In my article on NIS2, one term kept coming back as “the practical answer”: CyberFundamentals, or CyFun for short. But what exactly is it? And how do you get started without immediately hiring an expensive consultant? This guide explains it in plain language.
What is CyFun?
CyberFundamentals is a cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It’s not an academic model but a set of concrete measures that help prevent the most common cyberattacks. It builds on established international standards (the NIST Cybersecurity Framework, ISO 27001, the CIS Controls and IEC 62443), but translates them into something an SME without a dedicated security team can actually carry.
Two things make it especially attractive for Belgian businesses. First: it’s free. The CCB makes the full documentation, self-assessment tools and policy templates available at no cost. Second: it’s the officially recognised route to NIS2 compliance in Belgium. The latest version, CyFun 2025, is also aligned with the updated NIST Cybersecurity Framework 2.0 and with the NIS2 Directive.
The four levels
CyFun works as a growth model. You don’t start at the highest level. You pick what matches your risk and size:
- Small: an entry level with a handful of basic rules, intended for micro-organisations or businesses with limited technical knowledge. Ideal for making a first assessment.
- Basic: 34 concrete measures around essential cyber hygiene. According to the CCB, this level alone already covers around 82% of the most common attacks. For most SMEs, it’s the realistic target.
- Important: builds on Basic with considerably more measures, good for roughly 94% coverage. Intended for organisations handling more sensitive data or higher risks.
- Essential: the full package, aimed at critical entities, with coverage up to 100%.
Each level contains all the measures of the previous one, plus more. The CCB’s aim is for every Belgian organisation to eventually meet at least the Basic level.
The six functions
Like the NIST framework it’s built on, CyFun 2025 splits all measures into six core functions. Together they form a logical cycle:
- Govern: policy, responsibilities and risk management at leadership level.
- Identify: knowing what you have: systems, data, suppliers.
- Protect: protection: access management, updates, backups, training.
- Detect: spotting in good time that something is going wrong.
- Respond: reacting appropriately when there’s an incident.
- Recover: restoring and learning the lessons.
Those middle functions, and Detect above all, are precisely where many SMEs fall short. It’s no coincidence that we come back to it shortly.
How do you achieve CyFun?
The CCB describes a three-step path:
- Selection & risk assessment. Using the CCB’s free Selection Tool, you determine which level fits your organisation, based on a simple risk estimate.
- Self-assessment. You score your own maturity against the measures using a supplied Excel tool, and document the evidence.
- Verification or certification. For an official label, you get assessed by a recognised, accredited body (CAB). For Basic and Important this is called verification; for Essential, certification.
Already ISO 27001 certified? The CCB accepts that as an equivalent route to compliance, provided your scope checks out. For most SMEs starting fresh, though, CyFun is faster and more accessible. Budget roughly two to four months of work for the Basic level.
An important nuance: a label is not a free pass
Let me clear up one misconception straight away. A CyFun label does not mean you’re automatically fully NIS2 compliant. Specific NIS2 obligations, such as the strict incident notification deadlines (24 hours, 72 hours, 30 days), must be anchored separately in your internal procedures. CyFun gets you the vast majority of the way, but the final stretch needs attention.
Where monitoring comes in
Look again at those six functions. Detect is entirely about spotting problems in time. A large part of Identify revolves around an up-to-date inventory of your systems. And Respond only begins once you know something is happening.
In other words: a substantial part of CyFun, and certainly of the Basic level, is monitoring in practice. You can’t detect anomalous behaviour, report an incident or respond to something you don’t see. This is exactly where I help businesses: setting up monitoring that not only fulfils these CyFun measures but also makes them demonstrable to an auditor.
Getting started, practically
My advice for an SME: download the CCB’s Selection Tool, aim for the Basic level, and work through the self-assessment honestly. You’ll find that detection and visibility are probably where you have the most work. That’s good news, because that’s exactly what’s fastest and most visible to address.
Want to know how monitoring accelerates your path to CyFun Basic, and strengthens your NIS2 position at the same time? I’m happy to think it through with you.