CyberFundamentals Framework
NIS2 says what you must achieve, never how you demonstrate it. Belgium, Ireland, Romania answer with CyFun — one yardstick across 3 member states. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the accepted alternative route. Belgian entities in scope are expected to work to either CyberFundamentals or ISO/IEC 27001.
4 tiers, cumulative
Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.
| Level | Adds | Cumulative | Intended for |
|---|---|---|---|
| Small | — | — | Micro-organisations and businesses with limited technical capacity |
| Basic | 34 | 34 | Entry-level assurance — essential cyber hygiene |
| Important | 99 | 133 | Higher-risk organisations — maps to NIS2 important entities |
| Essential | 85 | 218 | Critical entities — maps to NIS2 essential entities |
An entry tier of a handful of basic rules. Not an assurance level in the same sense as the three below — it exists so that the smallest organisations have somewhere to start.
Thirty-four concrete controls. The CCB's own position is that this set alone addresses the large majority of the attack patterns seen in its incident casework.
Ninety-nine further controls on top of Basic. This is where the governance measures of CSF 2.0 enter.
Eighty-five advanced controls on top of Important. Published totals for this level vary between 217 and 218 depending on the source.
Assessment is a maturity score out of 5, documented per control.
Every threshold, level by level, in the catalogue below — including the ones this framework sets per category, which a single figure hides.
What it is built on
CyFun does not invent its own taxonomy. It sits on NIST Cybersecurity Framework 2.0.
Six functions, because CSF 2.0 adds GOVERN to IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Governance measures start at the Important level.
Where it is heading
- Alignment with NIST CSF 2.0, including the new GOVERN function.
- Substantially expanded supply chain security coverage.
- Operational technology (OT) security addressed explicitly.
- Governance measures introduced from the Important level upwards.
- Control wording refined after review by more than eighty experts and organisations.
- Minimum maturity thresholds clarified per assurance level.
Why one framework across several states matters
Belgium, Ireland and Romania are joint owners of the scheme. Ireland's NCSC has adopted CyFun as its national assessment and certification scheme. A group with entities in more than one of those states can run a single assessment programme instead of one per country, which is the closest thing to an economy of scale NIS2 offers.
How it covers the ten NIS2 measures
Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.
CyFun 2025 adopts the NIST CSF 2.0 Core unchanged, so its categories are the CSF categories. Each article 21(2) measure is mapped to the categories whose outcomes it requires.
Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | Measure | CyFun — NIST CSF 2.0 category |
|---|---|---|
| (a) | Risk analysis and security policies | GV.OC GV.RM GV.PO ID.RA |
| (b) | Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI |
| (c) | Business continuity | PR.DS PR.IR RC.RP RC.CO |
| (d) | Supply chain security | GV.SC ID.RA |
| (e) | Security in acquisition, development and maintenance | ID.RA PR.PS |
| (f) | Assessing the effectiveness of the measures | GV.OV ID.IM |
| (g) | Basic cyber hygiene and cybersecurity training | PR.AT PR.PS |
| (h) | Cryptography and encryption | PR.DS |
| (i) | Human resources security, access control and asset management | GV.RR ID.AM PR.AA |
| (j) | Multi-factor authentication and secured communications | PR.AA PR.IR |
22 NIST CSF 2.0 category units, in full
- GV.OC — Organizational Context
- GV.RM — Risk Management Strategy
- GV.RR — Roles, Responsibilities and Authorities
- GV.PO — Policy
- GV.OV — Oversight
- GV.SC — Cybersecurity Supply Chain Risk Management
- ID.AM — Asset Management
- ID.RA — Risk Assessment
- ID.IM — Improvement
- PR.AA — Identity Management, Authentication and Access Control
- PR.AT — Awareness and Training
- PR.DS — Data Security
- PR.PS — Platform Security
- PR.IR — Technology Infrastructure Resilience
- DE.CM — Continuous Monitoring
- DE.AE — Adverse Event Analysis
- RS.MA — Incident Management
- RS.AN — Incident Analysis
- RS.CO — Incident Response Reporting and Communication
- RS.MI — Incident Mitigation
- RC.RP — Incident Recovery Plan Execution
- RC.CO — Incident Recovery Communication
What you already have, for the same measure
Nobody in scope starts from nothing. CyFun is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| NIS2 art. 21(2) Directive (EU) 2022/2555 | CyFun | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | GV.OC GV.RM GV.PO ID.RA | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | PR.DS PR.IR RC.RP RC.CO | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | GV.SC ID.RA | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | ID.RA PR.PS | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | GV.OV ID.IM | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | PR.AT PR.PS | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | PR.DS | 8.24 | SC |
| (i) HR, access, assets | GV.RR ID.AM PR.AA | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | PR.AA PR.IR | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
218 requirements, and the level each one enters at
A mapping says which of the ten measures a framework serves. A catalogue says which requirement, at which level, and against what maturity score. Here are all 218, as Centre for Cybersecurity Belgium (CCB) publishes them.
