White Telekom Logo

Menu

A female employee working at screens in a medical setting

Immediate cybersecurity programme: prepare now or explain later

Summary
€1.84 billion. Programme launch: August 2026. First funding call: Q4 2026. The Immediate Cybersecurity Programme addresses the urgent need for modernization in the healthcare sector and is designed to help healthcare organizations strengthen and demonstrably improve their cyber resilience – not only technically, but also organizationally. For healthcare organizations, now is the ideal time to start preparing.

Not what you are searching for?

Expert authors
Page content
    Cybersecurity in health

    Prepare now to secure funding and implementation

    With the launch of the funding programme, healthcare organizations face not only the opportunity to secure investment, but also the need to structure projects clearly, demonstrate funding eligibility, and consider implementation requirements from the outset.

    Those who start preparing now can gain a significant advantage: eligible measures can be planned more precisely, budgets can be established with greater certainty, and the required documentation can be prepared early. Organizations that only start once the funding call is launched, on the other hand, risk facing the same challenges already seen with the KHZG: unclear scope, incomplete documentation, and the need to provide additional explanations after the project has been completed.

    Who is eligible to apply?

    Before planning specific measures, healthcare organizations first need to determine which part of the programme is relevant to them. Eligibility, funding logic and documentation requirements differ depending on the type of organization.

    Part A: Hospitals pursuant to Section 108 of the German Social Code Book V (SGB V). Funding is not provided through a conventional individual application, but through a needs notification via the National Association of Statutory Health Insurance Funds (GKV-Spitzenverband) and the German Hospital Federation (DKG). This reduces the formal administrative effort, but does not replace thorough preparation.

    Part B: Medical care centres (MVZ), laboratory associations, hospital pharmacies and radiology providers. Here, funding is provided as conventional project funding pursuant to Section 44 of the Federal Budget Code (BHO). Around 4,000 projects are planned, with the first funding call scheduled for Q4 2026.

    This distinction is particularly relevant for hospital groups with MVZ structures or outpatient services. They should clarify now which funding scheme applies to which entity. This allocation affects not only the application process, but also the documentation requirements and the scope of the subsequent project.

    Once the funding logic has been clarified, the next question is: What is the current situation of the respective organization, and how can the specific need for action be substantiated in a robust and credible way?

    What the programme requires without exception

    A key requirement is cybersecurity maturity measurement before the start of the programme, annually, and upon completion. This means cybersecurity is not treated merely as a one-time technical investment, but as a measurable process of continuous development.

    An IT security assessment based on NIS2 and B3S provides a sound foundation for this. It establishes the current maturity level, highlights vulnerabilities and areas requiring action, and helps prioritize eligible measures. At the same time, it creates an initial structured basis for the application, implementation and subsequent documentation.

    The assessment therefore serves a purpose beyond simply taking stock of the current situation: it connects the existing security status with the planned investment programme. This connection is crucial if funding is not only to be applied for, but ultimately also used in a transparent and verifiable manner.

    The next challenge is therefore to determine what actually qualifies as an eligible investment and where the boundary between investment and ongoing operations lies.

    What is eligible for funding – and what is not?

    Eligible investments are very likely to include areas such as Identity and Access Management, network segmentation, SIEM, endpoint protection, medical device security, business continuity management (BCM) and incident response. Training for management-level staff as well as audits and documentation for compliance may also potentially be eligible.

    Under previous programmes, ongoing operating costs were generally not eligible for funding, or only eligible to a limited extent.

    We will keep you up to date on the exact funding guidelines as soon as further information becomes available.

    The distinction between investment and operations is an important aspect of subsequent documentation and verification. This is precisely why early structuring is so important: a project can be technically sound and strategically necessary from a cybersecurity perspective, yet still encounter difficulties during the funding process or subsequent use-of-funds verification if cost types, services and project outcomes have not been clearly differentiated from the outset.

    Experience from previous funding programmes shows that successful implementation alone is not enough – it must also be transparent and verifiable. Organizations that determine at the planning stage which measures are eligible, how costs will be allocated and which documentation will be required can significantly reduce subsequent risks.

    This makes it clear what organizations should do now. Preparation can be broken down into five key steps.

    What to do now

    The key point: These steps should not begin only after the funding call has been launched. The earlier the current situation, prioritization and funding logic are brought together, the more robustly the subsequent project can be structured.

    1. Commission a current-state assessment: NIS2 assessment based on B3S. Now.

    2. Structure and prioritize eligible measures: Derive specific investment projects and a robust prioritization from the assessment.

    3. Decide between Part A and Part B: Clarify which funding route applies to which organization before the funding call – not afterwards.

    4. Build the application dossier: Prepare the project description, cost plan and documentation structure at an early stage.

    5. Establish the implementation structure: Set up responsibilities, governance and project organization before the funding decision is issued.

    Prepare now instead of explaining later

    The Immediate Cybersecurity Programme provides healthcare organizations with an important opportunity to systematically modernize their cyber resilience. At the same time, it increases the responsibility to plan investments in a funding-compliant, transparent and sustainable manner from the outset.

    Organizations that start with a robust current-state assessment now can make use of the funding call rather than simply waiting for it. Because ultimately, it is not only about securing funding, but also about being able to demonstrate that it has been used effectively and in compliance with the requirements.

    Our experts

    Get to know us.

    Our Consulting Expertise

    Discover where we provide tailored solutions to enhance value for our clients.

    Our expertise
    All insights

    Select your location

    Contact

    You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

    More Information

    On this page

    On this page

    Get in touch

    Contact

    You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.

    More Information