ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems

The NCC topic funds the operating capacity of National Coordination Centres and their communities, including financial support to third parties. Who can join, what FSTP requires, the ownership and control assessment and the Italian NCC-IT context.

October 05, 2026 15 min read

Training session with employees listening to a trainer Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. NCC Funding at a Glance
  4. Who Can Participate
  5. What the Topic Can Fund
  6. FSTP Is Not Procurement or Ordinary Subcontracting
  7. Mandatory FSTP Open-Call Rules
  8. Ownership and Control Assessment Before Every Award
  9. A Credible National Ecosystem Model
  10. Expected Outcomes and Evidence
  11. Mandatory KPI Contract
  12. A Practical Work-Package Model
  13. Funding and Cost Model
  14. How Evaluators Will Read the Proposal
  15. Eligibility, Security and Application Package
  16. The Italian NCC-IT Context
  17. Readiness Checklist
  18. Frequently Asked Questions
  19. Conclusion
  20. Guides in the ECCC 2027 Series
  21. Official Sources

Applies to: Commission-recognized National Coordination Centres and public, private, academic or research partners preparing a consortium for DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC.

The NCC topic provides an €11 million envelope to strengthen the operation of National Coordination Centres and their support for cybersecurity communities, SMEs, skills and European technology uptake. The expected EU contribution is €2-3 million per project, the maximum funding rate is 50%, and the indicative project duration is 36 months. Applications are due by 14 January 2027 at 17:00 CET. The topic is not an open entry point for any cybersecurity company: it targets NCCs recognized by the European Commission, while other public and private entities, including academia and research organizations, may participate in consortium with an NCC (official call document).

In Brief

  • A Commission-recognized NCC must anchor the applicant structure; a non-NCC organization cannot treat this as a standalone vendor call.
  • Each NCC may select the official activities and deliverables that fit its mandate. It does not have to implement the full topic catalogue.
  • Financial Support to Third Parties (FSTP) is optional and may fund selected external recipients through transparent open calls.
  • The maximum financial support is €100,000 per third party. The call recognizes that amounts above €60,000 may be necessary because of the nature of the actions.
  • An FSTP open call must remain open for at least two months, be published on the Funding & Tenders Portal and participant websites, and have a clear European dimension.
  • Ownership and Control Assessments (OCAs) must be completed before support is awarded and before a sub-grant agreement is signed.
  • The three mandatory KPIs cover solution uptake, cybersecurity-capacity support including SMEs, and FSTP recipients.
  • Article 12(5) security restrictions apply to consortium participants, subcontractors and third-party recipients.

Scope and Source Boundary

This guide explains the target applicant model, eligible activity families, FSTP administration, OCA evidence, funding mechanics and proposal design for the NCC topic. It does not determine whether a specific entity, cost or third-party scheme is eligible and does not replace the official call, Grant Agreement conditions or the live Funding & Tenders record.

National Coordination Centres were established under Regulation (EU) 2021/887 to work as a network, develop national Cybersecurity Competence Communities and support the European Cybersecurity Competence Centre. This topic funds that institutional and ecosystem role, rather than a single commercial product deployment.

NCC Funding at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-NCC
Topic budget €11 million
Type of action Simple Grant
Maximum funding rate 50%, including any FSTP budget
Expected EU contribution €2-3 million per project
Indicative duration 36 months
Applicant boundary Recognized NCCs; other entities in consortium with NCCs
Consortium minimum No numeric minimum in the common rules
FSTP ceiling €100,000 per third party
Equipment-cost treatment Depreciation only
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The €11 million topic budget is not the grant for one project. The expected project contribution is €2-3 million, and a different amount may be considered when duly justified. The final award may be lower than requested. Availability of the call budget remains subject to final adoption of the relevant 2025-2027 Work Programme amendment.

Who Can Participate

The call targets NCCs that the Commission has recognized as capable of managing funds for the mission defined by Regulation (EU) 2021/887. Other private and public entities, including universities and research organizations, may participate in consortium with those NCCs.

Participant Appropriate role
Recognized NCC National mandate, project governance, ECCC coordination and community support
Public authority or agency Policy alignment, public-service reach, sector coordination and institutional uptake
SME, startup or technology provider Market-ready solutions, deployment expertise, ecosystem needs and innovation pathways
University or research organization Competence mapping, training, evidence, observatory work and technology transfer
Incubator, accelerator or investor network Access-to-market, access-to-finance and scale-up support
Cybersecurity association or community actor Outreach, matchmaking, member engagement and dissemination

The absence of a numeric consortium minimum does not remove the NCC condition. A single applicant is viable only when that applicant is an eligible recognized NCC and can demonstrate the necessary capacity. A consortium should add implementation capability, not merely names: every partner needs a defined output, resource allocation and measurable contribution.