What this page does not reproduce, and why
This site is commercial, and both restrictions bite on exactly that. The structure, the identifiers and the numbers below are facts about the framework and are published; the wording is the CCB's and is not.
Withheld here, and only here:
- requirement wording
- the CCB crosswalk to article 21(2), the Belgian law, ISO/IEC 27001 and 27002, CIS v8.1 and IEC 62443
- the wording of the maturity level definitions
What you see instead. CyFun 2025 is built on NIST CSF 2.0 and reuses its identifiers. The CCB writes its own requirement against each of them, and that wording is not ours to publish. What you see instead is what the CSF itself says the outcome must be — NIST wording, public domain. Read it as the target CyFun works towards, never as the text a Belgian assessor will hold you to. NIST, Cybersecurity Framework 2.0 — Work of the US federal government: public domain.
CCB booklets: reproduction of extracts authorised for non-commercial purposes only. Mapping table and key-measure list: TLP:GREEN. Read the terms. Consent to publish the rest is theirs to give: certification@ccb.belgium.be.
- CCB, CyFun 2025 self-assessment tools, BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25)
- CCB, CyFun 2025 mapping table, work in progress version of May 2026 (TLP:GREEN)
- CCB, CyFun 2025 Key Measures, TLP:GREEN
- CCB, CyberFundamentals 2025 booklets, version 2025-10-01
Get the official documents from https://cyfun.eu/en/cyberfundamentals-framework-2025 — the framework and everything published with it belong to its owner, and that publication is the version that binds. The relations shown below come from a mapping table the owner publishes as work in progress; read them as guidance, not as a conformity statement.
- The catalogue comes from the self-assessment tools; the relations come from the CCB mapping table, which is published as work in progress and dated May 2026.
- The mapping table writes PR.AT-01,4 with a comma where the tool writes PR.AT-01.4. Normalised here, and recorded rather than silently corrected.
- Requirement wording follows the ESSENTIAL tool v3.1, the most recent of the three.
What each level adds, and demands
Depth is two things at once: more requirements, and a higher score on each of them. Both are read from the official tools, level by level.
| Level | Adds | Cumulative | Key measures | Each key measure | Each category | Overall average |
|---|---|---|---|---|---|---|
| Basic | +34 | 34 | 13 | ≥2.5/5 | n/a | ≥2.5/5 |
| Important | +99 | 133 | 9 | ≥3/5 | n/a | ≥3/5 |
| Essential | +85 | 218 | 7 | ≥3/5 | ≥3/5 | ≥3.5/5 |
The maturity scale
Each requirement is scored twice, and the thresholds above apply to the roll-up of those scores — not to a single answer per control.
- Documentation and implementation are scored separately on every requirement.
- The two are averaged, then rolled up per subcategory and per category.
- A requirement marked not applicable counts as 3 in the roll-up.
- The overall maturity level is the mean of the category scores.
Read from the formulas of the official self-assessment tool.
| Level |
|---|
| 1 Initial |
| 2 Repeatable |
| 3 Defined |
| 4 Managed |
| 5 Optimizing |
The catalogue, requirement by requirement
6 functions, 22 categories, 218 requirements. Each row carries the level at which it becomes due.
