Logo displaying the text 'REPLIKA PRO' in white letters on a dark blue background.

SOC-EU

Security operations center as a service
Targeted call
ITEA 4
Proposal deadline
11 February 2027
Target number of partners
10–15
Proposal coordinator
Replika PRO, Slovenia
Contact us
Irena Mesarič, project manager
Blue check mark inside a circle symbol indicating confirmation or approval.
Challenge

NIS2 brings a much larger group of European SMEs and mid-market organisations into mandatory cyber incident management, reporting and evidence obligations. These organisations need 24/7 security monitoring, but current SIEM/SOAR and MDR offerings are priced and staffed for large enterprises, with a high share of cost driven by human L1/L2 analysts.

Existing European sovereign SecOps platforms mainly provide tools for analysts, while emerging AI-SOC solutions rely heavily on US cloud services and do not provide auditable guarantees on missed incidents. For NIS2-regulated SMEs, uncontrolled AI triage, manual tenant-by-tenant rule tuning and consultant-led compliance reporting are not sufficient.

The market need is a lower-cost, EU-sovereign SOC service that can safely serve many SME tenants with the same analyst team, reduce alert fatigue, share validated detection knowledge across tenants without exposing raw data, and generate NIS2 evidence directly from operational telemetry.

Blue check mark inside a circle symbol indicating confirmation or approval.
Solution

SOC-EU proposes a multi-tenant SOC service in which an open-weight, security-specialised LLM performs L1/L2 alert triage under a selective-autonomy model: only cases with sufficient calibrated confidence are closed automatically, while uncertain or high-risk cases are escalated to human analysts. The target is to automate a large share of routine triage while maintaining a statistically bounded false-negative escape rate that can be audited.

The service will automatically tune detections per tenant and continuously measure rule performance, reducing false positives without degrading coverage for other tenants. When an incident is confirmed for one tenant, the system will convert it into a validated detection artefact, such as a Sigma rule, test it for regressions and deploy it to other tenants without exporting raw logs or sensitive customer data.

NIS2 compliance will be embedded in the operational workflow. Incident timelines, triage decisions, evidence and response actions will be derived from the same runtime telemetry and linked into structured reports for early warning, notification and later audit preparation. The inference layer will run on EU infrastructure using a small, adapted security LLM suitable for SME economics and multilingual European environments.

Blue check mark inside a circle symbol indicating confirmation or approval.
Main activities

The consortium will design and implement the SOC-EU multi-tenant SOC-as-a-service architecture on EU-sovereign infrastructure, including secure tenant isolation, telemetry pipelines, analyst workflows and integration with existing SOC tooling.

It will develop and validate the calibrated LLM triage layer, including uncertainty estimation, selective autonomy, fail-safe escalation to human analysts, audit trails and red-team validation of the false-negative escape rate across pilot tenants.

The project will build automated cross-tenant detection engineering capabilities: tenant-specific rule calibration, continuous rule efficacy measurement, regression testing and deployment of validated detection artefacts across tenants without sharing raw logs.

It will implement NIS2 evidence-by-design functions, linking runtime telemetry, triage decisions and incident handling actions into structured early-warning, notification and audit evidence workflows, with support for national transposition requirements where relevant.

The partners will adapt and evaluate an open-weight, security-specialised LLM for EU-sovereign inference on 1–2 GPUs, including multilingual SME-relevant data such as local-language phishing and operational logs. Pilots will measure alert automation, false-positive reduction, onboarding time, time to collective protection, reporting effort and inference cost.

Blue check mark inside a circle symbol indicating confirmation or approval.
Consortium status
  • ACTUAL I.T. d.d. — SOC operator
Blue check mark inside a circle symbol indicating confirmation or approval.
Partners sought
  • SOC operator — Leads the project, owns the SOC-as-a-service business case, defines operational requirements and drives exploitation. Provides SOC processes, analyst workflows, customer onboarding logic, service-level targets and integration with existing managed security services. This role should normally be held by ACTUAL I.T. or another industrial SOC/MSSP-type organisation with clear market access.
  • Technology provider — Develops the multi-tenant SOC platform, SIEM/SOAR integrations, detection engineering pipeline, tenant isolation and deployment architecture. Converts confirmed incidents into reusable detection artefacts and supports integration with MISP/STIX/Sigma and customer telemetry sources. INFORMATIKA is a natural fit here given the SmartSOC track record, potentially supported by one specialised SME.
  • AI provider — Builds the LLM-based triage, confidence calibration, selective autonomy, multilingual security model adaptation and cost-efficient inference pipeline. Must deliver the core innovation around automated L1/L2 triage with fail-safe escalation and measurable false-negative escape limits. This can be an AI SME, cyber-AI company or applied AI lab with production ML capabilities.
  • Research organisation — Provides the scientific credibility for conformal prediction, statistical guarantees, evaluation methodology, red-team validation and benchmarking against state of the art. This partner should help make the “provable missed-incident bound” believable to ITEA reviewers and national funders. It should stay applied and validation-oriented, not turn the project into an academic RIA.
  • Cloud provider — Supplies EU-based GPU/cloud or on-prem infrastructure for sovereign inference, secure multi-tenant hosting, monitoring and cost validation. Demonstrates that the service can run within EU jurisdiction at SME-compatible cost and without dependency on US cloud AI APIs. This role can be a full partner if infrastructure sovereignty is central, or a strongly committed technical partner if national funding allows.
  • Compliance partner — Translates NIS2 obligations and national transpositions into machine-readable evidence, reporting templates and audit trails. Validates 24-hour, 72-hour and final incident reporting workflows and ensures the evidence-by-design concept is credible for regulated SMEs. This role can be a legal-tech/compliance SME or a cybersecurity governance consultancy with technical API capability.
  • Pilot users — Provide real operational telemetry, onboarding constraints, sector-specific NIS2 requirements and validation environments. Ideally include SMEs from 2-3 sectors newly affected by NIS2, such as manufacturing, logistics, healthcare suppliers, energy services, digital providers or municipal service operators. Their role is to prove affordability, usability, reduced analyst effort, reporting value and cross-country replicability.
Eureka network and Eureka Clusters

Eureka Projects under Replika PRO coordination

Replika PRO coordinates and supports international Eureka network projects — from partner search and proposal preparation to reporting. See how we can help your consortium succeed.

Learn more