ECCC Regional Cable Hubs 2027: Funding for Cross-Border Undersea Cable Security

The REGCABH topic funds Regional Cable Hubs that pool maritime, cyber and operator data to detect threats to undersea cables. The mandatory authority consortium, the three project routes, secure information sharing, the KPIs and the 70% funding model.

October 06, 2026 14 min read

Server room aisle with racks and cabling Made with AI
Contents
  1. In Brief
  2. Scope and Source Boundary
  3. REGCABH at a Glance
  4. The Mandatory Consortium Boundary
  5. Three Eligible Project Routes
  6. The Hub Operating Model
  7. An All-Hazards Security Model
  8. Secure Data and Information-Sharing Design
  9. Private-Sector and Defence Cooperation
  10. Expected Outcomes and Evidence
  11. Mandatory KPI Contract
  12. A Practical Work-Package Model
  13. Funding and Cost Model
  14. How Evaluators Will Read the Proposal
  15. Eligibility, Security and Application Package
  16. Readiness Checklist
  17. Frequently Asked Questions
  18. Conclusion
  19. Guides in the ECCC 2027 Series
  20. Official Sources

Applies to: competent public authorities responsible for cable security, maritime security, resilience or critical-infrastructure protection, and technical or operational partners considering DIGITAL-ECCC-2027-DEPLOY-CYBER-11-REGCABH.

REGCABH provides €5 million to establish, expand or upgrade Regional Cable Hubs that improve threat detection and operational security for undersea cables. The expected EU contribution is about €2.5 million per project, the funding rate is an exceptional 70%, and the indicative duration is 36 months. Proposals are due by 14 January 2027 at 17:00 CET. Unlike the other topics in this call, REGCABH requires a cross-border, multi-beneficiary consortium: at least two independent applicants from two eligible countries and competent public authorities from at least two Member States concerned by the relevant sea basin (official call document).

In Brief

  • The authority core is mandatory: competent public authorities from at least two Member States in the same sea basin must participate.
  • Other public or private partners may support technical and operational implementation, but cannot replace the cross-border authority requirement.
  • Projects may establish a new hub, expand an existing funded hub to additional Member States or upgrade its capabilities.
  • The operating result is near-real-time situational awareness based on pooled data, automated analysis, incident reporting and secure authority-to-authority information sharing.
  • The scope follows an all-hazards model that covers cyber threats and the physical environment, including malicious cable damage.
  • The two mandatory KPIs count deployed infrastructures, tools and services and implemented processes for detection, reporting and information sharing.
  • Article 12(5) security restrictions apply because hubs handle sensitive operational information.
  • The 70% rate is exceptional and reflects the geopolitical importance of cable-security activities.

Scope and Source Boundary

This guide explains the official consortium model, three project routes, operational capabilities, evidence requirements, funding mechanics and security controls for REGCABH. It does not determine whether a specific authority, sea basin, technology or cost is eligible and does not replace the call document, applicable classified-information rules or the live Funding & Tenders record.

The topic implements the EU Action Plan on Cable Security, which addresses prevention, detection, response, recovery and deterrence for critical submarine infrastructure. Regional Cable Hubs are the sea-basin cooperation mechanism for the detection and operational-awareness layer.

REGCABH at a Glance

Parameter Official value
Topic DIGITAL-ECCC-2027-DEPLOY-CYBER-11-REGCABH
Topic budget €5 million
Type of action Simple Grant
Funding rate 70%
Expected EU contribution €2.5 million per project
Indicative duration 36 months
Minimum consortium Two independent beneficiaries from two eligible countries
Authority requirement Competent public authorities from at least two Member States in the relevant sea basin
Equipment-cost treatment Depreciation and full cost for listed equipment
Part B limit 70 pages
Submission deadline 14 January 2027, 17:00 CET

The expected €2.5 million contribution is a planning value, not an automatic award or fixed ceiling. A different amount may be considered when duly justified, and the final grant may be lower than requested. The call budget remains subject to final adoption of the relevant 2025-2027 Work Programme amendment.

The Mandatory Consortium Boundary

REGCABH has a stricter composition rule than the other six topics in the call.