Govern · 40 requirements
Organisational Context (GV.OC)
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (a)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.OC-01.1 | Important | The organizational mission is understood and informs cybersecurity risk management GV.OC-01 · NIST Cybersecurity Framework 2.0 |
| GV.OC-02.1 | Essential | Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered GV.OC-02 · NIST Cybersecurity Framework 2.0 |
| GV.OC-03.1 | Basic | Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed GV.OC-03 · NIST Cybersecurity Framework 2.0 |
| GV.OC-03.2 | Important | Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed GV.OC-03 · NIST Cybersecurity Framework 2.0 |
| GV.OC-04.1 | Important | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0 |
| GV.OC-04.2 | Important | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0 |
| GV.OC-04.3 | Essential | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0 |
| GV.OC-04.4 | Essential | Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0 |
| GV.OC-05.1 | Important | Outcomes, capabilities, and services that the organization depends on are understood and communicated GV.OC-05 · NIST Cybersecurity Framework 2.0 |
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (f)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.OV-02.1 | Essential | The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks GV.OV-02 · NIST Cybersecurity Framework 2.0 |
| GV.OV-03.1 | Essential | Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed GV.OV-03 · NIST Cybersecurity Framework 2.0 |
Organizational cybersecurity policy is established, communicated, and enforced — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (a)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.PO-01.1 | Basic | Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced GV.PO-01 · NIST Cybersecurity Framework 2.0 |
| GV.PO-01.2 | Important | Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced GV.PO-01 · NIST Cybersecurity Framework 2.0 |
Risk Management Strategy (GV.RM)
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (a)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.RM-01.1 | Important | Risk management objectives are established and agreed to by organizational stakeholders GV.RM-01 · NIST Cybersecurity Framework 2.0 |
| GV.RM-02.1 | Important | Risk appetite and risk tolerance statements are established, communicated, and maintained GV.RM-02 · NIST Cybersecurity Framework 2.0 |
| GV.RM-03.1 | Basic | Cybersecurity risk management activities and outcomes are included in enterprise risk management processes GV.RM-03 · NIST Cybersecurity Framework 2.0 |
| GV.RM-03.2 | Important | Cybersecurity risk management activities and outcomes are included in enterprise risk management processes GV.RM-03 · NIST Cybersecurity Framework 2.0 |
| GV.RM-04.1 | Important | Strategic direction that describes appropriate risk response options is established and communicated GV.RM-04 · NIST Cybersecurity Framework 2.0 |
| GV.RM-05.1 | Important | Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties GV.RM-05 · NIST Cybersecurity Framework 2.0 |
Roles, Responsibilities and Authorities (GV.RR)
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (i)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.RR-01.1 | Essential | Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving GV.RR-01 · NIST Cybersecurity Framework 2.0 |
| GV.RR-02.1 key measure | Important | Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced GV.RR-02 · NIST Cybersecurity Framework 2.0 |
| GV.RR-02.2 | Essential | Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced GV.RR-02 · NIST Cybersecurity Framework 2.0 |
| GV.RR-03.1 | Important | Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies GV.RR-03 · NIST Cybersecurity Framework 2.0 |
| GV.RR-03.2 | Important | Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies GV.RR-03 · NIST Cybersecurity Framework 2.0 |
| GV.RR-04.1 | Basic | Cybersecurity is included in human resources practices GV.RR-04 · NIST Cybersecurity Framework 2.0 |
| GV.RR-04.2 | Important | Cybersecurity is included in human resources practices GV.RR-04 · NIST Cybersecurity Framework 2.0 |
Cybersecurity Supply Chain Risk Management (GV.SC)
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (d)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| GV.SC-01.1 | Essential | A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders GV.SC-01 · NIST Cybersecurity Framework 2.0 |
| GV.SC-02.1 | Important | Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally GV.SC-02 · NIST Cybersecurity Framework 2.0 |
| GV.SC-03.1 | Essential | Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes GV.SC-03 · NIST Cybersecurity Framework 2.0 |
| GV.SC-05.1 | Important | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0 |
| GV.SC-05.2 key measure | Essential | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0 |
| GV.SC-05.3 key measure | Essential | Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0 |
| GV.SC-06.1 | Essential | Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships GV.SC-06 · NIST Cybersecurity Framework 2.0 |
| GV.SC-07.1 | Important | The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0 |
| GV.SC-07.2 | Essential | The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0 |
| GV.SC-07.3 | Essential | The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0 |
| GV.SC-07.4 | Essential | The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0 |
