TRUNSPORT Open Call 1
TRUNSPORT Open Call 1
TRUNSPORT is an EU-funded initiative dedicated to strengthening cybersecurity resilience across the transport sector and related critical infrastructures. As digitalisation accelerates, transport systems face growing cyber threats that can disrupt operations and compromise safety. TRUNSPORT addresses these challenges through its Cyber Security Hub (CSH), a one-stop platform offering advanced services for preparedness, protection, and mutual assistance. Our approach combines Preparedness Support Services (PSS), Human Shield Strategies (HSS), and Mutual Assistance Support (MAS), powered by cutting-edge technologies like Generative Artificial Intelligence. From real-time risk monitoring and vulnerability testing to tailored training and compliance evaluation, TRUNSPORT empowers organisations to anticipate, prevent, and neutralise cyber threats. By fostering collaboration and innovation, we aim to create a secure, resilient, and future-ready transport ecosystem across Europe.
Entité de financement
Commission Européenne - Digital Europe ProgrammeClôture de l'appel
30 septembre 2026Zone géographique
eurObjectif
The TRUNSPORT Open Call 1 (OC1) is designed to support the adoption and validation of cybersecurity solutions within the transport sector. The Call will enable transport-related organisations to strengthen cyber preparedness, improve operational resilience, and test innovative cybersecurity technologies in operational or simulated environments.
The Open Call 1 has five (5) overarching objectives:
1. Support transport-sector organisations in improving their cyber preparedness and resilience against evolving cyber threats affecting both IT and OT environments through innovative cybersecurity tools, methodologies, and operational practices.
2. Enhance cybersecurity awareness, skills, and operational readiness among transport operators, infrastructure managers, and personnel through human-centric approaches and training-oriented activities.
3. Support real-life experimentation, pilot deployments, and validation activities within operational transport environments to assess the effectiveness and scalability of proposed solutions.
4. Stimulate collaboration between transport operators, technology providers, SMEs, research organisations, public authorities, and cybersecurity experts to address shared cybersecurity challenges.
5. Engage external transport-sector entities in the TRUNSPORT ecosystem and contribute to the refinement, validation, and broader uptake of the Cyber Security Hub services and tools.
Critères d'éligibilité
Applications may be submitted by transport systems operators, transport service providers, startups, technology and digital providers, infrastructure managers, IT solutions providers and integrators, logistics and freight transportation companies, consulting companies in the transportation and cybersecurity domains, and other related public sector entities/organizations/authorities/stakeholders operating within the transport sectors (air, water, road, rail) ecosystem.
Eligible applicants are SMEs, mid-caps, large companies, research centres (including universities), and public bodies that are registered and established in EU Member States (including overseas countries and territories (OCTs) and EEA countries (Norway, Iceland, Liechtenstein).
Project proposals may be submitted either by a single entity (mono-beneficiary) or by a consortium of entities collaborating on a joint innovation project (multi-beneficiary).
Applicants are encouraged to leverage open-source cybersecurity solutions and frameworks where appropriate. Examples include Wazuh, Kali Linux, MISP, OpenCTI, Suricata, etc.
Technologies clés
The examples presented below highlight representative cybersecurity challenges within the transport domain, for which the Open Calls aim to support the development, testing, and validation of innovative solutions capable of enhancing cyber resilience and mitigating the impacts of such threats.
Air Transport Domain: Boarding Pass Validation, Manipulation of biometric passenger identification systems, Manipulation of CCTV surveillance systems for physical security evasion, Manipulation of baggage handling systems, Manipulation of X-ray screening systems for baggage inspection, Unauthorized access to restricted airport areas through access control system breaches, Cyber-induced disruption of airport core IT services, AI-assisted deepfake social engineering attacks on airport operations, Manipulation of passenger information display systems
Road Transportation Domain: Manipulation of Variable Message Signs (VMS), Cyberattacks on electronic toll collection systems, Manipulation of traffic signal control systems, Manipulation of traffic monitoring and measuring equipment, Manipulation of crowdsourced navigation and incident-reporting platforms, Cyberattacks on Cooperative Intelligent Transportation Systems (C-ITS), Cyberattacks on electromobility infrastructure and charging systems, Cyberattacks on transport data exchange infrastructures, Manipulation of parking guidance systems, Cyberattacks on tunnel control systems, Manipulation of incident and violation detection systems, Manipulation of traffic management plans and strategy libraries, Cyberattacks on inter-TMC coordination systems, Manipulation of emergency vehicle priority systems, Manipulation of connected and automated vehicle ecosystems
2.4.3 Public and Multimodal Transport Domain: Manipulation of public transport signal priority systems, Manipulation of smart ticketing and fare collection systems, Manipulation of real-time passenger information systems, False emergency and evacuation alerts in stations and vehicles
Rail Transport Domain: Cyberattacks on rail-road level crossing systems, Manipulation of rail passenger information systems, Cyberattacks on European Rail Traffic Management System (ERTMS) communications, Communication spoofing or jamming between trains, stations, and control centers, Manipulation of digital rail maps and positioning systems
Maritime an Inland Waterways Domain: Manipulation of vessel navigation systems (GPS/AIS spoofing), Cyberattacks on Vessel Traffic Management and Information Systems (VTMIS), Manipulation of port terminal operating systems (TOS), Compromise of smart port access control systems, Cyberattacks on shipboard OT systems, Manipulation of cargo tracking and logistics platforms, Cyberattacks on lock and bridge control systems in inland waterways, Manipulation of environmental and hydrological monitoring systems
Typologie de consortium
A maximum financial support of EUR 60.000 will be allocated per project (co-financing minimum of 50% of total project costs-applicants should co-finance with at least 50% of the total project costs (Lumpsum Scheme).
The project max. implementation duration is of 9 months.
The expected outcomes of the TRUNSPORT Open Call 1 selected projects include but are not limited to:
1. All selected projects are expected to address at least one of the transport-specific cyber challenges, validate their approach in an operational, simulated, virtualised or cyber-range environment, and provide evidence of the results achieved.
2. Applicants are expected to develop, configure, integrate cybersecurity solutions that improve the ability to prevent, identify, assess and/or mitigate cyber threats affecting transport systems and services.
3. Projects should demonstrate measurable improvements against a defined baseline, such as enhanced visibility of critical assets, increased detection coverage, reduced exposure, improved identification of vulnerabilities, and improved effectiveness of mitigation measures.
... among other outcomes specified in the Applicants Guide:https://trunsport.eu/wp-content/uploads/2026/08/Annex1_Applcants_Guide_v4.pdf.