Applies to: Commission-recognized National Coordination Centres and public, private, academic or research partners preparing a consortium for DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC.
The NCC topic provides an €11 million envelope to strengthen the operation of National Coordination Centres and their support for cybersecurity communities, SMEs, skills and European technology uptake. The expected EU contribution is €2-3 million per project, the maximum funding rate is 50%, and the indicative project duration is 36 months. Applications are due by 14 January 2027 at 17:00 CET. The topic is not an open entry point for any cybersecurity company: it targets NCCs recognized by the European Commission, while other public and private entities, including academia and research organizations, may participate in consortium with an NCC (official call document).
In Brief
- A Commission-recognized NCC must anchor the applicant structure; a non-NCC organization cannot treat this as a standalone vendor call.
- Each NCC may select the official activities and deliverables that fit its mandate. It does not have to implement the full topic catalogue.
- Financial Support to Third Parties (FSTP) is optional and may fund selected external recipients through transparent open calls.
- The maximum financial support is €100,000 per third party. The call recognizes that amounts above €60,000 may be necessary because of the nature of the actions.
- An FSTP open call must remain open for at least two months, be published on the Funding & Tenders Portal and participant websites, and have a clear European dimension.
- Ownership and Control Assessments (OCAs) must be completed before support is awarded and before a sub-grant agreement is signed.
- The three mandatory KPIs cover solution uptake, cybersecurity-capacity support including SMEs, and FSTP recipients.
- Article 12(5) security restrictions apply to consortium participants, subcontractors and third-party recipients.
Scope and Source Boundary
This guide explains the target applicant model, eligible activity families, FSTP administration, OCA evidence, funding mechanics and proposal design for the NCC topic. It does not determine whether a specific entity, cost or third-party scheme is eligible and does not replace the official call, Grant Agreement conditions or the live Funding & Tenders record.
National Coordination Centres were established under Regulation (EU) 2021/887 to work as a network, develop national Cybersecurity Competence Communities and support the European Cybersecurity Competence Centre. This topic funds that institutional and ecosystem role, rather than a single commercial product deployment.
NCC Funding at a Glance
| Parameter | Official value |
|---|---|
| Topic | DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC |
| Topic budget | €11 million |
| Type of action | Simple Grant |
| Maximum funding rate | 50%, including any FSTP budget |
| Expected EU contribution | €2-3 million per project |
| Indicative duration | 36 months |
| Applicant boundary | Recognized NCCs; other entities in consortium with NCCs |
| Consortium minimum | No numeric minimum in the common rules |
| FSTP ceiling | €100,000 per third party |
| Equipment-cost treatment | Depreciation only |
| Part B limit | 70 pages |
| Submission deadline | 14 January 2027, 17:00 CET |
The €11 million topic budget is not the grant for one project. The expected project contribution is €2-3 million, and a different amount may be considered when duly justified. The final award may be lower than requested. Availability of the call budget remains subject to final adoption of the relevant 2025-2027 Work Programme amendment.
Who Can Participate
The call targets NCCs that the Commission has recognized as capable of managing funds for the mission defined by Regulation (EU) 2021/887. Other private and public entities, including universities and research organizations, may participate in consortium with those NCCs.
| Participant | Appropriate role |
|---|---|
| Recognized NCC | National mandate, project governance, ECCC coordination and community support |
| Public authority or agency | Policy alignment, public-service reach, sector coordination and institutional uptake |
| SME, startup or technology provider | Market-ready solutions, deployment expertise, ecosystem needs and innovation pathways |
| University or research organization | Competence mapping, training, evidence, observatory work and technology transfer |
| Incubator, accelerator or investor network | Access-to-market, access-to-finance and scale-up support |
| Cybersecurity association or community actor | Outreach, matchmaking, member engagement and dissemination |
The absence of a numeric consortium minimum does not remove the NCC condition. A single applicant is viable only when that applicant is an eligible recognized NCC and can demonstrate the necessary capacity. A consortium should add implementation capability, not merely names: every partner needs a defined output, resource allocation and measurable contribution.
What the Topic Can Fund
An NCC may choose one or more activity families according to its national mandate and maturity.
Community and ECCC Coordination
- act as the national contact point for the Cybersecurity Competence Community;
- assess national requests to join the Community;
- support community registration and management tools;
- promote participation in ECCC and other EU-funded cross-border projects;
- provide applicant assistance while managing conflicts of interest and coordinating with National Contact Points;
- create synergies among national, regional and local initiatives.