| GV.SC-08.1 | Important | Relevant suppliers and other third parties are included in incident planning, response, and recovery activities GV.SC-08 · NIST Cybersecurity Framework 2.0 |
| GV.SC-09.1 | Essential | Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle GV.SC-09 · NIST Cybersecurity Framework 2.0 |
| GV.SC-10.1 | Essential | Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement GV.SC-10 · NIST Cybersecurity Framework 2.0 |
Identify · 55 requirements
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (i)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| ID.AM-01.1 | Basic | Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0 |
| ID.AM-01.2 | Important | Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0 |
| ID.AM-01.3 | Important | Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0 |
| ID.AM-01.4 | Essential | Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0 |
| ID.AM-02.1 | Basic | Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0 |
| ID.AM-02.2 | Important | Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0 |
| ID.AM-02.3 | Important | Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0 |
| ID.AM-02.4 | Important | Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0 |
| ID.AM-02.5 | Essential | Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0 |
| ID.AM-03.2 | Important | Representations of the organization's authorized network communication and internal and external network data flows are maintained ID.AM-03 · NIST Cybersecurity Framework 2.0 |
| ID.AM-03.3 key measure | Essential | Representations of the organization's authorized network communication and internal and external network data flows are maintained ID.AM-03 · NIST Cybersecurity Framework 2.0 |
| ID.AM-04.1 | Important | Inventories of services provided by suppliers are maintained ID.AM-04 · NIST Cybersecurity Framework 2.0 |
| ID.AM-04.2 | Essential | Inventories of services provided by suppliers are maintained ID.AM-04 · NIST Cybersecurity Framework 2.0 |
| ID.AM-05.1 | Basic | Assets are prioritized based on classification, criticality, resources, and impact on the mission ID.AM-05 · NIST Cybersecurity Framework 2.0 |
| ID.AM-07.1 | Basic | Inventories of data and corresponding metadata for designated data types are maintained ID.AM-07 · NIST Cybersecurity Framework 2.0 |
| ID.AM-07.2 | Important | Inventories of data and corresponding metadata for designated data types are maintained ID.AM-07 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.10 key measure | Essential | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.11 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.12 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.13 | Essential | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.2 key measure | Basic | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.3 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.4 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.5 | Essential | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.6 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.7 key measure | Essential | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.8 | Important | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
| ID.AM-08.9 key measure | Essential | Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0 |
Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (f)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| ID.IM-02.1 | Important | Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties ID.IM-02 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.1 | Basic | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.2 | Important | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.3 | Important | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.4 | Important | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.5 | Important | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.6 | Important | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.7 | Essential | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.8 | Essential | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-03.9 | Essential | Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0 |
| ID.IM-04.1 | Important | Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved ID.IM-04 · NIST Cybersecurity Framework 2.0 |
| ID.IM-04.2 | Essential | Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved ID.IM-04 · NIST Cybersecurity Framework 2.0 |
The cybersecurity risk to the organization, assets, and individuals is understood by the organization — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (a) (d) (e)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| ID.RA-01.1 | Basic | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-01.2 | Important | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-01.3 | Important | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-01.4 | Essential | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-01.5 | Important | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-01.6 | Important | Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0 |
| ID.RA-02.1 | Important | Cyber threat intelligence is received from information sharing forums and sources ID.RA-02 · NIST Cybersecurity Framework 2.0 |
| ID.RA-02.2 | Essential | Cyber threat intelligence is received from information sharing forums and sources ID.RA-02 · NIST Cybersecurity Framework 2.0 |
| ID.RA-03.1 | Important | Internal and external threats to the organization are identified and recorded ID.RA-03 · NIST Cybersecurity Framework 2.0 |