Requirement Practical meaning
Multi-beneficiary application A single applicant cannot submit a valid REGCABH proposal
Two independent applicants At least two beneficiaries, not merely affiliated entities
Two eligible countries The independent applicants must come from different eligible countries
Two Member State authorities Competent public authorities from at least two Member States concerned by the sea basin must be included
Sea-basin relevance The authority mandate and operational role must relate to the same proposed regional basin

Competent authorities may include ministries, agencies or other public entities responsible for cable security, maritime security, resilience or critical-infrastructure protection. A larger number of Member States is preferable. Cable operators, telecom providers, maritime-data actors, satellite or sensor providers, cyber operators, research organizations and other specialists may join when needed for implementation.

The proposal should document each authority's mandate, data contribution, decision rights, incident role and operational commitment. A consortium that meets the country count but lacks authority to share or act on sensitive information will remain structurally weak.

Three Eligible Project Routes

The topic supports three distinct starting points.

1. Establish a New Regional Cable Hub

Create governance, processes, technical environments and services for a sea basin that does not yet have the required cooperative capability. The proposal needs an operating model, not only a platform acquisition.

2. Expand an Existing Hub

Bring additional Member States into a Regional Cable Hub project funded under an earlier call. Expansion should add operational coverage, information sources, authority participation or response capability rather than simply reproduce the existing arrangement.

3. Upgrade Hub Capabilities

Extend scope or introduce more predictive, automated, interoperable and operationally actionable situational awareness. Upgrades may include a defence dimension where Member States choose to integrate relevant capacities.

In June 2026, the Commission announced funding for the first Regional Cable Hubs in the Baltic and Mediterranean seas. The current call can build on that progress but does not limit proposals to those two regions or guarantee continuation funding (European Commission announcement).

The Hub Operating Model

A Regional Cable Hub is a cooperative operational structure, not a static database. Its capability chain should connect data collection to action.

Capability Operational result Evidence to define
Data aggregation Pool authorized maritime, cyber, cable, sensor and satellite information Sources, legal basis, quality, latency and ownership
Automated analysis Detect patterns, anomalies and emerging threats Models, rules, performance, analyst review and limitations
Situational awareness Maintain a near-real-time regional operating picture Coverage, update frequency, confidence and user workflows
Incident reporting Receive, classify, enrich and route reports Intake criteria, severity, timestamps, escalation and audit trail
Information sharing Exchange actionable information among designated authorities Classification, access, release rules, formats and secure channels
Response coordination Support decisions and rapid action across jurisdictions Roles, triggers, playbooks, exercises and after-action evidence

The call explicitly references existing sources and systems such as the Integrated Maritime System, Common Information Sharing Environment (CISE), National Cyber Hubs, Copernicus and MARSUR. A proposal should show how it will integrate relevant systems without assuming unrestricted access or duplicating their functions.

An All-Hazards Security Model

Undersea cables fall within the NIS 2 all-hazards approach. The topic therefore treats cable cybersecurity and the physical environment as one risk system.

A useful threat model should cover:

  • malicious cuts, sabotage and coordinated physical-cyber actions;
  • accidental damage from maritime activity;
  • compromise of cable-management, monitoring or landing-station systems;
  • manipulation, loss or delayed sharing of operational data;
  • supply-chain, maintenance and repair dependencies;
  • disruption affecting communications, energy links or connected essential services;
  • insider, credential and access-control risks;
  • cascading impact across borders and other critical infrastructures.

Controls should connect prevention, detection, escalation, response and recovery. A strong proposal does not claim that surveillance alone secures the cable: it defines how a verified signal reaches an authority that can assess and act.

Secure Data and Information-Sharing Design

The hubs are expected to exchange information rapidly, potentially including classified information. Participating authorities must establish procedural cooperation and information-sharing arrangements.

Define at least:

  1. data owners, permitted purposes and legal bases for every source;
  2. classification levels, handling rules and releasability across jurisdictions;
  3. identity, role, need-to-know and least-privilege controls;
  4. secure ingestion, transport, storage, logging and retention;
  5. quality, provenance, confidence and false-positive handling;
  6. human validation and authorization for operational decisions;
  7. incident-reporting thresholds and escalation paths;
  8. continuity, backup and degraded-mode operation;
  9. rules for voluntary private-sector reporting and onward disclosure;
  10. governance for adding new Member States, partners or data sources.

The proposal should separate what can be shared automatically, what requires analyst approval and what cannot leave a national or classified domain.