SME, Startup and Technology Uptake
- support adoption and dissemination of state-of-the-art cybersecurity solutions;
- help startups and SMEs reach market readiness, commercialization and scale-up;
- connect innovators with procurement, investment, accelerators and technology-transfer programmes;
- deploy current tools and services that improve prevention, protection and incident response;
- develop marketplace, matchmaking or access-to-finance mechanisms with European reach.
Skills, Awareness and Exercises
- deliver campaigns on safer digital behaviour and cyber hygiene;
- organize boot camps, challenges, training, workshops and simulation activities;
- support cybersecurity education for students, teachers and young professionals;
- strengthen collaboration among higher-education institutions;
- run exercises for SMEs and critical sectors;
- contribute to the Cybersecurity Skills Academy and EU Cybersecurity Challenges.
The project should avoid duplicating ENISA, Commission, national or existing EU-funded initiatives. Reuse and coordination need to be explicit in the proposal.
FSTP Is Not Procurement or Ordinary Subcontracting
Financial Support to Third Parties is a cascading-support mechanism through which a beneficiary runs an open selection and awards support to external recipients. It is different from buying a service for the consortium.
| Mechanism | Purpose | Selection logic |
|---|---|---|
| FSTP | Support external entities in carrying out eligible ecosystem activities | Open, transparent call and sub-grant or equivalent arrangement |
| Subcontracting | Purchase a task needed by the beneficiary's project | Best-value procurement under grant and organizational rules |
| Consortium participation | Deliver project work as a beneficiary or affiliated entity | Included in the proposal with assigned work, rights and budget |
Use FSTP when the project intends to select independent recipients through a competitive scheme. Use procurement when the NCC needs a supplier to deliver its own project task. Misclassifying the mechanism can undermine eligibility, conflict-of-interest controls and budget traceability.
Mandatory FSTP Open-Call Rules
If the project includes FSTP, its open calls must:
- be open, widely published and compliant with transparency, equal treatment, confidentiality and conflict-of-interest standards;
- appear on the Funding & Tenders Portal and the relevant participants' websites;
- remain open for at least two months;
- publish deadline changes immediately and notify registered applicants;
- publish outcomes, including selected-project descriptions, award dates, durations, legal names and countries of final recipients;
- have a clear European dimension.
The FSTP ceiling is €100,000 per recipient. The topic states that amounts above €60,000 may be necessary due to the nature of the action, but this does not make them automatic. The open-call objectives, cost logic, selection criteria and expected outputs still need to justify each award.
The 50% topic funding rate applies to the total eligible costs of the action, including the budget allocated to FSTP. The proposal should therefore model EU contribution, co-financing and cash flow at both project and scheme level without promising a recipient rate that the final open-call conditions do not support.
Ownership and Control Assessment Before Every Award
Because this is a restricted cybersecurity call, an NCC implementing FSTP must be able to assess each intended recipient's establishment, geographic location, ownership, control and security compliance. The applicant must demonstrate that operational capacity in Part B, Section 2.3, at proposal stage.
The OCA method should cover:
- governance and allocation of responsibilities for the FSTP scheme;
- staffing, expertise and independent review of conclusions;
- application forms, declarations and supporting-document requirements;
- direct, indirect and ultimate ownership chains;
- voting, veto, appointment and other strategic-control rights;
- de jure and de facto control;
- board composition, quorum and majority arrangements;
- commercial, financial or other links that may confer decisive influence;
- clarification, decision, approval and conflict-of-interest procedures;
- confidentiality, retention, audit trail and access-to-file controls.
The assessment must be complete before the financial support award and before signature of the sub-grant or equivalent arrangement. A selected recipient needs a complete OCA file. If the recipient does not satisfy the applicable restrictions, support must not be awarded or proceed. The granting authority may inspect individual files or samples during preparation and implementation. The Commission's official ownership-and-control guidance should be incorporated into the scheme design.
A Credible National Ecosystem Model
The strongest proposals connect community-building activities into one operating loop:
- Map: maintain evidence on national stakeholders, capabilities, gaps, solutions and funding needs.
- Engage: register community members, run targeted outreach and collect structured demand.
- Match: connect SMEs, public buyers, research, investors and cross-border partners.
- Support: provide technical assistance, training, tools or transparent third-party funding.
- Measure: track uptake, capacity improvement, market access and community participation.
- Reuse: share practices with other NCCs and embed successful services into sustained national operations.
A collection of unrelated events is weaker than a service model with defined users, entry criteria, hand-offs, evidence and repeatable outcomes.