What the Topic Can Fund

An NCC may choose one or more activity families according to its national mandate and maturity.

Community and ECCC Coordination

  • act as the national contact point for the Cybersecurity Competence Community;
  • assess national requests to join the Community;
  • support community registration and management tools;
  • promote participation in ECCC and other EU-funded cross-border projects;
  • provide applicant assistance while managing conflicts of interest and coordinating with National Contact Points;
  • create synergies among national, regional and local initiatives.

SME, Startup and Technology Uptake

  • support adoption and dissemination of state-of-the-art cybersecurity solutions;
  • help startups and SMEs reach market readiness, commercialization and scale-up;
  • connect innovators with procurement, investment, accelerators and technology-transfer programmes;
  • deploy current tools and services that improve prevention, protection and incident response;
  • develop marketplace, matchmaking or access-to-finance mechanisms with European reach.

Skills, Awareness and Exercises

  • deliver campaigns on safer digital behaviour and cyber hygiene;
  • organize boot camps, challenges, training, workshops and simulation activities;
  • support cybersecurity education for students, teachers and young professionals;
  • strengthen collaboration among higher-education institutions;
  • run exercises for SMEs and critical sectors;
  • contribute to the Cybersecurity Skills Academy and EU Cybersecurity Challenges.

The project should avoid duplicating ENISA, Commission, national or existing EU-funded initiatives. Reuse and coordination need to be explicit in the proposal.

FSTP Is Not Procurement or Ordinary Subcontracting

Financial Support to Third Parties is a cascading-support mechanism through which a beneficiary runs an open selection and awards support to external recipients. It is different from buying a service for the consortium.

Mechanism Purpose Selection logic
FSTP Support external entities in carrying out eligible ecosystem activities Open, transparent call and sub-grant or equivalent arrangement
Subcontracting Purchase a task needed by the beneficiary's project Best-value procurement under grant and organizational rules
Consortium participation Deliver project work as a beneficiary or affiliated entity Included in the proposal with assigned work, rights and budget

Use FSTP when the project intends to select independent recipients through a competitive scheme. Use procurement when the NCC needs a supplier to deliver its own project task. Misclassifying the mechanism can undermine eligibility, conflict-of-interest controls and budget traceability.

Mandatory FSTP Open-Call Rules

If the project includes FSTP, its open calls must:

  1. be open, widely published and compliant with transparency, equal treatment, confidentiality and conflict-of-interest standards;
  2. appear on the Funding & Tenders Portal and the relevant participants' websites;
  3. remain open for at least two months;
  4. publish deadline changes immediately and notify registered applicants;
  5. publish outcomes, including selected-project descriptions, award dates, durations, legal names and countries of final recipients;
  6. have a clear European dimension.

The FSTP ceiling is €100,000 per recipient. The topic states that amounts above €60,000 may be necessary due to the nature of the action, but this does not make them automatic. The open-call objectives, cost logic, selection criteria and expected outputs still need to justify each award.

The 50% topic funding rate applies to the total eligible costs of the action, including the budget allocated to FSTP. The proposal should therefore model EU contribution, co-financing and cash flow at both project and scheme level without promising a recipient rate that the final open-call conditions do not support.

Ownership and Control Assessment Before Every Award

Because this is a restricted cybersecurity call, an NCC implementing FSTP must be able to assess each intended recipient's establishment, geographic location, ownership, control and security compliance. The applicant must demonstrate that operational capacity in Part B, Section 2.3, at proposal stage.

The OCA method should cover:

  • governance and allocation of responsibilities for the FSTP scheme;
  • staffing, expertise and independent review of conclusions;
  • application forms, declarations and supporting-document requirements;
  • direct, indirect and ultimate ownership chains;
  • voting, veto, appointment and other strategic-control rights;
  • de jure and de facto control;
  • board composition, quorum and majority arrangements;
  • commercial, financial or other links that may confer decisive influence;
  • clarification, decision, approval and conflict-of-interest procedures;
  • confidentiality, retention, audit trail and access-to-file controls.

The assessment must be complete before the financial support award and before signature of the sub-grant or equivalent arrangement. A selected recipient needs a complete OCA file. If the recipient does not satisfy the applicable restrictions, support must not be awarded or proceed. The granting authority may inspect individual files or samples during preparation and implementation. The Commission's official ownership-and-control guidance should be incorporated into the scheme design.