Private-Sector and Defence Cooperation

Direct cooperation with cable operators and other private entities is expected to increase access to information on threats and voluntary incident reporting within a highly secure framework. Private partners may also contribute sensing, analytics, communications, maintenance, repair or cyber-operational services.

Member States may progressively integrate relevant defence capacities, such as naval or surveillance capabilities, using a dual-use approach. This is an option controlled by participating Member States, not a requirement that every consortium include defence bodies. Civilian authority, classification, data-use and command boundaries must remain explicit.

Where participating states decide, a hub may coordinate deployment and activation of modular repair equipment across the sea basin. The topic may also support additional infrastructure, tools, instruments, equipment or services that improve cable resilience and security. Acquisition must remain connected to an operating capability, trained users, maintenance and measurable use.

Expected Outcomes and Evidence

The expected result is stronger collective situational awareness, detection and operational capacity for cable security.

Outcome family Evidence of completion
Hub governance Signed cooperation model, mandates, decision rights and operational procedures
Regional awareness Integrated sources, coverage, service availability and validated operating picture
Threat detection Detection methods, verified events, performance and analyst workflow
Incident reporting Tested intake, classification, authority routing and response records
Secure information sharing Connected authorities, exchange tests, classification controls and audit logs
Private cooperation Agreements, voluntary reporting workflows and data-use controls
Response and repair Exercised playbooks, mobilization conditions, equipment readiness and lessons learned
Expansion or upgrade New country coverage, capabilities, integrations or operational users accepted into service

Preparatory and running costs may be supported, as may infrastructure, tools and services needed to establish or operate the hub. The proposal should still distinguish a deliverable from an operational outcome: buying sensors is not the same as maintaining a verified regional detection service.

Mandatory KPI Contract

The call defines two mandatory topic indicators:

  1. Number of cybersecurity infrastructures, tools and services developed or acquired to establish, operate or upgrade the Hub and strengthen cable security and resilience.
  2. Number of processes established and implemented for threat detection and analysis, incident reporting and authority information sharing.

Optional indicators include surveillance and protection solutions, active collaborations for threat information and voluntary reporting, CTI and situational-awareness services, and tools for automated threat detection and incident response.

Each applicable KPI needs a baseline, target, unit, evidence source, collection frequency and responsible partner. Count an item under the category that best reflects its principal nature and do not count it twice. Process indicators should require implementation and testing, not only approved documentation.

A Practical Work-Package Model

This is a planning pattern, not a mandatory ECCC template.

Work package Purpose Representative outputs
WP1 Cross-border governance Establish mandates, decisions, security and cooperation Consortium governance, sharing procedures, risk register
WP2 Data and integration Connect authorized maritime, cyber, satellite and operator data Data agreements, interfaces, quality and classification controls
WP3 Detection and awareness Build or upgrade analytics and regional operating picture Detection services, dashboards, analyst workflows and validation
WP4 Reporting and response Route incidents and coordinate authority action Reporting function, playbooks, exercises and after-action reports
WP5 Private and defence interfaces Govern voluntary reporting and optional dual-use inputs Partnership agreements, release rules and operational boundaries
WP6 Operations and sustainability Run, measure and maintain the Hub Service levels, KPI evidence, maintenance and continuation plan

The common rules also require a dissemination and exploitation deliverable within the first six months and yearly deliverables covering relevant KPIs and project outputs. Dissemination must be reconciled with sensitive and classified-information restrictions.

Funding and Cost Model

REGCABH is a Simple Grant with an exceptional 70% co-funding rate. The expected EU contribution is €2.5 million per project, and the indicative duration is 36 months.

The budget-based mixed actual-cost grant uses the cost categories and controls defined by the call. Planning should account for:

  • indirect costs at 7% of applicable eligible direct costs;
  • depreciation and full cost for listed equipment;
  • the consortium's remaining co-financing requirement;
  • secure infrastructure, integration, operations and maintenance;
  • classified-capable environments and personnel where necessary;
  • exercises, validation, travel and cross-border coordination;
  • lifecycle costs beyond acquisition, including updates, support and replacement.

Full-cost treatment is limited to listed equipment under the grant conditions. Every item should trace to a work package, user, capability, acceptance criterion and maintenance owner.

