Funding ProgrammesAll you need to know about each Funding program

For each of the Subsidy Scheme below a new call for proposals/ applications is expected during the following period.

In order to create the conditions necessary for the utilization of the Scheme that meets your needs it is important to start preparing early, as your idea should be evaluated and shaped accordingly, information within the context of the proposal/ business plan to be prepared needs to be collected and analyzed, and quotations as well as other documentation material must be gathered according to the requirements of each specific Scheme.

In order for us to assist you determine whether you are eligible for the Scheme of your interest and help you prepare timely, you can complete the “Eligibility Check” form or “Contact Us" or by phone at 70005054.

Information on Expected Subsidy Schemes, below, is based on the most recent Call for Proposal Submission for the specific Scheme. Please note that changes may occur between Calls. Information for the new Call will be posted in the section Subsidy Schemes.

Enhancing Cybersecurity in Small and Medium Cypriot Enterprises

The information below is based on the most recent Call, NCC-CY-ENTERPRISES/0925.

According to the RIF Call Calendar, there will be a new call for proposals in the 3rd quarter of 2026.

We can assist you in preparing and submitting a proposal based on the requirements of the specific Programme.

Contact us for support with the preparation and submission of your proposal.

INTRODUCTION
The Research and Innovation Foundation (RIF) in collaboration with the Digital Security Authority (DSA) as the National Cybersecurity Coordination Centre (NCC-CY), announce the Call for Proposals for the Programme «Enhancing Cybersecurity for Small and Medium Enterprises in the Republic of Cyprus 2025» invites beneficiaries to submit relevant Project Proposals (Proposals).

The present Call is announced as part of a series of actions of the NCC-CY. With the introduction of European Regulation (EU) 2021/887 by the European Parliament and the Council on May 20, 2021, the European Competence Centre (ECCC) for Industrial, Technological, and Research Issues in Cybersecurity was established, consisting of the National Coordination Centres (NCCs) in each EU member state, with the goal of developing technological and industrial capabilities for cybersecurity issues in the European Union. By a decision of the Council of Ministers on December 21, 2021, DSA, as an entity of the broader Public Sector, was appointed as the NCC-CY for cybersecurity matters in the Republic of Cyprus. At the same time, the Research and Innovation Foundation (RIF) was appointed as a member of the NCC-CY consortium, with responsibilities for managing funds secured by NCC-CY through European Programmes, with the aim of providing financial support to small and medium-sized enterprises (SMEs) within the Republic of Cyprus.

The «N4CY2-Advancing the NCC-CY: The Next Chapter of the National Cybersecurity Coordination Centre of Cyprus» (Grant Agreement 101195086) project is co-financed by the Republic of Cyprus and the "Digital Europe" Programme of the European Union.

GENERAL CALL INFORMATION

Programme ENHANCING CYBERSECURITY IN SMALL AND MEDIUM ENTERPRISES IN THE REPUBLIC OF CYPRUS 2025
 Call Code NCC-CY-ENTERPRISES/0925
 Call Budget 1.500.000Euro
 Minimum funding per proposal 20.000 Euro
 Maximum Funding per proposal

65.000 Euro or


75.000 Euro in cases where the ENISA AR-in-a-Box tool is adopted

 Funding Intensity 70%
 Date of Publication 12th September 2025,
 Closing Date

18th November 2025, 13:00

The English version of the Call, even though an official translation endorsed by the Research and Innovation Foundation, is provided for information purposes only. Only the Greek version of the Call is legally binding and shall prevail in case of any divergence in interpretation.

OBJECTIVES
The Programme aims to ensure that SMEs reach a basic level of cybersecurity in order to protect their infrastructures, systems and information. This will be achieved through the purchase of solutions and services to maintain and strengthen the level of security and resilience of small and medium enterprises (SMEs), as well as through the evaluation and identification of challenges and weaknesses. Additionally, the Programme seeks to achieve their compliance of SMES with European and internationally accepted measures and standards through a certification scheme, the Cyber-Hygiene Framework for Small and Medium Enterprises (SME) of the NCC-CY.

DESCRIPTION
Through the Programme, SMEs 1 will have the opportunity to obtain a Cybersecurity Certification. The Certification is issued by Certification Bodies, which have been accredited according to ISO 17021 and ISO 27006, hence are competent to carry out inspections and certifications for information security management systems according to ISO/IEC 27001:2013 and/or ISO/IEC 27001:2022. Following acquirement of the Certification, enterprises will be able to assess their current level of maturity, identify vulnerabilities and mitigate risk, while strengthening their cybersecurity practices. It will also allow them to invest in the protection of information and data, based on specific specifications and minimum requirements set out in the NCC-CY Cyber-Hygiene Framework for SMEs.

