IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

CCB CyberFundamentals (CyFun): The Complete Belgium Guide

CyberFundamentals is Belgium's official cybersecurity framework, providing a clear path from basic protection to full NIS2 compliance. This guide covers everything you need to know: the framework structure, how to get started, and what each tier involves.

CyberFundamentals complete framework overview
CyberFundamentals: The complete Belgian cybersecurity framework

What is CyberFundamentals?

CyberFundamentals (CyFun) is the official Belgian cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It provides organizations with a structured, evidence-based approach to cybersecurity that scales from small businesses to critical infrastructure.

  • Official Belgian framework - recognized for NIS2 compliance
  • Based on international standards: NIST CSF 2.0, ISO 27001, CIS Controls
  • Tiered approach - start simple, grow as needed

The 3 Security Tiers

CyberFundamentals uses a progressive tier system. Each tier builds on the previous one, adding more controls for increased protection.

Basic Free

The entry level: 34 controls. Defends against 82% of attack types.

34
controls
82%
Multi-factor authenticationAccess managementNetwork securityIncident procedures
Learn about the Basic tier

Important

Builds on every Basic control with broader coverage.

133
controls
94%
All Basic controlsSecurity monitoringVulnerability managementSupply chain security

Essential

Builds on every Important control. The default level for essential NIS2 entities.

218
controls
100%
All Important controlsAdvanced threat detectionContinuous monitoringFull audit trail

The 6 Core Functions

CyberFundamentals organizes all security controls into six functions, following the NIST Cybersecurity Framework structure:

GV

Govern

Establish cybersecurity governance, policies, roles, and risk strategy

ID

Identify

Know your assets, business environment, and risk exposure

PR

Protect

Implement safeguards: access control, training, data security

DE

Detect

Monitor for anomalies, security events, and potential threats

RS

Respond

Take action when incidents occur, contain and mitigate impact

RC

Recover

Restore operations, learn from incidents, improve defenses

Getting Started

Starting with CyberFundamentals is straightforward. Here's the recommended path:

1

Start with the Basic tier

Begin with the 34 controls of the entry level. They cover the fundamentals across every category.

2

Assess your current state

Use a self-assessment tool to evaluate where you stand on each control.

3

Implement controls progressively

Work through the controls one by one. Document your progress as you go.

4

Upgrade when ready

Once Basic is complete, decide if you need Important or Essential based on your risk profile and NIS2 requirements.

Certification

While self-assessment is valuable, official certification provides external validation of your security posture.

  • Certification available through CCB-authorised auditors
  • Validates your compliance with the chosen tier
  • Useful for customers, insurers, and regulatory requirements
  • Valid for 3 years with surveillance audits

CyberFundamentals and NIS2

If your organization falls under NIS2, CyberFundamentals provides the implementation path in Belgium:

Important entities: Important tier (133 controls) or higher if you opt for an assessment (Royal Decree, Art. 11)
Essential entities: Essential tier (218 controls) by default; lower only where your risk assessment justifies it (Art. 7)
Learn more about NIS2 requirements →

Deep Dive Articles

How Easy Cyber Protection Helps

We make CyberFundamentals implementation simple and guided:

Step-by-step guidance : Clear tasks for each control, no guessing what to do
Progress tracking : See your compliance percentage in real-time
Evidence collection : Built-in documentation for audits

Frequently Asked Questions

Is CyberFundamentals the same as ISO 27001?

No, but they're related. CyberFundamentals incorporates ISO 27001 principles but is tailored for the Belgian context and NIS2 requirements. Importantly, the CCB accepts both CyFun and ISO/IEC 27001:2022 as valid paths to NIS2 conformity. They carry the same legal presumption. For organizations already ISO 27001 certified, you can submit a Statement of Applicability (SoA) to the CCB showing equivalence to the relevant CyFun level. For organizations starting fresh, CyFun is generally faster and more accessible for Belgian SMEs.

Which tier do I need?

Essential entities default to Essential and may go lower only where their own risk assessment justifies it (Royal Decree, Art. 7), shown by 18 April 2027. Important entities have no mandatory assessment; a voluntary CyFun assessment is at least Important (Art. 11). Most SMEs outside NIS2 scope do well with Basic.

How long does implementation take?

Basic tier: 2-4 months. Important tier: 6-12 months. Essential tier: 12+ months. These are ongoing programs - security is never "done."

Do I need external help?

Not necessarily. The Basic tier can often be implemented internally. Higher tiers may benefit from expert guidance, especially for complex controls.

Is certification mandatory?

Certification is voluntary for most organizations. Essential NIS2 entities are the exception: they need an Essential-level conformity assessment by 18 April 2027, or a lower level their own risk assessment justifies. Contracts or insurers may also ask for it.

Related Topics

Sources

  1. CCB CyberFundamentals Framework : Official CCB documentation
  2. NIS2 Directive (EU) 2022/2555 : European cybersecurity directive
  3. NIST Cybersecurity Framework : Foundation for CyberFundamentals structure
  4. CCB: FAQ NIS2 and CyberFundamentals
  5. Royal Decree of 9 June 2024 (NIS2, French text) : Art. 7 and 11