Digital Europe: Coordinated preparedness testing and other preparedness actions

The content of this page has been checked on 4 September 2026

This Digital Europe Programme call aims to strengthen the cyber resilience of organisations operating in highly critical and other critical sectors through coordinated preparedness testing and other cybersecurity preparedness measures. The funding supports Member States in improving their preparedness for cyber threats and incidents by providing testing, risk assessments, monitoring, training, and expert support.

Practical information

  • Application period: 1 September 2026 – 14 January 2027
  • Budget: € 15 million. A – € 10 million, B – € 5 million 
  • Expected number of projects funded: 10
  • Estimated project duration: 2 years
  • Subsidy programme: Digital Europe Programme, Cybersecurity work programme

The funding consists of two components:

A) Coordinated Preparedness Testing – funding for activities such as penetration testing, threat and risk assessments, cybersecurity capability evaluations, cyber ranges, stress testing, and consultancy services to improve the security of critical infrastructure.

B) Other Preparedness Actions – funding for continuous risk monitoring, coordinated vulnerability disclosure and management, supply chain risk management, cybersecurity exercises, training programmes, and awareness-raising activities to support compliance with EU cybersecurity legislation.

Conditions

Proposals should contribute to achieving at least one of the following objectives:  

• (part 1) Coordinated preparedness testing of entities operating in sectors of high criticality across the Union (including penetration testing and threat assessment) considering ICT as well as Operational Technology/Industrial Control Systems.  

• (part 2) Other preparedness actions for entities operating in sectors of high criticality and other critical sectors (i.e. vulnerability monitoring, exercises and training courses).

Submission criteria

For (A): Public bodies acting as cybersecurity competent authorities or CSIRTs. Public bodies subject to the NIS 2 Directive, CRA, CSA, CSoA, DORA etc.

For (B): Public bodies acting as cybersecurity competent authorities or CSIRTs, National Cyber Hubs, as identified by the Member States. Public bodies and other entities subject to the NIS 2 Directive (highly critical and other critical sectors entities), CRA, CSA, CSoA, DORA etc. Or Industry stakeholders, other public and private entities that can support the implementation of the NIS 2 Directive (along with or for highly critical and other critical sectors or entities), CRA, CSA, CSoA, DORA, GDPR, etc. Trusted cybersecurity service providers.

Only entities based in the EU (including Overseas Countries and Territories (OCTs)), Norway, Iceland and Liechtenstein are eligible for this grant, provided that they are not (potentially) subject to influence or control by entities outside the EU, Norway, Iceland and Liechtenstein.

Learn more about the conditions of the call on the Funding and Tender Portal.

Questions about cybersecurity subsidies?

Need help finding the right subsidy? Then, fill in our contact form and an adviser will contact you for personal advice.

Commissioned by:
  • Logo Funded by the European Union
In association with:
  • Logo Funded by the European Union