Expected Outcomes and Evidence
The topic permits a broad outcome portfolio, but each selected result needs verifiable completion evidence.
| Outcome family | Evidence to plan |
|---|---|
| Community operation | Registered and active entities, support interactions, governance and engagement records |
| Solution uptake | Organizations onboarded, tools or services deployed, acceptance evidence and measured capacity gain |
| FSTP delivery | Published calls, evaluations, OCA files, signed awards, recipient outputs and audit trail |
| Startup and SME growth | Market-readiness milestones, matchmaking, procurement or investment pathways and follow-up |
| Skills and awareness | Target groups, competency objectives, participation, assessment and behaviour or capability change |
| Cross-border NCC cooperation | Joint activities, shared methods, interoperable services and reused practices |
| Observatory or marketplace | Data model, active users, maintained records, governance and sustainability |
The proposal should define what continues after the grant: service ownership, platform maintenance, recurring funding, community stewardship and reuse by other NCCs.
Mandatory KPI Contract
The call defines three mandatory topic indicators:
- Number of entities supported through NCC project activities to adopt state-of-the-art cybersecurity solutions.
- Number of entities supported in solution uptake, dissemination and cybersecurity-capacity strengthening, including the number of SMEs.
- Number of entities receiving Financial Support to Third Parties.
Optional KPIs include access to EU cybersecurity facilities, incident-preparedness support, Community candidates, matchmaking and funding events, local assistance interactions, promotion actions and collaboration with other NCCs and the ECCC.
For every applicable KPI, define baseline, target, counting rule, evidence source, collection frequency and responsible partner. Avoid double counting the same entity across overlapping activities unless the indicator definition explicitly permits it. If FSTP is not included, explain why the third mandatory indicator is not applicable to the proposed activity mix.
A Practical Work-Package Model
This is a planning pattern, not a mandatory ECCC template.
| Work package | Purpose | Representative outputs |
|---|---|---|
| WP1 Governance and ECCC coordination | Control mandate, security, finance, risks and network relations | Governance plan, controls, coordination records |
| WP2 Community and observatory | Map, register and engage national stakeholders | Community data, services, engagement evidence |
| WP3 Uptake and market support | Move European solutions toward adoption and scale | Assessments, matchmaking, deployment support |
| WP4 Skills and awareness | Improve role-based capability and cyber hygiene | Training, exercises, campaigns and assessments |
| WP5 FSTP and OCA | Run transparent support calls and recipient controls | Call package, evaluations, OCA files, awards and monitoring |
| WP6 Measurement and sustainability | Prove results and preserve successful services | KPI evidence, annual outputs and continuity plan |
The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables covering relevant KPIs and project outputs.
Funding and Cost Model
NCC is a Simple Grant with a maximum EU funding rate of 50%, including FSTP allocations. The expected EU contribution is €2-3 million per project and the indicative duration is 36 months.
The budget-based mixed actual-cost grant includes the cost categories and controls specified in the call. Planning should account for:
- indirect costs at 7% of applicable eligible direct costs;
- depreciation-only treatment for equipment;
- the €100,000 maximum per third-party recipient;
- staffing for open calls, evaluations, OCAs, monitoring, audit and recipient support;
- co-financing, pre-financing needs and financial capacity;
- non-deductible VAT rules, including the exclusion applicable when public bodies act as public authorities.
FSTP is not administratively free. The project budget needs enough qualified capacity for selection, ownership checks, contracting, payment, monitoring, record retention and recovery or suspension where conditions are breached.
How Evaluators Will Read the Proposal
| Criterion | NCC evidence to emphasize | Pass threshold |
|---|---|---|
| Relevance | Recognized NCC mandate, selected official activities, national need, ECCC and EU complementarity | 3/5 |
| Implementation | Operational capacity, partner roles, FSTP/OCA method, resources, milestones and risk controls | 3/5 |
| Impact | Measurable uptake, stronger capacities, SME reach, community value, cross-border reuse and sustainability | 3/5 |
| Overall | Combined score | 10/15 |
For NCC, three general award subcriteria are explicitly not applicable: reinforcement of the EU digital technology supply chain, overcoming lack of market finance and contribution to environmental sustainability or Green Deal goals. Passing the thresholds does not guarantee funding; ranking and subsequent legal, financial and security checks still apply.
Eligibility, Security and Application Package
Beneficiaries and affiliated entities must generally be eligible legal entities established in EU Member States or Norway, Iceland or Liechtenstein. Article 12(5) restrictions limit participation in every capacity to entities established in and controlled from eligible countries. Project activities and subcontracted work must also take place there.
