Directive NIS2 European Union
CyFun® 2025 · version 2

CyberFundamentals Framework

NIS2 says what you must achieve, never how you demonstrate it. Belgium, Ireland, Romania answer with CyFun — one yardstick across 3 member states. If you operate there, this is what your regulator reads.

Published
Assurance levels
4
Controls at Essential
218
Member states using it
3

Reviewed . Verify against the scheme owner before relying on this for a certification decision.

This framework is not compliance

Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.

We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the accepted alternative route. Belgian entities in scope are expected to work to either CyberFundamentals or ISO/IEC 27001.

Assurance levels

4 tiers, cumulative


Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.

CyFun levels with the number of controls each adds and the cumulative total
Level Adds Cumulative Intended for
Small Micro-organisations and businesses with limited technical capacity
Basic 34 34 Entry-level assurance — essential cyber hygiene
Important 99 133 Higher-risk organisations — maps to NIS2 important entities
Essential 85 218 Critical entities — maps to NIS2 essential entities
Small

An entry tier of a handful of basic rules. Not an assurance level in the same sense as the three below — it exists so that the smallest organisations have somewhere to start.

Basic · +34 controls

Thirty-four concrete controls. The CCB's own position is that this set alone addresses the large majority of the attack patterns seen in its incident casework.

Important · +99 controls

Ninety-nine further controls on top of Basic. This is where the governance measures of CSF 2.0 enter.

Essential · +85 controls

Eighty-five advanced controls on top of Important. Published totals for this level vary between 217 and 218 depending on the source.

Maturity, not a checkbox

Assessment is a maturity score out of 5, documented per control.

Every threshold, level by level, in the catalogue below — including the ones this framework sets per category, which a single figure hides.

What it is built on

CyFun does not invent its own taxonomy. It sits on NIST Cybersecurity Framework 2.0.

Six functions, because CSF 2.0 adds GOVERN to IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Governance measures start at the Important level.

Where it is heading

  • Alignment with NIST CSF 2.0, including the new GOVERN function.
  • Substantially expanded supply chain security coverage.
  • Operational technology (OT) security addressed explicitly.
  • Governance measures introduced from the Important level upwards.
  • Control wording refined after review by more than eighty experts and organisations.
  • Minimum maturity thresholds clarified per assurance level.

Why one framework across several states matters

Belgium, Ireland and Romania are joint owners of the scheme. Ireland's NCSC has adopted CyFun as its national assessment and certification scheme. A group with entities in more than one of those states can run a single assessment programme instead of one per country, which is the closest thing to an economy of scale NIS2 offers.

Mapping

How it covers the ten NIS2 measures


Article 21(2) is the article of NIS2 — Directive (EU) 2022/2555 — that lists the ten risk-management measures every entity in scope owes, lettered (a) to (j). Those ten letters are the first column of each table on this page, and the keys every mapping we publish hangs off. The ten measures, one by one.

Basis

CyFun 2025 adopts the NIST CSF 2.0 Core unchanged, so its categories are the CSF categories. Each article 21(2) measure is mapped to the categories whose outcomes it requires.

Limit of this mapping

Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.

Mapped at the level of
NIST CSF 2.0 category
Units in the framework
22
Units carrying article 21(2)
22
Each of the ten risk-management measures of article 21(2), mapped to the NIST CSF 2.0 category units of CyFun
NIS2 art. 21(2) Directive (EU) 2022/2555 Measure CyFun — NIST CSF 2.0 category
(a) Risk analysis and security policies GV.OC GV.RM GV.PO ID.RA
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI
(c) Business continuity PR.DS PR.IR RC.RP RC.CO
(d) Supply chain security GV.SC ID.RA
(e) Security in acquisition, development and maintenance ID.RA PR.PS
(f) Assessing the effectiveness of the measures GV.OV ID.IM
(g) Basic cyber hygiene and cybersecurity training PR.AT PR.PS
(h) Cryptography and encryption PR.DS
(i) Human resources security, access control and asset management GV.RR ID.AM PR.AA
(j) Multi-factor authentication and secured communications PR.AA PR.IR
22 NIST CSF 2.0 category units, in full
  • GV.OC — Organizational Context
  • GV.RM — Risk Management Strategy
  • GV.RR — Roles, Responsibilities and Authorities
  • GV.PO — Policy
  • GV.OV — Oversight
  • GV.SC — Cybersecurity Supply Chain Risk Management
  • ID.AM — Asset Management
  • ID.RA — Risk Assessment
  • ID.IM — Improvement
  • PR.AA — Identity Management, Authentication and Access Control
  • PR.AT — Awareness and Training
  • PR.DS — Data Security
  • PR.PS — Platform Security
  • PR.IR — Technology Infrastructure Resilience
  • DE.CM — Continuous Monitoring
  • DE.AE — Adverse Event Analysis
  • RS.MA — Incident Management
  • RS.AN — Incident Analysis
  • RS.CO — Incident Response Reporting and Communication
  • RS.MI — Incident Mitigation
  • RC.RP — Incident Recovery Plan Execution
  • RC.CO — Incident Recovery Communication
The chain continues

What you already have, for the same measure


Nobody in scope starts from nothing. CyFun is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.

