Devops iconDevopsSep 8, 2026 ~3 min source read

EU’s CodeSupply Offers €400,000 in Grants for Open Source Software Supply Chain R&D

CodeSupply, an EU-funded initiative coordinated by the NLnet Foundation, invites proposals for €5,000–€50,000 grants to improve software package metadata, supply chain security, and related tooling. Proposals are due Nov. 3 and must demonstrate a clear European dimension.

EU-Funded CodeSupply Offers Grants for Open Source Software Supply Chain R&D

Share this story

Send the public story page.

Useful takeaways from this story.

CodeSupply is allocating €400,000 for open source R&D projects that improve software package metadata, supply chain security, license compliance, and interoperable datasets.

Eligible activities include software engineering, research, security audits, formal proofs, usability work, documentation, standardization, infrastructure costs, and participation in technical events.

CodeSupply is run by NLnet Foundation with AboutCode, the Edsger Institute, and Universidad Rey Juan Carlos, and is funded by the European Commission under Horizon Europe.

# What CodeSupply is funding CodeSupply program is offering €400,000 in grants for open source research and development aimed at improving software package data and the software supply chain. The funding targets work that makes metadata, provenance, licensing information, and security-related package data more available, accurate, and interoperable across tools and registries.

# Who coordinates the program CodeSupply is coordinated by the NLnet Foundation and runs with three partners: AboutCode, the Edsger Institute, and Universidad Rey Juan Carlos. Funding is provided by the European Commission's Directorate-General for Communications Networks, Content and Technology through Horizon Europe.

# Amounts, timeline, and basic requirements Projects may request between €5,000 and €50,000. Proposals must be written in English, focus primarily on research and development, and have a clear European dimension. The current call has a submission deadline of Nov. 3. Applications are screened for alignment with CodeSupply goals before evaluation on feasibility, relevance, potential impact, and value for money.

# What types of projects are eligible The call covers both new and existing technologies that can demonstrate real-world impact. Eligible activities listed by CodeSupply include:

  • Scientific research and software engineering for package metadata and supply chain tooling.
  • Security audits, formal security proofs, and technical validation.
  • Documentation, usability improvements, and participation in technical events.
  • Standardization efforts and mechanisms to publish essential datasets more widely.
  • Open source hardware work where relevant, project management, and essential infrastructure costs.
  • Tools for open source license compliance that help identify, document, or manage licensing requirements.

# Objectives and scope One of CodeSupply's primary objectives is publishing current, correct, and comprehensive software metadata. That can mean work that improves how components, dependencies, and licensing information are recorded, shared, and consumed by security and compliance tools. The initiative expects applicants to define a concrete problem, describe the proposed technical work, and explain expected impact on the open source ecosystem and software supply chain reliability.

# Evaluation criteria After the initial screening for alignment and eligibility, proposals are judged on technical feasibility, relevance to CodeSupply goals, potential impact on the ecosystem, and cost-effectiveness. Applicants should make clear how their work contributes to the stated objectives and provide evidence or plans for real-world applicability.

# Who this call is for The funding targets small to medium-sized R&D efforts in open source that can produce reusable outcomes for supply chain security, metadata quality, and interoperability. That includes researchers, maintainers of tooling, nonprofit organizations working on provenance and licensing, and projects that can demonstrate a European link in governance, implementation, or deployment.

# Practical next steps for applicants Prepare a proposal in English that:

  • Clearly states the problem and how it ties to CodeSupply objectives.
  • Describes the R&D activities, deliverables, and measures of impact.
  • Shows technical feasibility and a plan for real-world use or adoption.
  • Documents the European dimension of the project.
  • Includes a realistic budget within the €5,000–€50,000 range.

Deadline: Nov. 3. Coordinate with partnering organizations or stakeholders when possible to strengthen the European dimension and real-world validation of the proposal.

More context around this story.

The 60-second procurement test
Dri iconDriSep 9, 2026

The 60-second procurement test

I believe any Open Source project with a commercial or institutional funding ecosystem should publish an official contribution record: who contributes, how much and over what period, what kind of work they do, which parts of the project they work on, and, where disclosed, who paid for the work. The test for a good reco

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app