CyberFundamentals Framework
NIS2 says what you must achieve, never how you demonstrate it. Belgium, Ireland, Romania answer with CyFun — one yardstick across 3 member states. If you operate there, this is what your regulator reads.
Reviewed . Verify against the scheme owner before relying on this for a certification decision.
This framework is not compliance
Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.
We put that first because it is the most expensive misunderstanding about any national framework. ISO/IEC 27001 is the accepted alternative route. Belgian entities in scope are expected to work to either CyberFundamentals or ISO/IEC 27001.
4 tiers, cumulative
Each level contains everything below it. The counts are the controls a level adds, because that is the figure that stays stable across publications.
| Level | Adds | Cumulative | Intended for |
|---|---|---|---|
| Small | — | — | Micro-organisations and businesses with limited technical capacity |
| Basic | 34 | 34 | Entry-level assurance — essential cyber hygiene |
| Important | 99 | 133 | Higher-risk organisations — maps to NIS2 important entities |
| Essential | 85 | 218 | Critical entities — maps to NIS2 essential entities |
An entry tier of a handful of basic rules. Not an assurance level in the same sense as the three below — it exists so that the smallest organisations have somewhere to start.
Thirty-four concrete controls. The CCB's own position is that this set alone addresses the large majority of the attack patterns seen in its incident casework.
Ninety-nine further controls on top of Basic. This is where the governance measures of CSF 2.0 enter.
Eighty-five advanced controls on top of Important. Published totals for this level vary between 217 and 218 depending on the source.
Assessment is a maturity score out of 5, documented per control.
What it is built on
CyFun does not invent its own taxonomy. It sits on NIST Cybersecurity Framework 2.0.
Six functions, because CSF 2.0 adds GOVERN to IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Governance measures start at the Important level.
Where it is heading
- Alignment with NIST CSF 2.0, including the new GOVERN function.
- Substantially expanded supply chain security coverage.
- Operational technology (OT) security addressed explicitly.
- Governance measures introduced from the Important level upwards.
- Control wording refined after review by more than eighty experts and organisations.
- Minimum maturity thresholds clarified per assurance level.
Why one framework across several states matters
Belgium, Ireland and Romania are joint owners of the scheme. Ireland's NCSC has adopted CyFun as its national assessment and certification scheme. A group with entities in more than one of those states can run a single assessment programme instead of one per country, which is the closest thing to an economy of scale NIS2 offers.
How it covers article 21(2)
CyFun 2025 adopts the NIST CSF 2.0 Core unchanged, so its categories are the CSF categories. Each article 21(2) measure is mapped to the categories whose outcomes it requires.
Category level, not subcategory. No official crosswalk from CyFun subcategories to article 21(2) exists; treat this as a scoping aid, not as a substitute for reading the controls at your assurance level.
| Art. 21(2) | Measure | CyFun — NIST CSF 2.0 category |
|---|---|---|
| (a) | Risk analysis and security policies | GV.OC GV.RM GV.PO ID.RA |
| (b) | Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI |
| (c) | Business continuity | PR.DS PR.IR RC.RP RC.CO |
| (d) | Supply chain security | GV.SC ID.RA |
| (e) | Security in acquisition, development and maintenance | ID.RA PR.PS |
| (f) | Assessing the effectiveness of the measures | GV.OV ID.IM |
| (g) | Basic cyber hygiene and cybersecurity training | PR.AT PR.PS |
| (h) | Cryptography and encryption | PR.DS |
| (i) | Human resources security, access control and asset management | GV.RR ID.AM PR.AA |
| (j) | Multi-factor authentication and secured communications | PR.AA PR.IR |
22 NIST CSF 2.0 category units, in full
- GV.OC — Organizational Context
- GV.RM — Risk Management Strategy
- GV.RR — Roles, Responsibilities and Authorities
- GV.PO — Policy
- GV.OV — Oversight
- GV.SC — Cybersecurity Supply Chain Risk Management
- ID.AM — Asset Management
- ID.RA — Risk Assessment
- ID.IM — Improvement
- PR.AA — Identity Management, Authentication and Access Control
- PR.AT — Awareness and Training
- PR.DS — Data Security
- PR.PS — Platform Security
- PR.IR — Technology Infrastructure Resilience
- DE.CM — Continuous Monitoring
- DE.AE — Adverse Event Analysis
- RS.MA — Incident Management
- RS.AN — Incident Analysis
- RS.CO — Incident Response Reporting and Communication
- RS.MI — Incident Mitigation
- RC.RP — Incident Recovery Plan Execution
- RC.CO — Incident Recovery Communication
What you already have, for the same measure
Nobody in scope starts from nothing. CyFun is what your supervisor reads; ISO 27001 and NIST 800-53 are what most organisations already run. Read a row across and you have the whole path, from the article to the control you can point at today.
