Clients asking about NIS2?

White-label NIS2/CyFun compliance platform for MSPs

Use our platform to get you and your clients audit-ready. Step by step, through CyFun (Cyber Fundamentals), the official framework for NIS2 compliance in Belgium, Cyprus, Ireland, Malta and Romania. You stay the expert; the busywork goes.

No newsletter. GDPR-compliant, built in Belgium.

An MSP intern achieved 91% audit-ready in 11 weeks, working one day weekly

while also handling second-line helpdesk support

Day 1. He connected the integrations, determined the CyFun level, and started the risk assessment questionnaire with the CEO. The platform showed what a CAB auditor would find that day, and turned that into a roadmap.
Then. The integrations read MFA state, device inventory and EDR coverage out of the tools they already ran, so the implementation side evidenced itself. The eleven weeks went into the documentation: completing the policies and procedures and getting them approved. That took 31 of the 34 CyFun Basic controls to audit-ready, at a five-person MSP, by someone who knew nothing about this beforehand.
Line chart of one client's CyFun maturity over about eleven weeks. Documentation and implementation both start below the 2.5 target and finish above it.
Maturity for the MSP's own environment, directly from the platform. Documentation and implementation aligned with the 2.5 target of a CyFun verification.
Why. The workflow is built around what an MSP already does, not around a compliance consultant's.
Not us. The securing itself, MFA, backups, firewalls, stays your work. Audit-ready means evidence a CAB auditor, the official inspector, would accept. Not a passed audit.

See the measured data

Why your clients (will) ask for NIS2 compliance

Since 2024, the EU law NIS2 requires about 4,000 Belgian companies (registered by January 2026) to prove protection against hackers. Your client doesn't need to be on that list to face the question.

You're already their IT provider. This isn't a new vendor for them to evaluate. It's the next step in what you already handle for them.

Two people walking on a beach, relaxed

No extra hires. No new department.

Not a new department, but what you already handle for clients, presented differently.

What your clients pay for the platform, and what you resell

One fee per client, no base fee, no modules. Determined by the client's employee count. All CyFun levels, from Basic to Essential, are included, with no cost for switching.

Drag the total, or any row, to match your own book.

Extra turnover€29,220per year

That is €2,435 per month of recurring revenue.

Recurring revenue you are not billing today, and the gaps it surfaces (MFA, backups, patching) become projects on top.

The requirement comes from the framework, not from you. You stop arguing for a security budget and start reporting against a standard.

BandEmployees at that clientClientsPer client / monthSubtotal
Nano1 – 4
0
€49€0
Micro5 – 12
1
€99€99
Core13 – 29
2
€169€338
Growth30 – 49
2
€229€458
Medium50 – 249
2
€395€790
Large250 – 999
1
€750€750
Enterprise1,000+
0
——
Total8€2,435

Pre-pay monthly (MSRP), quarterly (−6%), six-monthly (−8%) or annually (−12%).

Plus €400 onboarding, once. That is for you, not per client: one guided session where we walk through the platform together. Adding a client is immediate, not a rollout. After that you move at your own pace, not ours. All amounts excluding VAT.

Connect a client's Microsoft 365 and stop chasing screenshots

Most of a CyFun Basic file is proving things that are already true inside the client's tenant: who has multi-factor switched on, which accounts are administrators, whether the old mail protocols are still open. ECP reads that straight from Microsoft 365 and files it against the right control, so the answer is waiting when the auditor asks for it.

Seventeen of the thirty-four Basic controls take their evidence straight from Microsoft 365. Three more if the client runs Defender for Endpoint.

Twelve separate checks look at identity

It reports what it finds, including when the answer is no. A failing check is evidence too. Some name the accounts involved, others report on a setting. Either way it reads as a task list rather than a score.

The platform identifies security gaps; remediation remains your responsibility.

It acts as a scoreboard, not a gym, showing you what is missing without doing the heavy lifting for you.

Platform vs. manual responsibilities

What the platform does

  • Identifies missing controls so you know what is lacking.
  • Provides remediation steps to guide your fixes.
  • Drafts policy documents for your final review.
  • Allows continuous re-checking to track progress.

