Directive NIS2 European Union
CyFun® 2025 · version 2

CyberFundamentals Framework

NIS2 says what you must achieve, never how you demonstrate it. Belgium, Ireland, Romania answer with CyFun — one yardstick across 3 member states. If you operate there, this is what your regulator reads.

Published
Assurance levels
4
Controls at Essential
218
Member states using it
3

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the accepted alternative route. Belgian entities in scope are expected to work to either CyberFundamentals or ISO/IEC 27001.

Assurance levels

4 tiers, cumulative


Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.

CyFun levels with the number of controls each adds and the cumulative total
Level Adds Cumulative Intended for
Small Micro-organisations and businesses with limited technical capacity
Basic 34 34 Entry-level assurance — essential cyber hygiene
Important 99 133 Higher-risk organisations — maps to NIS2 important entities
Essential 85 218 Critical entities — maps to NIS2 essential entities
Small

An entry tier of a handful of basic rules. Not an assurance level in the same sense as the three below — it exists so that the smallest organisations have somewhere to start.

Basic · +34 controls

Thirty-four concrete controls. The CCB's own position is that this set alone addresses the large majority of the attack patterns seen in its incident casework.

Important · +99 controls

Ninety-nine further controls on top of Basic. This is where the governance measures of CSF 2.0 enter.

Essential · +85 controls

Eighty-five advanced controls on top of Important. Published totals for this level vary between 217 and 218 depending on the source.

Maturity, not a checkbox

Assessment is a maturity score out of 5, documented per control.

Basic requires
2.5 / 5 minimum
Essential requires
3.5 / 5 minimum

What it is built on

CyFun does not invent its own taxonomy. It sits on NIST Cybersecurity Framework 2.0.

Six functions, because CSF 2.0 adds GOVERN to IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Governance measures start at the Important level.

Where it is heading

  • Alignment with NIST CSF 2.0, including the new GOVERN function.
  • Substantially expanded supply chain security coverage.
  • Operational technology (OT) security addressed explicitly.
  • Governance measures introduced from the Important level upwards.
  • Control wording refined after review by more than eighty experts and organisations.
  • Minimum maturity thresholds clarified per assurance level.

Why one framework across several states matters

Belgium, Ireland and Romania are joint owners of the scheme. Ireland's NCSC has adopted CyFun as its national assessment and certification scheme. A group with entities in more than one of those states can run a single assessment programme instead of one per country, which is the closest thing to an economy of scale NIS2 offers.

Mapping

How it covers article 21(2)


Basis

CyFun 2025 adopts the NIST CSF 2.0 Core unchanged, so its categories are the CSF categories. Each article 21(2) measure is mapped to the categories whose outcomes it requires.

Limit of this mapping

Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.

Mapped at the level of
NIST CSF 2.0 category
Units in the framework
22
Units carrying article 21(2)
22
Each of the ten risk-management measures of article 21(2), mapped to the NIST CSF 2.0 category units of CyFun
Art. 21(2) Measure CyFun — NIST CSF 2.0 category
(a) Risk analysis and security policies GV.OC GV.RM GV.PO ID.RA
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI
(c) Business continuity PR.DS PR.IR RC.RP RC.CO
(d) Supply chain security GV.SC ID.RA
(e) Security in acquisition, development and maintenance ID.RA PR.PS
(f) Assessing the effectiveness of the measures GV.OV ID.IM
(g) Basic cyber hygiene and cybersecurity training PR.AT PR.PS
(h) Cryptography and encryption PR.DS
(i) Human resources security, access control and asset management GV.RR ID.AM PR.AA
(j) Multi-factor authentication and secured communications PR.AA PR.IR
22 NIST CSF 2.0 category units, in full
  • GV.OC — Organizational Context
  • GV.RM — Risk Management Strategy
  • GV.RR — Roles, Responsibilities and Authorities
  • GV.PO — Policy
  • GV.OV — Oversight
  • GV.SC — Cybersecurity Supply Chain Risk Management
  • ID.AM — Asset Management
  • ID.RA — Risk Assessment
  • ID.IM — Improvement
  • PR.AA — Identity Management, Authentication and Access Control
  • PR.AT — Awareness and Training
  • PR.DS — Data Security
  • PR.PS — Platform Security
  • PR.IR — Technology Infrastructure Resilience
  • DE.CM — Continuous Monitoring
  • DE.AE — Adverse Event Analysis
  • RS.MA — Incident Management
  • RS.AN — Incident Analysis
  • RS.CO — Incident Response Reporting and Communication
  • RS.MI — Incident Mitigation
  • RC.RP — Incident Recovery Plan Execution
  • RC.CO — Incident Recovery Communication
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. CyFun is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to CyFun and to the enterprise frameworks an organisation is likely to already operate
Art. 21(2) CyFun ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis GV.OC GV.RM GV.PO ID.RA 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity PR.DS PR.IR RC.RP RC.CO 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain GV.SC ID.RA 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development ID.RA PR.PS 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness GV.OV ID.IM 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training PR.AT PR.PS 5.37 6.3 8.7 AT SI CM
(h) Cryptography PR.DS 8.24 SC
(i) HR, access, assets GV.RR ID.AM PR.AA 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms PR.AA PR.IR 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Common questions

Does a CyFun label make us NIS2 compliant?
No, and this is the most expensive misunderstanding about the framework. Ireland's NCSC states it plainly: CyFun "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Your obligations are owed under your national transposition law. CyFun is the instrument most regulators in Belgium, Ireland and Romania expect you to use to demonstrate that you have met them — evidence, not exemption.
Is CyFun only for Belgium?
Not any more. Belgium, Ireland and Romania are joint owners of the scheme, and Ireland has adopted CyberFundamentals as its national assessment and certification scheme. If your group has entities in more than one of those states, you can run one assessment programme rather than three — which is close to the only economy of scale NIS2 offers.
How many controls are there at each level?
Basic adds 34 controls. Important adds 99 on top of Basic, for 133. Essential adds 85 further advanced controls, bringing the cumulative total to about 218 — published figures for that top level vary between 217 and 218 depending on the source, so treat the additions rather than the total as the stable number. A fourth tier, Small, sits below Basic as an entry point for micro-organisations and is not an assurance level in the same sense.
What is the difference between CyFun 2.0 and CyFun 2025?
They are the same thing. The Centre for Cybersecurity Belgium published version 2 of the framework on 24 October 2025 and brands it CyFun 2025. If a document refers to "CyFun 2.0", it means this edition. The substantive change is alignment with NIST Cybersecurity Framework 2.0, which adds a sixth function, GOVERN, alongside expanded supply chain and operational technology coverage.
Can we use ISO 27001 instead?
Yes. ISO/IEC 27001 is the accepted alternative route, and entities in scope in Belgium are expected to work to either CyberFundamentals or ISO 27001. The practical trade-off: ISO 27001 is internationally recognised and certifiable anywhere, while CyFun is free to use, mapped to the national supervisor's expectations, and considerably lighter at its lower levels. Organisations already certified to ISO 27001 rarely have reason to switch.
Is passing an assessment a yes-or-no result?
No. Each control is scored for maturity out of five, and the level is awarded on documented maturity thresholds: at least 2.5 out of 5 for Basic and 3.5 out of 5 for Essential. That means an organisation can implement every control and still fall short if it cannot evidence how consistently they operate. In practice the documentation is what decides the outcome.
How does CyFun relate to article 21 of the directive?
Article 21(2) of the directive sets out ten risk-management measures as an outcome to achieve. CyFun is one way of structuring and evidencing them, organised by NIST CSF function rather than by the article's ten points, so the mapping is thematic rather than one-to-one. Note also that national law renumbers: Belgium carries these measures at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy.
Cart 0