+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Français
  • België
  • Dutch
  • English
  • Français
  • België
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Talk to an expert
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • The ultimate checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • The certification process step by step
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities within the management system
  • What should you know about certificate suspension or revocation?
  • Transfer of certification

General

10
  • Whitepaper management system audits
  • Quality Management: best practices for success
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

Audits information security

2
  • Excelling in information security: best practices
  • Operational Capabilities: The Backbone of Information Security

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

3
  • Self-assessment & CyFun verification: best chance of success
  • NIS2 liability for board members
  • NIS2 & the Belgian CyberFundamentals

Assurance audits

1
  • ISAE 3402 vs SOC 2: what is the difference?

Audits privacy

8
  • Checklist for your BC 5701 certification
  • Transition to ISO/IEC 27701:2025
  • Whitepaper GDPR Certification Standard and Criteria BC 5701
  • BC 5701 certification: where do you start?
  • Data breach: What is it and how do you prevent it?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
View Categories

Self-assessment & CyFun verification: best chance of success

3 min. leestijd

This article explains what your organization can expect during a CyFun verification. Which preparations are necessary to ensure the verification process runs smoothly? Careful preparation contributes to an efficient verification. It helps prevent delays or duplication of work.

We like to share key lessons learned from previous engagements to help you prepare effectively. Let’s make sure the process runs as smoothly as possible!

CyFun Preparation Sessions

Brand Compliance organizes online CyFun preparation sessions for its clients. During these sessions the CyFun verification process is explained. There is ample opportunity to discuss key points of attention and to ask practical questions. Participation is voluntary and free of charge. After concluding an agreement, you will receive an invitation to attend one of these sessions.

CyFun self-assessment: Minimum Maturity Level

For CyFun Basic, the overall maturity level must be at least 2.5. For CyFun Important, this must be at least 3. These minimum maturity levels also apply individually to all key measures.

Substantiation of self-assessment Maturity Scores

CyFun verificationEnsure that the ‘Details’ tab is fully completed at the measure level. The explanation of the chosen maturity levels must be clear and specific, with explicit references to the objective evidence supporting this justification.

The explanation for each measure must be self-contained and comprehensible to an external verifier. This prevents the need for additional time during the audit. It contributes to an efficient audit process.

Describe the explanation for each measure explicitly from two perspectives: documentation and implementation. This structured approach makes the justification more concrete and easier for an external auditor to verify. This helps to minimize the risk of the audit being delayed or extended.

Objective evidence during the verification

At the start of the on-site CyFun verification, your organization must ensure that all objective evidence included in the self-assessment is immediately available. The verifier will not search for evidence independently.

It is not intended that the objective evidence be submitted in advance, together with the self-assessment.

Original format of the self-assessment

When submitting the self-assessment, always use the original Excel format provided by the Centre for Cybersecurity Belgium. If a modified version is submitted, the request for verification cannot be processed.

Dealing with misstatements

The self-assessment must not be amended during the CyFun verification process, unless this is done in response to an identified misstatement. In such cases, the self-assessment may only be adjusted downwards.

If the verifier identifies a misstatement, your organization amends the self-assessment itself. The amended version, which reflects the verifier’s conclusion, is then submitted to Brand Compliance. This version forms the basis for the final verification statement.

The value of a well-prepared self-assessment

Thorough and comprehensive preparation helps ensure a smooth and efficient verification process. Submit the self-assessment carefully prepared and well-substantiated. This way you increase the likelihood of a smooth verification process and a positive verification statement.

If a claim cannot be confirmed, a new CyFun verification offers the option to have it reassessed at a later time.

Questions

If you have any questions regarding the CyFun verification or its preparation, please contact us!

Share This Article :

  • Facebook
  • X
  • LinkedIn
Updated on 25 March 2026
NIS2 & the Belgian CyberFundamentalsNIS2 liability for board members

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 technical area 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2026 Brand Compliance
Thank you for your rating!
Thank you for your rating and comment!
This page was translated from: Dutch
Please rate this translation:
Your rating:
Change
Please give some examples of errors and how would you improve them: