CyFun assessment

Your CyberFundamentals level measured honestly, evidenced properly, and prepared so that verification is a formality rather than a discovery.

← Back to home

What CyFun actually is

CyberFundamentals is the framework the Centre for Cybersecurity Belgium built to give Belgian organisations a proportionate and testable way to show they manage cyber risk. It is the route most Belgian organisations take toward NIS2 conformity, and it is also used well outside NIS2 by organisations that simply want a credible baseline they can explain to a customer.

It uses a proportional assurance model with three assurance levels, Basic, Important and Essential, preceded by an entry level called Small for micro-organisations making a first assessment. Which level applies to you starts from your NIS2 classification rather than from your size, and a documented risk analysis can move it from there. This is worth stating plainly because the names cause constant confusion: the CyFun levels Important and Essential are not the same thing as the NIS2 entity categories that carry those names, even though the royal decree links the two.

The 2025 edition is the current one. CyFun 2023 and CyFun 2025 coexist until 18 April 2027, and until then the edition you apply is your choice, which leaves organisations already mid-track with a decision worth making deliberately rather than by default.

Where CyFun assessments go wrong

Three failure modes account for most of the wasted money. The first is choosing a level that is too high, usually phrased as taking the safe option. A level you do not need multiplies the measures you must implement, evidence and maintain, permanently.

The second is scoring the self-assessment the way you would like it to read. That feels efficient right up to the point where an assessment body looks at the same measures, and then the gap arrives all at once, with a deadline attached.

The third is treating the score as the deliverable. The score is a summary of your evidence. If the evidence was never assembled, the score describes nothing and will not survive contact with a verification.

How I run a CyFun assessment

  1. Establish the applicable level We determine which assurance level applies, and I will argue with you if the answer looks inflated. Choosing one level higher than you need is one of the most expensive decisions available in this framework, and it is usually made in the first meeting.
  2. Assess against the framework A measure-by-measure assessment with the evidence recorded next to each score. Where something is partially in place, it is scored as partially in place. An honest baseline is the only kind you can build a plan on.
  3. Gaps, priorities and real risk A remediation plan ordered by what genuinely reduces your risk, cross-referenced with what moves your score. Those two orderings are not identical, and where they diverge I will tell you which is which so the choice stays yours.
  4. Evidence prepared for verification Your evidence assembled and organised the way an assessment body will ask for it, so that verification confirms what you already know rather than discovering it.
  5. Reuse toward ISO 27001 If certification is on your horizon, the assessment is structured so the work carries over. The CCB publishes mappings between CyberFundamentals and other frameworks, including ISO 27001, which show where evidence is reusable.

What you get

Who this is for

Belgian organisations taking the CyFun route toward NIS2, and organisations outside NIS2 that want a recognised baseline they can put in front of a customer. It works best when you want to know where you actually stand, including the parts that are inconvenient.

I will not score you higher than your evidence supports. Neither will the assessment body, and they will do it later, at greater cost, in front of an audience. If you need an assessment that produces a particular number, we are not a good fit.

Questions I get

Which level do we need?

It starts from your NIS2 classification rather than from your size. Under the royal decree of 9 June 2024 an essential entity is expected at Essential, and an important entity that opts into a conformity assessment at Important or higher. From there a documented risk analysis can justify a lower level, and the CCB publishes a risk assessment tool for exactly that decision. The justification stays your responsibility, so it is worth having the conversation before anyone starts implementing measures.

Is a self-assessment enough, or do we need verification?

It depends on why you are doing this. Essential entities are proactively supervised and are subject to a regular conformity assessment, with three routes open to them: CyFun verification or certification by a conformity assessment body accredited by BELAC and authorised by the CCB, an ISO 27001 certification with the right scope and Statement of Applicability, or direct inspection by the CCB on the basis of a self-assessment. On the CyFun route the milestones are a Basic or Important verification by 18 April 2026 and, at the Essential level, certification by 18 April 2027. Important entities are not subject to a mandatory conformity assessment at all; where they take the CyFun route voluntarily, their self-assessment is verified by an assessment body. Outside NIS2, verification is primarily a commercial argument, and a good one when your customers keep asking.

Can we reuse CyFun work for ISO 27001 later?

A large part of it, yes. The CCB publishes mappings between CyberFundamentals and other frameworks, ISO 27001 among them. Treat those mappings as a guide to where evidence is reusable rather than as a calculation of conformity: they tell you where to look, not whether you comply.

Should we use the 2023 or the 2025 edition?

Both remain usable until 18 April 2027, and until then the choice is yours. If you are starting now, start on 2025 rather than adopting a framework you will have to migrate off. If you are already well into a 2023 track with a verification in sight, finishing it is usually the cheaper path.

Do you issue the certificate?

No, and nobody who prepares you should. Verification and certification are issued by conformity assessment bodies accredited by BELAC and authorised by the CCB. My role is to get you into a position where that step is uneventful.

How CyFun fits into your NIS2 obligations

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call