The ten measures of article 21(2), each mapped to CyFun and to the enterprise frameworks an organisation is likely to already operate
NIS2 art. 21(2) Directive (EU) 2022/2555 CyFun ISO 27001 ISO/IEC 27001:2022 Annex A control NIST 800-53 NIST SP 800-53 Rev. 5 control family
(a) Risk analysis GV.OC GV.RM GV.PO ID.RA 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 RA PL PM
(b) Incident handling DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 IR AU SI
(c) Continuity PR.DS PR.IR RC.RP RC.CO 5.29 5.30 7.5 7.11 7.12 8.13 8.14 CP PE
(d) Supply chain GV.SC ID.RA 5.19 5.20 5.21 5.22 5.23 SR SA
(e) Secure development ID.RA PR.PS 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 SA CM MA RA SI
(f) Effectiveness GV.OV ID.IM 5.33 5.35 5.36 8.16 CA PM
(g) Hygiene and training PR.AT PR.PS 5.37 6.3 8.7 AT SI CM
(h) Cryptography PR.DS 8.24 SC
(i) HR, access, assets GV.RR ID.AM PR.AA 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 PS AC IA CM MP PE
(j) MFA and comms PR.AA PR.IR 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 IA AC SC

A crosswalk is not an equivalence

Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:

  • ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
  • NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.

Use a row to find the evidence you already hold, then read the requirement itself.

Measure catalogue

218 requirements, and the level each one enters at


A mapping says which of the ten measures a framework serves. A catalogue says which requirement, at which level, and against what maturity score. Here are all 218, as Centre for Cybersecurity Belgium (CCB) publishes them.

Requirements
218
Key measures
29
Functions
6
Categories
22
Subcategories
90
Maturity scale
1–5

What this page does not reproduce, and why

This site is commercial, and both restrictions bite on exactly that. The structure, the identifiers and the numbers below are facts about the framework and are published; the wording is the CCB's and is not.

Withheld here, and only here:

  • requirement wording
  • the CCB crosswalk to article 21(2), the Belgian law, ISO/IEC 27001 and 27002, CIS v8.1 and IEC 62443
  • the wording of the maturity level definitions

What you see instead. CyFun 2025 is built on NIST CSF 2.0 and reuses its identifiers. The CCB writes its own requirement against each of them, and that wording is not ours to publish. What you see instead is what the CSF itself says the outcome must be — NIST wording, public domain. Read it as the target CyFun works towards, never as the text a Belgian assessor will hold you to. NIST, Cybersecurity Framework 2.0 — Work of the US federal government: public domain.

CCB booklets: reproduction of extracts authorised for non-commercial purposes only. Mapping table and key-measure list: TLP:GREEN. Read the terms. Consent to publish the rest is theirs to give: certification@ccb.belgium.be.

  • CCB, CyFun 2025 self-assessment tools, BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25)
  • CCB, CyFun 2025 mapping table, work in progress version of May 2026 (TLP:GREEN)
  • CCB, CyFun 2025 Key Measures, TLP:GREEN
  • CCB, CyberFundamentals 2025 booklets, version 2025-10-01

Get the official documents from https://cyfun.eu/en/cyberfundamentals-framework-2025 — the framework and everything published with it belong to its owner, and that publication is the version that binds. The relations shown below come from a mapping table the owner publishes as work in progress; read them as guidance, not as a conformity statement.

  • The catalogue comes from the self-assessment tools; the relations come from the CCB mapping table, which is published as work in progress and dated May 2026.
  • The mapping table writes PR.AT-01,4 with a comma where the tool writes PR.AT-01.4. Normalised here, and recorded rather than silently corrected.
  • Requirement wording follows the ESSENTIAL tool v3.1, the most recent of the three.

What each level adds, and demands

Depth is two things at once: more requirements, and a higher score on each of them. Both are read from the official tools, level by level.

