1 October 2026 – Following the successful first funding call, the EU-funded SECURE – Strengthening EU SMEs Cyber Resilience project is launching its second call for proposals on 1 October 2026. European micro, small and medium-sized enterprises (SMEs) can submit applications until 11 December 2026. A total of €11.5 million in funding is available under the second call, giving more companies the opportunity to implement concrete measures to strengthen their cybersecurity and prepare for the requirements of the Cyber Resilience Act (CRA).
The response to the first SECURE call significantly exceeded expectations: with €5 million in funding available, around 260 applications were received from 28 European countries. The high number of applications and their broad geographical distribution underline the strong relevance of the topic and the significant need for support among SMEs in implementing the new European cybersecurity requirements for products.
€11.5 Million for the Next Phase of CRA Implementation
With its second call, SECURE is further expanding its funding opportunities for European SMEs. Eligible companies can submit projects that help them make their products with digital elements more secure and gradually implement the requirements of the Cyber Resilience Act.
The CRA – Regulation (EU) 2024/2847 – establishes harmonised cybersecurity requirements for products with digital elements placed on the EU market. These requirements cover the entire product lifecycle, from design and development to the provision of updates and vulnerability management, as well as maintenance and documentation.
The main requirements of the CRA will fully apply from 11 December 2027. Initial obligations, including the reporting of actively exploited vulnerabilities and serious security incidents, have already applied since September 2026. As the CRA requirements are phased in towards December 2027, companies face an increasing need to establish the necessary structures, processes and technical measures at an early stage.
“For ACN, supporting micro, small and medium-sized enterprises in implementing the Cyber Resilience Act means making cybersecurity an integral part of product development and competitiveness. Through SECURE, funding is complemented by training and practical tools that help companies identify and address their needs. The second call strengthens this commitment, drawing on European cooperation to bring resources and expertise closer to businesses, including those in Italy,” said Luca Nicoletti, Head of the Industrial, Technological and Research Programmes Service and Head of the NCC IT.
From Gap Analysis to Concrete Implementation
The first call showed that companies particularly need support with preparatory measures. Almost half of the proposals submitted focused on activities such as gap and maturity assessments, analysis of CRA requirements, governance and risk management.
The second call builds on this identified need and aims to support companies in taking their next steps towards CRA compliance. Funding can be used for measures that contribute to meeting CRA requirements and strengthening the cybersecurity and resilience of products with digital elements.
The funding is particularly aimed at manufacturers, importers and distributors of products with digital elements, as well as open-source software stewards, provided they fall within the scope of the CRA and meet the respective funding eligibility requirements.
Support Beyond Financial Funding
SECURE supports SMEs with more than financial assistance. The project also provides free training, workshops, events and practical resources. A central Repository brings together guides, self-assessment tools and open-source resources to support CRA compliance.
Applications Open Until 11 December 2026
The second SECURE funding call is open from 1 October to 11 December 2026. Interested SMEs can submit their applications via the SECURE platform. The entire process – from registration and application through evaluation to implementation and impact assessment – is handled digitally.
Submitted proposals will be assessed, among other criteria, based on their relevance to the objectives of the Cyber Resilience Act, expected impact, and the quality and feasibility of the proposed project. Further information on the second call, eligibility requirements, evaluation criteria and information events is available on the SECURE4SME second open call application page.
About SECURE
The EU-funded project SECURE – Strengthening EU SMEs Cyber Resilience (Grant Agreement No. 101190325) supports European micro, small and medium-sized enterprises in strengthening their cybersecurity and preparing for the requirements of the Cyber Resilience Act. With a total budget of almost €22 million, including €16.5 million in direct financial support for SMEs, SECURE combines financial support with practical knowledge, training, guidance and freely accessible resources.
Visit the SECURE4SME website and follow SECURE on LinkedIn for updates.
Register to the SECURE Newsletter to stay informed about latest news.
Project Partners
Agenzia per la cybersicurezza nazionale (ACN), Italy • Naukowa i Akademicka Siec Komputerowa (NASK), Poland • Instituto Nacional de Ciberseguridad (INCIBE), Spain • Centre for Cybersecurity Belgium (CCB), Belgium • Luxembourg House of Cybersecurity (LHC), Luxembourg • Cyber 4.0 - Centro di Competenza Nazionale per la Cybersecurity, Italy • IDEA-Re Ideas & Research Hub, Italy • National Cybersecurity Coordination Center (NCC-RO), Romania • Plattform Industrie 4.0 Österreich, Austria • TU Wien, Austria • PROFACTOR GmbH, Austria • Salzburg Research Forschungsgesellschaft mbH, Austria • VIRTUAL VEHICLE, Austria