HomeFrameworksNational Cyber & Cloud SchemesCyFun

Framework  National Cyber & Cloud Schemes

CyFun

The CyberFundamentals Framework (CyFun) is the Centre for Cybersecurity Belgium's (CCB) national cybersecurity framework, designed so that Belgian organizations of any size can structure and demonstrate their security, and since NIS2 transposition it is the recognized route for Belgian NIS2 entities to show compliance.

It has a Small starter level plus three assurance levels: Basic, Important, and Essential, which correspond to rising threat exposure and, under Belgian NIS2 law, to whether an entity is important or essential. The controls are drawn from NIST CSF, ISO/IEC 27001 and 27002, IEC 62443, and the CIS Controls, and each level has a self-assessment tool that produces a maturity score.

CyFun 2025 is the current edition, aligned with NIST CSF 2.0 (verify the edition in force on the CCB site).

CyFun has a formal conformity assessment scheme validated by BELAC, the Belgian accreditation body: a Conformity Assessment Body accredited by BELAC and authorized by the CCB verifies the organization's self-assessment and issues a verification (Basic) or certification (Important and Essential).

Essential entities under Belgian NIS2 law must obtain either a CyFun Essential certificate or an ISO/IEC 27001 certificate or accept a CCB inspection.

In writing, an organization needs an information security policy, an asset inventory, a risk assessment, the completed CyFun self-assessment with evidence for each control at the target level, incident response and business continuity plans, supplier management records, and the management approval of the self-assessment.

AI-compiled
Share
Sponsored
CyFun
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CyFun
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary for most Belgian organizations. Under the Belgian NIS2 law, essential and important entities must demonstrate compliance and the CCB recognizes CyFun (at the matching level) or ISO/IEC 27001 as the presumption of conformity; essential entities must be certified or face regular CCB inspections.

Belgian public bodies and supply chain partners of NIS2 entities are increasingly asked for CyFun verification.

What the assessor asks to see

Completed CyFun self-assessment at the target level with supporting evidence per control; information security policy and governance roles; asset inventory; risk assessment; access control and MFA configuration; patching and vulnerability management records; backup and recovery tests; logging and detection; incident response plan and incident register; business continuity plan; supplier and third-party risk records; awareness training records; management approval of the self-assessment.

Levels

Small (starter, no assurance), Basic (verified self-assessment), Important, and Essential (certified). Under the Belgian NIS2 law, important entities map to CyFun Important and essential entities to CyFun Essential.

Assessors

Who assesses CyFun

Conformity Assessment Bodies accredited by BELAC under the CyFun conformity assessment scheme and authorized by the CCB. Verification at Basic level and certification at Important and Essential levels. Accredited by BELAC, the Belgian national accreditation body, with CCB authorization of each body.

Public register of assessors: https://cyfun.eu/en/cabs/cabs-belgium

No firm has claimed a CyFun assessor listing yet. Claim yours →

Consultants

Who helps with CyFun

Belgian IT security consultancies, sector federations (Agoria, Beltug), and managed service providers help organizations complete the self-assessment and prepare evidence; the CCB publishes free toolboxes. Engagements run a few weeks for Basic to several months for Essential.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CyFun consultant listing yet. Claim yours →

Software

Tools for CyFun

Tools that name this framework in their own material.

No firm has claimed a CyFun tool listing yet. Claim yours →

Related reading

  1. CyFun 2025 explained: Belgium's NIS2 frameworkExplains the Basic, Important and Essential levels and how verification or certification produces a presumption of NIS2 conformity.NIS Institute
  2. CyFun framework: cybersecurity and NIS2 complianceBelgian certification body on which assurance level an organisation should target and what the conformity assessment involves.Qfor

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CyFun

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CyFun

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.