CyFun levels: requirements added, cumulative total, key measures, and the maturity score demanded at that level
Level Adds Cumulative Key measures Each key measure Each category Overall average
Basic +34 34 13 ≥2.5/5 n/a ≥2.5/5
Important +99 133 9 ≥3/5 n/a ≥3/5
Essential +85 218 7 ≥3/5 ≥3/5 ≥3.5/5

The maturity scale

Each requirement is scored twice, and the thresholds above apply to the roll-up of those scores — not to a single answer per control.

  • Documentation and implementation are scored separately on every requirement.
  • The two are averaged, then rolled up per subcategory and per category.
  • A requirement marked not applicable counts as 3 in the roll-up.
  • The overall maturity level is the mean of the category scores.

Read from the formulas of the official self-assessment tool.

The 5 maturity levels of CyFun, with what each expects of documentation and of implementation
Level
1 Initial
2 Repeatable
3 Defined
4 Managed
5 Optimizing

The catalogue, requirement by requirement

6 functions, 22 categories, 218 requirements. Each row carries the level at which it becomes due.

Govern  · 40 requirements

Organisational Context (GV.OC)

The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organization's cybersecurity risk management decisions are understood — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (a)

CyFun requirements in GV.OC, Organisational Context
Requirement Level NIST CSF 2.0 outcome
GV.OC-01.1 Important The organizational mission is understood and informs cybersecurity risk management GV.OC-01 · NIST Cybersecurity Framework 2.0
GV.OC-02.1 Essential Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered GV.OC-02 · NIST Cybersecurity Framework 2.0
GV.OC-03.1 Basic Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed GV.OC-03 · NIST Cybersecurity Framework 2.0
GV.OC-03.2 Important Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed GV.OC-03 · NIST Cybersecurity Framework 2.0
GV.OC-04.1 Important Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0
GV.OC-04.2 Important Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0
GV.OC-04.3 Essential Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0
GV.OC-04.4 Essential Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated GV.OC-04 · NIST Cybersecurity Framework 2.0
GV.OC-05.1 Important Outcomes, capabilities, and services that the organization depends on are understood and communicated GV.OC-05 · NIST Cybersecurity Framework 2.0

Oversight (GV.OV)

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management strategy — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (f)

CyFun requirements in GV.OV, Oversight
Requirement Level NIST CSF 2.0 outcome
GV.OV-02.1 Essential The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks GV.OV-02 · NIST Cybersecurity Framework 2.0
GV.OV-03.1 Essential Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed GV.OV-03 · NIST Cybersecurity Framework 2.0

Policy (GV.PO)

Organizational cybersecurity policy is established, communicated, and enforced — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (a)

CyFun requirements in GV.PO, Policy
Requirement Level NIST CSF 2.0 outcome
GV.PO-01.1 Basic Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced GV.PO-01 · NIST Cybersecurity Framework 2.0
GV.PO-01.2 Important Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced GV.PO-01 · NIST Cybersecurity Framework 2.0

Risk Management Strategy (GV.RM)

The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support operational risk decisions — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (a)

CyFun requirements in GV.RM, Risk Management Strategy
Requirement Level NIST CSF 2.0 outcome
GV.RM-01.1 Important Risk management objectives are established and agreed to by organizational stakeholders GV.RM-01 · NIST Cybersecurity Framework 2.0
GV.RM-02.1 Important Risk appetite and risk tolerance statements are established, communicated, and maintained GV.RM-02 · NIST Cybersecurity Framework 2.0
GV.RM-03.1 Basic Cybersecurity risk management activities and outcomes are included in enterprise risk management processes GV.RM-03 · NIST Cybersecurity Framework 2.0
GV.RM-03.2 Important Cybersecurity risk management activities and outcomes are included in enterprise risk management processes GV.RM-03 · NIST Cybersecurity Framework 2.0
GV.RM-04.1 Important Strategic direction that describes appropriate risk response options is established and communicated GV.RM-04 · NIST Cybersecurity Framework 2.0
GV.RM-05.1 Important Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties GV.RM-05 · NIST Cybersecurity Framework 2.0

Roles, Responsibilities and Authorities (GV.RR)

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (i)

CyFun requirements in GV.RR, Roles, Responsibilities and Authorities
Requirement Level NIST CSF 2.0 outcome
GV.RR-01.1 Essential Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving GV.RR-01 · NIST Cybersecurity Framework 2.0
GV.RR-02.1 key measure Important Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced GV.RR-02 · NIST Cybersecurity Framework 2.0
GV.RR-02.2 Essential Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced GV.RR-02 · NIST Cybersecurity Framework 2.0
GV.RR-03.1 Important Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies GV.RR-03 · NIST Cybersecurity Framework 2.0
GV.RR-03.2 Important Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies GV.RR-03 · NIST Cybersecurity Framework 2.0
GV.RR-04.1 Basic Cybersecurity is included in human resources practices GV.RR-04 · NIST Cybersecurity Framework 2.0
GV.RR-04.2 Important Cybersecurity is included in human resources practices GV.RR-04 · NIST Cybersecurity Framework 2.0

Cybersecurity Supply Chain Risk Management (GV.SC)

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (d)

CyFun requirements in GV.SC, Cybersecurity Supply Chain Risk Management
Requirement Level NIST CSF 2.0 outcome
GV.SC-01.1 Essential A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders GV.SC-01 · NIST Cybersecurity Framework 2.0
GV.SC-02.1 Important Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally GV.SC-02 · NIST Cybersecurity Framework 2.0
GV.SC-03.1 Essential Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes GV.SC-03 · NIST Cybersecurity Framework 2.0
GV.SC-05.1 Important Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0
GV.SC-05.2 key measure Essential Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0
GV.SC-05.3 key measure Essential Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties GV.SC-05 · NIST Cybersecurity Framework 2.0
GV.SC-06.1 Essential Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships GV.SC-06 · NIST Cybersecurity Framework 2.0
GV.SC-07.1 Important The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0
GV.SC-07.2 Essential The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0
GV.SC-07.3 Essential The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0
GV.SC-07.4 Essential The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship GV.SC-07 · NIST Cybersecurity Framework 2.0
GV.SC-08.1 Important Relevant suppliers and other third parties are included in incident planning, response, and recovery activities GV.SC-08 · NIST Cybersecurity Framework 2.0
GV.SC-09.1 Essential Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle GV.SC-09 · NIST Cybersecurity Framework 2.0
GV.SC-10.1 Essential Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement GV.SC-10 · NIST Cybersecurity Framework 2.0
Identify  · 55 requirements

Asset Management (ID.AM)

Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identified and managed consistent with their relative importance to organizational objectives and the organization's risk strategy — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (i)

CyFun requirements in ID.AM, Asset Management
Requirement Level NIST CSF 2.0 outcome
ID.AM-01.1 Basic Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0
ID.AM-01.2 Important Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0
ID.AM-01.3 Important Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0
ID.AM-01.4 Essential Inventories of hardware managed by the organization are maintained ID.AM-01 · NIST Cybersecurity Framework 2.0
ID.AM-02.1 Basic Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0
ID.AM-02.2 Important Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0
ID.AM-02.3 Important Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0
ID.AM-02.4 Important Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0
ID.AM-02.5 Essential Inventories of software, services, and systems managed by the organization are maintained ID.AM-02 · NIST Cybersecurity Framework 2.0
ID.AM-03.2 Important Representations of the organization's authorized network communication and internal and external network data flows are maintained ID.AM-03 · NIST Cybersecurity Framework 2.0
ID.AM-03.3 key measure Essential Representations of the organization's authorized network communication and internal and external network data flows are maintained ID.AM-03 · NIST Cybersecurity Framework 2.0
ID.AM-04.1 Important Inventories of services provided by suppliers are maintained ID.AM-04 · NIST Cybersecurity Framework 2.0
ID.AM-04.2 Essential Inventories of services provided by suppliers are maintained ID.AM-04 · NIST Cybersecurity Framework 2.0
ID.AM-05.1 Basic Assets are prioritized based on classification, criticality, resources, and impact on the mission ID.AM-05 · NIST Cybersecurity Framework 2.0
ID.AM-07.1 Basic Inventories of data and corresponding metadata for designated data types are maintained ID.AM-07 · NIST Cybersecurity Framework 2.0
ID.AM-07.2 Important Inventories of data and corresponding metadata for designated data types are maintained ID.AM-07 · NIST Cybersecurity Framework 2.0
ID.AM-08.10 key measure Essential Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.11 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.12 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.13 Essential Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.2 key measure Basic Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.3 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.4 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.5 Essential Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.6 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.7 key measure Essential Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.8 Important Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0
ID.AM-08.9 key measure Essential Systems, hardware, software, services, and data are managed throughout their life cycles ID.AM-08 · NIST Cybersecurity Framework 2.0

Improvement (ID.IM)

Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (f)

CyFun requirements in ID.IM, Improvement
Requirement Level NIST CSF 2.0 outcome
ID.IM-02.1 Important Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties ID.IM-02 · NIST Cybersecurity Framework 2.0
ID.IM-03.1 Basic Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.2 Important Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.3 Important Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.4 Important Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.5 Important Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.6 Important Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.7 Essential Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.8 Essential Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-03.9 Essential Improvements are identified from execution of operational processes, procedures, and activities ID.IM-03 · NIST Cybersecurity Framework 2.0
ID.IM-04.1 Important Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved ID.IM-04 · NIST Cybersecurity Framework 2.0
ID.IM-04.2 Essential Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved ID.IM-04 · NIST Cybersecurity Framework 2.0

