Cluster 3 — Call 2026: The Ethical-Legal Map of This Year’s Civil Security Topics

The Horizon Europe Cluster 3 “Civil Security for Society” call for 2026 — HORIZON-CL3-2026-01 — is where this year’s civil security proposals will be won or lost. Across its five Destinations, the topics on the table touch surveillance, biometrics, minors, critical infrastructure and even synthetic biology. In this cluster, the ethical and legal dimension is not a section you write last; it is a design constraint the Work Programme places at the heart of security research, demanding solutions “as minimally intrusive as possible while respecting freedoms, rights and values.”

And uniquely in Cluster 3, that demand is enforced through two appraisal procedures that run before your Grant Agreement can be signed. Getting both right — for the specific 2026 topic you target — is what makes a proposal fundable.

Two procedures, one deadline to plan for

Every proposal passes the Ethics Appraisal Procedure, starting from your ethics self-assessment and its Ethics Issues Table (How to complete your ethics self-assessment, v2.0). Cluster 3 adds the Security Appraisal Procedure: a security self-assessment and Security Issues Table, followed — for security-sensitive topics — by security scrutiny by national security experts (HE Programme Guide, v5.1). That scrutiny can impose contractual security requirements before signature (limiting dissemination, classifying deliverables, appointing a project security officer or security advisory board), and in the worst case declare a proposal “too sensitive to be funded.” Breach of ethics or security obligations can trigger grant reduction or termination (HE MGA Art. 13 and Annex 5; HE Regulation 2021/695 Art. 20; Commission Decision (EU, Euratom) 2015/444).

The 2026 topics, read through an ethical-legal lens

Fighting Crime and Terrorism (FCT). This year’s FCT topics are among the most ethically loaded of the whole call. FCT-02 (misuse of emerging technologies for criminal purposes, including lawful access to data) goes straight to the tension between security and the Law Enforcement Directive (2016/680) and GDPR — necessity, proportionality and lawful basis. FCT-06 (misuse of synthetic biology for bioterrorism) is a textbook dual-use / potential-misuse case demanding a misuse risk assessment and, very likely, classification. FCT-03 (missing persons), FCT-04 (the addictions–crime nexus) and FCT-05 (protecting citizens against lone-actor violence in confined spaces such as schools) all engage vulnerable groups — including minors — and special-category or health data (Arts. 9–10 GDPR).

Border Management (BM). BM-01 (advanced border surveillance and situational awareness) is precisely the surveillance-technology scenario the guidance singles out: the proposal must justify why the surveillance is “necessary and proportionate in a democratic society,” with a DPIA (Art. 35 GDPR) and Charter analysis. BM-02 (travel facilitation) turns on biometrics and large-scale personal data. BM-03 (reliability of age assessment methods) is one of the most sensitive topics in the entire call — it concerns children and the determination of minority, with profound fundamental-rights implications for a highly vulnerable population.

Resilient Infrastructure (INFRA). INFRA-01 (stress tests of critical infrastructure) and INFRA-03 (resilience to natural and human-induced disasters, including hybrid scenarios) generate exactly the kind of results the misuse guidance flags — information that “could adversely affect critical infrastructure.” Expect security scrutiny, and plan classification handling (RESTREINT / CONFIDENTIEL / SECRET UE) from the proposal stage (Classification of information in HE projects, v1.0).

Disaster-Resilient Society (DRS). The 2026 DRS topics — risk awareness and preparedness (DRS-01), multi-hazard cascading impacts (DRS-02), search and rescue in hazardous conditions (DRS-03), innovation uptake (DRS-04) and climate-security scenarios (DRS-05) — process personal data of affected populations and first responders, and call for data-minimisation and proportionate, least-intrusive design.

Support to Security Research and Innovation (SSRI). The open topic on disruptive innovation (SSRI-01) and the procurement instruments (SSRI-02 PCPSSRI-03 PPI) bring ethics-by-design, dual-use screening and integrity into the innovation and procurement pipeline; SSRI-04 (secured European critical communication system) again raises classification and security-sensitive results.

The cross-cutting layer every 2026 proposal shares

Beneath the topic-specific issues sit obligations common to the whole call: trustworthy AI where detection and analytics rely on it (the Ethics Guidelines for Trustworthy AI and the operational ALTAI, increasingly alongside the EU AI Act’s high-risk regime); research integrity under the ALLEA European Code of Conduct (2023), sharpened by the mandatory involvement of police and border practitioners; and the gender and intersectional dimension (Gendered Innovations 2), a content requirement in several topics rather than a checkbox.

Why an ethics partner — not just an advisor

An external ethics advisor, appointed after award, reviews from the outside. An ethics partner inside your consortium builds compliance into the proposal from day one: leading the ethics and data-protection work package, drafting the ethics self-assessment and Security Issues Table, running the DPIA and the misuse and human-rights risk assessments, designing classification and data governance, and embedding ethics-by-design into the technical work. In the 2026 call, where security scrutiny can decide the fate of a grant, that work must be done before submission — as a full beneficiary.

Where Plus Ethics comes in

Plus Ethics joins consortia as their dedicated ethics partner — the beneficiary that owns the ethical-legal dimension across the whole 2026 proposal and the project that follows. We bring command of the instruments this call turns on — GDPR and the Law Enforcement Directive, the Charter, the misuse and classification regimes, trustworthy AI and research integrity — and translate them into a proposal that convinces evaluators and survives both the ethics and the security appraisals. We already work across the security domain in Horizon Europe, see our portfolio at https://www.plusethics.com/projects/

The HORIZON-CL3-2026-01 topics are open now, and in Cluster 3 the decisive ethics and security work happens at the proposal stage. Bring us into your consortium early, and your team can focus on the technology while we secure the ethical-legal foundation it stands on.

Preparing a Cluster 3 2026 proposal? Partner with Plus Ethics as the ethics beneficiary in your consortium — from proposal design to project close.