FreeTender
Accepting bidsgrant

CFAs: Coordinated Cybersecurity Preparedness Testing and Resilience Actions

Issued by European Commission · via fundsforNGOs — grants & funding calls

Published
20 Sept 2026
Closes
14 Jan 2027, 23:59 UTC
Reference
cfas-coordinated-cybersecurity-preparedness-testing-and-resilience-actions
Sector
IT & Telecom

Details

Deadline: 14-Jan-2027

The European Commission is supporting coordinated preparedness testing and other cybersecurity actions to strengthen resilience among entities operating in sectors of high criticality across the EU and EEA. With a total budget of €15 million and approximately €1.5 million per project, the action supports threat and risk assessment, penetration testing, vulnerability monitoring, cybersecurity exercises, training, compliance improvement, and infrastructure security. This action supports efforts to strengthen cybersecurity preparedness, resilience, and cooperation across the European Union and European Economic Area (EEA). It forms part of the Cyber Solidarity Act and is designed to complement cybersecurity activities already being implemented at Member State and European Union levels. The action provides knowledge, expertise, practical support, and coordinated activities to help eligible entities improve their ability to prevent, identify, assess, and respond to cyber threats and incidents. The programme supports a range of cybersecurity preparedness and resilience activities, including: These activities are intended to help organizations identify vulnerabilities, strengthen security capabilities, and improve preparedness for cyber incidents. One major area of the action is coordinated preparedness testing for entities operating in sectors of high criticality.

Testing activities may include:

Coordinated testing can help participating organizations better understand their security weaknesses and identify areas requiring improvement. Threat and risk assessment activities can help organizations identify cybersecurity risks affecting their infrastructure and operations.

Supported work may examine:

The findings can be used to improve cybersecurity planning and resilience. The action also supports vulnerability monitoring and coordinated vulnerability disclosure. These activities can help organizations identify security weaknesses and establish appropriate processes for addressing and communicating vulnerabilities. Improved vulnerability management can contribute to stronger protection against cyber threats and incidents. Preparedness is also supported through practical skills development.

Projects may organize:

These activities can help relevant personnel strengthen their knowledge and practical capabilities for responding to cybersecurity risks. Applicants can also provide consulting and technical support aimed at improving infrastructure security. Projects may evaluate existing cybersecurity capabilities and identify measures that can improve an organization’s overall level of security maturity. This can include assessing current practices, identifying gaps, recommending improvements, and supporting the deployment of appropriate digital testing tools. The action has a total available budget of €15,000,000. Approximately €1,500,000 is allocated per project. Applicants should ensure that their proposed activities and requested funding are proportionate to the objectives and scope of the project. Eligible applicants must be legal entities established in eligible European countries.

Applicants can be:

The organization must be established in:

The proposed project must correspond wholly or partly to the topic description. The action covers organizations established in the European Union and eligible EEA countries.

Eligible EEA countries include:

EU Member States, including their overseas countries and territories, are also within the eligibility scope. Applications should address at least one of the following objectives: Projects can focus on coordinated cybersecurity preparedness testing for entities operating in sectors of high criticality.

Possible activities include:

Projects may alternatively address other cybersecurity preparedness activities, such as: Projects can therefore focus on testing activities, broader preparedness measures, or a combination of relevant actions. The action particularly focuses on entities operating in sectors of high criticality. The purpose is to strengthen their ability to prepare for and withstand cybersecurity threats and incidents. Projects should demonstrate a clear connection between their proposed activities and improved cybersecurity preparedness or resilience for relevant high-criticality entities. A strong proposal should clearly connect the planned activities with identifiable cybersecurity preparedness and resilience needs.

Applicants should explain:

The proposal should also clearly demonstrate that the planned activities correspond to at least one of the stated objectives. Cybersecurity preparedness is an important part of protecting critical infrastructure, services, organizations, and digital systems from cyber threats. Testing, risk assessment, vulnerability monitoring, training, and practical exercises can help organizations identify weaknesses before they result in serious incidents. Through coordinated support across the EU and EEA, this action aims to strengthen cooperation, cybersecurity capabilities, and resilience among entities operating in sectors of high criticality. It is a European Commission-supported action under the Cyber Solidarity Act that aims to strengthen cybersecurity preparedness, cooperation, and resilience among entities operating in sectors of high criticality across the EU and EEA. The total available budget is €15 million, with approximately €1.5 million allocated per project. Eligible applicants are legal entities, including public or private bodies, established in an EU Member State or an eligible EEA country. The eligible EEA countries identified for this action are Norway, Iceland, and Liechtenstein. Activities can include penetration testing, threat and risk assessment, vulnerability monitoring, coordinated vulnerability disclosure, cybersecurity exercises, training courses, workshops, digital testing tools, capability evaluation, and consulting for infrastructure security. Proposals should addres

Context for bidders

We hold 69 notices from European Commission, going back to August 202669 of them still open. They buy mostly in IT & Telecom, Financial & Professional Services and Healthcare & Pharma. There are 5,159 open IT & Telecom tenders. This one closes in 117 days.

Before you bid on this tender

A quick checklist to help you decide whether to bid and prepare a compliant submission for this it & telecom opportunity. Always verify the details on the official source.

  • Confirm the exact closing date and time (and time zone) on the official portal — deadlines are strict and can be revised by a corrigendum.
  • Read the full notice and every attached document, including the scope, specifications and any bill of quantities or terms of reference.
  • Check the eligibility criteria — prior similar experience, annual turnover, certifications and registrations — and make sure you qualify before investing effort.
  • Prepare any earnest-money deposit (EMD) or bid security and the required formats early; missing or wrongly-formatted documents are a common cause of rejection.
  • Note how bids must be submitted (online or physical), in what format, and whether a digital signature or portal registration is required.
  • Watch for corrigenda and clarifications right up to the deadline — requirements and dates can change.

More IT & Telecom tenders

All IT & Telecom tenders →

FreeTender mirrors this notice for reference. Verify the details and bid on the official portal.

Verify & apply on the official portal →