Grants of up to €60,000 for Secure Digital Products. The Call Opens in November — and Requires a Technical Partner.

Funding / Security / Compliance

· 10 min read

Romania's NCC-RO launched the state aid scheme on 30 September. The applicant guide arrives end of October, the call opens in November. Grants of €20,000–€60,000 for SMEs making products with digital elements. What to prepare now.

On 8 October 2026, Ana-Maria Bușoniu, Director General of Romania's National Coordination Centre for Cybersecurity (NCC-RO), announced a concrete timeline on the "Frontier Defense" podcast hosted by G4Media for a funding scheme many companies had been waiting for.

The state aid scheme was launched on 30 September. The applicant guide follows at the end of October. The call opens in November.

The amounts: between €20,000 and €60,000 per SME, depending on the level of intervention required.

But the eligibility condition is what changes how you should prepare: you apply together with a cybersecurity provider, not alone.

What It Actually Funds

Directly from the announcement: if you are an SME that makes products with digital elements, you can apply together with a cybersecurity provider to access a compliance package.

The key word is compliance. This is not a general digitalisation grant. It is a package dedicated to aligning with the requirements of the Cyber Resilience Act (CRA).

And here something worth clarifying, which many companies have not yet registered: if you sell software, a mobile app, a commercial web platform, a connected device or anything else with digital elements on the European market — you are within the scope of the CRA.

Not just hardware manufacturers. Not just large firms.

The Context That Makes This Call Urgent, Not Optional

Bușoniu was direct in the podcast: cybersecurity is no longer optional in business. She added that the fines provided for under the Cyber Resilience Act will be considerable and that the entire compliance stage is mandatory, not optional.

She also flagged the operational risk: all studies show SMEs are the most affected, and a cyberattack can even push an SME into bankruptcy.

The regulatory timeline confirms the urgency. The CRA does not apply all at once — it applies in stages:

The first stage has already passed. Since 11 September 2026, manufacturers of software and connected equipment must report actively exploited vulnerabilities and severe incidents.

Reporting deadlines: an initial warning within 24 hours, a more detailed notification within 72 hours, a final report within 14 days. Reporting goes through the single ENISA platform, operational since 11 September, with DNSC acting as market surveillance authority in Romania.

Fines for failing to meet the obligations in Articles 13 and 14: up to €15 million or 2.5% of total worldwide annual turnover — whichever is higher.

And one detail many firms overlook: the reporting obligations also apply to products already placed on the market before 11 December 2027, if they fall within the regulation's scope.

Meaning the product you launched in 2023 and have not looked at since.

The CRA Does Not Arrive Alone

For a company, the same security event can simultaneously trigger obligations under the CRA, NIS2, GDPR, DORA or customer contracts.

NIS2 is already in force, with penalties of up to €10 million or 2% of turnover — and with responsibility falling directly on management.

GDPR we have seen applied concretely: over the past 12 months, Romania's data protection authority fined four online shops following cyberattacks, with fines between €3,000 and €20,700, invoking Article 32 — the one requiring adequate technical measures.

The overlap is not theoretical. It is architectural. A system designed to satisfy a single regulation, as a separate checkbox, will be redesigned three times.

"AI in Security Has Become as Important as Antivirus"

The part of the interview that caught our attention most is the observation about AI's role in defence.

Bușoniu said that artificial intelligence in cybersecurity has become as important today as antivirus was a few years ago — and that there is no option of not adopting AI in protection, or even in the design of security products. The reason: attackers already use algorithms built to create breaches and vulnerabilities, and these can only be countered using the same mechanisms with which they were built.

Practical confirmation arrived three weeks earlier. On 22 September, Microsoft disrupted EvilTokens — the first cybercrime service in which AI ran the entire attack chain, linked to more than 12,000 compromised inboxes across more than 10,000 organisations.

The staffing shortfall makes the problem sharper: Europe is short roughly 300,000 cybersecurity experts. This is why NCC-RO is preparing, together with the National Directorate and the Ministry of Education, the launch of a National Cybersecurity Academy — a project to be presented at this autumn's Bucharest Cybersecurity Conference.

What You Need Ready Before November

The call opens in November and the guide arrives at the end of October. That leaves a few weeks. Here is what can and should start now:

  1. Classify your product portfolio. Which of your products contain digital elements and fall within the CRA's scope? The assessment is made against the text of the regulation and actual contracts, not intuition. Older products are not automatically excluded.
  2. Technical inventory. Which components, libraries and third-party dependencies do you use in each product? This inventory becomes the SBOM required from December 2027, but it is also the basis of any compliance assessment.
  3. Real capacity to meet the 24-hour deadline. Without continuous monitoring, a 24-hour deadline is not a procedure — it is a hope. The practical question: if a vulnerability in your product is actively exploited at 3 a.m. on a Saturday, who finds out, and how quickly?
  4. Working access to the reporting platform. Account configured, people designated, procedure written and tested.
  5. The technical partner. The scheme requires applying in partnership. A provider is not found in two days after the guide is published.

Where We Come In

Visual AI Labs builds software products with security designed in from the start, not bolted on when the first audit arrives. For companies within the CRA's scope, that means concretely:

Data in the EU, maintainable code for the long term, and we deliver fast — without replacing the systems that already work for you.

If You Make Products with Digital Elements

It is worth knowing, before the call opens, whether you fall within the CRA's scope — and at what level of intervention you would sit.

Write to us on the contact page with a short description of your products. We will come back with an honest assessment: whether you are in scope, what compliance would involve and whether it makes sense to apply together for the November call.

Write to us on the contact page →

Verified sources: G4Media — Frontier Defense Ep. 20, interview with Ana-Maria Bușoniu, NCC-RO (8 Oct. 2026); StartupCafé — Fines of up to €15 million (11 Sept. 2026); Economedia (Sept. 2026); Mondaq (Sept. 2026); Playtech (Sept. 2026); European Commission — Cyber Resilience Act, practical guidance (27 Jul. 2026); ncc.gov.ro

Contact