CCB CyberFundamentals (CyFun): The Complete Belgium Guide
CyberFundamentals is Belgium's official cybersecurity framework, providing a clear path from basic protection to full NIS2 compliance. This guide covers everything you need to know: the framework structure, how to get started, and what each tier involves.
What is CyberFundamentals?
CyberFundamentals (CyFun) is the official Belgian cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It provides organizations with a structured, evidence-based approach to cybersecurity that scales from small businesses to critical infrastructure.
- Official Belgian framework - recognized for NIS2 compliance
- Based on international standards: NIST CSF 2.0, ISO 27001, CIS Controls
- Tiered approach - start simple, grow as needed
The 3 Security Tiers
CyberFundamentals uses a progressive tier system. Each tier builds on the previous one, adding more controls for increased protection.
Basic Free
The entry level: 34 controls. Defends against 82% of attack types.
Important
Builds on every Basic control with broader coverage.
Essential
Builds on every Important control. The default level for essential NIS2 entities.
The 6 Core Functions
CyberFundamentals organizes all security controls into six functions, following the NIST Cybersecurity Framework structure:
Govern
Establish cybersecurity governance, policies, roles, and risk strategy
Identify
Know your assets, business environment, and risk exposure
Protect
Implement safeguards: access control, training, data security
Detect
Monitor for anomalies, security events, and potential threats
Respond
Take action when incidents occur, contain and mitigate impact
Recover
Restore operations, learn from incidents, improve defenses
Getting Started
Starting with CyberFundamentals is straightforward. Here's the recommended path:
Start with the Basic tier
Begin with the 34 controls of the entry level. They cover the fundamentals across every category.
Assess your current state
Use a self-assessment tool to evaluate where you stand on each control.
Implement controls progressively
Work through the controls one by one. Document your progress as you go.
Upgrade when ready
Once Basic is complete, decide if you need Important or Essential based on your risk profile and NIS2 requirements.
Certification
While self-assessment is valuable, official certification provides external validation of your security posture.
- Certification available through CCB-authorised auditors
- Validates your compliance with the chosen tier
- Useful for customers, insurers, and regulatory requirements
- Valid for 3 years with surveillance audits
CyberFundamentals and NIS2
If your organization falls under NIS2, CyberFundamentals provides the implementation path in Belgium:
Deep Dive Articles
What is CyberFundamentals?
Introduction to Belgium's cybersecurity framework
CyberFundamentals Levels
Basic vs Important vs Essential - which tier is right for you?
CyFun Scoring: the 5 CMMI Maturity Levels
How every control is scored on Documentation and Implementation maturity (1-5)
How to Get CyFun Certified
Step-by-step certification process and costs
CyberFundamentals vs ISO 27001
When to use which framework
The 22 Control Categories
All CyberFundamentals controls, category by category
What is the CCB?
Belgium's Centre for Cybersecurity - the organization behind CyberFundamentals
CyFun Audit Preparation: 8-Week Plan
Week-by-week plan to be CAB-audit ready in CyFun BASIC. Scope, risk register, policies, evidence, mock run, submission.
CyFun CAB Audit Cost
Honest cost ranges for a Belgian NIS2 CAB audit. Preparation, audit fees, internal time. Direct consultancy vs MSP-channel economics.
How to Run a CyFun Mock Audit
5-phase DIY self-check using the same CCB workbook + 1-5 maturity rubric a real CAB audit uses. Catch gaps before audit fees start running.
How Much Work Is CyFun Basic? Measured
A real implementation measured from the event log: 91% audit-ready over about 11 weeks at a day a week, 87% of actions automated. Full data, method and limits.
CyFun Basic, by the Numbers: Documentation and Evidence
How much documentation and evidence CyFun Basic really needs, counted from one real implementation: ~38 documents, 123 pieces of evidence, most collected automatically.
How Easy Cyber Protection Helps
We make CyberFundamentals implementation simple and guided:
Frequently Asked Questions
Is CyberFundamentals the same as ISO 27001?
No, but they're related. CyberFundamentals incorporates ISO 27001 principles but is tailored for the Belgian context and NIS2 requirements. Importantly, the CCB accepts both CyFun and ISO/IEC 27001:2022 as valid paths to NIS2 conformity. They carry the same legal presumption. For organizations already ISO 27001 certified, you can submit a Statement of Applicability (SoA) to the CCB showing equivalence to the relevant CyFun level. For organizations starting fresh, CyFun is generally faster and more accessible for Belgian SMEs.
Which tier do I need?
Essential entities default to Essential and may go lower only where their own risk assessment justifies it (Royal Decree, Art. 7), shown by 18 April 2027. Important entities have no mandatory assessment; a voluntary CyFun assessment is at least Important (Art. 11). Most SMEs outside NIS2 scope do well with Basic.
How long does implementation take?
Basic tier: 2-4 months. Important tier: 6-12 months. Essential tier: 12+ months. These are ongoing programs - security is never "done."
Do I need external help?
Not necessarily. The Basic tier can often be implemented internally. Higher tiers may benefit from expert guidance, especially for complex controls.
Is certification mandatory?
Certification is voluntary for most organizations. Essential NIS2 entities are the exception: they need an Essential-level conformity assessment by 18 April 2027, or a lower level their own risk assessment justifies. Contracts or insurers may also ask for it.
Related Topics
Sources
- CCB CyberFundamentals Framework : Official CCB documentation
- NIS2 Directive (EU) 2022/2555 : European cybersecurity directive
- NIST Cybersecurity Framework : Foundation for CyberFundamentals structure
- CCB: FAQ NIS2 and CyberFundamentals
- Royal Decree of 9 June 2024 (NIS2, French text) : Art. 7 and 11