What Is CodeSupply and Why Does It Matter?
Software supply chain security depends on accurate package data. That data is often scattered across multiple sources. It can be inconsistent or hard to access. A new EU-funded initiative called CodeSupply aims to fix that. CodeSupply is making €400,000 in open source grants available for research and development projects. These projects focus on software supply chain security, metadata, and related areas.
CodeSupply is coordinated by the NLnet Foundation, a Dutch public benefit organization. It is part of the European Commission’s Open Internet Stack initiative. That initiative supports open and reusable digital infrastructure. The funding comes from the European Commission’s Directorate-General for Communications Networks, Content and Technology through Horizon Europe.
Grant Details: How Much and What for?
Projects can request between €5,000 and €50,000. Proposals are due Nov. 3. The total pool of open source grants is €400,000. Eligible activities include:
- Scientific research
- Software engineering
- Security audits
- Formal security proofs
- Technical validation
- Documentation and standardization
- Open source hardware development
- Usability improvements
- Participation in technical events
- Project management and essential infrastructure costs
The call covers new and existing technologies. Projects must demonstrate real-world impact. Work focused on open source license compliance also qualifies. That includes tools for identifying, documenting, or managing licensing requirements.
Software Metadata: A Core Objective
CodeSupply lists publishing current, correct, and comprehensive software metadata as one of its three main objectives. Better metadata helps teams understand software components, dependencies, licensing, and security information. The call does not prescribe a specific type of metadata project. Relevant work could include research, software development, or mechanisms for making essential datasets more accessible across the open source ecosystem.
This focus on metadata is critical. Many open source compliance tools and security scanners rely on metadata that is incomplete or outdated. Improving that data quality benefits the entire supply chain.
Who Can Apply and How?
Proposals must meet several requirements:
| Requirement | Details |
|---|---|
| Language | Written in English |
| Alignment | Must align with CodeSupply’s goals |
| Primary objective | Research and development |
| Geographic scope | Clear European dimension |
After initial screening, projects are evaluated on technical feasibility, relevance, potential impact, and value for money. Applicants should define the problem, describe the technical work, and explain expected impact.
The initiative is a collaboration among four organizations: NLnet Foundation (coordinator), AboutCode (Belgian nonprofit focused on software origin and supply chain security), Edsger Institute (Dutch nonprofit specializing in reproducible hosting stacks), and Universidad Rey Juan Carlos (public research university in Spain).
Why This Matters for Remote Tech Workers and EU Developers
For developers and researchers across Europe, these open source grants Europe 2026 represent a concrete funding opportunity. The grants are small enough for individual contributors or small teams. They are large enough to fund meaningful work. Remote R&D jobs in the open source space often rely on grant funding like this. CodeSupply’s focus on supply chain security aligns with growing demand for remote software supply chain security jobs.
The European Commission’s investment signals continued support for open source infrastructure. If you work on software composition analysis, dependency management, or license compliance tools, this call is worth your attention.
How to Prepare Your Proposal
Start early when applying for open source grants. The Nov. 3 deadline is firm. Focus your proposal on CodeSupply’s three objectives: software supply chain security, software metadata, and open internet reliability. Show a clear link between your work and open source development. Be specific about the problem and your technical solution. Demonstrate European relevance — this can include team location, target users, or compliance with EU regulations.
Consider partnering with one of the participating organizations if your project aligns with their expertise. NLnet Foundation has a strong track record with NGI Zero grants. AboutCode brings deep knowledge of package origin and licensing. The Edsger Institute understands reproducible builds. Universidad Rey Juan Carlos offers academic rigor.
When preparing your proposal, keep in mind that these open source grants range from €5,000 to €50,000, so tailor the scope of your work accordingly. Eligible activities include software development, security audits, formal proofs, and documentation — choose the format that best demonstrates your solution. Since CodeSupply is part of the European Commission’s Open Internet Stack initiative, emphasizing how your project supports open and reusable digital infrastructure can strengthen your case. Be precise about the problem you're solving and how your technical approach aligns with CodeSupply's objectives, such as improving software metadata accuracy or supply chain security.
Conclusion
CodeSupply’s €400,000 in open source grants is a timely opportunity for anyone working on software supply chain security, metadata, or compliance. The application process is straightforward. The funding range is accessible. The deadline is Nov. 3. If you have a project that improves how open source packages are tracked, secured, or documented, this EU-funded initiative deserves a close look.
These open source grants are part of a larger push by the European Commission to strengthen digital infrastructure. CodeSupply, coordinated by the NLnet Foundation, is one of several initiatives under the Open Internet Stack umbrella. That means successful projects could feed into broader EU efforts to make software supply chains more transparent and secure. For developers and researchers, this is a chance to get funded for work that aligns with policy-level goals, not just technical fixes.
