CRA funding: a gap analysis under the second SECURE Open Call
SECURE Open Call 2 · deadline 11 December 2026

Cyber Resilience Act funding

CRA funding: a gap analysis under the second SECURE Open Call

The EU project SECURE co-finances projects in which small and medium-sized enterprises implement the Cyber Resilience Act. The programme names the CRA gap analysis explicitly as an example. Blackfort Technology can carry it out as an external provider in your project and supplies the description of services for that part. The application itself comes from your company.

What the SECURE Open Call is

SECURE (Strengthening EU SMEs Cyber Resilience) is funded under the Digital Europe Programme and coordinated by the Italian National Cybersecurity Agency ACN. The second call runs from 1 October to 11 December 2026 with a budget of EUR 11.5 million. It covers 50% of eligible costs, capped at EUR 30,000 per project. A project lasts at most 180 calendar days from signature of the Sub-Grant Agreement.

The grant is a lump sum. If requested with the proposal, 40% may be paid as pre-financing when the Sub-Grant Agreement is signed; the balance follows once the final Technical Report is approved and the milestones and KPIs are evidenced. Partial achievement can lead to a reduction; if they are not achieved, the final payment is not made and any pre-financing must be repaid. The documents at https://www.secure4sme.eu/cascade-funding/second-open-call are authoritative; this page reflects them as of 9 October 2026.

How Blackfort Technology supports you

We handle the technical part. The application and responsibility for the grant stay with you.

Gap analysis as project content

Product register, technical assessment of role and product class, a gap report per product against Annex I and the other manufacturer obligations, and a prioritised remediation plan.

About the CRA gap analysis

Quotation with a description of services

Tasks, deliverables and approach for our part in English, the language of the application, so that you can name us as a service provider and evidence the costs. You submit the application yourself.

What you end up with

Before the application and after the Sub-Grant Agreement is signed.

  1. 01

    Quotation for the subcontract

    With tasks and deliverables, for the project description and budget template.

  2. 02

    Gap report and remediation plan

    Per product, prioritised, as evidence for your final report.

Annex 2 categories and our services

A selection, as of the second call.

Category in Annex 2Second callOur service
Cat. 2, module 1: CRA conformity gap analysislisted as exampleCRA gap analysis
Cat. 2, module 2: compliance needs and risk analysislisted as exampleThreat modeling and risk assessment
8 Penetration testslisted as examplePenetration testing is not part of our services
1, 9 Certificate, third-party assessmentnot eligibleNot something we provide
15 Technical documentationnot eligibleOutside the grant

Source: ANNEX 2 - CRA Scope & Eligible Activities, Services and Goods - Call2. The mapping to our services is our own assessment.

How it works

From the first conversation to the final report.

  1. 1

    Free initial consultation

    Products, role, status. We show which Annex 2 categories fit your plans from a technical standpoint; the programme decides on funding.

  2. 2

    Application

    You confirm SME status and check with your NCC; we supply the quotation with a description of services; you submit by 11 December 2026.

  3. 3

    After the Sub-Grant Agreement is signed

    Costs are eligible only from signature. Work carried out earlier is at your own expense.

  4. 4

    Close-out

    Results and evidence for your final report.

The programme expects to notify results about three months after the deadline. Reporting obligations under Article 14 CRA have applied since 11 September 2026, the remaining manufacturer obligations apply from 11 December 2027 (Art. 71(2)).

Who can apply

Single enterprises that qualify as SMEs under Recommendation 2003/361/EC, established in the EU or one of the further countries named in the guidelines. Consortia are excluded. The company must develop, manufacture, import or distribute products with digital elements that fall, or will fall, within the scope of the CRA. According to the FAQ, pure consultancies can only take part as subcontractors.

Eligibility is checked by the National Cybersecurity Coordination Centre (NCC) of the company’s home country. The documents do not say whether the German NCC does so for the second call. The programme recommends asking your NCC before applying (https://cybersecurity-centre.europa.eu/nccs_en).

What is funded and what is not

Annex 2 of the call gives examples, including gap analysis, risk analysis and remediation plan (category 2), training, security by design, incident response planning and tools for the project period. Whether a project is funded is decided by the programme’s evaluators.

In the second call, audits with a CRA certificate, third-party conformity assessment and support with the technical documentation (categories 1, 9 and 15) are not eligible. External providers may be engaged if the task is described and justified in the proposal, the contract is awarded under your usual procurement rules on the basis of best value for money or lowest price, there is no conflict of interest, and the provider is registered and works in the EU or EFTA. Costs incurred before the Sub-Grant Agreement is signed are not funded.

Scope

To set clear expectations:

  • Blackfort Technology is not part of the SECURE consortium and has no say in funding decisions.
  • Your company makes and is responsible for the funding application. We are not a grant advisory service and give no assurance or guarantee of approval.
  • No legal services: we assess scope, role and product class from a technical standpoint and flag legal questions for review by your legal department or law firm.
  • Not a notified body or certification body: we issue no certificates of any kind.
  • Penetration testing is not part of our services.

The obligations under the CRA remain with your company. We help you meet them and demonstrate that you do.

Frequently asked questions

Is a CRA gap analysis eligible for SECURE funding?+

Annex 2 lists the CRA Conformity Gap Analysis as module 1 of category 2. Whether your project is funded is decided by the evaluators.

Why are technical documentation and certification not eligible?+

In the second call, Annex 2 excludes audits with a CRA certificate (category 1), third-party conformity assessment (category 9) and support with the technical documentation (category 15). According to the programme, they become eligible once the mechanisms and standards for product certification have been identified. The risk analysis is eligible, although under Article 13(4) the cybersecurity risk assessment belongs in the technical documentation. The documents do not say where the line with category 15 lies. Clarify this with the programme at submission-support@secure4sme.eu before you submit.

Can we start before the grant is approved?+

Yes, but that work will not be funded. Only costs incurred after the Sub-Grant Agreement is signed are eligible, and according to the FAQ earlier results are not recognised. Work you do now at your own expense does not belong in the proposal.

Can we name Blackfort Technology as a subcontractor in the proposal?+

Subcontracting to consultancies is allowed. Subcontracts are listed in the project description and budget template and awarded under your usual procurement rules to the best-value offer. Blackfort Technology is based in Bonn, Germany.

Further reading

This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).

Last updated: 2026-10-09

Kontakt aufnehmen

Discuss a funded project

Tell us about your products and where you stand. In a free, no-obligation initial consultation we show which Annex 2 categories fit your plans from a technical standpoint and discuss the quotation for an application by 11 December 2026.