Share
Print

Register and select a membership plan to access this feature.
22 October 2025
The call EDF-2025-RA-SI closed at 17.00 on 16 October 2025. 16 proposals were submitted for evaluation.
TOPIC ID: EDF-2025-LS-RA-SI-CYBER-3RAV-STEP
Type of grant: Call for proposals
General information
Programme:
Call: Spin-in EDF research actions implemented via lump sum grants (EDF-2025-LS-RA-SI)
Type of action: EDF-LS EDF Lump Sum Grants
Type of MGA: EDF Lump Sum Grant [EDF-AG-LS]
Status: Forthcoming
Deadline model: single-stage
Planned Opening Date: 18 February 2025
Deadline dates: 16 October 2025 17:00 (Brussels time)
Topic description
Expected Impact:
The outcomes should contribute to:
Objective:
Unmanned vehicles (UxV) such as drones, ground vehicles, and surface/underwater vessels are bound to become an integral part of military operations. Advanced autonomous capabilities are being developed for these systems to enable them to carry out different missions, both with and without human intervention, thus increasing efficiency and minimising risk. From a security perspective, this poses various new challenges that need to be properly resolved to deploy these vehicles in real missions and exploit their full potential.
The cyber-physical nature of UxVs affects security in various way. It brings the attack surface of a typical computer (network) into a new context where successful cyber-attacks can have serious consequences in the physical world, while imposing new physical and operational constraints on available and well-established cyber security controls. New attack vectors emerge, and threat models need to be revised. If autonomous capabilities that rely heavily on sensor data to make their decisions are employed, the environment itself can become a new attack vector, as it can be manipulated to exploit vulnerabilities in these new capabilities. Sensors themselves become a new part of the threat model, and the protection of confidentiality of data on the vehicles needs to be weighed against the protection of the availability of effectors and actuators and the integrity of control information.
Specific objective
Designing appropriate security controls for UxVs requires capabilities to identify and evaluate complex trade-offs between data protection, cybersecurity and assured autonomy to best support a mission. Automating parts of the analysis process is necessary to handle the complexity of this task, including processing large amount of data, reducing costs and risks associated with testing physical systems, and producing structured and traceable documentation.
Existing security and safety approaches may be tailored to suit UxVs so that they can be made both secure and robust against well-known deliberate and accidental threats, however new solutions are expected. An additional challenge is whether UxVs can be made resilient in the sense that they can still react in a way that minimises the consequences, and possibly allows for alternative ways to complete the mission autonomously, in the presence of a successful cyber-attack.
This call topic contributes to the STEP objectives, as defined in STEP Regulation, in the target investment area of deep and digital technologies.
Scope:
The capability of UxVs to be resilient so that they can minimise the consequences of an cyber-attack, and allowing for alternative ways to complete the mission autonomously, is called in this context autonomous cyber defence, which is consisting of four main components: monitoring, detecting, reacting, and reconfiguring (or learn). A central part of this capability is the ability to monitor the system and detect potentially harmful anomalies, but also to understand the risk associated with both their impact and possible responses. For instance, if a malware was detected on a UxV trying to exfiltrate classified data, and the source was a malicious component critical for flight, the system might have to evaluate the risk and feasibility associated to either: preventing a breach of confidentiality by shutting down the malicious component and crash onto the ground, thus possibly damaging people or infrastructure; accepting the loss of data to prevent the UxV from crashing; or reconfiguring itself to perform an emergency landing while gradually shutting down the rotors in time to prevent significant data leakage.
A “risk-evaluation engine” is central to this capability to generate risk-based courses of actions (CoA) that take into consideration the effect of each action on the various assets connected to the UxV that need to be protected. This includes the mission goals the UxV supports, the confidential information on the UxV and the safety of the UxV itself and its surroundings. This presupposes a sufficient understanding of the UxV´s systems, its interactions, the environment and the dependencies between the UxV´s capabilities and the mission. Additionally, the anomalies should be detected with a high degree of precision to estimate their potential effect before they compromise the UxV beyond repair.
