CyFun verification and NIS2

Have your organisation’s cybersecurity measures independently assessed against
the CyberFundamentals Framework.

With our BELAC accreditation, we can perform a verification for
CyberFundamentals (CyFun).

If you successfully complete the verification, you can apply for a CyFun label.
This allows you to demonstrate (a presumption of) compliance with NIS2!

Request CyFun verification

What is the CyberFundamentals Framework?

The CyberFundamentals Framework, also known as CyFun®, is a framework developed by the Centre for Cybersecurity Belgium (CCB). It contains practical measures designed to protect data, reduce the risks associated with the most common cyberattacks and strengthen organisations’ cyber resilience.

CyFun can be used by entities subject to Belgian NIS2 legislation as well as by other organisations that want to structure and assess their cybersecurity measures.

The framework provides several assurance levels, allowing the measures and verification to be adapted to the organisation’s risk profile, potential impact and exposure to cyber threats.

Scope of the Belgian NIS2 Law

To be covered by the Belgian NIS2 Act, an organization must be established in Belgium and provide a service listed in Annexes I and II of the NIS2 Act. The thresholds for medium-sized enterprises must be exceeded. This includes, among others, medium-sized enterprises with more than 50 employees or an annual turnover of more than €10 million.

Use this NIS2 scope test tool to test whether your organization is a so-called essential or important entity.

Who is CyFun® intended for?

The NIS2 Act applies to organizations that provide essential services as listed in Annexes I and II of the Act. CyFun is suitable for:

  • Small and medium-sized enterprises (SMEs): Those who want to improve their basic security without complex management systems;
  • Large enterprises: Those who want to lay a solid foundation for further security measures;
  • Public and semi-public institutions: Those who are required to comply with the requirements of the NIS2 directive;
  • Service providers and suppliers: Those who want to offer customers certainty about their information security.

In short, CyFun is relevant for any organization that takes cybersecurity seriously and/or wants to comply with laws and regulations.

CyFun® 2023 and CyFun® 2025

A new version of the CyberFundamentals Framework was published in October 2025. CyFun® 2023 and CyFun® 2025 will coexist until 18 April 2027.

During this transition period, organisations can choose which version of the framework they wish to apply, subject to the conditions applicable to their situation.

View the official information about CyFun® 2023 and CyFun® 2025 on Safeonweb@work.

Why choose a CyFun verification?

Achieving CyFun verification offers numerous benefits for Belgian organizations looking to take their cybersecurity to the next level.

The key benefits include:

  • Protection against cyber threats: Minimizes the risk of data breaches and cyberattacks;
  • Customer and partner trust: Demonstrates your organization’s commitment to cybersecurity;
  • Legal compliance: Helps meet legal obligations;
  • Operational continuity: Reduces the risk of business disruptions due to cyber incidents;
  • Continuous improvement: Supports the regular evaluation and optimization of security measures.
Receive an initial assessment for your organization

What levels does CyFun have?

CyberFundamentals offers three levels, each designed for organizations of varying sizes and risk profiles:

CyFun® Basic
The CyFun Basic assurance level includes standard information security measures suitable for all companies. These measures provide effective protection using technology and processes that are generally already available. If necessary, the measures are adapted and refined.

CyFun® Important
The CyFun Important assurance level is designed to minimize the risk of targeted cyberattacks by actors with common skills and resources, in addition to known cybersecurity risks.

CyFun® Essential
The CyFun Essential assurance level provides additional protection against advanced cyberattacks by actors with extensive skills and resources.

The verification process

To obtain CyberFundamentals verification, an organization must complete the following steps:

  • Conduct a risk assessment
    Use the CyFun Selection Tool to select the appropriate assurance level;
  • Complete your Self-Assessment and implement corrective actions
    Use the CyFun Self-Assessment Tool for self-assessment and management reporting;
  • Request verification from Brand Compliance
    Brand Compliance carries out an independent assessment to determine whether your organisation meets the requirements of the selected CyFun® assurance level;
  • Receive the verification statement from Brand Compliance
    If the verification result is positive, Brand Compliance issues a CyFun® verification statement;
  • Apply for the CyFun® label through Safeonweb@work
    Once the verification statement has been issued, your organisation can apply for the CyFun® label in accordance with the procedure established by the CCB.
Book a no-obligation consultation

The process at Brand Compliance

The Brand Compliance process will look like this:

Obligations to important and essential entities

The NIS2 Act imposes several obligations on essential and important entities. Organizations within its scope must take measures to improve their cybersecurity, manage incidents, and report them.

  1. Registration
    Essential and important entities falling within the scope of the Belgian NIS2 Act must register their organization with the Belgian Cybersecurity Centre (CCB);
  2. Cybersecurity Risk Measures
    Essential and important entities must implement appropriate measures to secure their networks and information systems, prevent incidents, and mitigate the impact of incidents on their customers and other services;
  3. Significant Incident Reporting
    Both entities must inform the national CSIRT (in Belgium, this is the CCB) of any major incident affecting their services, including information on potential cross-border effects;
  4. Management Responsibility
    The governing bodies of NIS2 entities must approve cybersecurity measures and oversee their implementation. If the entity fails to comply with these measures, the governing body is responsible.

Essential entities must also undergo a mandatory regular conformity assessment, choosing from three options: CyFun certification, ISO/IEC 27001 certification, or an inspection by the CCB inspection service.

Important entities are legally required to conduct their own risk assessment and implement appropriate security measures to protect their networks and information systems. The CyFun program is the means by which cybersecurity can be demonstrated.

Supervision and sanctions

The CCB has been designated as the national authority for cybersecurity and will monitor compliance with the law.

Fines

The CCB can impose fines for failure to report, discipline directors, and fail to comply with oversight. Significant fines can be imposed on important and essential entities.

Warnings

The CCB may also issue warnings, including instructions to stop or change behavior, disclose violations, appoint a control officer, implement recommendations, suspend certifications or licenses, and ban management positions for essential entities.

ISO 27001 & CyberFundamentals

In some cases, it is also possible to obtain a CyFun® label through ISO 27001 certification. The certification must then meet specific requirements.

Read more in this article about a presumption of NIS2 conformity through ISO 27001 certification.

Read more in this article about ISO 27001 certification in the context of NIS2.

ISO 27001:2023

Request a proposal for your CyFun® verification

This field is for validation purposes and should be left unchanged.
Name
News letter