The Call is Open until 10 November 2026, 13:00, or until the budget is exhausted.
INTRODUCTION
The Research and Innovation Foundation (RIF) in collaboration with the Digital Security Authority (DSA) as the National Cybersecurity Coordination Centre (NCC-CY), announce the Call for Proposals for the Programme «Enhancing Cybersecurity for Small and Medium Enterprises (SMEs) designated as Important Entities Falling Within the Scope of the NIS2 Directive» and invites beneficiaries to submit relevant Project Proposals (Proposals).
The present Call is announced as part of a series of actions of the National Coordination Centre–NCC-CY. With the introduction of European Regulation (EU) 2021/887 by the European Parliament and the Council on May 20, 2021, the European Competence Centre (ECCC) for Industrial, Technological, and Research Issues in Cybersecurity was established, consisting of the National Coordination Centers(NCCs) in each EU member state, with the goal of developing technological and industrial capabilities for cybersecurity issues in the European Union.
By a decision of the Council of Ministers on December 21, 2021, DSA, as an entity of the broader Public Sector, was appointed as the NCC-CY for cybersecurity matters in the Republic of Cyprus. At the same time, the Research and Innovation Foundation (RIF) was appointed as a member of the NCC-CY consortium, with responsibilities for managing funds secured by NCC-CY through European Programmes, with the aim of providing financial support to small and medium-sized enterprises (SMEs) within the Republic of Cyprus.
The Call is co-financed by the Republic of Cyprus and the Digital Europe Programme in the frame of the «N4CY2-Advancing the NCC-CY: The Next Chapter of the National Cybersecurity Coordination Centre of Cyprus» (Grant Agreement 101195086) project.
GENERAL CALL INFORMATION
| Programme | ENHANCING CYBERSECURITY IN SMALL AND MEDIUM ENTERPRISES (SMEs) DESIGNATED AS IMPORTANT ENTITIES FALLING WITHIN THE SCOPE OF THE NIS2 DIRECTIVE | |
| Call Code | NCC-CY-NIS2/0826 | |
| Call Budget | 1.530.000Euro | |
| Minimum funding per proposal | 20.000 Euro | |
| Maximum Funding per proposal |
100.000 Euro |
|
| Funding Intensity | 70% | |
| Date of Publication | 28 August 2026, | |
| Closing Date |
Open Call until 10 November 2026, 13:00, or until the budget is exhausted. |
|
OBJECTIVES
The “NCC-CY - NIS2” Program aims to ensure a baseline level of cybersecurity for a number of important entities covered by the NIS2 Directive, with the goal of protecting their infrastructure, systems, and information through the procurement of relevant cybersecurity solutions and services. The NIS2 Directive (EU 2022/ 2555), which entered into force on October 18, 2024, constitutes the updated pan-European framework for cybersecurity, aimed at strengthening digital security in critical sectors of economic and social activity. It expands upon the original NIS Directive by imposing stricter security measures, mandatory incident reporting, and severe penalties for noncompliance across a broader range of “essential” and “important” entities. The Program aims to obtain a verification certificate from the Digital Security Authority (DSA) for Beneficiaries regarding their compliance with the cybersecurity measures of the Belgian CyberFundamentals (CYFUN) framework, at the Basic level, as of the 2025 edition (for more information, click HERE). These measures will be adopted by the Digital Security Authority (DSA) and will form part of the beneficiary entities’ compliance with the requirements under national legislation transposing the NIS2 Directive.
DESCRIPTION
Through this program, small and medium-sized enterprises are given the opportunity to obtain a verification certificate from DSA for the implementation of the relevant measures. Verification audits will be conducted by Cybersecurity Maturity Auditors from the relevant registry managed by the Cyprus Organization for Standardization (CYS). For more information, click HERE.
BENEFICIARIES
Small and Medium-Sized Enterprises (Categories B.1, B.2), which are designated as Important Entities within the scope of the NIS2 Directive (EU 2022/2555) as designated by the Digital Security Authority.
Eligible applicants for this call are those who have no outstanding amounts owed to the Digital Security Authority, in accordance with the Network and Information Systems Security Law of 2020 (Law 89(I)/2020), as amended and/or replaced from time to time, and the Network and Information Systems Security (Fees) Regulations of 2020 (K.D.P. 359/2020), as amended and/or replaced from time to time.
Furthermore, pursuant to Article 12 of Regulation (EU) 2021/694, Host Organisations must not be under the direct or indirect control of an ineligible third country or entities/nationals of such a country.
SPECIFIC RESTRICTIONS AND CONDITIONS FOR PARTICIPATION
- Each Entity may submit only one (1) Project Proposal as a Host Organization under this Call. If an Entity submits more than one (1) proposal as a Host Organization in the Call, the first proposal will be considered valid based on the order of submission and the remaining proposals will be considered invalid.
- Participation of entities engaged in an economic activity in a proposal shall be deemed valid, if they are legally established and are active in territories under the control of the Republic of Cyprus. The activity of the entities is documented by the existence of facilities and staff in territories under the control of the Republic of Cyprus and, indicatively and not restrictively, by audited financial statements, the tax return of the entity in the Republic of Cyprus, etc. These conditions should be met to the satisfaction of RIF and without prejudice to the Foundation to request further data and information from the entities.
