Guide ·

EPSO AD8 in cybersecurity: EPSO/AD/430/26

A hardware security key plugged into a closed laptop in a dim room, with monitors showing network maps in the background.
Image generated with AI

In short

The cybersecurity field of EPSO/AD/430/26 offers 254 places for AD8 administrators in the EU institutions. Applications close on 13 October 2026 at 12:00 Brussels time, and you cannot also apply for the artificial intelligence field of the same notice. The tests are remote: verbal, numerical and abstract reasoning, a 30-question cybersecurity test and a 40-minute essay on EU matters. Only the cybersecurity test ranks candidates; the others only have to be passed.

Key facts

Notice
EPSO/AD/430/26, field 2, Official Journal C/2026/4668, 8 September 2026
Grade
AD8, administrators
Places
254 in cybersecurity (the AI field has 240 more)
Applications
Until 13 October 2026, 12:00 Brussels time, with a copy of your ID or passport
Supporting documents
By 14 January 2027, 12:00 Brussels time
Languages
Language 1 at C1 for reasoning; language 2 at B2 for the field test and the essay
Tests
Reasoning · cybersecurity field test, 30 questions in 40 min · essay (EUFTE), 40 min
What ranks you
The cybersecurity field test only, with a pass mark of 15/30

What is the cybersecurity field of EPSO/AD/430/26?

EPSO/AD/430/26, published on 8 September 2026 (Official Journal C/2026/4668), builds reserve lists of AD8 administrators in two fields. Field 2 is cybersecurity, with 254 places, the larger of the two; field 1 is artificial intelligence, with 240 and its own guide. You apply for one field only.

It is aimed at experienced professionals: AD8 is above the usual entry grades, and every route to eligibility asks for at least five years of relevant experience. The notice describes a broad, technical profile: five categories of duties that run from risk management and architecture to the security operations centre, governance and advice, and every one of them "requires technical expertise".

Who is eligible for the cybersecurity field?

Besides EU citizenship and two EU languages (one at C1, another at B2), you need one of four combinations of studies and experience. The experience counts from the date of your diploma and has to match the cybersecurity duties in Annex II of the notice.

StudiesRelevant experience
3 years, in an accepted area7 years
4 years, in an accepted area6 years
5 years, in an accepted area5 years
3 years, in any other area9 years

A master's or a PhD in an accepted area satisfies the four- and five-year options whatever your first degree was. The accepted areas come in three groups:

  • Accepted as they are: cybersecurity, information security or information assurance; security engineering; digital forensics and incident response; cryptography and key management.
  • Accepted with a focus on ICT security: systems architecture, software, computer or electrical engineering, information systems, automation and control, embedded systems, human-computer interaction, networks, telecommunications, operational technology, IoT and cyber-physical systems, ICT governance and management, IT audit, risk management, business informatics and project management.
  • Accepted with a focus on security, cryptography, risk analysis or security analytics: data science or data engineering, AI or machine learning applications, applied mathematics or statistics.

The focus is proven with a recognised specialisation on the diploma or transcript, at least 30 ECTS (one semester full time), a thesis, a peer-reviewed article or conference paper on cybersecurity, or a main contribution to a national or European research project, the last two made during your studies.

What are the tests?

All tests are remote and supervised, on the dates in your invitation, and not necessarily in this order.

TestLanguageQuestions and timePass markRole
Verbal reasoningLanguage 120 in 35 min10/20Pass or fail
Numerical reasoningLanguage 110 in 20 min10/20 combined with abstractPass or fail
Abstract reasoningLanguage 110 in 10 min10/20 combined with numericalPass or fail
Cybersecurity field testLanguage 230 in 40 min15/30Ranks candidates
EUFTE essayLanguage 2One assignment, 40 min5/10Pass or fail

The reasoning tests have the same format and pass marks as in EPSO's other 2026 competitions. For the platform and the rules of remote testing, see the guide to TAO.

How is the reserve list decided?

In a strict order, set out in the notice:

  1. The reasoning tests are marked first. Fail them and nothing else is marked.
  2. The cybersecurity field test is marked for those who passed reasoning. Everyone with at least 15/30 is ranked by that score.
  3. From the top of that ranking, a limited number of candidates, in principle no more than 1.5 times the places, have their essay marked and their eligibility checked. In cybersecurity that is about 381 candidates, plus any ties at the cut-off.
  4. Those who pass the essay and are eligible go onto the reserve list, in ranking order, until the 254 places are filled.

So the field test is the only score that counts. There is no interview and no assessment centre before the list, and results are only sent at the end of the competition, whatever stage you reached.

What does the cybersecurity field test cover?

The notice publishes no syllabus: the test is "specific to the field". The closest thing is Annex II, which sets out five categories of duties. It is also what your experience is measured against.