What requires your involvement

  • Enforcing technical controls (MFA, firewalls).
  • Running backup drills to ensure resilience.
  • Gathering auditor proof to verify compliance.
  • Making policy decisions based on judgment calls.

Project breakdown & expectations

Phase Description & cost structure Benchmark case study timeline
1. Getting audit-ready A dedicated project phase requiring manual setup and remediation. 11 weeks total, averaging 1 day per week (based on a 5-person MSP: CyFun Basic with a sound baseline).
2. Continuous compliance A lighter, ongoing phase driven by automated integrations. Tasks are limited to reviewing changes and re-approving documents.

Expect to invest real time on both sides. The remediation tasks involve the same MFA, firewall, and backup work you already manage for clients, there is nothing new to learn.

The client file opens on what is wrong: ten key measures below the bar, and the one number that is not the gate.
The client file opens on what is wrong: ten key measures below the bar, and the one number that is not the gate.
Every control diagnosed against what a CAB auditor would accept, then ranked by what is quickest to fix.
Every control diagnosed against what a CAB auditor would accept, then ranked by what is quickest to fix.
Policies and procedures are generated, versioned, and published, awaiting your review and approval.
Policies and procedures are generated, versioned, and published, awaiting your review and approval.

How to resell this?

Reselling this to clients?

Partners buy below the rates above and invoice their own client under their own brand. It is a fixed percentage off the published card, the same for a partner with three clients as for one with fifty. We don't publish the number, because your clients read this page too. One rate card, the same for every partner, not negotiated. Ask for access and the card comes with my reply.

No newsletter. GDPR-compliant, built in Belgium.

50 pages, free. Provide your work email, and the PDF is delivered immediately. Preview the opening chapters without obligation.

What MSP owners ask before they say yes

Is compliance expertise required?

The platform doesn't replace your judgment but eliminates the routine tasks. Automated features include control mapping, evidence collection, gap analysis, and audit packages. You handle scope, risk acceptance, and evidence quality. Solo CyFun consultants report this reduces their per-client hours by about 40-50%.

What do my clients see?

Your branding is featured on all reports, emails, and pages. Clients recognize you as the compliance expert.

Can I determine my own pricing?

Yes. We bill you per client. You set the price for your clients.

How do we begin?

Schedule a 20-minute call with Tom. He guides you through the platform, sets up your first client, and you launch the same week. No contract required.

What does "audit-ready" mean?

It means your client has documented evidence of security controls aligned with the CyFun framework. The actual audit is done by certified CAB auditors, not by us or you. Five bodies can verify CyFun at Basic and Important level today, and none is authorised for Essential yet, so those entities currently take the ISO 27001 route.

How is pricing structured?

A single fee per client, based on size, as shown in the table above. Plus a one-time €400 onboarding fee. No monthly base charge. Rates are billed monthly.

You select your term:

  • Monthly
  • Quarterly, 6% off
  • Six-monthly, 8% off
  • Annually prepaid (12% discount)

Larger volumes can be billed more frequently. Just let us know.

You set your own pricing. The table shows the end client's cost. Consider it a suggested retail price, guidance, not a requirement. Set rates based on your market. The difference between the partner rate and this price is designed to be favorable.

Every licence includes AI support. If you want a human involved, there is an optional ladder on top of it. Each rung includes the one below it:

  • Guidance, €400 a quarter: unlimited AI support, five human-reviewed email questions a quarter, a one-hour onboarding session and a quarterly report
  • Asynchronous advisory, €1,500 a month: email and WhatsApp, responded to within 24 hours
  • Half a day a week, €4,500 a month: the above plus four hours of meetings a week
  • One day a week, €7,000 a month: the above plus eight hours of meetings a week, on site or online

Guidance does not replace the one-time €400 onboarding.

Convert NIS2 into recurring revenue. No additional staff.

Request access, take the guide, or look at the demo first.

Tom Janssens

"I personally onboard every MSP partner to ensure we're the right fit."

Tom Janssens, Founder

20+ years across IT and innovation management, including Eurocontrol (the organisation behind European air traffic) and Belgian SMEs.