The application includes online Part A, technical Part B limited to 70 pages, and the required ownership-and-control declarations. An applicant planning FSTP must also describe its operational capacity and OCA methodology at proposal stage. Submission is exclusively electronic through the Funding & Tenders Portal.
| Date or period | Milestone |
|---|---|
| 1 September 2026 | Call opening |
| 14 January 2027, 17:00 CET | Submission deadline |
| February-March 2027 | Indicative evaluation |
| April 2027 | Indicative result notification |
| October 2027 | Indicative grant-agreement signature |
The Italian NCC-IT Context
In Italy, the National Cybersecurity Agency is NCC-IT under Decree-Law 82/2021 and Regulation (EU) 2021/887. ACN describes NCC-IT as the contact point between the national cybersecurity stakeholder community and the ECCC. It promotes ECCC opportunities, supports the national Community and evaluates requests for membership.
This context does not make every Italian stakeholder a direct applicant under CYBER-11-NCC. Companies, universities, research bodies and associations should distinguish among consortium participation with a recognized NCC, future FSTP opportunities, Community membership and other ECCC topics for which they may apply directly.
Readiness Checklist
- Confirm that a Commission-recognized NCC anchors the proposed applicant structure.
- Select only the official activity families that fit the NCC's mandate and national need.
- Map existing EU, national and regional initiatives and document non-duplication.
- Assign measurable outputs, resources and responsibilities to every consortium partner.
- Decide whether FSTP is necessary or whether consortium delivery and procurement are more appropriate.
- If using FSTP, design a two-month public call, selection criteria, award package and European dimension.
- Build OCA staffing, methodology, evidence, review and audit access before proposal submission.
- Define the three mandatory KPIs and prevent double counting.
- Model 50% co-financing, FSTP cash flow, equipment depreciation and administrative cost.
- Verify ownership, control, location and subcontracting restrictions and submit the live portal forms before the deadline.
Frequently Asked Questions
Can a cybersecurity company apply without an NCC?
Not under the target model stated by this topic. It exclusively targets Commission-recognized NCCs, while other private and public entities may participate in consortium with NCCs.
Must every NCC proposal include FSTP?
No. The call says FSTP may be used. An NCC can select other eligible activities according to its mandate. If FSTP is omitted, the proposal should make the non-applicability of the related KPI explicit.
Is €100,000 the project grant amount?
No. It is the maximum financial support for one third-party recipient. The expected EU contribution to an NCC project is €2-3 million, within an €11 million topic budget.
Can an FSTP call stay open for one month?
No. The official conditions require it to remain open for at least two months and to be published on both the Funding & Tenders Portal and participant websites.
Can the OCA be completed after selecting and paying a recipient?
No. The OCA must be complete before financial support is awarded and before the sub-grant or equivalent agreement is signed. A non-compliant recipient cannot receive the support.
Does the 50% rate exclude the FSTP budget?
No. The call states that the maximum 50% EU funding rate applies to total eligible action costs, including any FSTP allocation.
Does reaching 10/15 guarantee funding?
No. The proposal must also achieve at least 3/5 for each criterion, rank within the available budget and pass subsequent legal, financial, ownership and security checks.
Conclusion
CYBER-11-NCC funds the operating capacity that connects national cybersecurity communities with European programmes, solutions and skills. A strong proposal starts from a recognized NCC mandate, selects a coherent service portfolio and proves how community support will produce measurable adoption and durable capacity.
Where FSTP is used, the administration is part of the cybersecurity result: transparent selection, ownership-control evidence, conflict management and auditable recipient monitoring are mandatory design elements. Our Virtual CISO service can help you structure risk, governance, evidence and monitoring workflows; for the SMEs receiving support, the Cyber Check-up provides a first documented measure of their security posture.
Guides in the ECCC 2027 Series
- Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics
- ECCC Cybersecurity Call 2027: Eligibility and Application Guide
- ECCC AI4SME Funding 2027: Guide for SMEs and Cybersecurity Providers
- ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability
- ECCC CYBERAI Funding 2027: Secure AI for European Cyber Operations
- ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing
- ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security
- ECCC Dual-Use Cybersecurity Funding 2027: From Civilian-Defence Cooperation to Deployment
Official Sources
- ECCC - Official call document, version 1.0
- ECCC - Call overview and NCC topic summary
- EUR-Lex - Regulation (EU) 2021/887 establishing the ECCC and NCC Network
- European Commission - Guidance on participation in restricted calls with ownership and control restrictions
- ACN - NCC Italia
- European Commission - Funding & Tenders call search