The SECURE open call: EU co-funding for Cyber Resilience Act work
Last updated: 2026-10-09
SECURE is a project funded by the European Union that co-finances the work small companies do to meet the Cyber Resilience Act; it is coordinated by Italy's national cybersecurity agency, the Agenzia per la Cybersicurezza Nazionale (ACN). Its second open call was published on 1 October 2026 and closes on 11 December 2026. It pays 50 % of a project's eligible costs, up to EUR 30,000, to micro, small and medium-sized enterprises established in the EU (its overseas countries and territories included), Norway, Iceland, Liechtenstein or Switzerland, whose ultimate beneficial owner is a citizen of one of those countries and which are controlled from them. The call's documents name SBOM management among the work it can fund and SBOM management tools among the purchases it can cover. This page quotes those documents and reads them plainly; the documents themselves and the call's help desk decide what applies to you.
What the text says
The grant, Application Guidelines (Annex 1), section 1.3:
"Successful Applicants will receive a grant covering 50% of the total eligible costs of their Project, up to a maximum SECURE contribution of EUR 30,000. If the total Project cost exceeds EUR 60,000, the SECURE contribution will remain capped at EUR 30,000."
What it is for, the project's FAQ:
"The SECURE funding is intended to support SMEs in achieving compliance with the Cyber Resilience Act for their own products, processes, and operations."
SBOM work in development, Annex 2, Category 11:
"Integration of security into the Software Development Lifecycle (SDLC) in alignment with CRA principles. This includes threat modelling, secure coding standards, software bill of materials (SBOM) management, and security testing embedded in CI/CD pipelines."
SBOM work in the supply chain, Annex 2, Category 13:
"Activities include supplier audits, contractual security provisions, and SBOM-driven risk assessment to minimise supply chain vulnerabilities."
Tools, Annex 2, "Goods and Licensing":
"Applicants may also purchase goods or technologies where such acquisitions are necessary to complete one of the eligible activities mentioned above, or where they are instrumental to the successful implementation of the Project or the achievement of CRA compliance objectives."
One of the examples that follow it:
"Software Bill of Materials (SBOM) management tools and dependency scanning solutions for supply chain security;"
For how long, the same section:
"Please note that the costs of goods and licenses will be covered only for the period of use within the 180-day Project implementation timeframe."
Suppliers, Proposal Budget Guidelines (Annex 1.2), section 2.4. The beneficiary cannot use service providers or subcontractors that:
"are not registered in an EU or EFTA Member State;"
"are directly or indirectly controlled by a country outside the EU/EFTA or by an entity registered in an ineligible country."
Payment, Application Guidelines, section 1.3:
"The full payment of the grant is conditional on the successful implementation of all activities and the attainment of the Milestones and KPIs (Key Performance Indicators) specified in the application and confirmed in the Sub-Grant Agreement signed with Cyber 4.0."
What this means in practice
- The dates are fixed: published on 1 October 2026, closing on 11 December 2026. Applications go through the project's own platform, and the call's total budget is EUR 11.5 million.
- A project lasts at most 180 calendar days. The grant is a lump sum of half the estimated eligible costs, never more than EUR 30,000; a pre-financing of 40 % can be asked for with the proposal.
- The call funds a company's own CRA work. The FAQ says companies whose core activity is CRA services for others are not eligible as direct beneficiaries, unless they place products with digital elements on the market themselves; they may take part as subcontractors.
- SBOM work appears twice among the examples, each with example KPIs: "Percentage of components with SBOM" under Category 11, "Number of components analysed" and "Vulnerabilities identified" under Category 13.
- A tool can be a purchase cost. The Budget Guidelines give "Software licence (only for the period corresponding to the Project duration)" as an example, so a subscription counts for the months inside the project, about six at most.
- The lists are examples, not promises. Annex 2 calls them "generic examples"; evaluators score each proposal on excellence and relevance, impact and clarity, and implementation.
- Suppliers have a rule of their own, in section 2.4 of the Budget Guidelines and in the FAQ: registered in the EU or an EFTA state, not controlled from outside, and doing the work there. Check every supplier you name, and who issues its invoices, before you budget it.
- Every purchase is explained twice: in the budget template (item, description, amount) and in the technical proposal (the supplier in section 2.2, the cost in section 5).
- The grant is paid for results. The milestones and KPIs you write are what the final Technical Report is measured against, so choose KPIs you can prove.
What to keep as evidence
- The SBOM of every release made during the project, as the file your build produced, with a hash and a timestamp.
- The count behind each KPI and the day it was taken: components listed, components with a version and an identifier, vulnerabilities found and handled.
- For each vulnerability: when it was found, what was decided and when the fix shipped.
- Each supplier's name, country of registration and price list as they were on the day you budgeted, and the invoices that followed.
- The call documents in the version you applied under; the second call's files are marked "Call2".
Where DevKit Dossier fits
DevKit Dossier is an SBOM record-keeping service. Your CI uploads the CycloneDX or SPDX JSON file of each release; DevKit Dossier stores it byte for byte with a hash and an upload timestamp, checks its components every day against public vulnerability data and exports an evidence pack, as PDF and JSON, for a product and a period. Records of that kind are what a project with SBOM KPIs has to show at its end. DevKit Dossier is made and run by DevKit Srl, registered in Italy, and hosted in Frankfurt; the price is flat per organisation, 49, 99 or 249 EUR per month excluding VAT, public on the pricing page; payments are handled by Paddle as merchant of record, so the invoice is issued by Paddle.com Market Limited, a company registered in the United Kingdom. The call's supplier rule looks at a provider's registration, at who controls it and at where the work is done; whether a SECURE-funded budget may include DevKit Dossier is a question for the SECURE help desk, not one we can answer for you. DevKit Dossier is in early access: the waitlist is open and paid plans are not open yet. DevKit Srl is not part of the SECURE consortium, and this page is not endorsed by it. DevKit Dossier supports your evidence: it gives no legal advice and does not decide what a call accepts.
Sources
- Second SECURE Open Call: call page and documents (Annex 1, Annex 1.2, Annex 2)
- SECURE project FAQ
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
This guide is general information, not legal advice.
DevKit Dossier