- Upon completion of the projects, each SME will be required to undertake at least one publicity activity (media/social media publication, video, event, etc.) highlighting the achievement of the verification following the implementation of the funded project, with references to the benefit derived from the funding. For publicity actions, the obligations for promotion and publicity for projects funded by the Digital Europe Programme should be applied, including the logos of the NCC-CY, the Research and Innovation Foundation (RIF), the Commissioner of Communications and the Digital Security Authority, as well as reference to the co-funding by the Republic of Cyprus.
PROJECT ACTIVITIES
The projects involve the implementation of activities related to strengthening cybersecurity and preparing for compliance with the requirements of the NIS2 Directive. Eligible activities include the implementation of organizational and technical measures, the development of information security policies and procedures, staff training, and the implementation of basic cybersecurity technology solutions.
The Program’s initial goal is the gradual implementation of all measures outlined in Belgium’s CyberFundamentals (CYFUN) framework up to the “Basic” assurance level, which includes 34 essential cybersecurity measures (for more information, click HERE). This approach strengthens business resilience, risk management, and preparedness against cyber threats, while also establishing a minimum level of security and compliance with European standards and cybersecurity requirements.
The 34 key measures included in Belgium’s CyberFundamentals (CYFUN) framework (version dated October 1, 2025) are fully aligned with the NIS2 Directive. For more information, click HERE.
NOTE: Please note that funding will be disbursed ONLY if the company is fully compliant with all 34 cybersecurity measures of the CyberFundamentals (CYFUN) framework (for more information, click HERE). Entities that complete part of these measures will not be eligible for funding. It should also be noted that the funding covers the cost of the audit for obtaining the verification certificate confirming the implementation of the measures.
DURATION OF PROJECT IMPLEMENTATION
Up to twelve (12) months
Upon completion of the projects, a «Final Activity Report» and a «Funding Payment Request» must be submitted within one (1) month in order to secure the final installment, provided that a verification certificate confirming the implementation of the measures has been obtained.
BUDGET
€ 1.530.000
MINIMUM - MAXIMUM FUNDING PER PROJECΤ
€20.000 – €100.000
The aid intensity is 70% of eligible costs.
If, upon completion of the projects, the total eligible expenses based on approved costs (total amount of eligible expenses taking into account the aid intensity – 70%) are less than the minimum project funding €20,000, the funding will not be granted to the beneficiary.
ELIGIBLE EXPENSES
Costs which will fall under the categories «Costs for external services» and/or «Costs for Instruments and Equipment».
Eligible expenses are considered to be all expenses incurred based on the results of the Gap Assessment and documented as necessary for the verification of Beneficiaries, in accordance with the requirements of the CyberFundamentals framework - CYFUN, version 2025-10-01 (for more information, click HERE).
Indicatively, funding covers consulting services (implementation of policies, procedures, and organizational/technical measures; staff training and awareness), the necessary hardware and software for network, system, and data security, as well as the cost of one (1) audit to obtain verification of the measures’ implementation.
The above list is indicative and not exhaustive, as any service, hardware, software, or tool that is documented as necessary for the implementation of the CYFUN framework measures and the successful verification (verification) of the Beneficiary, provided that it is deemed reasonable during the verification process by the Cybersecurity Maturity Auditor.
The cost of the audit to obtain the verification certificate confirming the implementation of the measures is also eligible.
Beneficiaries must receive and evaluate at least three (3) independent tenders for each purchase exceeding Euro 15,000 (excluding VAT) resulting in the selection of the most economical solution that meets their needs.
VAT is not considered an eligible cost. Beneficiaries are responsible for VAT payments to all consultants and solution providers and certification bodies.
The total amount of funding is committed at the time of Project Contract preparation, and the funding is made as a lump sum payment as de minimis aid (EU Regulation 2023/2831 of 13th December 2023) in two instalments.
The first instalment of 50% is paid upon signing of the Project Contract and the second instalment is paid upon approval of the «Final Activity Report» and the «Funding Payment Request» which are submitted within one (1) month from the completion of the works by the Host Organization.
Failure to secure the Verification certificate for all 34 measures within the duration of the funded project will result in the funding not being granted and a refund of the pre-financing will be requested.
It is clarified that, according to the EU Regulation 2023/2831 on de minimis funding, enterprises active in the fisheries and aquaculture sectors and in the primary production of agricultural products cannot be funded.
PROJECT SELECTION
Evaluation Procedure
For the evaluation of the Proposals in this Call, a process of Preliminary Check and remote evaluation process conducted by two (2) independent evaluators, as described in the RESTART WorkProgramme for the period May 2022-December 2026 will be followed.
Evaluation Criteria
- Relevance (Excellence) – Weight 30%
- Added Value and Benefit – Weight 40%
- Implementation – Weight 30%
Selection
Prioritised in order of submission to the RIF (non-competitive procedures apply) on the condition that proposals have been deemed eligible for funding following the evaluation procedure until the sum of the requested funding in proposals approved equals the total Call budget.
RESTART-2016-2020-WORK-PROGRAMME – VERSION 17 – MAY 2022 – JUNE 2025