The Programme has a simple procedure for submitting proposals, short time for the evaluation and announcement of results and ensures timely implementation of projects in the pre-defined maximum implementation period for resolving problems faced by enterprises in cybersecurity matters.

For the purposes of participating in the Programme and submitting a Proposal, a gap analysis is required. The gap analysis will determine an SMEs’ current cybersecurity situation in real time, at a technical, operational and strategic level in relation to the set of rules, control measures and procedures set out for establishing a basic level of cybersecurity as defined in the NCC-CY Cyber-Hygiene for SMEs framework and which are summarized as follows:

  1. Security Policy
    1. Control Measure 1.1: The organisation's senior management has created, approved and communicated its cybersecurity policy internally and externally. The cybersecurity policy shall be reviewed at least once a year and updated as required.
  2. Awareness and Training
    1. Control Measure 2.1: Staff employed by the organisation and users who have access to its information (regardless of their employment relationship) must be aware of information security and in particular how they contribute to it through their role. Appropriate cybersecurity awareness activities shall be carried out on a regular basis and at least once a year. 
    2. Control Measure 2.2: Staff employed by the organisation and users who have access to its information (regardless of their employment relationship) receive education, training and information on the policies, procedures, security measures implemented by the organisation as well as relevant technological or organisational issues. The training provided shall be tailored to the security requirements of the different roles within the organisation.
  3. Software Update
    1. Control Measure 3.1: The organisation's IT and communications systems must have the latest, stable security updates installed from trusted sources only (e.g. the manufacturer).
    2. Control Measure 3.2: Automated vulnerability scanning and penetration tests are implemented once a year (vulnerability scanning and penetration tests).
    3. Control Measure 3.3: Information and communication systems that are no longer supported by their manufacturers with (at least) end-of-life security updates shall not be used by the organisation.
  4. Protection from Malicious Software
    1. Control Measure 4.1: Malicious software protection programmes and functions are installed on all of the organisation's IT and communication systems and are updated on a regular basis.
  5. Network Security
    1. Control Measure 5.1: The organisation has installed and configured firewalls at appropriate points in its network, in order to effectively protect its systems and information from relevant threats.
    2. Control Measure 5.2: If the organisation provides the capability for wireless access to the organisation's network, this should be done with appropriate routing and protection through the installed firewall(s).
  6. Backups
    1. Control Measure 6.1: The organisation identifies its critical information and backs it up on a regular basis in alignment with the relevant backup policy.
  7. Access Control
    1. Control Measure 7.1: The organisation identifies where important information is located. For each information type and based on its use and criticality, the organisation has created a structure in an appropriate storage area, which allows it to grant access rights to authorised and authenticated users following the need-to-know principle.
    2. Control Measure 7.2: The organisation has created an appropriate password policy, which is implemented in all its systems.
    3. Control Measure 7.3: Administrative rights or privileged rights (admin/privileged rights) are granted to a minimum necessary number of authorised staff.
  8. Security Incidents
    1. Control Measure 8.1: The organisation has established structures and process for responding to security incidents. The staff involved in the respective procedures are appropriately trained.
  9. Physical Security Measures
    1. Control Measure 9.1: The organisation has adopted physical security measures to protect systems and facilities from natural and environmental threats.
  10. Data Protection
    1. Control Measure 10.1: The organisation designs, implements, approves and publishes a Personal Data Protection Policy based on the general GDPR regulation.
  11. Operational Impact Analysis
    1. Control Measure 11.1: The organization has designed and implemented an appropriate methodology for operational impact analysis. The results and key figures resulting from the application of the methodology are recorded, maintained and utilized accordingly to design relevant measures and implementations.

Depending on the analysis of the current situation of the company in relation to the above analysis, interested enterprises will prepare their proposal, which will include the list of solutions and services they intend to use in order to gain the “Cyber-Hygiene Framework for SME of NCC-CY” certification.

ENISA AR-in-a-Box
As an optional but valuable resource, SMEs may consider the use of ENISA’s Awareness Raising in a Box (AR-in-a-Box) to support and enhance cybersecurity awareness and training activities. Developed by the European Union Agency for Cybersecurity (ENISA), AR-in-a-Box is a comprehensive toolkit designed to assist organizations in building effective cybersecurity awareness programmes tailored to their specific needs.

The toolkit provides structured guidance for the design and implementation of internal and external awareness campaigns. It includes templates, communication strategy recommendations, and guidance on selecting appropriate communication channels. It also supports the development of key performance indicators (KPIs) to assess the effectiveness of awareness initiatives. Additionally, AR-in-a-Box contains interactive materials such as quizzes and games, which can be used to engage staff in understanding cybersecurity principles. It also offers support for the creation of cyber crisis communication plans.