  1. Risk management and security assurance. Risk management frameworks, from identification to monitoring; capability and maturity models; security assessments, vulnerability management, penetration testing and access reviews; metrics and reporting on controls.
  2. Architecture, design and technology. Security architecture across the life of IT systems, cloud and hybrid included; security products and controls such as network security devices, SIEM, XDR, cloud detection and response, IAM and PAM, tailored to risk; secure development, code review, cryptography and key management, DevSecOps; and the use of AI, machine learning and quantum computing in security.
  3. Security operations and incident response. Monitoring, detection and threat hunting; digital forensics and incident response, from network and system forensics to log analysis; improving a security operations centre (engineering, threat intelligence automation, red teaming, detection engineering); and incident response capability (CSIRC) services.
  4. Governance, policy and coordination. Project, programme and portfolio management; leading teams; a rolling multiannual security strategy; policies, standards and procedures; compliance, audits and attestations; representing the institution in interinstitutional and expert groups; continual improvement.
  5. Awareness, skills and advice. Awareness campaigns and training; expert advice on identity and access management, electronic signatures and trust services.

The breadth is the point: someone who comes from a SOC has to cover governance and strategy, and someone who comes from governance has to cover detection and forensics. The notice names no legislation, but the duties are carried out under EU rules worth having at hand: Regulation (EU, Euratom) 2023/2841 on cybersecurity in the Union institutions, bodies, offices and agencies; the NIS2 Directive (EU) 2022/2555; the Cybersecurity Act, Regulation (EU) 2019/881; the Cyber Resilience Act, Regulation (EU) 2024/2847; and eIDAS, Regulation (EU) No 910/2014, for electronic signatures and trust services.

How to prepare

  1. Check your eligibility now. Count your years of experience from the date of your diploma. If your degree is in the second or third group, gather the proof of your security focus: transcript, ECTS, thesis or publication. Documents are due by 14 January 2027, but a gap found then cannot be fixed.
  2. Do not underestimate reasoning. It only has to be passed, but it comes first, and an experienced professional who has not sat a psychometric test in years can fail it with a CV that would top the ranking. Practise the real format: 40 questions in 65 minutes across three timed tests.
  3. Put most of your time into the field test. It is the only score that ranks you: 30 questions in 40 minutes, about 80 seconds each, in your second language. Go through the five categories of Annex II and start with the one furthest from your own job.
  4. Learn the vocabulary in your second language. Risk treatment, threat hunting or key management will come to you in that language, not in the one you work in.
  5. Read the essay documentation as soon as EPSO publishes it. The EUFTE is based on EU documentation that EPSO puts on its website before the test, and it is marked on written communication, not on facts or language.
  6. Apply before the last day. The deadline is 13 October 2026 at 12:00 Brussels time, and the ID copy must be uploaded by then too.
Was this guide useful?

Frequently asked questions

How many cybersecurity places are there in EPSO/AD/430/26?
254, at grade AD8. The same notice has 240 places in artificial intelligence, but each candidate can apply for only one of the two fields.
Do I need a degree in cybersecurity?
No. Engineering, networks, information systems, IT audit, risk management, data science and other areas are accepted if your studies had a proven security focus. With a degree in any area you need nine years of relevant experience instead of five to seven.
What is the deadline?
13 October 2026 at 12:00 Brussels time, including the copy of your ID or passport. The other supporting documents are due by 14 January 2027 at 12:00.
Does my reasoning score count in the ranking?
No. The reasoning tests and the essay are pass or fail. Candidates are ranked only by the cybersecurity field test, among those who scored at least 15/30.
In which language are the tests?
Reasoning in your language 1, at C1 level. The field test and the essay in your language 2, a different EU language at B2 level or above.
Is there an interview?
No. The notice has no interview or assessment centre: the reserve list comes from the field test ranking, once the essay is passed and eligibility is confirmed.

Sources

  1. Notice of open competition EPSO/AD/430/26 – Administrators (AD 8): artificial intelligence; cybersecurity · Official Journal of the EU, C/2026/4668 · September 8, 2026
  2. Specialists (Administrators – AD6 to AD9): tests · EPSO
  3. Regulation (EU, Euratom) 2023/2841 on a high common level of cybersecurity at the Union institutions, bodies, offices and agencies · Official Journal of the EU
  4. Directive (EU) 2022/2555 (NIS2 Directive) · Official Journal of the EU
  5. Regulation (EU) 2019/881 (Cybersecurity Act) · Official Journal of the EU
  6. Regulation (EU) 2024/2847 (Cyber Resilience Act) · Official Journal of the EU
  7. Regulation (EU) No 910/2014 (eIDAS) · Official Journal of the EU