Risk Assessment (ID.RA)

The cybersecurity risk to the organization, assets, and individuals is understood by the organization — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (a) (d) (e)

CyFun requirements in ID.RA, Risk Assessment
Requirement Level NIST CSF 2.0 outcome
ID.RA-01.1 Basic Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-01.2 Important Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-01.3 Important Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-01.4 Essential Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-01.5 Important Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-01.6 Important Vulnerabilities in assets are identified, validated, and recorded ID.RA-01 · NIST Cybersecurity Framework 2.0
ID.RA-02.1 Important Cyber threat intelligence is received from information sharing forums and sources ID.RA-02 · NIST Cybersecurity Framework 2.0
ID.RA-02.2 Essential Cyber threat intelligence is received from information sharing forums and sources ID.RA-02 · NIST Cybersecurity Framework 2.0
ID.RA-03.1 Important Internal and external threats to the organization are identified and recorded ID.RA-03 · NIST Cybersecurity Framework 2.0
ID.RA-05.1 Basic Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0
ID.RA-05.2 Important Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0
ID.RA-05.3 Essential Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization ID.RA-05 · NIST Cybersecurity Framework 2.0
ID.RA-06.1 Important Risk responses are chosen, prioritized, planned, tracked, and communicated ID.RA-06 · NIST Cybersecurity Framework 2.0
ID.RA-08.1 key measure Important Processes for receiving, analyzing, and responding to vulnerability disclosures are established ID.RA-08 · NIST Cybersecurity Framework 2.0
ID.RA-08.2 Essential Processes for receiving, analyzing, and responding to vulnerability disclosures are established ID.RA-08 · NIST Cybersecurity Framework 2.0
Protect  · 79 requirements

Identity Management, Authentication, and Access Control (PR.AA)

Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauthorized access — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (i) (j)

CyFun requirements in PR.AA, Identity Management, Authentication, and Access Control
Requirement Level NIST CSF 2.0 outcome
PR.AA-01.1 key measure Basic Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0
PR.AA-01.2 Important Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0
PR.AA-01.3 Essential Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0
PR.AA-01.4 Essential Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0
PR.AA-01.5 Essential Identities and credentials for authorized users, services, and hardware are managed by the organization PR.AA-01 · NIST Cybersecurity Framework 2.0
PR.AA-02.1 Important Identities are proofed and bound to credentials based on the context of interactions PR.AA-02 · NIST Cybersecurity Framework 2.0
PR.AA-02.2 Essential Identities are proofed and bound to credentials based on the context of interactions PR.AA-02 · NIST Cybersecurity Framework 2.0
PR.AA-03.1 Basic Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0
PR.AA-03.2 key measure Basic Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0
PR.AA-03.3 key measure Important Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0
PR.AA-03.4 Essential Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0
PR.AA-03.5 Essential Users, services, and hardware are authenticated PR.AA-03 · NIST Cybersecurity Framework 2.0
PR.AA-04.1 Essential Identity assertions are protected, conveyed, and verified PR.AA-04 · NIST Cybersecurity Framework 2.0
PR.AA-05.1 key measure Basic Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.2 key measure Basic Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.3 key measure Basic Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.4 key measure Basic Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.5 Important Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.6 Important Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.7 Important Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.8 Essential Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-05.9 Essential Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties PR.AA-05 · NIST Cybersecurity Framework 2.0
PR.AA-06.1 Basic Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0
PR.AA-06.2 Important Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0
PR.AA-06.3 Essential Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0
PR.AA-06.4 Essential Physical access to assets is managed, monitored, and enforced commensurate with risk PR.AA-06 · NIST Cybersecurity Framework 2.0

Awareness and Training (PR.AT)

The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (g)

CyFun requirements in PR.AT, Awareness and Training
Requirement Level NIST CSF 2.0 outcome
PR.AT-01.1 Basic Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0
PR.AT-01.2 Important Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0
PR.AT-01.3 Important Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0
PR.AT-01.4 Essential Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind PR.AT-01 · NIST Cybersecurity Framework 2.0
PR.AT-02.1 Important Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0
PR.AT-02.2 Important Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0
PR.AT-02.3 Important Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind PR.AT-02 · NIST Cybersecurity Framework 2.0

Data Security (PR.DS)

Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (c) (h)