| Art. 21(2) | CyFun | ISO 27001 ISO/IEC 27001:2022 Annex A control | NIST 800-53 NIST SP 800-53 Rev. 5 control family |
|---|---|---|---|
| (a) Risk analysis | GV.OC GV.RM GV.PO ID.RA | 5.1 5.2 5.3 5.4 5.7 5.31 5.35 5.36 | RA PL PM |
| (b) Incident handling | DE.CM DE.AE RS.MA RS.AN RS.CO RS.MI | 5.5 5.6 5.7 5.24 5.25 5.26 5.27 5.28 6.8 8.15 8.16 | IR AU SI |
| (c) Continuity | PR.DS PR.IR RC.RP RC.CO | 5.29 5.30 7.5 7.11 7.12 8.13 8.14 | CP PE |
| (d) Supply chain | GV.SC ID.RA | 5.19 5.20 5.21 5.22 5.23 | SR SA |
| (e) Secure development | ID.RA PR.PS | 5.8 8.8 8.9 8.25 8.26 8.27 8.28 8.29 8.30 8.31 8.32 8.33 8.34 | SA CM MA RA SI |
| (f) Effectiveness | GV.OV ID.IM | 5.33 5.35 5.36 8.16 | CA PM |
| (g) Hygiene and training | PR.AT PR.PS | 5.37 6.3 8.7 | AT SI CM |
| (h) Cryptography | PR.DS | 8.24 | SC |
| (i) HR, access, assets | GV.RR ID.AM PR.AA | 5.9 5.10 5.11 5.12 5.13 5.15 5.16 5.17 5.18 6.1 6.2 6.4 6.5 6.6 6.7 7.1 7.2 7.3 7.4 7.6 7.7 7.8 7.9 7.10 7.13 7.14 8.1 8.2 8.3 8.4 8.10 8.11 8.12 8.18 8.19 | PS AC IA CM MP PE |
| (j) MFA and comms | PR.AA PR.IR | 5.14 8.5 8.6 8.17 8.20 8.21 8.22 8.23 | IA AC SC |
A crosswalk is not an equivalence
Holding the controls in a row does not discharge the measure. Each framework words its requirement differently, and each mapping has a stated limit:
- ISO 27001 — Mapping a control does not make it applicable: applicability comes from your risk assessment and your Statement of Applicability. Note also that the risk-assessment obligation of article 21(2)(a) is carried by clause 6.1 of the standard, not by Annex A — a control-only reading misses it.
- NIST 800-53 — Family level, not control. A family contains controls of very different scope, and which of them apply depends on the baseline and tailoring you operate — so a family match is a starting point for scoping, never evidence that a measure is met.
Use a row to find the evidence you already hold, then read the requirement itself.
Common questions
Does a CyFun label make us NIS2 compliant?
Is CyFun only for Belgium?
How many controls are there at each level?
What is the difference between CyFun 2.0 and CyFun 2025?
Can we use ISO 27001 instead?
Is passing an assessment a yes-or-no result?
How does CyFun relate to article 21 of the directive?
- https://ccb.belgium.be/news/cyfunr-2025-here
- https://atwork.safeonweb.be/tools-resources/cyberfundamentals-framework
- https://www.ncsc.gov.ie/CyFun/CyFunFAQ/
- https://cyfun.eu/en/cyberfundamentals-framework-2025
We are not affiliated with Centre for Cybersecurity Belgium (CCB). CyFun and related marks belong to their owners.