DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STRENGTHENCRA

Strengthen Cybersecurity capacities of European SMEs in line with CRA requirements and obligations -

Related topics

Drag to rearrange · hover a topic or connection to preview why it's linked, click to pin that panel open

Topics in this graph

Bold node = current topic · node color = call status · hover for details, click to pin · smaller, lighter topics are two steps away

Call text (as on F&T portal)

View on F&T portal
Expected Outcome:

Deliverables:

  • Financial support for SMEs and other stakeholders for CRA compliance.
  • Openly available platform with CRA-related resources (such as guidelines and supporting documents), providing supporting community building and upskilling
  • Workshops, events, networking and exchange of experience of stakeholders
  • Contributions to CRA standardisation
Objective:

The objective of this topic is to support European SMEs, with a focus on micro and small enterprises, to strengthen their cybersecurity capacities and to support the implementation of the proposed Regulation on the Cyber Resilience Act (CRA).

Scope:

In synergy with other actions launched under this WP which will be developing compliance tools for the CRA, the action should distribute cascade financing grants to European SMEs, with a focus on micro and small enterprises, though remaining open to other stakeholders, to support achieving compliance with requirements and obligations stemming from the CRA.

Applicants are encouraged to identify categories of cascade financing recipients, including at least the following:

  • Manufacturers of products with digital components, including software developers.
  • Providers of tools and solutions that facilitate compliance with CRA obligations.
  • Other well-justified categories in line with CRA (e.g., distributors, importers, open-source community).

For each identified stakeholder category, a dedicated set of activities should be devised taking into consideration the specific needs of target consumers, business users, and other relevant stakeholders.

The proposed project should include actions addressing the following:

  • Awareness raising, dissemination and other stakeholder engagement actions with the focus on the cascade financing to European SMEs, with a focus on micro and small enterprises.
  • Managing an open call process to distribute cascade funding, including impartial evaluation of proposals and monitoring the implementation of grants.
  • Establish an openly available platform providing links to CRA-related resources that the proposed project itself would collect or develop or which would be available from external sources and supporting community building and upskilling. This includes for example a dedicated central repository website to allow easy finding of internal and external resources, step-by-step guidelines, compliance tools, training materials, free and open-source code implementations, and other relevant resources to achieve CRA compliance. This should include, amongst others, tools procured for this purpose under this work programme.
  • In close coordination with the EU Cybersecurity Skills Academy, perform trainings and upskilling of stakeholders to achieve CRA compliance, i.e. organise workshops, training sessions, and events, draft guidelines, supporting actions to facilitate interaction among European SMEs, including drafting reports or other material discussing the implementation of CRA compliance requirements and promoting awareness, including by contributing to relevant deliverables of standardisation bodies e.g. through a sectoral perspective and informed by the needs of companies on the ground.
  • Facilitate and share CRA compliance best-practices and use-cases.
  • Contribute to standardisation efforts, as appropriate, considering the activities of European and international standardisation that are directly relevant to the CRA implementation.

Third parties receiving grants should, in particular:

  • Engage in testing, detecting and addressing vulnerabilities, producing documentation, carrying out conformity assessment and implementing other measures necessary to comply with the CRA.
  • Participate in workshops, training sessions, and events that facilitate interaction among European SMEs, with a focus on micro and small enterprises, to discuss and implement CRA compliance.
  • Contribute to the proposed project’s efforts in collecting the needs and perspectives of SMEs towards CRA-related standardisation deliverables.

Priority should be given to solutions available to use free of charge or free and open-source software (FOSS) solutions both when setting up the openly available platform and when distributing cascading finance grants.

These activities should be carried out in close coordination, and where possible collaboration, with the European Cybersecurity Competence Centre (ECCC), the Network of National Coordination Centres (NCCs), the European Digital Innovation Hubs (EDIHs) network, other relevant European and National cybersecurity entities, and other projects of this work programme.

The operational involvement of NCCs in implementing and running such actions is strongly recommended.

Indicatively one proposal is expected to be financed via this topic. Proposed projects should foresee at least 75% of the budget to be distributed for cascade financing grants.

