National SOCs

Opened

Programme Category

EU Competitive Programmes

Programme Name

Digital Europe Programme

Programme Description

Digital Europe Programme is the first EU programme that aims to accelerate the recovery and drive the digital transformation of Europe.

Worth €7.6 billion (in current prices), the Programme is a part of the next long-term EU budget, (the Multiannual Financial Framework), and it covers 2021 to 2027. It will provide funding for projects in five crucial areas: supercomputing, artificial intelligence, cybersecurity, advanced digital skills, and ensuring the wide use of digital technologies across the economy and society.

The Programme is fine-tuned to fill the gap between the research of digital technologies and their deployment, and to bring the results of research to the market – for the benefit of Europe’s citizens and businesses, and in particular SMEs. Investments under the Digital Europe programme supports the Union’s twin objectives of a green transition and digital transformation and strengthens the Union’s resilience and strategic autonomy.

Programme Details

Identifier Code

DIGITAL-ECCC-2024-DEPLOY-CYBER-07-SOC

Call

National SOCs

Summary

National SOCs are public entities given the role at national level to act as clearinghouses for detecting, gathering and storing data on cybersecurity threats, analysing this data, and sharing and reporting Cyber Threat Intelligence (CTI), reviews and analyses.

The objective is to create or strengthen National SOCs, in particular with state-of-the- art tools for monitoring, understanding and proactively managing cyber events, in close collaboration with relevant entities such as CSIRTs. They will also, where possible, benefit from information and feeds from other SOCs in their countries and use the aggregated data and analysis to deliver early warnings to targeted critical infrastructures on a need-to-know basis.

Detailed Call Description

The aim is capacity building for new or existing National SOCs, e.g., equipment, tools, data feeds, as well as costs related to data analysis, interconnection with Cross-Border SOC platforms, etc. This can include for example automation, analysis and correlation tools and data feeds covering Cyber Threat Intelligence (CTI) at various levels ranging from field data to Security Information and Event Management (SIEM) data to higher level CTI. National SOCs should also leverage state of the art technology such as artificial intelligence and dynamic learning of the threat landscape and context. This also includes the use of shared cybersecurity information, to the extent possible based on existing taxonomies and/or ontologies, and hardware to ensure the secure exchange and storage of information. The operations should be built upon live network data. Where relevant, consideration should be given to SMEs as the ultimate recipients of cybersecurity operational information.

A key element is the translation of advanced AI/ML, data analytics and other relevant cybersecurity tools from research results to operational tools, and further testing and validating them in real conditions in combination with access to supercomputing facilities (e.g., to boost the correlation and detection features of cross-border platforms).

Another key role for National SOCs is knowledge transfer, such as training of cybersecurity analysts. For example, SOCs dealing with critical infrastructures play a key role and should benefit from the knowledge and experience acquired by or concentrated in National SOCs.

National SOCs must share information with other stakeholders in a mutually beneficial exchange of information and commit to apply to participate in a cross-border SOC platform within the next 2 years, with a view to exchanging information with other National SOCs.

To achieve this aim, a call for expression of interest will be launched to select entities in Member States that provide the necessary facilities to host and operate National SOCs. Applicants to the call for expressions of interest should describe the aims and objectives of the National SOC, describe its role and how such role relates to other cybersecurity actors, and its eventual cooperation with other public or private cybersecurity stakeholders. Applicants should also provide the detailed planning of the activities and tasks of the National SOC, the services it will offer, the way they will operate and be operationalised, and describe the duration of the activity as well as the main milestones and deliverables. They should also specify what equipment, tools and services need to be procured and integrated to build up the National SOC, its services and its infrastructure.

To support the above activities of a National SOC, the following two workstreams of activities are foreseen:

  • Procurement] A Joint Procurement Action – with the Member State where the national SOC is located: this will cover the procurement of the main equipment, tools and services needed to build up the National SOC
  • Building up and running the National SOC – A grant will also be available to cover, among others, the preparatory activities for setting up the National SOC, its interaction and cooperation with other stakeholders, as well as the running/operating costs involved, enabling the effective operation of the National SOC, e.g., using the equipment, tools and services purchased through the joint procurement. These will also indicate milestones and deliverables to monitor progress.

Applications shall be made to both workstreams.
Applications will be object of evaluations procedures.
Grants will only be awarded to applicants that have succeeded the evaluation of the joint procurement action.

These actions aim at creating or strengthening national SOCs, which occupy a central role in ensuring the (cyber-)security of national authorities, providers of critical infrastructures and essential services. SOCs are tasked with monitoring, understanding and proactively managing cybersecurity threats. In light of the crucial operative role of SOCs for ensuring cybersecurity in the Union, the nature of the technologies involved as well as the sensitivity of the information handled, SOCs must be protected against possible dependencies and vulnerabilities in cybersecurity to pre-empt foreign influence and control.

Call Total Budget

€5.800.000

Financing percentage by EU or other bodies / Level of Subsidy or Loan

50%

Maximum grant amount: €1.000.000 – €2.000.000 per project (but other amounts are not excluded)

Thematic Categories

  • Public Administration
  • Research, Technological Development and Innovation
  • Small-Medium Enterprises and Competitiveness

Eligibility for Participation

  • Central Government
  • Legal Entities
  • Other Beneficiaries
  • Private Bodies
  • Researchers/Research Centers/Institutions
  • Small and Medium Enterprises (SMEs)
  • State-owned Enterprises

Eligibility For Participation Notes

In order to be eligible, the applicants (beneficiaries and affiliated entities) must:

  • be legal entities (public or private bodies)
  • be established in one of the eligible countries, i.e.:
    • EU Member States (including overseas countries and territories (OCTs)
    • EEA countries (Norway, Iceland, Liechtenstein)

Please be aware that all topics of this call are subject to restrictions due to security, therefore entities must not be directly or indirectly controlled from a country that is not an eligible country. All entities will have to fill in and submit a declaration on ownership and control.

Moreover:

  • participation in any capacity (as beneficiary, affiliated entity, associated partner, subcontractor or recipient of financial support to third parties) is limited to entities established in and controlled from eligible countries
  • project activities (included subcontracted work) must take place in eligible countries (see section geographic location below and section 10)
  • the Grant Agreement may provide for IPR restrictions (see section 10).

Grants will only be awarded to applicants that have succeeded the evaluation of the joint procurement action.

Consortium composition
Only entities designated at Member State level as National SOCs are allowed to apply for funding and the project should be mono-beneficiary.

The target stakeholders under a) and b) above are public bodies acting as National SOCs linked to a “call for expression of interest to deploy and operate National SOC platforms to improve the detection of cybersecurity threats and share cybersecurity data in the EU”. Actions under proposals for grants shall complement submission for the successful applicants to this call for expression of interest.

Call Opening Date

04/07/2024

Call Closing Date

21/01/2025

National Contact Point(s)

Ministry of Research, Innovation and Digital Policy
Directorate of Research and Innovation

Eleana Gabriel
Telephone: +357 22 691918
Email: egabriel@dmrid.gov.cy