Summary
- The European Cybersecurity Competence Centre has opened a €96 million funding call under the Digital Europe Programme.
- Funding covers AI-based cyber tools, SME security, preparedness testing, regional cable hubs, regulatory implementation, and dual-use technology.
- Applications remain open until 14 January 2027, with several streams aimed directly at NIS2 and critical-sector resilience.
The European Union has opened a €96 million cybersecurity funding round covering AI-based defence tools, critical-infrastructure preparedness, undersea cable resilience, regulatory implementation, and dual-use technology.
The European Cybersecurity Competence Centre opened the call on 1 September under the Digital Europe Programme, dividing the budget across six deployment areas rather than concentrating it on research alone.
The largest single allocations include €20 million for AI-powered cybersecurity tools aimed at European small and medium-sized businesses and another €20 million for building cyber capability around EU legislation including NIS2, the Cyber Resilience Act, DORA, the Cybersecurity Act, GDPR, and parts of the AI Act.
A further €15 million is reserved for cybersecure technologies and services relying on artificial intelligence, including generative AI. The eligible deployment areas include threat and vulnerability detection, mitigation, recovery, data analysis, and information sharing for national authorities, Computer Security Incident Response Teams, public bodies, Cyber Hubs, and organisations covered by NIS2.
The programme’s design reflects a shift in European cyber spending towards implementation. Large parts of the EU regulatory framework have already moved from legislative negotiation into operational compliance, leaving member states and regulated organisations to build the testing, reporting, monitoring, and response capacity needed to make those rules workable.
Another €15 million will fund coordinated preparedness testing and other activities under the Cyber Solidarity Act’s Cybersecurity Emergency Mechanism. Eligible work includes penetration testing, threat assessment, vulnerability monitoring, risk monitoring, coordinated vulnerability disclosure, exercises, and training for organisations operating in highly critical and other critical sectors.
Undersea infrastructure receives a dedicated €5 million allocation for Regional Cable Hubs. The EU wants a hub in each sea basin to improve threat detection, near-real-time situational awareness, incident reporting, and information sharing around submarine cables, which have become an increasingly prominent part of Europe’s infrastructure-security agenda.
The National Coordination Centre network receives €11 million to expand support for the cybersecurity community, including smaller businesses and start-ups, while €10 million is earmarked for dual-use cyber technology spanning civilian and defence requirements.
The funding structure gives a useful indication of where Brussels expects practical gaps to persist. Compliance alone accounts for a substantial share, but the programme also directs money towards capabilities that sit between regulation and operations: testing, incident coordination, threat visibility, recovery, and infrastructure monitoring.
AI appears on both sides of that equation. The call will fund its use in defensive tooling while also requiring attention to the security, robustness, and trustworthiness of AI systems themselves. That distinction is becoming increasingly important as European organisations adopt agentic and generative systems with access to development environments, enterprise data, and operational workflows.
The applications window runs until 14 January 2027. Successful projects will therefore begin against a regulatory backdrop in which NIS2 implementation is already under way, DORA is established across financial services, and Cyber Resilience Act reporting duties are beginning to apply to product manufacturers.
The €96 million will not resolve the uneven cyber capacity that remains across the bloc, but its distribution shows the areas in which the EU now expects deployment rather than policy design to carry more of the burden.