| ID.RA-05.1 | Basic | Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0 |
| ID.RA-05.2 | Important | Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0 |
| ID.RA-05.3 | Essential | Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0 |
| ID.RA-06.1 | Important | Risk responses are chosen, prioritized, planned, tracked, and communicated ID.RA-06 · NIST Cybersecurity Framework 2.0 |
| ID.RA-08.1 key measure | Important | Processes for receiving, analyzing, and responding to vulnerability disclosures are established ID.RA-08 · NIST Cybersecurity Framework 2.0 |
| ID.RA-08.2 | Essential | Processes for receiving, analyzing, and responding to vulnerability disclosures are established ID.RA-08 · NIST Cybersecurity Framework 2.0 |
Protect · 79 requirements
Identity Management, Authentication, and Access Control (PR.AA)
Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (i) (j)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| PR.AA-01.1 key measure | Basic | Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0 |
| PR.AA-01.2 | Important | Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0 |
| PR.AA-01.3 | Essential | Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0 |
| PR.AA-01.4 | Essential | Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0 |
| PR.AA-01.5 | Essential | Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0 |
| PR.AA-02.1 | Important | Identities are proofed and bound to credentials based on the context of interactions PR.AA-02 · NIST Cybersecurity Framework 2.0 |
| PR.AA-02.2 | Essential | Identities are proofed and bound to credentials based on the context of interactions PR.AA-02 · NIST Cybersecurity Framework 2.0 |
| PR.AA-03.1 | Basic | Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0 |
| PR.AA-03.2 key measure | Basic | Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0 |
| PR.AA-03.3 key measure | Important | Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0 |
| PR.AA-03.4 | Essential | Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0 |
| PR.AA-03.5 | Essential | Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0 |
| PR.AA-04.1 | Essential | Identity assertions are protected, conveyed, and verified PR.AA-04 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.1 key measure | Basic | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.2 key measure | Basic | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.3 key measure | Basic | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.4 key measure | Basic | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.5 | Important | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.6 | Important | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.7 | Important | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.8 | Essential | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-05.9 | Essential | Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0 |
| PR.AA-06.1 | Basic | Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0 |
| PR.AA-06.2 | Important | Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0 |
| PR.AA-06.3 | Essential | Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0 |
| PR.AA-06.4 | Essential | Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0 |
Awareness and Training (PR.AT)
The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (g)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| PR.AT-01.1 | Basic | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0 |
| PR.AT-01.2 | Important | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0 |
| PR.AT-01.3 | Important | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0 |
| PR.AT-01.4 | Essential | Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0 |
| PR.AT-02.1 | Important | Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0 |
| PR.AT-02.2 | Important | Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0 |
| PR.AT-02.3 | Important | Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0 |
Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (c) (h)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| PR.DS-01.1 | Important | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.2 | Essential | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.3 | Essential | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.4 | Important | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.5 | Important | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.6 | Essential | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-01.9 | Basic | The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0 |
| PR.DS-02.1 key measure | Essential | The confidentiality, integrity, and availability of data-in-transit are protected PR.DS-02 · NIST Cybersecurity Framework 2.0 |
| PR.DS-02.2 | Essential | The confidentiality, integrity, and availability of data-in-transit are protected PR.DS-02 · NIST Cybersecurity Framework 2.0 |
| PR.DS-10.1 | Essential | The confidentiality, integrity, and availability of data-in-use are protected PR.DS-10 · NIST Cybersecurity Framework 2.0 |
| PR.DS-11.1 key measure | Basic | Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0 |
| PR.DS-11.2 | Important | Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0 |
| PR.DS-11.3 | Important | Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0 |
| PR.DS-11.4 | Essential | Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0 |
| PR.DS-11.5 | Essential | Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0 |
Technology Infrastructure Resilience (PR.IR)
Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (c) (j)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| PR.IR-01.1 key measure | Basic | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.2 key measure | Basic | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.3 key measure | Important | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.4 key measure | Important | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.5 | Essential | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.6 | Essential | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.7 | Essential | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.8 | Essential | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-01.9 | Essential | Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0 |
| PR.IR-02.1 | Important | The organization's technology assets are protected from environmental threats PR.IR-02 · NIST Cybersecurity Framework 2.0 |
| PR.IR-02.2 | Essential | The organization's technology assets are protected from environmental threats PR.IR-02 · NIST Cybersecurity Framework 2.0 |
| PR.IR-03.1 | Essential | Mechanisms are implemented to achieve resilience requirements in normal and adverse situations PR.IR-03 · NIST Cybersecurity Framework 2.0 |
| PR.IR-04.1 | Important | Adequate resource capacity to ensure availability is maintained PR.IR-04 · NIST Cybersecurity Framework 2.0 |
The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (e) (g)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| PR.PS-01.1 key measure | Important | Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0 |
| PR.PS-01.2 | Essential | Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0 |
| PR.PS-01.3 | Essential | Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0 |
| PR.PS-01.4 | Essential | Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0 |
| PR.PS-01.5 | Essential | Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0 |
| PR.PS-02.1 | Important | Software is maintained, replaced, and removed commensurate with risk PR.PS-02 · NIST Cybersecurity Framework 2.0 |
| PR.PS-03.1 | Important | Hardware is maintained, replaced, and removed commensurate with risk PR.PS-03 · NIST Cybersecurity Framework 2.0 |
| PR.PS-04.1 key measure | Basic | Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0 |
| PR.PS-04.2 | Important | Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0 |
| PR.PS-04.3 | Important | Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0 |
| PR.PS-04.4 | Essential | Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0 |
| PR.PS-04.5 | Essential | Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0 |
| PR.PS-05.1 | Basic | Installation and execution of unauthorized software are prevented PR.PS-05 · NIST Cybersecurity Framework 2.0 |
| PR.PS-05.2 | Important | Installation and execution of unauthorized software are prevented PR.PS-05 · NIST Cybersecurity Framework 2.0 |
| PR.PS-06.1 | Important | Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0 |
| PR.PS-06.2 | Important | Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0 |
| PR.PS-06.3 | Essential | Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0 |
| PR.PS-06.4 | Essential | Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0 |
Detect · 22 requirements
Adverse Event Analysis (DE.AE)
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| DE.AE-02.1 | Important | Potentially adverse events are analyzed to better understand associated activities DE.AE-02 · NIST Cybersecurity Framework 2.0 |
| DE.AE-02.2 | Essential | Potentially adverse events are analyzed to better understand associated activities DE.AE-02 · NIST Cybersecurity Framework 2.0 |
| DE.AE-03.1 key measure | Basic | Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0 |
| DE.AE-03.2 | Important | Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0 |
| DE.AE-03.3 | Essential | Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0 |
| DE.AE-04.1 | Essential | The estimated impact and scope of adverse events are understood DE.AE-04 · NIST Cybersecurity Framework 2.0 |
| DE.AE-06.1 | Important | Information on adverse events is provided to authorized staff and tools DE.AE-06 · NIST Cybersecurity Framework 2.0 |
| DE.AE-08.1 | Important | Incidents are declared when adverse events meet the defined incident criteria DE.AE-08 · NIST Cybersecurity Framework 2.0 |
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| DE.CM-01.1 | Basic | Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0 |
| DE.CM-01.2 key measure | Basic | Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0 |
| DE.CM-01.3 key measure | Important | Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0 |
| DE.CM-01.4 | Essential | Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0 |
| DE.CM-02.1 | Important | The physical environment is monitored to find potentially adverse events DE.CM-02 · NIST Cybersecurity Framework 2.0 |
| DE.CM-02.2 | Essential | The physical environment is monitored to find potentially adverse events DE.CM-02 · NIST Cybersecurity Framework 2.0 |
| DE.CM-03.1 | Basic | Personnel activity and technology usage are monitored to find potentially adverse events DE.CM-03 · NIST Cybersecurity Framework 2.0 |
| DE.CM-03.2 | Important | Personnel activity and technology usage are monitored to find potentially adverse events DE.CM-03 · NIST Cybersecurity Framework 2.0 |
| DE.CM-06.1 | Important | External service provider activities and services are monitored to find potentially adverse events DE.CM-06 · NIST Cybersecurity Framework 2.0 |