How Evaluators Will Read the Proposal

Criterion REGCABH evidence to emphasize Pass threshold
Relevance Sea-basin need, authority mandates, correct consortium and alignment with the EU cable-security plan 3/5
Implementation Mature governance, secure data access, technical integration, staffing, equipment and operational tests 3/5
Impact Regional coverage, faster detection and exchange, operational use, expansion and sustainable cooperation 3/5
Overall Combined score 10/15

For REGCABH, three general award subcriteria are explicitly not applicable: reinforcement of the EU digital technology supply chain, overcoming lack of market finance and contribution to environmental sustainability or Green Deal goals. Passing the thresholds does not guarantee funding; ranking and legal, financial and security checks still apply.

Eligibility, Security and Application Package

The consortium must satisfy both the common eligible-country rules and the topic-specific Member State authority requirement. Article 12(5) restrictions limit participation in every capacity to entities established in and controlled from eligible countries. Project activities and subcontracted work must also take place there.

The application includes online Part A, technical Part B limited to 70 pages, and required ownership-and-control declarations. Because the Hub may handle sensitive or classified information, the proposal should identify applicable security approvals, environments, roles and constraints rather than defer them to implementation.

Date or period Milestone
1 September 2026 Call opening
14 January 2027, 17:00 CET Submission deadline
February-March 2027 Indicative evaluation
April 2027 Indicative result notification
October 2027 Indicative grant-agreement signature

Readiness Checklist

  1. Define the relevant sea basin and document the regional cable-security need.
  2. Include two independent beneficiaries from two eligible countries.
  3. Include competent public authorities from at least two concerned Member States.
  4. Choose whether the project establishes, expands or upgrades a Hub.
  5. Secure authority and operator commitments for data, decisions and incident workflows.
  6. Map cyber, physical, supply-chain, repair and cross-border dependencies.
  7. Define classification, access, release, retention and audit controls before integration.
  8. Connect infrastructure and equipment to accepted operational services and trained users.
  9. Set both mandatory KPIs and test each implemented process.
  10. Build the 70% funding and co-financing model and submit the live portal forms before the deadline.

Frequently Asked Questions

Can one authority submit a REGCABH proposal alone?

No. Multi-beneficiary applications are mandatory. The consortium needs at least two independent applicants from two eligible countries and competent public authorities from at least two Member States concerned by the sea basin.

Can a cable operator or technology company lead without public authorities?

No. Private entities may support technical and operational implementation, but they do not replace the mandatory public-authority composition.

Must the proposal create a completely new Hub?

No. It may create a new Hub, expand an existing funded project to new Member States or upgrade capabilities such as automation, interoperability, prediction or the defence dimension.

Is the topic limited to cyber incidents?

No. It follows an all-hazards approach that includes physical events and malicious cable damage as part of cable-security risk.

Is defence participation mandatory?

No. Participating Member States may progressively integrate relevant defence capacities. The proposal must define civilian, security, data and command boundaries when it does so.

Is €2.5 million the maximum grant?

No. It is the expected EU contribution per project. A different amount may be considered when duly justified, and the final award may be lower than requested.

Does reaching 10/15 guarantee funding?

No. The proposal must also reach 3/5 for every criterion, rank within the available budget and pass subsequent legal, financial and security checks.

Conclusion

REGCABH funds cross-border operational capacity, not a standalone surveillance platform. A strong proposal joins competent authorities around one sea basin, establishes secure data and decision arrangements, and proves that detection, reporting and information sharing can work under real operational constraints.

We can help you structure governance, risk, controls and evidence through our Virtual CISO service, and define your NIS 2 incident notification workflows. Final eligibility, classified-information, procurement, cost and submission decisions must remain anchored to the official call, applicable national and EU rules and the live Funding & Tenders record.

Guides in the ECCC 2027 Series

Official Sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

October 02, 2026

ECCC COORDPREP 2027: Funding for Coordinated Cyber Preparedness Testing

The COORDPREP topic funds coordinated preparedness testing and wider preparedness services, led by designated public cybersecurity bodies with privat…

September 30, 2026

ECCC EULEG Funding 2027: From Cybersecurity Law to Shared Capability

The EULEG topic funds shared capacity to implement EU cybersecurity law, from NIS 2 reporting to CRA testing and certification. What it pays for, wha…

October 05, 2026

ECCC NCC Network Funding 2027: How National Coordination Centres Support Cyber Ecosystems

The NCC topic funds the operating capacity of National Coordination Centres and their communities, including financial support to third parties. Who …