Types of activities
The following types of activities are eligible for this topic:
|
Types of activities (art 10(3) EDF Regulation) |
Eligible |
|
|
(a) |
Activities that aim to create, underpin and improve knowledge, products and technologies, including disruptive technologies, which can achieve significant effects in the area of defence (generating knowledge) |
Yes (mandatory) |
|
(b) |
Activities that aim to increase interoperability and resilience, including secured production and exchange of data, to master critical defence technologies, to strengthen the security of supply or to enable the effective exploitation of results for defence products and technologies (integrating knowledge) |
Yes (mandatory) |
|
(c) |
Studies, such as feasibility studies to explore the feasibility of new or upgraded products, technologies, processes, services and solutions |
Yes (mandatory) |
|
(d) |
Design of a defence product, tangible or intangible component or technology as well as the definition of the technical specifications on which such design has been developed, including partial tests for risk reduction in an industrial or representative environment |
Yes (mandatory) |
|
(e) |
System prototyping of a defence product, tangible or intangible component or technology (prototype) |
No |
|
(f) |
Testing of a defence product, tangible or intangible component or technology |
No |
|
(g) |
Qualification of a defence product, tangible or intangible component or technology |
No |
|
(h) |
Certification of a defence product, tangible or intangible component or technology |
No |
|
(i) |
Development of technologies or assets increasing efficiency across the life cycle of defence products and technologies |
No |
The following tasks must be performed as part of the mandatory activities of the proposals:
Functional requirements
The proposals should meet the following functional requirements:
described in section 5 of the call document.(available shortly)
Proposal page limits and layout: described in Part B of the Application Form available in the Submission System.
described in section 6 of the call document.
described in section 6 of the call document.
described in section 7 of the call document.
described section 8 of the call document and the Online Manual.
described in section 9 of the call document.
described in section 4 of the call document.
described in section 10 of the call document.
Call document (available shortly)
Application form templates
Standard application form (EDF) — the application form specific to this call is available in the Submission System (available shortly)
Detailed budget table (EDF LS RA) (available shortly)
Participant information (EDF)
List of infrastructure, facilities, assets and resources (EDF)
Actual indirect cost methodology declaration (EDF)
Ownership control declaration
PRS declaration (EDF)
Model Grant Agreements (MGA)
EDF, ASAP and EDIRPA Lump Sum MGA
EDF Annual Work Programme
EDF Regulation 2021/697
EDF Programme Security Instruction (PSI)
EU Financial Regulation 2024/2509
Rules for Legal Entity Validation, LEAR Appointment and Financial Capacity Assessment
EU Grants AGA — Annotated Model Grant Agreement
Funding & Tenders Portal Online Manual
Funding & Tenders Portal Terms and Conditions
Funding & Tenders Portal Privacy Statement
Start submission
The submission system is planned to be opened on the date stated on the topic header.
Get support
Please read carefully all provisions below before the preparation of your application.
For help related to this call, please contact [email protected]
Funding & Tenders Portal FAQ – Submission of proposals.
IT Helpdesk – Contact the IT helpdesk for questions such as forgotten passwords, access rights and roles, technical aspects of submission of proposals, etc.
Online Manual – Step-by-step online guide through the Portal processes from proposal preparation and evaluation to reporting on your ongoing project. Valid for all 2021-2027 programmes.

EuropeAid is an agency responsible for designing European international cooperation and development policy and delivering aid worldwide. Its purpose is to aid in the reduction and eventual abolition of poverty in developing nations by fostering sustainable development, democracy, peace and security. With its partner nations, EuropeAid walks alongside them on their journey to sustainable development, continually adapting its help to their changing requirements. EuropeAid is also concerned with increasing the value and impact of aid money by ensuring that help is provided appropriately.
Under the donor EC - European Commission, DevelopmentAid covers the following entities:
Departments / Directorate Generals
Agencies
EU Bodies
Focuses on strengthening safety and security systems while supporting conflict prevention, stabilization, and long-term peacebuilding efforts.
Covers the supply, operation, and maintenance of vehicles used for land, water, air, and specialized transport purposes.