A Credible National Ecosystem Model

The strongest proposals connect community-building activities into one operating loop:

  1. Map: maintain evidence on national stakeholders, capabilities, gaps, solutions and funding needs.
  2. Engage: register community members, run targeted outreach and collect structured demand.
  3. Match: connect SMEs, public buyers, research, investors and cross-border partners.
  4. Support: provide technical assistance, training, tools or transparent third-party funding.
  5. Measure: track uptake, capacity improvement, market access and community participation.
  6. Reuse: share practices with other NCCs and embed successful services into sustained national operations.

A collection of unrelated events is weaker than a service model with defined users, entry criteria, hand-offs, evidence and repeatable outcomes.

Expected Outcomes and Evidence

The topic permits a broad outcome portfolio, but each selected result needs verifiable completion evidence.

Outcome family Evidence to plan
Community operation Registered and active entities, support interactions, governance and engagement records
Solution uptake Organizations onboarded, tools or services deployed, acceptance evidence and measured capacity gain
FSTP delivery Published calls, evaluations, OCA files, signed awards, recipient outputs and audit trail
Startup and SME growth Market-readiness milestones, matchmaking, procurement or investment pathways and follow-up
Skills and awareness Target groups, competency objectives, participation, assessment and behaviour or capability change
Cross-border NCC cooperation Joint activities, shared methods, interoperable services and reused practices
Observatory or marketplace Data model, active users, maintained records, governance and sustainability

The proposal should define what continues after the grant: service ownership, platform maintenance, recurring funding, community stewardship and reuse by other NCCs.

Mandatory KPI Contract

The call defines three mandatory topic indicators:

  1. Number of entities supported through NCC project activities to adopt state-of-the-art cybersecurity solutions.
  2. Number of entities supported in solution uptake, dissemination and cybersecurity-capacity strengthening, including the number of SMEs.
  3. Number of entities receiving Financial Support to Third Parties.

Optional KPIs include access to EU cybersecurity facilities, incident-preparedness support, Community candidates, matchmaking and funding events, local assistance interactions, promotion actions and collaboration with other NCCs and the ECCC.

For every applicable KPI, define baseline, target, counting rule, evidence source, collection frequency and responsible partner. Avoid double counting the same entity across overlapping activities unless the indicator definition explicitly permits it. If FSTP is not included, explain why the third mandatory indicator is not applicable to the proposed activity mix.

A Practical Work-Package Model

This is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Governance and ECCC coordination Control mandate, security, finance, risks and network relations Governance plan, controls, coordination records
WP2 Community and observatory Map, register and engage national stakeholders Community data, services, engagement evidence
WP3 Uptake and market support Move European solutions toward adoption and scale Assessments, matchmaking, deployment support
WP4 Skills and awareness Improve role-based capability and cyber hygiene Training, exercises, campaigns and assessments
WP5 FSTP and OCA Run transparent support calls and recipient controls Call package, evaluations, OCA files, awards and monitoring
WP6 Measurement and sustainability Prove results and preserve successful services KPI evidence, annual outputs and continuity plan

The common call rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables covering relevant KPIs and project outputs.

Funding and Cost Model

NCC is a Simple Grant with a maximum EU funding rate of 50%, including FSTP allocations. The expected EU contribution is €2-3 million per project and the indicative duration is 36 months.

The budget-based mixed actual-cost grant includes the cost categories and controls specified in the call. Planning should account for:

  • indirect costs at 7% of applicable eligible direct costs;
  • depreciation-only treatment for equipment;
  • the €100,000 maximum per third-party recipient;
  • staffing for open calls, evaluations, OCAs, monitoring, audit and recipient support;
  • co-financing, pre-financing needs and financial capacity;
  • non-deductible VAT rules, including the exclusion applicable when public bodies act as public authorities.

FSTP is not administratively free. The project budget needs enough qualified capacity for selection, ownership checks, contracting, payment, monitoring, record retention and recovery or suspension where conditions are breached.

How Evaluators Will Read the Proposal

Criterion NCC evidence to emphasize Pass threshold
Relevance Recognized NCC mandate, selected official activities, national need, ECCC and EU complementarity 3/5
Implementation Operational capacity, partner roles, FSTP/OCA method, resources, milestones and risk controls 3/5
Impact Measurable uptake, stronger capacities, SME reach, community value, cross-border reuse and sustainability 3/5
Overall Combined score 10/15

For NCC, three general award subcriteria are explicitly not applicable: reinforcement of the EU digital technology supply chain, overcoming lack of market finance and contribution to environmental sustainability or Green Deal goals. Passing the thresholds does not guarantee funding; ranking and subsequent legal, financial and security checks still apply.

