EU Funding
Cybersecurity spending inside EU-funded projects
Cybersecurity has climbed from optional line item to near-mandatory component of digitalization projects — and it stays the most vaguely specified category in most budgets.
A cybersecurity solution can mean anything from an antivirus to a full operations centre, and that elasticity is precisely what makes the category dangerous in a budget. Under the open POCIDIF 2.1 call, approved by MIPE Order 965 of 23 June 2026, security is not one heading but two: equipment dedicated to protecting IT infrastructure sits under state aid, inside the hardware share that may not exceed 20% of total eligible value where the project result is an innovative software solution, while the technical audit sits under de minimis aid and expressly covers application security, testing the security levels of the information system, information protection and personal-data compliance. That nomenclature belongs to a call open only to SMEs holding one of the ICT NACE codes listed in the guide and developing a product of their own for the market; a company hardening its own infrastructure reads the guide of whichever call it applies under. The C9 digitalization call under PNRR, Romania’s National Recovery and Resilience Plan, listed cybersecurity explicitly for SMEs, but its submissions closed on 30 June 2023, so there the conversation is about delivery and reimbursement. Verified on 30 July 2026 against the guide text and its annexed evaluation grid. Northdan delivers these components inside the applications it builds and separately, with specifications and implementation evidence a payment officer can check objectively.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
How we help
A security specification without empty words
Every line names a concrete measure — audit, backup, MFA, encryption — with a verifiable deliverable, rather than generic phrasing about advanced protection.
Security built into the application, not bolted on
When we develop the project's software, protection enters through the architecture: role-based access, audit logging, encrypted data — cheaper and sturdier than adding it later.
Implementation reports for reimbursement
We hand over audit results, the configurations applied and the tests performed in report form, which is exactly the document this category is proven with at payment.
What the security category concretely covers
The typical package in a digitalization project: a vulnerability assessment of existing systems, protection for workstations and servers, firewall and network segmentation, automated backups with a restore test, multi-factor authentication on critical systems, encryption of sensitive data and awareness sessions for employees.
In projects that include custom-built applications, security also has an internal dimension: role-based access, action logging, API protection, controlled updates. Those elements are specified in the application's technical offer, not as a separate security line.
Who may sign the technical audit report
The guide requires the technical auditor to hold CISA, CISM or CISSP, or another internationally recognised professional-level certification in IT audit, information security or cybersecurity — CCSP, CIPP/E, ISO 27001 Lead Auditor, OSCP — issued by an accredited international body and requiring formal examination and verifiable experience.
Proof at reimbursement is where this category either shines or collapses: audit reports with findings and remediation, screenshots of the configurations, backup logs, records of the training sessions. Without them, an invoice for security services stays a piece of paper. We do not sign the technical audit for a product we built ourselves.
Frequently asked questions
Which cybersecurity measures typically fit inside a funded project?
Vulnerability audit, workstation and network protection, automated backup with a restore test, multi-factor authentication, encryption of sensitive data and staff training. The exact permitted combination is defined by each call's guide.
In which calls was cybersecurity eligible?
Explicitly in the PNRR C9 SME digitalization call, whose submissions closed in June 2023, and — split across equipment and technical audit — in the open POCIDIF 2.1 call. For any other call, consult the respective guide.
How is a cybersecurity cost proven at payment?
Through tangible deliverables: the audit report with the remediations applied, screenshots of the active configurations, backup logs, training attendance records. We issue these documents at every acceptance, because in this category an invoice alone demonstrates nothing.
Does security bring any points at evaluation?
Indirectly. On the product-improvement sub-criterion the guide awards 2 points where the product gains markedly more advanced security mechanisms — multi-factor authentication, end-to-end encryption, a zero-trust model — or complies with new regulation. No intermediate scores are given on that sub-criterion.
Packages for this programme
Services for the software component
Similar pages
Related resources
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247