DEP – Support for implementation of EU legislation on cybersecurity and national cybersecurity strategies.

Deployment actions in the area of cybersecurity (DIGITAL-ECCC-2023-DEPLOY-CYBER-04)
Call for proposal Grant.
Programme: Digital Europe Programme (DIGITAL).
Status: Open for submission.
ExpectedOutcome:
  • Incident management solutions reducing the overall costs of cybersecurity for individual Member States and for the EU as a whole.
  • Better compliance with NIS2 (Directive (EU) 2022/2555) and higher levels of situational awareness and crisis response in Member States.
  • Organization of events, workshops, stakeholder consultations and white papers.
  • Enhanced cooperation, preparedness and cybersecurity resilience in the EU.
  • Support actions in the area of certification.
Objective:
The action focuses on capacity building and the enhancement of cooperation on cybersecurity at technical, operational and strategic levels, in the context of existing and proposed EU legislation on cybersecurity in particular the NIS2 Directive (Directive (EU) 2022/2555), the Cybersecurity Act and the proposed Cyber Resilience Act, and the Directive on attacks against information systems (Directive 2013/40). It complements the work of SOCs in the area of threat detection. It is a continuation of work currently supported under the previous WP.
In addition, the action also aims at improving industrial and market readiness for the cybersecurity requirements set in the proposal for a regulation on cybersecurity requirements for products with digital elements, known as the Cyber Resilience Act bolstering cybersecurity rules to ensure more secure hardware and software products.
Proposals should contribute to achieving at least one of these objectives;
  • Development of trust and confidence between Member States.
  • Effective operational cooperation of organisations entrusted with EU or Member State’s national level cybersecurity, in particular cooperation of CSIRTs (including in relation to the CSIRT Network) or cooperation of Operators of Essential Services including public authorities.
  • Better security and notification processes and means for Operators of Essential Services and for digital service providers in the EU.
  • Better reporting of cyber-attacks to law enforcement authorities in line with the Directive on attacks against information systems.
  • Improved security of network and information systems in the EU.
  • More alignment of Member States’ implementations of NIS2 (Directive (EU) 2022/2555).
  • Support cybersecurity certification in line with the Cybersecurity Act.
Scope:
The action will focus on the support of at least one of the following priorities:
  • Implementation, validation, piloting and deployment of technologies, tools and IT-based solutions, processes and methods for monitoring and handling cybersecurity incidents.
  • Collaboration, communication, awareness-raising activities, knowledge exchange and training, including through the use of cybersecurity ranges, of public and private organisations working on the implementation of NIS2 (Directive (EU) 2022/2555).
  • Twinning schemes involving originator and adopter organisations from at least two different Member States to facilitate the deployment and uptake of technologies, tools, processes and methods for effective cross-border collaboration preventing, detecting and countering Cybersecurity incidents.
  • Robustness and resilience building measures in the cybersecurity area that strengthen suppliers’ ability to work systematically with cybersecurity relevant information or supplying actionable data to CSIRTs.
  • Ensure that manufacturers improve the security of products with digital elements since the design and development phase and throughout the whole life cycle.
  • Ensure a coherent cybersecurity framework, facilitating compliance for hardware and software producers.
  • Enhance the transparency of security properties of products with digital elements.
  • Enable businesses across all sectors and consumers to use products with digital elements securely.
  • Support to Cybersecurity certification, including support to national cyber authorities and other relevant stakeholders, such as SMEs.
The support will target relevant Member State competent authorities, which play a central role in the implementation of NIS2 (Directive (EU) 2022/2555), as well as other actors with the scope of this Directive.
The action may support amongst other the continuation of the kind of cybersecurity activities funded through the CEF Telecom programme, building where relevant on the results from the CEF projects.
Support will be provided amongst other for the on boarding to the CEF Cybersecurity Core Service Platforms of public and private organisations working on the implementation of NIS2 (Directive (EU) 2022/2555) and are potential users of the CEF Cybersecurity Core Service Platforms.
The action also supports industry, with a particular focus on start-ups and SMEs, to seize the industrial and market uptake opportunities given by the proposed Cyber Resilient Act and Cybersecurity Act.
26-09-2023
€ 30 000 000.
N/A