Frameworks
CyberFundamentals: a practical route to NIS2 readiness
CyFun turns NIS2-shaped obligations into a graded set of concrete controls you can actually work through. We assess you against the right level and hand back a prioritised backlog — in days, not months.
A framework built to be implemented, not admired
CyberFundamentals was developed by the Centre for Cybersecurity Belgium and draws on NIST CSF, ISO/IEC 27001 and IEC 62443. Its 2025 revision aligns more closely with NIST CSF 2.0 and with European regulatory developments including NIS2, with more weight on supply chain security, operational technology, governance and auditability.
Graded, not all-or-nothing
Four assurance levels, each a defined set of controls. You start where your risk is, and the level above is an extension of the one below rather than a different framework.
Mapped to what you may already have
Because it is built on NIST CSF and ISO 27001, work you have already done for another obligation usually counts. The mapping is the point of the exercise, not a side effect.
A recognised route for NIS2
For organisations in scope of NIS2, CyFun gives a structured way to demonstrate that the risk-management measures required by the directive are actually in place.
Small, Basic, Important, Essential
Which level fits depends on your risk profile, your operational context, your supplier exposure, and in some cases on national implementation specifics. Choosing it is the first thing we do with you, not something you have to decide before calling.
- Small
- An entry path for micro-organisations and teams with limited technical resources, written as non-technical guidelines and recommendations rather than as a control set.
- Basic
- 34 controls. A practical starting point covering the core fundamentals, and the level most organisations should reach before arguing about anything more advanced.
- Important
- 117 controls. For organisations with broader exposure, stronger expectations from customers or regulators, or a higher operational reliance on their systems staying up.
- Essential
- 140 controls. A higher assurance level for organisations that need a robust and formalised posture — and the level where certification logic applies rather than verification.

Four things, and then you have a plan
The assessment itself is short. What takes the thinking is turning its output into something your team can work through in an order that makes sense.
- 01
Level selection and scoping
We work out which assurance level fits, based on your systems, business processes, supplier exposure and risk profile — and we write down why, because that reasoning is the first thing an assessor will ask about.
- 02
Prioritised implementation backlog
Findings become a practical action plan ordered around the measures that matter most, rather than a list that runs in control-number order and buries the important items at the bottom.
- 03
Evidence package
What evidence should be collected, where it should live, and how it should be structured so that verification or certification does not turn into an archaeology project.
- 04
Reporting for management
The results translated into something leadership can review and act on, with category-level visibility rather than a single score that hides where the problem actually is.
Two reports, and the reasoning behind them
Both are written to be read outside the IT department, and both state what they are based on.
- 01
Cybersecurity analysis report
A high-level assessment of how effectively your organisation addresses cyber risk, with a prioritised list of recommendations to improve posture and reduce it.
- 02
Readiness report
Your compliance status against the framework, control by control, for the purpose of initial evaluation — based on the information you provide about your organisation, which the report says plainly.
- 03
The backlog and the evidence structure
The action plan and the evidence map described above, in a form your own team can keep using after we have finished.
We assess. Somebody else verifies
Formal verification or certification is carried out by an independent accredited conformity assessment body under the applicable scheme rules. We are not that body, and a firm that prepared you cannot also be the one that certifies you.
What we deliver is a readiness assessment and the plan to close the gaps in it. That is a different document from a certificate, and we would rather be exact about the difference before you buy than explain it afterwards.
The assessment is a fixed scope for a fixed fee, quoted before you start. If you want help implementing the backlog rather than just receiving it, that is separate work and we will scope it separately.
Not sure which level applies to you?
That is the normal starting position, and working it out is the first thing we do. Tell us roughly what you run and who depends on it.