Approaches and tools for security in software and hardware development and assessment
Open
Status as published by the data source.
Expected Outcome:
Proposals are expected to contribute to one or more of the following:
• Enhanced security frameworks for both hardware and software supply chains, building on root-of-trust architectures and secure lifecycle management;
• Secure and trusted chip architectures for next-generation computing and networking systems;
• Integrated security-by-design approaches in software development, aimed to be aligned with relevant regulatory requirements;
• Security testing methodologies, including formal verification approaches and AI-driven security testing methodologies;
• Standardised methodologies for hardware security assessment, also contributing to cybersecurity certification. Scope:
The increasing complexity and globalisation of software and hardware supply chains introduce new vulnerabilities that cyber adversaries can exploit. Ensuring the security of both software and hardware components across the lifecycle of digital systems is paramount. This topic aims to develop innovative tools, methods, and processes to secure the entire ecosystem of software and hardware development.
Proposals should explicitly select one main area of focus but can also address both:
a. Secured hardware systems over trusted Chips
The security of modern computing infrastructures relies heavily on the robustness of hardware components. This subtopic aims to develop robust security solutions for trusted hardware platforms, focusing on secured microprocessors, secure boot mechanisms, and cryptographic acceleration. Proposals are also expected to address the risks of hardware-based vulnerabilities and backdoors, ensuring the security of devices from edge to cloud, also taking into account emerging threats, including quantum where relevant. Synergies with existing EU initiatives on trusted hardware (e.g., CHIPS JU, EuroHPC) are encouraged. The topic is expected to:
• Develop new architectures for tamper-resistant chips and processors. Exploring novel designs for secure microprocessors, leveraging hardware-level security enhancements, and integrating cryptographic co-processors that may also support post-quantum cryptography (PQC), for enhanced protection against tampering and side-channel attacks.
• Enhance supply chain transparency for chip production and integration. Exploring innovative ways to improve traceability and accountability in chip manufacturing processes, including methods such as post-quantum secure hardware roots of trust, blockchain for tracking components, or certification mechanisms.
• Establish security-by-design methodologies for hardware security assessment. Advancing methodologies for systematic security testing of hardware components, including automated vulnerability analysis, verification frameworks, and integration of security assessment into chip design and lifecycle management.
• Develop methods and tools for an effective and efficient non-destructive authentication and physical analysis of integrated circuits and multi-chips modules (chiplets).
• Develop technical means for ensuring hardware supply chain security, and secure PQC implementations: hardware trojan and backdoor detection, hardware watermarking, relevant reverse engineering techniques, countermeasures also against new classes of hardware physical attacks. Develop self-healing firmware able to recover from cyber-attacks. Develop firmware able to leverage advanced anomaly detection, AI-driven threat mitigation and secure rollback mechanisms to automatically identify cyber-attacks, isolate compromised components restore the system to a trusted state while maintaining operational continuity. b. Software Supply Chain security
The integrity of software supply chains is critical to mitigating cybersecurity threats such as supply chain attacks, dependency vulnerabilities, and compromised software components. This subtopic focuses on mitigating security risks in software supply chains, including secure code provenance, automated vulnerability detection, and secure software development lifecycle (SDLC) methodologies and tools, including those related to PQC security. Proposals should integrate formal verification approaches or AI-assisted security testing, leveraging upcoming European and International standards for supply chain security. The topic is expected to:
• Develop innovative tools for real-time software vulnerability detection and automatic patching. Advancing the state of automated detection techniques, incorporating dynamic analysis, AI-driven pattern recognition, predictive analytics to proactively identify security weaknesses before exploitation and self-healing mechanisms.
• Enhance secure software frameworks, including protection against the quantum threat. Exploring new methodologies for integrating security-by-design principles across development workflows, incorporating approaches such as automated security policy enforcement, modular security components, and improved dependency management.
• Improve resilience against supply chain cyber threats. Investigating novel mitigation strategies, including provenance tracking for software components and their analysis, secure update distribution mechanisms including protection from emerging quantum threats where relevant, enhanced anomaly detection, and multi-layer defence approaches to ensure integrity and trustworthiness.
- Status
- Open
- Deadline
- (time not stated)
- Opens
- Published
- Total budget
- €20,000,000
- Grant range
- €3,000,000 – €4,000,000
- Country
- European Union (EU-wide)
- Programme
- Horizon Europe (HORIZON)
- Official page
- Open at the source portal
Other calls under Horizon Europe (HORIZON)
- PV based electrification of the economy: Designing & optimising PV systems supporting industrial electrification and promoting participation in electricity markets (EUPI-PV Partnership)
- Advanced TSO control rooms to enhance grid observability, stability and resilience
- Advanced Distribution Management Systems (ADSM) for more efficient and flexible distribution grids
- Community of practice - Data-Driven Decision-Making in Energy
- Industrial processes and equipment for innovative, reliable and scalable tandem technologies (EUPI-PV Partnership)
- Integrated Approaches for Retrofitting Infrastructures with Innovative Energy Storage Technologies
- Demonstration of hydropower technologies for efficient and forward-looking refurbishment of existing hydropower plants
- Delivery of industrial CCUS clusters – Societal Readiness pilot
All calls under this programme
Similar opportunities
- Secure Computing Continuum (IoT, Edge, Cloud, Data spaces)
- Enhancing the Security, Privacy and Robustness of AI Models and Systems (SecureAI)
- Advanced cryptographic schemes and High-Assurance high-speed cryptographic implementations
- Secure PQC implementations, Cryptanalysis and Post-quantum Digital Trust
- Secure Computing Continuum (IoT, Edge, Cloud, Dataspaces)
- Fundamentals of Software Engineering (RIA)
Where this came from
- Source document
- https://ec.europa.eu/info/funding-tenders/opportunities/data/topicDetails/horizon-cl3-2026-02-cs-eccc-01.json
- Document fingerprint
00d3dbec7ecee703(SHA-256, first 16 hex characters)- Retrieved
- First recorded here
What has changed
- url first recorded as https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/opportunities/topic-details/horizon-cl3-2026-02-cs-eccc-01 on
- currency first recorded as EUR on
- amount_max first recorded as 4000000.00 on
- amount_min first recorded as 3000000.00 on
- budget_total first recorded as 20000000.00 on
- deadline first recorded as 2026-09-15 on
- opens_on first recorded as 2026-03-03 on
- published_on first recorded as 2025-12-12 on
- status_basis first recorded as source_status on
- status first recorded as open on
- title first recorded as Approaches and tools for security in software and hardware development and assessment on
Data source
© European Union, 2026. Source: EU Funding & Tenders Portal. Reused under Commission Decision 2011/833/EU — CC BY 4.0.
Retrieved from the source on .
The source last updated this document on Mon, 09 Mar 2026 15:28:58 GMT.
Personal data of natural persons has been dissociated by quiescence.eu.
This service is not affiliated with, sponsored or endorsed by the data publishers.