CyFun requirements in PR.DS, Data Security
Requirement Level NIST CSF 2.0 outcome
PR.DS-01.1 Important The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.2 Essential The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.3 Essential The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.4 Important The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.5 Important The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.6 Essential The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-01.9 Basic The confidentiality, integrity, and availability of data-at-rest are protected PR.DS-01 · NIST Cybersecurity Framework 2.0
PR.DS-02.1 key measure Essential The confidentiality, integrity, and availability of data-in-transit are protected PR.DS-02 · NIST Cybersecurity Framework 2.0
PR.DS-02.2 Essential The confidentiality, integrity, and availability of data-in-transit are protected PR.DS-02 · NIST Cybersecurity Framework 2.0
PR.DS-10.1 Essential The confidentiality, integrity, and availability of data-in-use are protected PR.DS-10 · NIST Cybersecurity Framework 2.0
PR.DS-11.1 key measure Basic Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0
PR.DS-11.2 Important Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0
PR.DS-11.3 Important Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0
PR.DS-11.4 Essential Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0
PR.DS-11.5 Essential Backups of data are created, protected, maintained, and tested PR.DS-11 · NIST Cybersecurity Framework 2.0

Technology Infrastructure Resilience (PR.IR)

Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizational resilience — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (c) (j)

CyFun requirements in PR.IR, Technology Infrastructure Resilience
Requirement Level NIST CSF 2.0 outcome
PR.IR-01.1 key measure Basic Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.2 key measure Basic Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.3 key measure Important Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.4 key measure Important Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.5 Essential Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.6 Essential Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.7 Essential Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.8 Essential Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-01.9 Essential Networks and environments are protected from unauthorized logical access and usage PR.IR-01 · NIST Cybersecurity Framework 2.0
PR.IR-02.1 Important The organization's technology assets are protected from environmental threats PR.IR-02 · NIST Cybersecurity Framework 2.0
PR.IR-02.2 Essential The organization's technology assets are protected from environmental threats PR.IR-02 · NIST Cybersecurity Framework 2.0
PR.IR-03.1 Essential Mechanisms are implemented to achieve resilience requirements in normal and adverse situations PR.IR-03 · NIST Cybersecurity Framework 2.0
PR.IR-04.1 Important Adequate resource capacity to ensure availability is maintained PR.IR-04 · NIST Cybersecurity Framework 2.0

Platform Security (PR.PS)

The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with the organization's risk strategy to protect their confidentiality, integrity, and availability — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (e) (g)

CyFun requirements in PR.PS, Platform Security
Requirement Level NIST CSF 2.0 outcome
PR.PS-01.1 key measure Important Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0
PR.PS-01.2 Essential Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0
PR.PS-01.3 Essential Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0
PR.PS-01.4 Essential Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0
PR.PS-01.5 Essential Configuration management practices are established and applied PR.PS-01 · NIST Cybersecurity Framework 2.0
PR.PS-02.1 Important Software is maintained, replaced, and removed commensurate with risk PR.PS-02 · NIST Cybersecurity Framework 2.0
PR.PS-03.1 Important Hardware is maintained, replaced, and removed commensurate with risk PR.PS-03 · NIST Cybersecurity Framework 2.0
PR.PS-04.1 key measure Basic Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0
PR.PS-04.2 Important Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0
PR.PS-04.3 Important Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0
PR.PS-04.4 Essential Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0
PR.PS-04.5 Essential Log records are generated and made available for continuous monitoring PR.PS-04 · NIST Cybersecurity Framework 2.0
PR.PS-05.1 Basic Installation and execution of unauthorized software are prevented PR.PS-05 · NIST Cybersecurity Framework 2.0
PR.PS-05.2 Important Installation and execution of unauthorized software are prevented PR.PS-05 · NIST Cybersecurity Framework 2.0
PR.PS-06.1 Important Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0
PR.PS-06.2 Important Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0
PR.PS-06.3 Essential Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0
PR.PS-06.4 Essential Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle PR.PS-06 · NIST Cybersecurity Framework 2.0
Detect  · 22 requirements

Adverse Event Analysis (DE.AE)

Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in DE.AE, Adverse Event Analysis
Requirement Level NIST CSF 2.0 outcome
DE.AE-02.1 Important Potentially adverse events are analyzed to better understand associated activities DE.AE-02 · NIST Cybersecurity Framework 2.0
DE.AE-02.2 Essential Potentially adverse events are analyzed to better understand associated activities DE.AE-02 · NIST Cybersecurity Framework 2.0
DE.AE-03.1 key measure Basic Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0
DE.AE-03.2 Important Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0
DE.AE-03.3 Essential Information is correlated from multiple sources DE.AE-03 · NIST Cybersecurity Framework 2.0
DE.AE-04.1 Essential The estimated impact and scope of adverse events are understood DE.AE-04 · NIST Cybersecurity Framework 2.0
DE.AE-06.1 Important Information on adverse events is provided to authorized staff and tools DE.AE-06 · NIST Cybersecurity Framework 2.0
DE.AE-08.1 Important Incidents are declared when adverse events meet the defined incident criteria DE.AE-08 · NIST Cybersecurity Framework 2.0