The use of AR-in-a-Box is not mandatory but can significantly enhance the organisation’s efforts in raising cybersecurity awareness. More information is available at official ENISA and EU website

BENEFICIARIES
Small and Medium Enterprises (Categories B.1, B.2)

Organisations that have secured funding under Call NCC-CY-ENTERPRISES/1223 are not eligible to participate.

Organisations operating in the tourism sector (hotel businesses or travel agencies/agents) are not eligible to participate in this Call. In such cases, Organisations should refer to the Call for Proposals NCC-CY-ENTERPRISES-TOURISM/XX25. 

Eligible applicants under this call are those who have no outstanding amounts owed to the Digital Security Authority, in accordance with the Network and Information Systems Security Law of 2020 (Law 89(I)/2020), as amended and/or replaced from time to time, and the Network and Information Systems Security (Fees) Regulations of 2020 (P.I. 359/2020), as amended and/or replaced from time to time.

SPECIFIC RESTRICTIONS AND CONDITIONS FOR PARTICIPATION
Each organisation can submit only one (1) project proposal a Host Organisation. In the event that an Organisation submits more than one (1) proposal as a Host Organisation, the first proposal will be considered valid based on the order of submission, and the remaining proposals will be considered invalid.

Participation of entities engaged in an economic activity in a proposal shall be deemed valid, if they are legally established and are active in territories under the control of the Republic of Cyprus. The activity of the entities is documented by the existence of facilities and staff in territories under the control of the Republic of Cyprus and, indicatively and not restrictively, by audited financial statements, the tax return of the entity in the Republic of Cyprus, etc.

These conditions should be met to the satisfaction of RIF and without prejudice to the Foundation to request further data and information from the entities.

Upon completion of the projects, each SME will be required to undertake at least one publicity activity (media/social media publication, video, event, etc.) highlighting the achievement of the Certification following the implementation of the funded project, with references to the benefit derived from the funding. For publicity actions, the obligations for promotion and publicity for projects funded by the Digital Europe Programme should be applied, including the logos of the NCC-CY, the Research and Innovation Foundation (RIF), the Commissioner of Communications and the Digital Security Authority, as well as reference to the co-funding by the Republic of Cyprus.

PROJECT ACTIVITIES
The projects include activities related to the process of obtaining the NCC-CY’s Cyber-Hygiene Certification for SMEs, aiming at the adoption of solutions and the purchase of services to achieve a basic level of cybersecurity and preparedness to protect infrastructures, systems and data of enterprises.

Specifically, eligible costs must be in line with the measures to be taken to enable certification by the Certification Bodies accredited to ISO 17021 and ISO 27006 to conduct information security management system audits and certifications in accordance with ISO/IEC 27001:2013 or ISO/IEC 27001:2022, as defined in the Annex of this Call for Proposals.

DURATION OF PROJECT IMPLEMENTATION
Up to nine (9) months

Upon the completion of the Project, the Host Organisation submits to the RIF a brief Report using the «Progress Report» document, and a «Funding Payment Request» available on the IRIS Portal, within one (1) month and two (2) months respectively.

BUDGET
€ 1.500.000

MINIMUM - MAXIMUM FUNDING PER PROJECΤ
€20.000 – €65.000 or €75.000 in cases where the ENISA AR-in-a-Box tool is adopted

The aid intensity is 70% of eligible costs.

If, upon completion of the projects, the total eligible expenses based on approved costs (total amount of eligible expenses taking into account the aid intensity – 70%) are less than the minimum project funding, the funding will not be granted to the beneficiary.

* With reference to Point 2 of the NCC-CY Cyber Hygiene Framework (Awareness and Training), companies that choose to adopt ENISA’s AR-in-a-Box tool may be eligible to apply for additional funding of up to €10,000.

ELIGIBLE EXPENSES
All expenditures necessary for the purposes of securing the Cybersecurity Certification, in accordance with the requirements of the NCC-CY through the Cyber-Hygiene Framework for SMEs, which will fall under the categories «Costs for external services» and/or «Costs for Instruments and Equipment».

