The **European Court of Auditors** has expressed concerns about how cybersecurity projects funded by the **Digital Europe program** are being monitored. The court warned that the performance data reported in the program’s statements should be viewed with caution, as its findings suggest problems with data accuracy and the methods used to collect it. The **Digital Europe program** is a major EU initiative aimed at advancing digital technologies across member states, and cybersecurity is a key component of this effort.
The cybersecurity portion of the program is funded with about 1.4 billion euros for the years 2021 to 2027. This funding is distributed through competitive calls for proposals, and each project is expected to report quantitative data on four specific areas: infrastructure and cybersecurity tools, deployed tools, user communities, and measures to prepare for and respond to cyber threats. The **European Cyber Security Competence Centre (ECCC)** is responsible for collecting and verifying this data, which is then integrated into the grant management system for use in mid-term and final project reviews.
However, the court found that this process is not consistently followed. In a review of seven projects that had reached the mid-term stage, only three had the required data systematically collected. In two of the cases, the data were incorrect—either not related to the right indicator or reflecting target values instead of actual results. The ECCC collects data through questionnaires rather than through the grant management system, and these methods are criticized for lacking quality and accuracy.
Eleven projects reviewed by the court, spread across three areas—transboundary cyber clusters, national coordination centers, and the development of Security Operations Center (SOC) capabilities—received about 38 million euros in EU subsidies between 2022 and 2025. Some of these projects faced challenges, such as failed or delayed procurement processes and difficulties in securing national co-financing. For security reasons, funding is often limited to entities based in the EU and controlled by member states or EU citizens, which can complicate operations, especially for subcontractors.
In three of the 11 projects, at least one beneficiary or consortium was excluded due to these restrictions, leading to delays and adjustments in project management. Many projects also lack appropriate monitoring frameworks, with few aligning with the required number of milestones and deliverables. Some performance indicators are not clearly measurable or lack specific target values or references.
Despite these issues, the audit report highlighted two projects that have delivered tangible benefits to small and medium-sized enterprises (SMEs). One project in Greece is working to establish a Security Operations Center (SOC) that will provide free cybersecurity solutions to SMEs for a year before transitioning to a commercial model. Another project in Ireland has awarded approximately 1.8 million euros in subsidies to about fifty SMEs, covering 80% of the costs of implementing cybersecurity recommendations.
European Court of Auditors Questions Cybersecurity Project Monitoring in Digital Europe Program
AI-rewritten from original reportingHow it works
cybersecuritydigital-europeauditeu-fundingproject-monitoring