Continuous Monitoring (DE.CM)

Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in DE.CM, Continuous Monitoring
Requirement Level NIST CSF 2.0 outcome
DE.CM-01.1 Basic Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0
DE.CM-01.2 key measure Basic Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0
DE.CM-01.3 key measure Important Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0
DE.CM-01.4 Essential Networks and network services are monitored to find potentially adverse events DE.CM-01 · NIST Cybersecurity Framework 2.0
DE.CM-02.1 Important The physical environment is monitored to find potentially adverse events DE.CM-02 · NIST Cybersecurity Framework 2.0
DE.CM-02.2 Essential The physical environment is monitored to find potentially adverse events DE.CM-02 · NIST Cybersecurity Framework 2.0
DE.CM-03.1 Basic Personnel activity and technology usage are monitored to find potentially adverse events DE.CM-03 · NIST Cybersecurity Framework 2.0
DE.CM-03.2 Important Personnel activity and technology usage are monitored to find potentially adverse events DE.CM-03 · NIST Cybersecurity Framework 2.0
DE.CM-06.1 Important External service provider activities and services are monitored to find potentially adverse events DE.CM-06 · NIST Cybersecurity Framework 2.0
DE.CM-06.2 Important External service provider activities and services are monitored to find potentially adverse events DE.CM-06 · NIST Cybersecurity Framework 2.0
DE.CM-09.1 Important Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0
DE.CM-09.2 Essential Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0
DE.CM-09.3 Essential Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0
DE.CM-09.4 Essential Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events DE.CM-09 · NIST Cybersecurity Framework 2.0
Respond  · 14 requirements

Incident Analysis (RS.AN)

Investigations are conducted to ensure effective response and support forensics and recovery activities — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in RS.AN, Incident Analysis
Requirement Level NIST CSF 2.0 outcome
RS.AN-03.1 Essential Analysis is performed to establish what has taken place during an incident and the root cause of the incident RS.AN-03 · NIST Cybersecurity Framework 2.0
RS.AN-06.1 Essential Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved RS.AN-06 · NIST Cybersecurity Framework 2.0
RS.AN-07.1 Essential Incident data and metadata are collected, and their integrity and provenance are preserved RS.AN-07 · NIST Cybersecurity Framework 2.0
RS.AN-08.1 Essential An incident's magnitude is estimated and validated RS.AN-08 · NIST Cybersecurity Framework 2.0

Incident Response Reporting and Communication (RS.CO)

Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in RS.CO, Incident Response Reporting and Communication
Requirement Level NIST CSF 2.0 outcome
RS.CO-02.1 Basic Internal and external stakeholders are notified of incidents RS.CO-02 · NIST Cybersecurity Framework 2.0
RS.CO-02.2 key measure Important Internal and external stakeholders are notified of incidents RS.CO-02 · NIST Cybersecurity Framework 2.0

Incident Management (RS.MA)

Responses to detected cybersecurity incidents are managed — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in RS.MA, Incident Management
Requirement Level NIST CSF 2.0 outcome
RS.MA-01.1 Basic The incident response plan is executed in coordination with relevant third parties once an incident is declared RS.MA-01 · NIST Cybersecurity Framework 2.0
RS.MA-01.2 Important The incident response plan is executed in coordination with relevant third parties once an incident is declared RS.MA-01 · NIST Cybersecurity Framework 2.0
RS.MA-02.1 Important Incident reports are triaged and validated RS.MA-02 · NIST Cybersecurity Framework 2.0
RS.MA-02.2 Essential Incident reports are triaged and validated RS.MA-02 · NIST Cybersecurity Framework 2.0
RS.MA-03.1 Important Incidents are categorized and prioritized RS.MA-03 · NIST Cybersecurity Framework 2.0
RS.MA-05.1 Important The criteria for initiating incident recovery are applied RS.MA-05 · NIST Cybersecurity Framework 2.0

Incident Mitigation (RS.MI)

Activities are performed to prevent expansion of an event and mitigate its effects — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (b)

CyFun requirements in RS.MI, Incident Mitigation
Requirement Level NIST CSF 2.0 outcome
RS.MI-01.1 Important Incidents are contained RS.MI-01 · NIST Cybersecurity Framework 2.0
RS.MI-01.2 key measure Important Incidents are contained RS.MI-01 · NIST Cybersecurity Framework 2.0
Recover  · 8 requirements

