Européen
CYSSDE Penetration Test Open Call
CYSSDE is looking for different types of penetration testing organizations, both individual companies and consortia (maximum of two entities). This includes technology providers, cybersecurity service companies, research institutions (public and private), and other related organizations. The goal is to conduct penetration testing and vulnerability assessments in key sectors (as defined in NIS2), such as essential service operators, digital service providers, government entities, and SMEs supporting these industries.
Cybersecurity penetration testing
This first open call will select up to ten (10) applications. Successful applicants will be receiving up to 200,000.00€ in 50% co-funding and up to 18 months of tailored support, structured across four key stages. The beneficiaries will receive support and counselling from CYSSDE mentors during this support programme.
At least 50% co-funding is required, selected beneficiaries have to co-finance the activity by a minimum of 50% of the total costs of the activity. Applicants seeking to receive 200,000.00 € therefore have to indicate that the total cost of the Pen Testing and Vulnerability Assessment activities will be 400,000.00 € or more.
Activities that can receive funding are the following:
● Hiring additional personnel, skills and expertise,
● Developing specialised skills through training and education,
● Developing additional technologies and tools, as well as performing applied research, for the required Penetration Testing and Vulnerability Assessments.
● Setting up, operating and maintaining or hiring testing and sandboxing environments, this can include specific architecture for Critical Infrastructure, Essential or Important Services, Class I and II critical or AI products and services or related,
● Services and components needed for vulnerability reporting (eg CVEs),
● Facilities and Range mechanisms to provide capture the flag actions, or hackathon resulting in Penetration Testing and Vulnerability Assessments
● Setting up, operating and maintaining Infrastructures or hiring facilities to gain deeper insights into device vulnerabilities (eg R/F scanners, testing equipment, …),
● Accessing and contributing intelligence services, risk monitoring platforms and services, and related efforts,
● Acquiring, Leasing, Hiring appliances and / or applications for device testing such as IoT, INFRA, and OT devices, (which can also be shared in consortium-based projects),
● Licensing, purchasing, renting, and hiring tooling for Penetration Testing or Vulnerability Assessments (according to the list of tools available on the cyssde.eu website, or others), for manual and automated assessments,
● Using external assessment services, provided that they use the same level of detailed description as above,
● Defining and providing external assessment services such as counselling, advisory, assistance, … to target entities (OES, essential and important entities, critical infrastructure, others …).
We are looking for individual entities or consortia of a maximum of 2 entities being SMEs (including micro-enterprises and start-ups), mid-caps or large companies, research centers and public bodies that are registered in the Member States of the European Union.