Service
Your CyberFundamentals level measured honestly, evidenced properly, and prepared so that verification is a formality rather than a discovery.
CyberFundamentals is the framework the Centre for Cybersecurity Belgium built to give Belgian organisations a proportionate and testable way to show they manage cyber risk. It is the route most Belgian organisations take toward NIS2 conformity, and it is also used well outside NIS2 by organisations that simply want a credible baseline they can explain to a customer.
It uses a proportional assurance model with three assurance levels, Basic, Important and Essential, preceded by an entry level called Small for micro-organisations making a first assessment. Which level applies to you starts from your NIS2 classification rather than from your size, and a documented risk analysis can move it from there. This is worth stating plainly because the names cause constant confusion: the CyFun levels Important and Essential are not the same thing as the NIS2 entity categories that carry those names, even though the royal decree links the two.
The 2025 edition is the current one. CyFun 2023 and CyFun 2025 coexist until 18 April 2027, and until then the edition you apply is your choice, which leaves organisations already mid-track with a decision worth making deliberately rather than by default.
Three failure modes account for most of the wasted money. The first is choosing a level that is too high, usually phrased as taking the safe option. A level you do not need multiplies the measures you must implement, evidence and maintain, permanently.
The second is scoring the self-assessment the way you would like it to read. That feels efficient right up to the point where an assessment body looks at the same measures, and then the gap arrives all at once, with a deadline attached.
The third is treating the score as the deliverable. The score is a summary of your evidence. If the evidence was never assembled, the score describes nothing and will not survive contact with a verification.
Belgian organisations taking the CyFun route toward NIS2, and organisations outside NIS2 that want a recognised baseline they can put in front of a customer. It works best when you want to know where you actually stand, including the parts that are inconvenient.
I will not score you higher than your evidence supports. Neither will the assessment body, and they will do it later, at greater cost, in front of an audience. If you need an assessment that produces a particular number, we are not a good fit.
It starts from your NIS2 classification rather than from your size. Under the royal decree of 9 June 2024 an essential entity is expected at Essential, and an important entity that opts into a conformity assessment at Important or higher. From there a documented risk analysis can justify a lower level, and the CCB publishes a risk assessment tool for exactly that decision. The justification stays your responsibility, so it is worth having the conversation before anyone starts implementing measures.
It depends on why you are doing this. Essential entities are proactively supervised and are subject to a regular conformity assessment, with three routes open to them: CyFun verification or certification by a conformity assessment body accredited by BELAC and authorised by the CCB, an ISO 27001 certification with the right scope and Statement of Applicability, or direct inspection by the CCB on the basis of a self-assessment. On the CyFun route the milestones are a Basic or Important verification by 18 April 2026 and, at the Essential level, certification by 18 April 2027. Important entities are not subject to a mandatory conformity assessment at all; where they take the CyFun route voluntarily, their self-assessment is verified by an assessment body. Outside NIS2, verification is primarily a commercial argument, and a good one when your customers keep asking.
A large part of it, yes. The CCB publishes mappings between CyberFundamentals and other frameworks, ISO 27001 among them. Treat those mappings as a guide to where evidence is reusable rather than as a calculation of conformity: they tell you where to look, not whether you comply.
Both remain usable until 18 April 2027, and until then the choice is yours. If you are starting now, start on 2025 rather than adopting a framework you will have to migrate off. If you are already well into a 2023 track with a verification in sight, finishing it is usually the cheaper path.
No, and nobody who prepares you should. Verification and certification are issued by conformity assessment bodies accredited by BELAC and authorised by the CCB. My role is to get you into a position where that step is uneventful.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call