NCC-RO prepares funding for cybersecurity and Cyber Resilience Act (CRA) compliance assessments for SMEs
The National Cybersecurity Coordination Centre (NCC-RO), within the Authority for the Digitalisation of Romania (ADR), is preparing Call 1 – “Financial support for CRA compliance”, with a budget of €2 million.
The funding is intended for micro, small and medium-sized enterprises in Romania for initial cybersecurity assessments and compliance with Regulation (EU) 2024/2847 on cyber resilience (Cyber Resilience Act – CRA), on the security of products with digital elements.
The de minimis aid scheme, approved by ADR President’s Decision no. 516 of 23 September 2026, was published in the Official Gazette of Romania, Part I, no. 821 of 28 September 2026. It is implemented within the project “Strengthening the capacities of the NCC-RO National Coordination Center”, based on the Grant Agreement no. 101227737.
The approval decision and the de minimis aid scheme can be consulted in the announcement published on the NCC-RO website: https://ncc.gov.ro/1/oportunitati-de-finantare/
The budget is provided in equal proportions from the Digital Europe Programme and from funds from the state budget. The non-reimbursable support covers a maximum of 75% of the eligible value of the services provided to each SME, and the own contribution is a minimum of 25%. The SME also bears the ineligible VAT, as well as the mandatory information and advertising expenses, under the conditions of the scheme.
SMEs can benefit from one of the four service packages, noted in scheme P1–P4. These include assessments and training activities with an increasing degree of complexity. Each SME is allocated a single package, chosen and justified by the provider according to the size of the company, the products evaluated and its level of cybersecurity training. At the maximum eligible value of each package and with the maximum support granted, the financing and own contribution are divided as follows:
Package 1 (P1) comprises the analysis of the applicability of the CRA, the identification of unmet requirements, the inventory and classification of products, as well as the CRA management training session. For eligible services of €10,000, the maximum grant is €7,500 and the SME’s contribution is €2,500.
Package 2 (P2) includes the services from P1 and adds vulnerability assessment, preliminary assessment of development processes and training of technical teams. For eligible services of €25,000, the maximum grant is €18,750 and the SME contribution is €6,250.
Package 3 (P3) includes the services from P2 and adds the full Secure SDLC audit, implementation of the framework and related templates, as well as penetration tests, depending on the CRA risk class of the evaluated product. For eligible services of €45,000, the maximum grant is €33,750 and the SME contribution is €11,250.
Package 4 (P4) includes the services from P3 and adds validation and optimization of extended SDLC processes and the multi-level training program. It is aimed at organizations with complex product portfolios. For eligible services of €60,000, the maximum grant is €45,000 and the SME contribution is €15,000.
The projects will be submitted by specialized cybersecurity service providers, as consortium leaders, in partnership with a minimum of 3 and a maximum of 5 SMEs in Romania. The de minimis aid is granted to each SME for the services it benefits from, and the grant is paid to the provider. The payment is made in two installments: 30% after acceptance of the preliminary deliverables provided by the scheme and 70% after the approval of the Final Technical Report. No pre-financing is granted.
The funding targets the evaluation and analysis stage, in order to identify the applicable requirements and substantiate the compliance measures. The scheme does not finance software development, research and development, purchases of software equipment and licenses, implementation of remediation measures or certification of products and processes.
Planned calendar of the NCC-RO call:
- September 30, 2026 – publication of the de minimis aid scheme on the NCC-RO website
- October 2026 – publication of the Applicant’s Guide for the first call
- November 2026 – launch of the first call for projects
The Applicant’s Guide will detail the eligibility conditions, service packages, required documents, evaluation procedure and project submission rules.
The project funded by Grant Agreement no. 101227737 is supported by the European Cybersecurity Competence Centre. Funded by the European Union. However, the views and opinions expressed belong solely to the author(s) and do not necessarily reflect the views and opinions of the European Union or the European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC). Neither the European Union nor the funding authority can be held liable for them.





