Start a free trial
Menu

What an EDF grant actually obliges you to prove

Most writing about the European Defence Fund covers the opportunity: the budget, the topics, the deadline. Far less covers the obligations - who may be a beneficiary, what a consortium has to demonstrate, and the security evidence a grant agreement requires before it is signed.

Search for guidance on the European Defence Fund and you will find the same article many times over: the budget, the list of topics, the closing date. It is useful once. What is much harder to find is an account of what the Fund obliges a participant to prove - and that is the half that decides whether a proposal is assessable at all, and the half that surfaces late, after the money for writing it has been spent.

This is a walk through those obligations, with the instrument named each time so you can check it. Requirements change; article numbers are checkable. Where the published documents disagree with each other, which happens more than you would expect, this says so.

Who may be a beneficiary

The first test is where you are, and who controls you.

Under Regulation (EU) 2021/697, Article 9(1)-(2), recipients and their subcontractors must be established in the Union or in an associated country, and their executive management structures must be established there too. That second limb catches organisations that are technically registered in a Member State while being run from elsewhere.

It is worth being precise about the wording, because a great deal of secondary writing renders it as "established in the EU". That is not what the Regulation says, and the difference is not academic: Norway participates in the Fund, and an entity established in Norway is eligible. Call documents express the same test as a list of eligible countries, which is the practical form to check yourself against.

The second limb is control. A beneficiary must not be controlled by a non-associated third country or a third-country entity, where control means the ability to exercise decisive influence, either directly or through one or more intermediate entities. Ownership is the obvious route to control; it is not the only one.

Entities from non-associated third countries are not banned from participating. They may take part, but they receive no EDF funding.

The derogation, and the detail that catches people

Control by a non-associated third country is not automatically fatal. Article 9(4) provides a derogation: the entity can participate where guarantees are provided.

Two things about that mechanism are routinely got wrong, including in material written for applicants.

The Member State approves the guarantee. The Commission assesses it. Not the reverse. The guarantee comes from the Member State or associated country in which the entity is established, and it certifies that the entity's involvement would not contravene the security and defence interests of the Union and its Member States.

A guarantee does not travel. The Commission's guidance on participation in calls with ownership and control restrictions (V2.0, 1 January 2026) is explicit that guarantees are programme-, call- and project-specific. A guarantee accepted for one project does not carry to the next one, and it does not carry from another EU programme. The Regulation itself is silent on this; the guidance is where it is stated, which is worth knowing if you are relying on it.

The practical consequence is a scheduling one. The assessment is substantive and it takes time. It is not a form you attach at submission.

What a consortium has to look like

The consortium rule lives in Article 10(4), not Article 9 - Article 9 governs eligible entities, Article 10 governs eligible actions. It has two limbs, and the second is the one that gets lost:

An action must involve at least three eligible entities established in at least three Member States or associated countries. Of those, at least three - established in at least two Member States or associated countries - must not be under common control, and must not control each other, for the whole duration of the action.

The shorthand "three independent entities from three Member States" collapses that control test into a single adjective. Three subsidiaries of one group in three countries do not satisfy Article 10(4), and that is exactly the arrangement the second limb exists to exclude.

Article 10(5) then disapplies paragraph 4 entirely - it does not soften it - for two categories of action: those relating to disruptive technologies for defence, and studies under Article 10(3)(c). Studies are frequently omitted from summaries of this rule.

You will also see a "two entities from two countries" figure quoted for disruptive-technology calls. That number comes from work programmes rather than the Regulation, and it is not applied uniformly: at least one 2026 disruptive-technology call still requires three independent applicants from three different eligible countries. Read the call fiche rather than the general rule.

The security obligations, and the letter that carries them

For classified work, the framework is set by an instrument many applicants never see referenced: the Security Aspects Letter. Under Article 27(4) of the EDF Regulation, the security framework for a classified grant is set out in a SAL annexed to the agreement, and it has to be in place before signature. Everything below reaches you through it.

The detailed rules are in Commission Decision (EU, Euratom) 2021/259, on industrial security for classified grants - not, as is often assumed, in the Model Grant Agreement.

Facility Security Clearances. The trigger is the classification level and national law, not the granting authority's discretion. Under Article 3(6), an FSC is required for handling information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET. Article 5(4) is blunter about the consequence: the classified grant agreement is not signed until the applicant's National or Designated Security Authority has confirmed the clearance. Article 3(3) requires the call documentation to state the timeline for obtaining one.

That is a scheduling fact rather than a paperwork fact. A clearance you begin after the award is a clearance that delays the signature.

Personnel clearances follow the same rule, not a different one. Article 3(7) covers both: in principle, neither an FSC nor a PSC is required for access to information classified RESTREINT UE/EU RESTRICTED. National exceptions exist and are published - Annex IV of the Decision lists them. So the honest answer to "do we need clearances at RESTREINT level" is: in principle no, and then check whether your Member State is one of the exceptions.

The contingency plan. This is the obligation with the least written about it and the most operational weight. Article 16 requires the classified grant agreement to oblige beneficiaries to set out business contingency plans for protecting EU classified information handled under the grant in emergency situations, and to put in place preventive and recovery measures. The beneficiaries must confirm to the granting authority that those plans are in place. The clause that binds the beneficiary directly sits in Annex III, Appendix A.

It applies to EUCI generally, not only at RESTREINT level. And it is a distinct obligation from the CIS Business Continuity Plan that governs backup frequency, storage and access control for communication and information systems. The two are easy to conflate and satisfying one does not satisfy the other.

Why this is an evidence problem

Read together, these obligations have a shape. None of them is satisfied by a statement. Each is satisfied by something you can produce on request, correct as at a particular date, sometimes years after the work was done.

Where is the entity established, and where does its executive management actually sit? Who controls it, through what chain? Which of your consortium partners are under common control, and can you show it for the whole duration of the action? When was the contingency plan last reviewed, who approved it, and what did it say on the date the incident happened?

Those are the questions a management system answers and a document folder does not. Requirements traced to the evidence that satisfies them, documents under version control with an approval history, and a record that stays answerable after the people who wrote it have moved on.

That is what requirements management and document control are for, and it is the same discipline behind the standards a defence supplier is already expected to hold. An EDF grant does not ask for a different kind of rigour. It asks for the rigour you should already have, evidenced against a different set of clauses.

Checking this yourself

Every claim above is drawn from a published document, and each is worth reading in the original if it bears on your proposal:

  • Regulation (EU) 2021/697 - Articles 9, 10 and 27
  • Commission Decision (EU, Euratom) 2021/259 - industrial security for classified grants
  • The Commission's guidance on participation in calls with ownership and control restrictions, V2.0, 1 January 2026
  • The call fiche for the specific call you are applying to, which is where the general rules become the ones you are actually held to

This article describes what the published rules say. It is not legal advice, and where a requirement turns on the national law of a Member State, that is the law that decides.