Eligibility, Security and Application Package

Beneficiaries and affiliated entities must generally be eligible legal entities established in EU Member States or Norway, Iceland or Liechtenstein. Article 12(5) restrictions limit participation in every capacity to entities established in and controlled from eligible countries. Project activities and subcontracted work must also take place there.

The application includes online Part A, technical Part B limited to 70 pages, and the required ownership-and-control declarations. An applicant planning FSTP must also describe its operational capacity and OCA methodology at proposal stage. Submission is exclusively electronic through the Funding & Tenders Portal.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

The Italian NCC-IT Context

In Italy, the National Cybersecurity Agency is NCC-IT under Decree-Law 82/2021 and Regulation (EU) 2021/887. ACN describes NCC-IT as the contact point between the national cybersecurity stakeholder community and the ECCC. It promotes ECCC opportunities, supports the national Community and evaluates requests for membership.

This context does not make every Italian stakeholder a direct applicant under CYBER-11-NCC. Companies, universities, research bodies and associations should distinguish among consortium participation with a recognized NCC, future FSTP opportunities, Community membership and other ECCC topics for which they may apply directly.

Readiness Checklist

  1. Confirm that a Commission-recognized NCC anchors the proposed applicant structure.
  2. Select only the official activity families that fit the NCC's mandate and national need.
  3. Map existing EU, national and regional initiatives and document non-duplication.
  4. Assign measurable outputs, resources and responsibilities to every consortium partner.
  5. Decide whether FSTP is necessary or whether consortium delivery and procurement are more appropriate.
  6. If using FSTP, design a two-month public call, selection criteria, award package and European dimension.
  7. Build OCA staffing, methodology, evidence, review and audit access before proposal submission.
  8. Define the three mandatory KPIs and prevent double counting.
  9. Model 50% co-financing, FSTP cash flow, equipment depreciation and administrative cost.
  10. Verify ownership, control, location and subcontracting restrictions and submit the live portal forms before the deadline.

Frequently Asked Questions

Can a cybersecurity company apply without an NCC?

Not under the target model stated by this topic. It exclusively targets Commission-recognized NCCs, while other private and public entities may participate in consortium with NCCs.

Must every NCC proposal include FSTP?

No. The call says FSTP may be used. An NCC can select other eligible activities according to its mandate. If FSTP is omitted, the proposal should make the non-applicability of the related KPI explicit.

Is €100,000 the project grant amount?

No. It is the maximum financial support for one third-party recipient. The expected EU contribution to an NCC project is €2-3 million, within an €11 million topic budget.

Can an FSTP call stay open for one month?

No. The official conditions require it to remain open for at least two months and to be published on both the Funding & Tenders Portal and participant websites.

Can the OCA be completed after selecting and paying a recipient?

No. The OCA must be complete before financial support is awarded and before the sub-grant or equivalent agreement is signed. A non-compliant recipient cannot receive the support.

Does the 50% rate exclude the FSTP budget?

No. The call states that the maximum 50% EU funding rate applies to total eligible action costs, including any FSTP allocation.

Does reaching 10/15 guarantee funding?

No. The proposal must also achieve at least 3/5 for each criterion, rank within the available budget and pass subsequent legal, financial, ownership and security checks.

Conclusion

CYBER-11-NCC funds the operating capacity that connects national cybersecurity communities with European programmes, solutions and skills. A strong proposal starts from a recognized NCC mandate, selects a coherent service portfolio and proves how community support will produce measurable adoption and durable capacity.

Where FSTP is used, the administration is part of the cybersecurity result: transparent selection, ownership-control evidence, conflict management and auditable recipient monitoring are mandatory design elements. Our Virtual CISO service can help you structure risk, governance, evidence and monitoring workflows; for the SMEs receiving support, the Cyber Check-up provides a first documented measure of their security posture.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

September 27, 2026

Digital Europe Cybersecurity Call 2027: €96 Million Across Seven ECCC Topics

The ECCC opened a €96 million Digital Europe call across seven cybersecurity topics, with a single-stage deadline of 14 January 2027 at 17:00 CET. Ho…

October 06, 2026

ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security

The REGCABH topic funds Regional Cable Hubs that pool maritime, cyber and operator data to detect threats to undersea cables. The mandatory authority…

October 02, 2026

ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing

The COORDPREP topic funds coordinated preparedness testing and wider preparedness services, led by designated public cybersecurity bodies with privat…