Cybersecurity Academic Startup Accelerator Programme Y10 Phase One (2026) - Historical Reference
Historical reference for the closed Cyber Security Academic Startup Accelerator Programme Y10 Phase 1 competition, delivered by Innovate UK with DSIT for UK academic institutions commercialising cyber security research.
The Cyber Security Academic Startup Accelerator Programme (CyberASAP) Y10 Phase 1 competition is closed. The official UKRI opportunity page records Innovate UK as the funder, the Department for Science, Innovation and Technology (DSIT) as co-funder, and a closing time of 11 February 2026 at 11:00am UK time. The linked Innovation Funding Service record also says that the competition is now closed. No later CyberASAP application cycle is announced on the official opportunity record, so this page is a historical reference rather than an active application listing.
Key details
| Detail | Official Y10 Phase 1 information |
|---|---|
| Programme | Cyber Security Academic Startup Accelerator Programme (CyberASAP), Y10 Phase 1 |
| Status | Closed |
| Funder | Innovate UK, part of UK Research and Innovation |
| Co-funder | Department for Science, Innovation and Technology |
| Funding type | Grant |
| Competition-wide maximum | Up to £800,000, subject to receiving enough high-quality applications |
| Project-level limit | Total eligible costs between £5,000 and £32,000 across both phases; no more than £16,000 in each phase |
| Opening date | 19 January 2026 at 9:30am UK time on the UKRI listing |
| Closing date | 11 February 2026 at 11:00am UK time |
| Intended project start | 1 April 2026 |
| Required end date | By 31 July 2026 |
| Eligible lead | A UK registered academic institution with a cyber security idea and an interest in commercialisation |
| Application route | Innovation Funding Service |
| Archive status | Historical reference; no next cycle announced on the official record |
The amount needs careful reading. The £800,000 figure was the maximum budget for the competition as a whole, not a guaranteed award to every applicant or a standard award for one project. The Innovation Funding Service guidance limited total eligible costs for an application to £32,000 across both phases. It also limited each phase to £16,000. The grant could fund 100% of eligible project costs, but an application still had to stay within those limits and use only eligible costs.
What Y10 Phase 1 was designed to do
CyberASAP Y10 Phase 1 was intended to identify promising commercial opportunities arising from the UK academic research base in cyber security. The official brief required a proposal to explain the area of research, the problem being solved, the proposed solution, and an initial market-validation plan. The purpose was therefore commercialisation of an academic cyber security idea, not an open-ended research project and not a general business grant.
The programme was described as a 10-month programme overall, with Y10 Phase 1 forming the first part of a potential two-phase competition. Phase 1 itself could last up to four months and was divided into two equal stages. The first stage focused on value-proposition development. The second focused on market-validation activity. Teams that demonstrated the strongest potential during the first stage could be invited to continue to the market-validation stage and present to an independent judging panel. The programme’s support included industry experts, including cyber security specialists.
The brief encouraged proposals related to three challenge areas:
- Security and resilience of operational technology.
- Software supply-chain security and resilience, including compliance with the Software Code of Practice and the security of cloud services.
- Emerging opportunities and technologies, including artificial intelligence in cyber security for access management, change management, threat detection and reporting, as well as drones and robotics.
The list was not exhaustive. The official guidance also welcomed other cyber security challenges, including online harms. A suitable proposal still needed to show a clear cyber security connection and a credible commercial opportunity. A generic software idea, a project unrelated to cyber security, or a proposal centred on academic research without a commercialisation route would not match the stated scope.
Eligibility and applicant structure
The competition was open to single applicants and collaborations. To apply alone or lead a collaborative project, the organisation had to be based in a UK registered academic institution. The lead also had to have a cyber security idea, be interested in commercialising it, have support from its technology transfer office or equivalent, and not act to gain a selective commercial or economic advantage from the project outputs.
Individuals based in UK academic institutions could participate, including early-career and senior academic researchers. For a funded collaboration, each partner organisation had to be a UK registered academic institution, interested in commercialisation, and supported by its technology transfer office or equivalent. The lead invited partners into the Innovation Funding Service. After accepting an invitation, each partner entered its own project costs and other required information.
The official guidance required a collaborative application to include at least the lead and one other organisation applying for funding, explain why the collaboration was needed, and describe how it would work. Non-funded partners could also take part. Those partners could be based in the UK, the European Union, or elsewhere, and could carry out project work from their home countries and exploit results outside the UK. Their costs still counted toward total eligible project costs if they were included in the Innovation Funding Service application. Subcontractors were not allowed.
There were also important exclusions. The competition would not fund work unrelated to cyber security, work led by an academic institution outside the UK, or a project whose academic lead had already led and completed a previous CyberASAP project. The brief also excluded arrangements classed as state aid or a subsidy that gave an undertaking a selective economic or commercial advantage. These conditions were part of the competition’s no-subsidy design and required applicants to assess their own position carefully.
Funding and eligible costs
The competition offered grant funding from a maximum pool of £800,000, subject to the quality and number of applications received. The official guidance did not promise that every high-scoring project would be funded. Innovate UK reserved the right to adjust allocations in exceptional circumstances, including changes in policy, portfolio funding considerations, or broader government funding decisions.
Each application had to budget between £2,500 and £16,000 for each phase. Across both phases, the total eligible cost had to be between £5,000 and £32,000. The award could cover 100% of eligible project costs, subject to the competition limits and the no-subsidy assessment.
The eligible cost categories were narrow. They included salaries of academics participating in the programme, together with travel and subsistence for the specified CyberASAP Y10 Phase 1 events. The guidance did not provide funding at this stage for project research, consumables, technology transfer officer costs, marketing, hardware or software, equipment, overheads, or estate costs. The list was expressly non-exhaustive, so applicants needed to follow the full competition guidance rather than assume that ordinary research-grant costs would qualify.
