EU Funding
Cybersecurity financed through EU funds
Cybersecurity is no longer a corporate luxury: funding bodies treat it as a natural part of any digital investment, and the guides name it explicitly.
The cybersecurity component has earned a stable place in digitalization funding. The PNRR C9 call of up to 100,000 EUR listed it distinctly among eligible costs — next to RPA and cloud — while the PNRR call for advanced digital technologies (500,000–3,000,000 EUR, closed, in implementation) counted cybersecurity among its target technologies. That 500,000–3,000,000 EUR band belongs to the closed call alone and does not carry over: under POCIDIF 2.1 the non-repayable aid starts at 200,000 EUR and is capped at 1,500,000 EUR for an innovative software result, while the 3,000,000 EUR figure applies only where the result is an innovative hardware product manufactured by the beneficiary. IT&C companies building security products have in POCIDIF 2.1, open until 30.09.2026, a framework for innovative solutions of their own — with one caveat competitors omit: the guide requires the project's technical audit report to be signed by an auditor holding CISA, CISM or CISSP, or an equivalent internationally recognised advanced certification. For an ordinary SME, the practical question is not whether but how much: what level of protection the budget justifies without turning the project into a pure security one. Northdan Soft answers from the developer's seat: we build applications with security embedded in the architecture, and in funded projects we size the protection component in the technical offer and in the budget of typically eligible costs, per the official applicant guide, then implement and document it for reimbursement.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
How we help
Security integrated into delivered solutions
Solid authentication, encryption, logging and backups belong to the application's architecture, not to optional annexes.
A protection component sized honestly
We budget measures in proportion to the company's risks — an SME does not need a bank's arsenal to be reasonably protected.
Measures demonstrable at acceptance
Every security mechanism in the offer can be shown working: a backup restore test, an access log, active policies.
Cybersecurity in the architecture of funding programmes
On SME digitalization calls, security appeared as one cost category among others: protection solutions, dedicated equipment, configuration services. PNRR C9 beneficiaries implementing until the summer of 2026 can verify now whether this budget component was delivered in full.
For developers of security products — IT&C companies with their own solutions — POCIDIF 2.1 funds building the product itself, with non-repayable aid of 200,000 to 1,500,000 EUR for a software result, provided that result fits one of the six smart-specialisation subdomains the guide lists. None of them is named cybersecurity, so a security product has to be argued into an existing subdomain, typically artificial intelligence systems or IoT. That is the key distinction: one company buys security as a digitalization beneficiary, another produces it as an IT&C grant beneficiary.
The Northdan approach: protection as a property of the system
When we deliver a web application, an ERP or an online store in a funded project, the security chapter of the technical offer covers access control, encryption of sensitive data, updates and the backup plan — every measure phrased verifiably for acceptance.
What we do not do: we never sign the technical audit report for a project where we are the software supplier, and we do not issue a second price offer for a cost we ourselves quoted. The guide requires at least two dated, signed offers per eligible cost and scores zero where offers are suspected of being arranged between the applicant and the bidders.
Frequently asked questions
What usually counts as cybersecurity in a digitalization budget?
Endpoint and server protection, access and authentication configuration, encryption, backup and logging systems, sometimes a security audit. The exact list depends on the call's guide — the category gets interpreted, never assumed.
Can security alone be funded, without other digital investments?
Generalist digitalization calls usually finance investment packages where security is one component. A security-only project makes more sense on dedicated calls or, for IT&C producers, as development of their own security product.
How do you prove at reimbursement that security measures exist?
Through demonstrations and artefacts: configured access policies, a data restore test run in front of the acceptance committee, scan reports, event logs. We prepare this package at handover, because invisible measures are the hardest to reimburse.
Packages for this programme
Services for the software component
Similar pages
Related resources
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247