Eligible costs may include the purchase and implementation of the following:

  • Design and implementation services related to Group Policies and other security features of domain controllers and other related equipment.
  • Services obtained from consultants for training and educating staff on cybersecurity
  • Installation of two-factor authentication.
  • Cybersecurity incident management systems, consulting and incident response services and products
  • Privileged Access Management
  • Sandbox technology solutions
  • Email filtering solutions
  • Security information and incident management services (SOC)
  • Implementation of physical security and access control measures
  • Development of a Business Continuity Plan
  • Web Application Firewall Solutions (WAF)
  • Tools / services for electronic fraud (phishing)
  • Firewall with or without integrated threat management
  • Software solutions and backup equipment (Storage, Tapes, Licensed Software)
  • Intrusion detection/prevention systems (IDS and IPS)
  • Antivirus software
  • Systems to detect and respond to network attacks
  • Penetration Testing
  • Planning and implementation services of policies and procedures
  • Consulting Services related to the Business Impact Analysis
  • Design and implementation services of a data privacy policy
  • Network equipment that enables/improves/supports cybersecurity (eg firewall, switch, concentrators, load balancers, access points)
  • Protection Services DoS/DDoS
  • Servers used for security related purposes (proxy servers, web application servers etc)
  • Equipment to achieve increased durability (hard drives, etc.)
  • Hardware/software SIEM
  • Consulting services for purposes of analysis and conclusions on the current situation of businesses in cybersecurity matters.
  • Cost of NCC-CY Cybersecurity Certification audit (the cost of a single audit may be covered)
  • Any other service, software/hardware or tools deemed necessary by the Host Organisation in order to meet the requirements of the Certification Scheme, provided that these are deemed reasonable during the evaluation process.

Beneficiaries must receive and evaluate at least three (3) independent tenders for each purchase exceeding Euro 15,000 (excluding VAT) resulting in the selection of the most economical solution that meets their needs.

VAT is not considered an eligible cost. Beneficiaries are responsible for VAT payments to all consultants and solution providers and certification bodies.

The total amount of funding is committed at the time of Project Contract preparation and the funding is made as a lump sum payment as De Minimis aid (EU Regulation No 2023/2831 of 13th of December 2023 on the application of Articles 107 and 108 of the Treaty on the Functioning of the European Union) in two instalments.

The first instalment of 50% is paid upon signing of the Project Contract and the second instalment is paid upon approval of the "Activity Report" and the "Funding Payment Request" which are submitted within one (1) month and two (2) months respectively from the completion of the project, by the Host Organization.

Failure to secure the Certification within the duration of the funded project will result in the funding not being granted and a refund of the pre-financing will be requested.

It is clarified that, according to the EU Regulation No. 2023/2831 on De Minimis funding, enterprises active in the fisheries and aquaculture sectors and in the primary production of agricultural products cannot be funded.

PROJECT SELECTION
Evaluation Procedure
For the evaluation of the Proposals in this Call, a process of Preliminary Check and Evaluation by an Independent Evaluation Committee (IEC) will be followed. The committee will include experts with a background in business and specialization in cybersecurity issues. Proposals that meet all the criteria will be forwarded for evaluation by the members of the IEC. During the IEC session, the members rank the Proposals in order of priority (ranking list) and document the rationale for their decision in a relevant Evaluation Report. Upon completion of the process, the Evaluation Report from the IEC regarding each proposal will be communicated to the Project Coordinator.

The final decision regarding the selection of a proposal for funding by the RIF, is at the discretion of the Committee. The Committee’s decision is final and cannot be appealed against.

Evaluation Criteria

  1. Relevance – Weight 30%
  2. Added Value and Benefit – Weight 40%
  3. Implementation – Weight 30%

Selection
Proposals deemed as eligible following proposal evaluation will be selected for funding according to their ranking. It is clarified that the total requested funding of selected projects will not exceed the total Call budget.

 

 1 The category of each enterprise will be checked by the RIF as part of the legal status check during the proposal submission stage and validated at the time of contract preparation and before the final decision for funding.

Small Enterprises: An enterprise which employs fewer than fifty (50) employees and has an annual turnover or an annual balance sheet total not exceeding ten (10) million Euros. Start-ups are also included in this category.
Medium Enterprise: An enterprise which employs fifty (50) to up to two hundred forty-nine (249) employees and has an annual turnover of up to fifty (50) million Euro or an annual balance sheet total not exceeding forty-three (43) million Euro.

 

CALL FOR PROPOSALS

GUIDE FOR EVALUATORS

RESTART-2016-2020-WORK-PROGRAMME – VERSION 17 – MAY 2022 – JUNE 2025

OTHER DOCUMENTS - FREQUENTLY ASKED QUESTIONS

 

 

Eligibility Check

Fill up the Eligibility Check form below and we will check FREE OF CHARGE if your company is eligible for subsidy

Contact Us

We will be happy to respond to any queries you may have, so feel free to contact us at anytime.


Telephone

+357 70005054



Contact Options

Contact Form