Incident Recovery Communication (RC.CO)

Restoration activities are coordinated with internal and external parties — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (c)

CyFun requirements in RC.CO, Incident Recovery Communication
Requirement Level NIST CSF 2.0 outcome
RC.CO-03.1 Important Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders RC.CO-03 · NIST Cybersecurity Framework 2.0
RC.CO-04.1 Important Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0
RC.CO-04.2 Essential Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0
RC.CO-04.3 Essential Public updates on incident recovery are shared using approved methods and messaging RC.CO-04 · NIST Cybersecurity Framework 2.0

Incident Recovery Plan Execution (RC.RP)

Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents — NIST Cybersecurity Framework 2.0

Our thematic mapping puts this group against (c)

CyFun requirements in RC.RP, Incident Recovery Plan Execution
Requirement Level NIST CSF 2.0 outcome
RC.RP-01.1 Basic The recovery portion of the incident response plan is executed once initiated from the incident response process RC.RP-01 · NIST Cybersecurity Framework 2.0
RC.RP-02.1 Essential Recovery actions are selected, scoped, prioritized, and performed RC.RP-02 · NIST Cybersecurity Framework 2.0
RC.RP-05.1 Important The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed RC.RP-05 · NIST Cybersecurity Framework 2.0
RC.RP-06.1 Important The end of incident recovery is declared based on criteria, and incident-related documentation is completed RC.RP-06 · NIST Cybersecurity Framework 2.0

Where each reference takes you

Every identifier on this page is a link. Inside the site: a requirement identifier links to itself, so you can cite a single row in an audit note; a group heading links to itself; and every article 21(2) letter opens that measure in full — its wording, what it means and what an auditor asks for.

Catalogue reviewed , against CyFun 2025 requirements of 2025-10-01. CyFun and the documents it comes from belong to Centre for Cybersecurity Belgium (CCB).

Common questions

Does a CyFun label make us NIS2 compliant?
No, and this is the most expensive misunderstanding about the framework. Ireland's NCSC states it plainly: CyFun "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Your obligations are owed under your national transposition law. CyFun is the instrument most regulators in Belgium, Ireland and Romania expect you to use to demonstrate that you have met them — evidence, not exemption.
Is CyFun only for Belgium?
Not any more. Belgium, Ireland and Romania are joint owners of the scheme, and Ireland has adopted CyberFundamentals as its national assessment and certification scheme. If your group has entities in more than one of those states, you can run one assessment programme rather than three — which is close to the only economy of scale NIS2 offers.
How many controls are there at each level?
Basic adds 34 controls. Important adds 99 on top of Basic, for 133. Essential adds 85 further advanced controls, bringing the cumulative total to about 218 — published figures for that top level vary between 217 and 218 depending on the source, so treat the additions rather than the total as the stable number. A fourth tier, Small, sits below Basic as an entry point for micro-organisations and is not an assurance level in the same sense.
What is the difference between CyFun 2.0 and CyFun 2025?
They are the same thing. The Centre for Cybersecurity Belgium published version 2 of the framework on 24 October 2025 and brands it CyFun 2025. If a document refers to "CyFun 2.0", it means this edition. The substantive change is alignment with NIST Cybersecurity Framework 2.0, which adds a sixth function, GOVERN, alongside expanded supply chain and operational technology coverage.
Can we use ISO 27001 instead?
Yes. ISO/IEC 27001 is the accepted alternative route, and entities in scope in Belgium are expected to work to either CyberFundamentals or ISO 27001. The practical trade-off: ISO 27001 is internationally recognised and certifiable anywhere, while CyFun is free to use, mapped to the national supervisor's expectations, and considerably lighter at its lower levels. Organisations already certified to ISO 27001 rarely have reason to switch.
Is passing an assessment a yes-or-no result?
No. Each control is scored for maturity out of five, and the level is awarded on documented maturity thresholds: at least 2.5 out of 5 for Basic and 3.5 out of 5 for Essential. That means an organisation can implement every control and still fall short if it cannot evidence how consistently they operate. In practice the documentation is what decides the outcome.
How does CyFun relate to article 21 of the directive?
Article 21(2) of the directive sets out ten risk-management measures as an outcome to achieve. CyFun is one way of structuring and evidencing them, organised by NIST CSF function rather than by the article's ten points, so the mapping is thematic rather than one-to-one. Note also that national law renumbers: Belgium carries these measures at article 30 of the Law of 26 April 2024 — and adds an eleventh, a coordinated vulnerability disclosure policy.
Cart 0