Evidence, not demos
Four pilots, on live telemetry
From early 2029, all four pilots run continuously for six months on real security events — no synthetic data — after adversarial validation in LIST's operational cyber range: over 1,000 test scenarios, red-team exercises, and consensus under Byzantine conditions. Together they produce the evidence for technology readiness level 7 (TRL 7) by September 2029.
Cross-sector threat intelligence
Lead: Mitigant · cloud-native adversary emulation platform
Telecom, finance, utilities and education infrastructure federate their detection — sectors that today discover shared campaigns in isolation, days apart. Adversary emulation runs continuously against the live federation, testing whether one sector's detection genuinely becomes every sector's defence.
- Proves — privacy-preserving correlation across organisational boundaries
- Infrastructure — cloud-native digital twins, sector-spanning telemetry
- Measured on — detection speed, cross-sector correlation accuracy, response automation

Healthcare under protection
Leads: Digital for Planet · Medisys, with Harokopio University of Athens
A live 250-bed hospital joins the federation — the hardest possible test, where a false positive can affect patient care. Sector-specific digital twins, validated to ≥95% fidelity by Red Alert Labs' ISO/IEC 17025-accredited laboratory, rehearse every automated response before it reaches clinical systems. Patient privacy is never traded for protection.
- Proves — NIS2-grade automation under regulatory scrutiny, safe for patient care
- Infrastructure — operational hospital environment, healthcare digital twins
- Measured on — twin fidelity, false-positive impact, SME deployment cost vs €500K–€2M baseline

Federated SOC collaboration
Lead: Eindhoven University of Technology, with Netcompany and LHC
TU/e's 24/7 security operations centre — processing over one million events a day on Security Onion — coordinates in real time with Netcompany's multi-country operations and Luxembourg's CSIRT. Each SOC keeps its detection methods secret; the federation still correlates, decides and responds together.
- Proves — consensus across sovereign boundaries with operational secrecy intact
- Infrastructure — production SIEM at 1M+ events/day, cross-border SOC links
- Measured on — alert investigation rate (target 85%+ vs ~50% baseline), analyst decision time (target <5 min vs 2+ h), response automation (target 60%)

EU-wide vulnerability intelligence
Lead: Luxembourg House of Cybersecurity · national CSIRT
Luxembourg's national CSIRT — operator of a production MISP platform serving more than 1,000 organisations worldwide — accelerates vulnerability intelligence across European CSIRTs, integrated with the vulnerability.circl.lu CVE database. Cross-border exercises with at least two further Member State CSIRTs put the sub-15-minute coordination target to the test.
- Proves — EU CSIRT network integration and GDPR-compliant cross-border exchange
- Infrastructure — production MISP, CVE feeds, MISP/STIX/TAXII standards compliance
- Measured on — cross-border coordination latency vs 12–24 h baseline, consensus accuracy across 10+ scenarios

The pilot phase is designed to grow.
Operators and CSIRTs beyond the consortium can engage with the federation ahead of the 2028 open-source alpha.