DevKit Dossier

Cyber Resilience Act guides

The SECURE open call: EU co-funding for Cyber Resilience Act work

Last updated: 2026-10-09

SECURE is a project funded by the European Union that co-finances the work small companies do to meet the Cyber Resilience Act; it is coordinated by Italy's national cybersecurity agency, the Agenzia per la Cybersicurezza Nazionale (ACN). Its second open call was published on 1 October 2026 and closes on 11 December 2026. It pays 50 % of a project's eligible costs, up to EUR 30,000, to micro, small and medium-sized enterprises established in the EU (its overseas countries and territories included), Norway, Iceland, Liechtenstein or Switzerland, whose ultimate beneficial owner is a citizen of one of those countries and which are controlled from them. The call's documents name SBOM management among the work it can fund and SBOM management tools among the purchases it can cover. This page quotes those documents and reads them plainly; the documents themselves and the call's help desk decide what applies to you.

What the text says

The grant, Application Guidelines (Annex 1), section 1.3:

"Successful Applicants will receive a grant covering 50% of the total eligible costs of their Project, up to a maximum SECURE contribution of EUR 30,000. If the total Project cost exceeds EUR 60,000, the SECURE contribution will remain capped at EUR 30,000."

What it is for, the project's FAQ:

"The SECURE funding is intended to support SMEs in achieving compliance with the Cyber Resilience Act for their own products, processes, and operations."

SBOM work in development, Annex 2, Category 11:

"Integration of security into the Software Development Lifecycle (SDLC) in alignment with CRA principles. This includes threat modelling, secure coding standards, software bill of materials (SBOM) management, and security testing embedded in CI/CD pipelines."

SBOM work in the supply chain, Annex 2, Category 13:

"Activities include supplier audits, contractual security provisions, and SBOM-driven risk assessment to minimise supply chain vulnerabilities."

Tools, Annex 2, "Goods and Licensing":

"Applicants may also purchase goods or technologies where such acquisitions are necessary to complete one of the eligible activities mentioned above, or where they are instrumental to the successful implementation of the Project or the achievement of CRA compliance objectives."

One of the examples that follow it:

"Software Bill of Materials (SBOM) management tools and dependency scanning solutions for supply chain security;"

For how long, the same section:

"Please note that the costs of goods and licenses will be covered only for the period of use within the 180-day Project implementation timeframe."

Suppliers, Proposal Budget Guidelines (Annex 1.2), section 2.4. The beneficiary cannot use service providers or subcontractors that:

"are not registered in an EU or EFTA Member State;"

"are directly or indirectly controlled by a country outside the EU/EFTA or by an entity registered in an ineligible country."

Payment, Application Guidelines, section 1.3:

"The full payment of the grant is conditional on the successful implementation of all activities and the attainment of the Milestones and KPIs (Key Performance Indicators) specified in the application and confirmed in the Sub-Grant Agreement signed with Cyber 4.0."

What this means in practice

What to keep as evidence

Where DevKit Dossier fits

DevKit Dossier is an SBOM record-keeping service. Your CI uploads the CycloneDX or SPDX JSON file of each release; DevKit Dossier stores it byte for byte with a hash and an upload timestamp, checks its components every day against public vulnerability data and exports an evidence pack, as PDF and JSON, for a product and a period. Records of that kind are what a project with SBOM KPIs has to show at its end. DevKit Dossier is made and run by DevKit Srl, registered in Italy, and hosted in Frankfurt; the price is flat per organisation, 49, 99 or 249 EUR per month excluding VAT, public on the pricing page; payments are handled by Paddle as merchant of record, so the invoice is issued by Paddle.com Market Limited, a company registered in the United Kingdom. The call's supplier rule looks at a provider's registration, at who controls it and at where the work is done; whether a SECURE-funded budget may include DevKit Dossier is a question for the SECURE help desk, not one we can answer for you. DevKit Dossier is in early access: the waitlist is open and paid plans are not open yet. DevKit Srl is not part of the SECURE consortium, and this page is not endorsed by it. DevKit Dossier supports your evidence: it gives no legal advice and does not decide what a call accepts.

Join the waitlist

Sources

This guide is general information, not legal advice.