| DE.CM-06.2 | Important | External service provider activities and services are monitored to find potentially adverse events DE.CM-06 · NIST Cybersecurity Framework 2.0 |
| DE.CM-09.1 | Important | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0 |
| DE.CM-09.2 | Essential | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0 |
| DE.CM-09.3 | Essential | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0 |
| DE.CM-09.4 | Essential | Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0 |
Respond · 14 requirements
Investigations are conducted to ensure effective response and support forensics and recovery activities — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RS.AN-03.1 | Essential | Analysis is performed to establish what has taken place during an incident and the root cause of the incident RS.AN-03 · NIST Cybersecurity Framework 2.0 |
| RS.AN-06.1 | Essential | Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved RS.AN-06 · NIST Cybersecurity Framework 2.0 |
| RS.AN-07.1 | Essential | Incident data and metadata are collected, and their integrity and provenance are preserved RS.AN-07 · NIST Cybersecurity Framework 2.0 |
| RS.AN-08.1 | Essential | An incident's magnitude is estimated and validated RS.AN-08 · NIST Cybersecurity Framework 2.0 |
Incident Response Reporting and Communication (RS.CO)
Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RS.CO-02.1 | Basic | Internal and external stakeholders are notified of incidents RS.CO-02 · NIST Cybersecurity Framework 2.0 |
| RS.CO-02.2 key measure | Important | Internal and external stakeholders are notified of incidents RS.CO-02 · NIST Cybersecurity Framework 2.0 |
Responses to detected cybersecurity incidents are managed — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RS.MA-01.1 | Basic | The incident response plan is executed in coordination with relevant third parties once an incident is declared RS.MA-01 · NIST Cybersecurity Framework 2.0 |
| RS.MA-01.2 | Important | The incident response plan is executed in coordination with relevant third parties once an incident is declared RS.MA-01 · NIST Cybersecurity Framework 2.0 |
| RS.MA-02.1 | Important | Incident reports are triaged and validated RS.MA-02 · NIST Cybersecurity Framework 2.0 |
| RS.MA-02.2 | Essential | Incident reports are triaged and validated RS.MA-02 · NIST Cybersecurity Framework 2.0 |
| RS.MA-03.1 | Important | Incidents are categorized and prioritized RS.MA-03 · NIST Cybersecurity Framework 2.0 |
| RS.MA-05.1 | Important | The criteria for initiating incident recovery are applied RS.MA-05 · NIST Cybersecurity Framework 2.0 |
Activities are performed to prevent expansion of an event and mitigate its effects — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (b)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RS.MI-01.1 | Important | Incidents are contained RS.MI-01 · NIST Cybersecurity Framework 2.0 |
| RS.MI-01.2 key measure | Important | Incidents are contained RS.MI-01 · NIST Cybersecurity Framework 2.0 |
Recover · 8 requirements
Incident Recovery Communication (RC.CO)
Restoration activities are coordinated with internal and external parties — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (c)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RC.CO-03.1 | Important | Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders RC.CO-03 · NIST Cybersecurity Framework 2.0 |
| RC.CO-04.1 | Important | Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0 |
| RC.CO-04.2 | Essential | Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0 |
| RC.CO-04.3 | Essential | Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0 |
Incident Recovery Plan Execution (RC.RP)
Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents — NIST Cybersecurity Framework 2.0
Our thematic mapping puts this group against (c)
| Requirement | Level | NIST CSF 2.0 outcome |
|---|---|---|
| RC.RP-01.1 | Basic | The recovery portion of the incident response plan is executed once initiated from the incident response process RC.RP-01 · NIST Cybersecurity Framework 2.0 |
| RC.RP-02.1 | Essential | Recovery actions are selected, scoped, prioritized, and performed RC.RP-02 · NIST Cybersecurity Framework 2.0 |
| RC.RP-05.1 | Important | The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed RC.RP-05 · NIST Cybersecurity Framework 2.0 |
| RC.RP-06.1 | Important | The end of incident recovery is declared based on criteria, and incident-related documentation is completed RC.RP-06 · NIST Cybersecurity Framework 2.0 |
Where each reference takes you
Every identifier on this page is a link. Inside the site: a requirement identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for.
Catalogue reviewed , against CyFun 2025 requirements of 2025-10-01. CyFun and the documents it comes from belong to Centre for Cybersecurity Belgium (CCB).
Common questions
Does a CyFun label make us NIS2 compliant?
Is CyFun only for Belgium?
How many controls are there at each level?
What is the difference between CyFun 2.0 and CyFun 2025?
Can we use ISO 27001 instead?
Is passing an assessment a yes-or-no result?
How does CyFun relate to article 21 of the directive?
- https://ccb.belgium.be/news/cyfunr-2025-here
- https://atwork.safeonweb.be/tools-resources/cyberfundamentals-framework
- https://www.ncsc.gov.ie/CyFun/CyFunFAQ/
- https://cyfun.eu/en/cyberfundamentals-framework-2025
We are not affiliated with Centre for Cybersecurity Belgium (CCB). CyFun and related marks belong to their owners.