rate, eligible acti…

September 28, 2026

ECCC Cybersecurity Call 2027: Eligibility and Application Guide

A step-by-step check of the common rules of DIGITAL-ECCC-2027-DEPLOY-CYBER-11: legal eligibility, establishment and control restrictions, consortium …