This action includes the creation of a central platform that serves as a reference point, and hence will enable interactions between providers of essential services and critical infrastructures, as well as other actors, regarding their cybersecurity measures and possible vulnerabilities. Also third parties receiving funding will engage in solutions for testing, detecting and addressing vulnerabilities. As such information could be exploited by malicious actors, the central entity handling such must be protected against possible dependencies and vulnerabilities in cybersecurity to pre-empt foreign influence and control. As previously noted, participation of non-EU entities entails the risk of highly sensitive information about security infrastructure, risks and incidents being subject to legislation or pressure that obliges those non-EU entities to disclose this information to non-EU governments, with an unpredictable security risk. Therefore, based on the outlined security reasons, the actions relating to these technologies are subject to Article 12(5) of Regulation (EU) 2021/694.

News flashes

2024-07-17

For information on the evaluations results of this call we invite you to consult the Flash call info (evaluation results) in the following link.

2024-07-17

For information on the evaluations results of this call we invite you to consult the Flash call info (evaluation results) in the following link.

2024-01-16
The submission session is now available for: DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STANDARDPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-TRANSITIONEUPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH(DIGITAL-JU-SIMPLE), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRA(DIGITAL-JU-SME), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STRENGTHENCRA(DIGITAL-JU-GFS), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-PQCINDUSTRY(DIGITAL-JU-SIMPLE)
2024-01-16
The submission session is now available for: DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STANDARDPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-TRANSITIONEUPQC(DIGITAL-JU-CSA), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-ENABLINGTECH(DIGITAL-JU-SIMPLE), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-COMPLIANCECRA(DIGITAL-JU-SME), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-STRENGTHENCRA(DIGITAL-JU-GFS), DIGITAL-ECCC-2024-DEPLOY-CYBER-06-PQCINDUSTRY(DIGITAL-JU-SIMPLE)
call topic details
Call status: Closed
Opening date: 2024-01-16 (2 years ago)
Closing date: 2024-03-26 (2 years ago)
Procedure: single-stage

Budget: 22,000,000
Expected grants: 0
News flashes

This call topic has been appended 4 times by the EC with news.

  • 2024-07-17
    for information on the evaluations resul...
  • 2024-07-17
    for information on the evaluations resul...
  • 2024-01-16
    the submission session is now available...
  • 2024-01-16
    the submission session is now available...
Call

DIGITAL-ECCC-2024-DEPLOY-CYBER-06

Call topics are often grouped together in a call. Sometimes this is for a thematic reason, but often it is also for practical reasons.

There are 5 other topics in this call:

Source information

Showing the latest information. Found 6 versions of this call topic in the F&T portal.

Information from

  • 2025-07-01_03-20-20
  • 2025-01-29_03-20-06
  • 2024-11-23_03-20-12
  • 2024-11-04_17-26-59
  • 2024-09-30_21-21-11
  • 2024-03-30_14-27-10

Check the differences between the versions.

Annotations

You must be logged in to add annotations
No annotations yet

Events

Hand-picked events relevant to this call topic.

No events yet

There are currently no events linked to this call topic.

Timeline

Track where this call stands in its lifecycle, from work programme to grant signature, and see what's likely to happen next.

Grant agreement signed · 26 Nov 2024 (1 year ago)

All expected milestones for this call have passed.

Today

Call opens

16 Jan 2024

Call closes

26 Mar 2024

Outcome expected

26 Aug 2024 · est.

Work programme published

30 Sep 2024

Call published

30 Sep 2024

Grant agreement signed

26 Nov 2024 · est.

Preparation Open for submission Evaluation Grant preparation Not yet reached
  1. Call opens

    16 Jan 2024 · 2 years ago

    Submissions can be made from this date.

  2. Call closes

    26 Mar 2024 · 2 years ago

    Deadline to submit a proposal.

  3. Outcome expected Estimated

    26 Aug 2024 · 2 years ago

    The maximum time to inform applicants of the evaluation outcome is five months after the call closes.

  4. Work programme published

    30 Sep 2024 · 2 years ago

    Topics are listed in the Work Programme before the call opens. Spotting this early gives you a head start on partner search and proposal planning.

  5. Call published

    30 Sep 2024 · 2 years ago

    This topic was first published in TopicTree.

  6. Grant agreement signed Estimated

    26 Nov 2024 · 1 year ago

    The maximum time to sign the grant agreement is three months after applicants are informed of the outcome.

Funded Projects

Loading...

Project information comes from CORDIS (for Horizon 2020 and Horizon Europe) and will be sourced from F&T Portal (for Digital Europe projects)

Call document info

This section will come soon and contain the scraped information from the call document, such as the expected impact, scope, and other relevant sections. In the meantime, you can find this information in the call text section or directly on the F&T portal. View on F&T portal