Framework National Cyber & Cloud Schemes
CyFun
The CyberFundamentals Framework (CyFun) is the Centre for Cybersecurity Belgium's (CCB) national cybersecurity framework, designed so that Belgian organizations of any size can structure and demonstrate their security, and since NIS2 transposition it is the recognized route for Belgian NIS2 entities to show compliance.
It has a Small starter level plus three assurance levels: Basic, Important, and Essential, which correspond to rising threat exposure and, under Belgian NIS2 law, to whether an entity is important or essential. The controls are drawn from NIST CSF, ISO/IEC 27001 and 27002, IEC 62443, and the CIS Controls, and each level has a self-assessment tool that produces a maturity score.
CyFun 2025 is the current edition, aligned with NIST CSF 2.0 (verify the edition in force on the CCB site).
CyFun has a formal conformity assessment scheme validated by BELAC, the Belgian accreditation body: a Conformity Assessment Body accredited by BELAC and authorized by the CCB verifies the organization's self-assessment and issues a verification (Basic) or certification (Important and Essential).
Essential entities under Belgian NIS2 law must obtain either a CyFun Essential certificate or an ISO/IEC 27001 certificate or accept a CCB inspection.
In writing, an organization needs an information security policy, an asset inventory, a risk assessment, the completed CyFun self-assessment with evidence for each control at the target level, incident response and business continuity plans, supplier management records, and the management approval of the self-assessment.
help
Who has to comply
Voluntary for most Belgian organizations. Under the Belgian NIS2 law, essential and important entities must demonstrate compliance and the CCB recognizes CyFun (at the matching level) or ISO/IEC 27001 as the presumption of conformity; essential entities must be certified or face regular CCB inspections.
Belgian public bodies and supply chain partners of NIS2 entities are increasingly asked for CyFun verification.
What the assessor asks to see
Completed CyFun self-assessment at the target level with supporting evidence per control; information security policy and governance roles; asset inventory; risk assessment; access control and MFA configuration; patching and vulnerability management records; backup and recovery tests; logging and detection; incident response plan and incident register; business continuity plan; supplier and third-party risk records; awareness training records; management approval of the self-assessment.
Levels
Small (starter, no assurance), Basic (verified self-assessment), Important, and Essential (certified). Under the Belgian NIS2 law, important entities map to CyFun Important and essential entities to CyFun Essential.
Assessors
Who assesses CyFun
Conformity Assessment Bodies accredited by BELAC under the CyFun conformity assessment scheme and authorized by the CCB. Verification at Basic level and certification at Important and Essential levels. Accredited by BELAC, the Belgian national accreditation body, with CCB authorization of each body.
Public register of assessors: https://cyfun.eu/en/cabs/cabs-belgium
No firm has claimed a CyFun assessor listing yet. Claim yours →
Consultants
Who helps with CyFun
Belgian IT security consultancies, sector federations (Agoria, Beltug), and managed service providers help organizations complete the self-assessment and prepare evidence; the CCB publishes free toolboxes. Engagements run a few weeks for Basic to several months for Essential.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CyFun consultant listing yet. Claim yours →
Software
Tools for CyFun
Tools that name this framework in their own material.
No firm has claimed a CyFun tool listing yet. Claim yours →
Related reading
- CyFun 2025 explained: Belgium's NIS2 frameworkExplains the Basic, Important and Essential levels and how verification or certification produces a presumption of NIS2 conformity.NIS Institute
- CyFun framework: cybersecurity and NIS2 complianceBelgian certification body on which assurance level an organisation should target and what the conformity assessment involves.Qfor
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CyFun
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CyFun
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.