Summary
- The ECCC has opened seven Digital Europe cybersecurity funding strands worth a combined €96 million, with applications closing in January.
- Funding spans AI security, SME protection, regulatory compliance, preparedness testing, undersea cables, national coordination, and dual-use technology.
- The programme concentrates on deployment and operational capacity as organisations absorb requirements under NIS2, DORA, the Cyber Resilience Act, and other EU rules.
Europe is putting another €96 million behind cybersecurity deployment, with a new funding round spanning AI-powered defence tools, regulatory compliance, critical infrastructure preparedness, undersea cables, and technology designed for both civilian and defence environments.
The European Cybersecurity Competence Centre opened seven calls under the Digital Europe Programme on 1 September, with proposals accepted until 14 January 2027. Much of the programme is directed towards deploying technology and building operating capacity around threats already reflected in European regulation and infrastructure planning.
The largest individual allocations are €20 million for AI-powered cybersecurity products aimed at European SMEs and another €20 million to help organisations strengthen capabilities in line with legislation including the Cyber Resilience Act, NIS2, GDPR, DORA, the Cybersecurity Act, and parts of the AI Act. A further €15 million is allocated to cybersecurity tools that themselves rely on AI.
Another €15 million will support coordinated preparedness testing, while €11 million is earmarked for the National Coordination Centre network. Regional undersea cable hubs receive €5 million, and a €10 million dual-use strand is intended to support prototypes, market-ready products, and operational infrastructure relevant to both civilian and defence environments.
The full ECCC call ranges from tooling for small businesses to infrastructure used by national authorities and operators in critical sectors.
Compliance is becoming an implementation market
European cyber legislation is normally discussed through obligations, reporting deadlines, and penalties, although implementation is also creating demand for software, services, training, and operational capacity. NIS2 expands requirements across sectors considered important to the economy, DORA applies operational resilience rules across financial services, and the Cyber Resilience Act extends security requirements into connected products and software.
The €20 million EULEG strand is designed around that implementation problem. Organisations face requirements to improve vulnerability management, incident handling, governance, and technical controls, while many smaller suppliers and public bodies lack the internal security capability needed to turn regulatory language into working processes.
Funding can narrow part of that gap, but it cannot remove the organisational work behind compliance. Security technology still has to be procured, integrated, maintained, and operated by people capable of interpreting alerts and managing incidents, while supply chains frequently connect organisations with very different levels of technical maturity.
The SME-focused AI programme addresses a related constraint because smaller organisations are increasingly expected to meet controls developed around threats that once sat mainly inside large enterprises. The ECCC intends the €20 million allocation to support practical risk management, threat detection, incident response, and notification tools rather than assuming every business can maintain a security operations centre.
AI sits on both sides of the security problem
Artificial intelligence occupies two positions in the programme, with one strand supporting AI-powered security tools and another explicitly addressing whether those systems remain secure, resilient, and trustworthy. The distinction becomes harder to ignore as generative models and software agents enter defensive operations while attackers use the same technology to automate reconnaissance, social engineering, and parts of vulnerability exploitation.
The €15 million CYBERAI strand covers systems for national and cross-border cyber hubs, incident-response teams, public bodies, NIS2 entities, and other security organisations. Threat detection and incident recovery sit alongside vulnerability discovery, data analysis, and information sharing, treating AI as part of the operational security stack rather than as a standalone product category.
Greater reliance on AI introduces another attack surface around models, data pipelines, access controls, and automated decisions. A defensive tool that can itself be manipulated, or whose outputs cannot be trusted, may transfer risk rather than reducing it, particularly when it has privileged access to other systems.
Physical infrastructure joins the cyber budget
The programme also gives visible funding to the physical systems carrying European data. Regional Cable Hubs receive €5 million for threat detection, situational awareness, incident reporting, and information exchange between national authorities involved in protecting undersea connectivity.
That allocation reflects a broader change in how digital resilience is understood. Cloud and telecommunications services ultimately depend on physical cables, landing stations, power, and network equipment, while disruption to those assets can have effects that software controls alone cannot repair.
The €15 million preparedness strand is similarly operational, supporting penetration testing, threat assessment, vulnerability monitoring, exercises, and training for organisations in highly critical sectors. Those activities sit within the Cyber Solidarity Act’s preparedness framework, where weaknesses are intended to be found before an incident develops into a cross-border disruption.
Meanwhile, the €10 million dual-use allocation illustrates the growing overlap between commercial cybersecurity, national security, and defence technology. Communications, identity, threat intelligence, and incident response can serve both civilian and government users, although projects in that category face additional European security requirements.
Digital Europe was designed to narrow the gap between research and practical adoption, and this funding round gives that objective a broad cybersecurity test. Once awards are made, the more demanding measure will be whether €96 million translates into tools and operating capacity that can function across fragmented national systems, regulated supply chains, and critical infrastructure already facing active threats.












