+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Français
  • België
  • Dutch
  • English
  • Français
  • België
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Talk to an expert
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • The ultimate checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • The certification process step by step
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities within the management system
  • What should you know about certificate suspension or revocation?
  • Transfer of certification

General

10
  • Whitepaper management system audits
  • Quality Management: best practices for success
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

Audits information security

2
  • Excelling in information security: best practices
  • Operational Capabilities: The Backbone of Information Security

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

5
  • Transition CyberFundamentals 2023 to 2025
  • ISO 27001 in a NIS2 context in Belgium
  • Self-assessment & CyFun verification: best chance of success
  • NIS2 liability for board members
  • CyberFundamentals Framework in Belgium: what is the relationship with NIS2?

Assurance audits

1
  • ISAE 3402 vs SOC 2: what is the difference?

Audits privacy

8
  • Checklist for your BC 5701 certification
  • Transition to ISO/IEC 27701:2025
  • Whitepaper GDPR Certification Standard and Criteria BC 5701
  • BC 5701 certification: where do you start?
  • Data breach: What is it and how do you prevent it?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
View Categories

Transition CyberFundamentals 2023 to 2025

3 min. leestijd

Transition CyberFundamentals 2023-2025CyberFundamentals 2025 is the revised version of CyberFundamentals 2023.  This update aligns more closely with international standards, current threats, and the Belgian context surrounding NIS2.

There is no need to switch immediately, as a transition period applies. However, it is advisable to determine in good time what the changes mean for your organization.

Would you like a quick understanding of the impact on your organization? Please contact us.

Transition period CyberFundamentals 2023-2025

During the transition period, both CyberFundamentals 2023 and CyberFundamentals 2025 will remain available. Until 18 April 2027, you may choose verification or certification based on CyFun 2023 or CyFun 2025. Certificates and verification statements based on CyFun 2023 will remain valid until 18 April 2028 at the latest. After that date, only CyFun 2025 will be accepted.

Key changes in CyFun 2025

CyberFundamentals 2025 includes several substantive and editorial improvements.

  • Stronger alignment with international standards and legislation:
    CyberFundamentals 2025 better aligns with European and national regulations, including the NIS2 legislation.
  • Expansion and clarification of requirements:
    The controls and guidelines have been revised and more clearly formulated.
  • Increased focus on supply chain and OT security:
    The new version explicitly addresses supply chain security and operational technology (OT).
  • Incorporation of user feedback:
    The 2025 version was developed partly based on feedback from the field, making the framework more practical and user-friendly.
  • Introduction of Governance Measures:
    New in 2025 are the “Governance Measures,” which ensure cybersecurity assurance at board level.
  • More extensive explanation and interpretation:
    The explanation of the requirements has been expanded so that organizations better understand what is expected.
  • Improved structure and readability:
    In addition to content changes, grammatical, editorial, and structural improvements have been made.

What does this mean for your organization?

Is your organization already working with CyFun 2023, or are you preparing for a verification or certification process? If so, it is wise to assess in good time which version best fits your planning, documentation, and cybersecurity approach. In doing so, it is important not only to consider the validity of existing processes, but also the impact of the new requirements on governance, supply chain security, and OT security. Brand Compliance will be pleased to help you gain a clear understanding of this transition.

FAQ transition CyberFundamentals 2023-2025

Do you need to switch to CyberFundamentals 2025 immediately?
No. During the transition period, you may still choose between CyFun 2023 or CyFun 2025. This transition period runs until 18 April 2027.

Until when will certificates and verification statements based on CyFun 2023 remain valid?
Certificates and verification statements based on CyFun 2023 will remain valid until 18 April 2028 at the latest.

What are the content changes in CyberFundamentals 2025?
The new version is more closely aligned with NIST CSF 2.0 and NIS2, places greater emphasis on supply chain security and OT, introduces governance measures, and provides more extensive guidance for interpretation and implementation.

Does CyFun 2025 mean that your organization is automatically NIS2 compliant?
No. In the Belgian context, CyFun is used in determining the presumption of conformity with NIS2 legislation. This therefore requires careful wording.

Questions about your situation?

Do you have questions about the impact of the changes in CyberFundamentals 2025 on your organization, verification or certification? Please contact us via +32 14 11 55 00 or info@brandcompliance.com.

Share This Article :

  • Facebook
  • X
  • LinkedIn
Updated on 3 April 2026
CyberFundamentals Framework in Belgium: what is the relationship with NIS2?ISO 27001 in a NIS2 context in Belgium

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 technical area 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2026 Brand Compliance
Thank you for your rating!
Thank you for your rating and comment!
This page was translated from: Dutch
Please rate this translation:
Your rating:
Change
Please give some examples of errors and how would you improve them: