SECURE Open Call: up to €30,000 for companies complying with the Cyber Resilience Act

6 Oct , 2026 - News

SECURE Open Call: up to €30,000 for companies complying with the Cyber Resilience Act

On 1 October the second open call of SECURE – Strengthening EU SMEs Cyber Resilience went live: a European project funded by the Digital Europe Programme and coordinated by Italy’s National Cybersecurity Agency (ACN). It makes €11.5 million available to help micro, small and medium-sized enterprises improve the security of products with digital elements and comply with the Cyber Resilience Act (CRA).

The call at a glance

  • Budget: €11.5 million.
  • Funding: 50% of eligible costs, up to €30,000 per company.
  • Who can apply: micro, small and medium-sized enterprises.
  • Applications: from 1 October to 11 December 2026, through the project platform.
The second SECURE open call at a glance: €11.5 million, 50% up to €30,000, applications from 1 October to 11 December 2026

A first call in high demand. The first call, launched on 28 January 2026, received 259 proposals for a budget of about €5 million. The second call increases the resources, but interest remains high.

Who can apply

The call is open to micro, small and medium-sized enterprises as defined at EU level (fewer than 250 employees and turnover up to €50 million or balance sheet total up to €43 million), with their headquarters or main business operations in an eligible country. Applications must come from a single company: consortia, business networks and joint applications are excluded.

Applicants do not need to be manufacturers, importers or distributors of digital products already, but their business must fall, or be able to fall, within the scope of the CRA. Eligibility is checked by the National Cybersecurity Coordination Centre of the company’s country. Companies in difficulty or subject to insolvency proceedings, among others, are excluded.

What can be funded

The call co-finances concrete actions for CRA compliance, the EU regulation on cybersecurity requirements for products with digital elements. Eligible activities include:

What can be funded under the SECURE call: compliance and governance, product security, resilience and training
  • Assessment and planning: CRA compliance gap analysis, risk analysis, remediation plan.
  • Security testing: vulnerability assessment, penetration testing and laboratory tests on software, firmware and hardware.
  • Security by design and continuity: secure coding, threat modelling and SBOM; business continuity, incident response and recovery plans; supply chain risk; GDPR and CRA compliance.
  • Training: on CRA obligations and technical cybersecurity.
  • Goods and licences: for example firewalls, EDR/XDR, identity and access management, vulnerability and patch management, SBOM tools, as long as they are used within the project duration.

What is not (yet) eligible. According to Annex 2 of the call, this round does not cover compliance audits with a CRA certificate issued by an accredited body, independent third-party assessment and support with regulatory documentation: these will become eligible only after the CRA is transposed in the Member States.

Funding, payments and timing

  • 50% co-financing up to €30,000: if the project costs more than €60,000, the contribution remains €30,000.
  • Optional 40% pre-financing upon signing the agreement; the balance after approval of the final technical report.
  • Maximum project duration: 180 days.

How to apply

How to apply to the SECURE call in 3 steps: registration, proposal and budget, evaluation and contract

The process includes registering on the platform with eligibility documents, completing and digitally signing the proposal and budget, formal, technical and eligibility evaluation and, for selected projects, signing the sub-grant agreement. Results are expected about three months after the call closes, with signature about one month after approval.

Proposals are assessed on three criteria: excellence and relevance, impact and clarity, implementation. A score below 10 out of 15 in two or more criteria, or overall, leads to exclusion. In case of a tie, the proposal submitted earlier ranks higher: a good reason not to wait until 11 December.

Required documents include the latest financial statements, evidence of the ownership structure and beneficial owners, and digital signatures: steps that take time.

The role of FinGreenTech

FinGreenTech SRL Società Benefit supports companies in assessing their compliance status, designing cybersecurity and cloud actions, and identifying the grant financing best suited to support the investment.

Want to know whether your company can access the SECURE call? Request a consultation with our experts or write to info@fingreentech.com.


Transparency note. This article was drafted with the support of artificial intelligence tools and reviewed by the FinGreenTech Team, which is editorially responsible for it. Information on calls and incentives is for general guidance only: the official call documents prevail in each case (sources: ACN and the SECURE project website).


, , , , ,

Leave a Reply

Your email address will not be published. Required fields are marked *