The project had to carry out its work in the UK and intend to exploit its results from or in the UK. It had to start on 1 April 2026 and end by 31 July 2026. Work could not begin before Innovate UK issued a Grant Offer Letter. A project leader progressing through both parts of Phase 1 had to be dedicated to the project for the two-month value-proposition activity and the additional two months of market validation. The guidance defined that commitment as being able and permitted to work on the project for at least two days per week, as well as attending the required programme events.
The published programme timetable
The official Innovation Funding Service timetable gave 19 January 2026 as the competition opening date and 11 February 2026 at 11:00am as the closing date. Applicants were due to be notified on 25 February 2026 at 9:41am, followed by a successful-applicant briefing for project setup on 3 March 2026. Projects were scheduled to start from 1 April 2026.
The planned value-proposition activities were also published. The in-person value-proposition bootcamp was scheduled for 15 and 16 April 2026. A webinar for technology transfer officers or equivalent was scheduled for 17 April 2026 from 11:30am to 12:30pm. The online mid-stage review was scheduled for 6 and 7 May 2026, followed by online pitches to the selection panel on 28 and 29 May 2026.
Teams selected for the market-validation stage were expected to attend further activities. Attendance at InfoSec at ExCel London from 2 to 4 June 2026 was optional. The in-person market-validation bootcamp was scheduled for 9 and 10 June 2026, followed by an in-person meet-the-mentor day on 11 June 2026. The online market-validation mid-stage review was scheduled for 30 June 2026, with an online meet-the-entrepreneur day on 1 July 2026. The final online market-validation pitch to the selection panel was scheduled across 22 and 23 July 2026. The guidance noted that teams had to pitch in an assigned slot on the relevant pitch days.
These dates describe the closed Y10 programme. They are not a current application timetable. The deadline field above retains the official closing date so the archived opportunity remains factually identifiable, while historicalReference = true prevents it from being presented as an expired live listing that applicants can still pursue.
What the application required
Applications were submitted through the Innovation Funding Service. The official process was divided into three sections: project details, application questions, and finances. The lead applicant was responsible for making sure the information was correct, the proposal met eligibility and scope requirements, all sections were complete, and any collaborators had completed their assigned sections and accepted the terms and conditions. A submitted application could be reopened and resubmitted until the closing time, but it had to be resubmitted before the deadline.
The project-details section asked for the project title, start date, duration, research category, project summary, and public description. The project summary could be no more than 50 words. The public description could be no more than 400 words and needed to be suitable for publication without commercially sensitive information. Applicants also had to explain how the proposal fitted the competition scope, with a scope answer of no more than 200 words. The application answers could not include website addresses or links.
The application questions covered several areas. Applicants had to provide location information, answer questions about animal testing, permits and licences, export controls, and trusted research and innovation, and select the cyber security challenge area. They had to explain the costs for the four-month programme, how costs were split between the value-proposition and market-validation stages, and whether anyone on the team had prior CyberASAP involvement.
The scored questions focused on the team and resources, the need or challenge, the approach and innovation, commercialisation, and market validation. The team answer needed to identify the project leader, relevant skills and experience, required resources and facilities, the technology-transfer or commercialisation contact supporting the application, other relevant people, partner relationships, and any roles still needing recruitment. The need or challenge answer had to explain the business need, technological challenge, or market opportunity; similar innovations and their limitations; work already completed; and wider factors influencing the opportunity.
The approach and innovation answer had to explain how the proposed work responded to the identified need and improved on comparable approaches. The commercialisation answer had to describe the route to market, the institution’s approach to intellectual property and commercialisation, and confirm technology-transfer office support, including participation in the commercialisation webinar. The market-validation answer had to set objectives, milestones, and measures of success; explain how the team would test whether the market liked the idea; describe evidence of willingness to buy; identify organisations to approach; and explain how the team would reach the right contacts.
The finance section required each organisation in the project to complete its own project costs, organisation details, and funding information. Costs had to follow the specific eligibility rules. A credible application would therefore connect its proposed commercialisation and validation work to academic staff time and the allowed travel and subsistence, rather than quietly including research equipment, marketing, or institutional overheads.
What applicants should take from the archived call
The central lesson from Y10 Phase 1 is that CyberASAP was aimed at turning a defined academic cyber security idea into a commercial proposition. A future call, if announced, may change its dates, budget, cost rules, challenge themes, or application questions. None of those details should be copied forward without a new official competition record.
For a future applicant, the useful preparation is to keep the research idea, user problem, proposed solution, evidence of market need, and institutional commercialisation support clearly connected. The official Y10 structure placed particular weight on value-proposition development and market validation. That means a strong future proposal would need to explain who experiences the problem, why existing approaches are insufficient, what the academic work contributes, and how the team will test commercial interest within the programme period.
It would also be important to establish the university’s position on intellectual property and the project leader’s availability before applying. The Y10 rules required technology-transfer office or equivalent support and a meaningful time commitment from the project leader. A collaboration needed a clear rationale, not merely a list of participating institutions. A future application should also confirm whether the new call permits companies, non-funded partners, or other structures, because the Y10 rules were specific and should not be assumed to carry over.
Application status and official source
There is no current application route for this Y10 Phase 1 record. The official UKRI page and the linked Innovation Funding Service record both identify the competition as closed. The official record does not announce a next CyberASAP cycle, so readers should not infer a new deadline from the historical schedule above. Anyone seeking a later round should check the Innovate UK and UKRI opportunity services for a newly published competition and rely on that record’s own eligibility, budget, dates, and application instructions.
Official source: UKRI funding opportunity: Cybersecurity academic startup accelerator programme Y10 phase one
