IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

CyFun Audit Preparation: The 8-Week CAB-Ready Plan

A Conformity Assessment Body (CAB) audit at CyFun BASIC tier is achievable in eight weeks if you work the right artifacts in the right order. This is the plan: what each week produces, what the CCB CyberFundamentals workbook expects to see, and where a managed compliance platform replaces hours of manual scaffolding.

Why These Eight Weeks, In This Order

The CCB CyberFundamentals workbook is the artifact that travels: to a CAB auditor, to an enterprise client doing supplier due diligence, to the CCB inspection service as a self-assessment, on that route. The 8-week plan reverse-engineers that workbook:

  • Scope and asset inventory first: every other control references "the assets in scope". Without that list, the workbook is unrenderable.
  • Risk register second: the GV-RM control family explicitly references "documented risk assessment" as evidence. Policies that follow are framed as risk treatments.
  • Policies before evidence: evidence is meaningless unless a policy says what good looks like.
  • Mock run before submission: a cold reviewer finds the gaps the CAB will. Cheaper to fix in W7 than in week 12 of an audit.

New to CyberFundamentals? Start with what is CyberFundamentals and how the CyFun maturity scoring works before working this plan.

Week 1

Scope: Define What You Are Certifying

Goal. Decide what is in scope and what is out, and write it down. Auditors will not let you redefine scope mid-audit.

What you ship this week

  • Scope statement: legal entity, sites, business processes, IT systems in and out of scope.
  • Asset inventory: hardware, software, cloud services, data stores. Mapped to which scope item owns each asset.
  • Stakeholder map: who is responsible for each scope element (named individuals, not roles).
Week 2

Risk Register: Document the Risks Your Controls Mitigate

Goal. A risk register that names threats, ranks them, and points each one at the control(s) that mitigate it. The BASIC workbook has risk controls in the GV.RM and ID.RA categories, and this register is what you show for them.

What you ship this week

  • Threat list: ransomware, phishing, insider misuse, supplier compromise, data theft, DDoS (at minimum the six the CCB risk catalog highlights for SMEs).
  • Likelihood × impact scoring per threat (5×5 matrix is the Belgian default).
  • Treatment decisions: mitigate (point at controls), accept (with sign-off), transfer (insurance, contracts), avoid.
Week 3

Policies (1/2): Information Security and Incident Response

Goal. Two of the four policies the CCB workbook checks for: an Information Security Policy approved at management level, and an Incident Response Plan that names roles and decision rights.

What you ship this week

  • Information Security Policy: scope, principles, roles, review cadence. Signed by an authority that exists in the org chart.
  • Incident Response Plan: severity levels, escalation tree, 24-hour notification path to the CCB (NIS2 Article 23), contact list with backups, lessons-learned template.
Week 4

Policies (2/2): Access Control and Supplier Security

Goal. The remaining two BASIC policies: an Access Control Policy (least privilege, joiner-mover-leaver, MFA enforcement) and a Supplier Security Policy (NIS2 Article 21(2)(d) is non-negotiable).

What you ship this week

  • Access Control Policy: identity lifecycle, MFA enforcement, privileged account separation, quarterly access review cadence.
  • Supplier Security Policy: critical-supplier criteria, due diligence checklist, contract security clauses, breach notification expectations.
  • Supplier register: at least the suppliers tagged "critical" with a documented risk rating.
Week 5

Evidence Collection (1/2): Identity, Access, and Endpoint

Goal. Walk through the BASIC controls in the GV, ID, and PR functions and collect the evidence that shows each one is in place. The workbook has no evidence column: you score documentation and implementation maturity per control, and from level 3 the implementation scale expects evidence to be available. This week handles identity, access, and endpoint protection.

What you ship this week

  • MFA enabled for all admin accounts: screenshot of admin role list, screenshot of MFA enforcement policy.
  • Joiner-mover-leaver process: the most recent leaver ticket showing access revocation timestamps.
  • Endpoint protection deployed: EDR or AV console screenshot showing coverage percentage, patch compliance report.
  • Quarterly access review: the most recent review document with sign-off.
Week 6

Evidence Collection (2/2): Backup, Logging, and Awareness

Goal. The remaining BASIC functions: detect, respond, and recover. Backup verification, security logging, and awareness training are the three areas that most often fail a workbook review.

What you ship this week

  • Backup verification: most recent restore-test report, retention policy document, evidence that backups are stored offline or immutable.
  • Security logging: SIEM or log aggregator screenshot, log retention period, evidence of alert review cadence.
  • Security awareness training: completion percentage, training content summary, dates of last campaign per employee.
  • Tabletop exercise: incident scenario walkthrough document with named participants and lessons learned.
Week 7

Mock Self-Assessment Run

Goal. A full pass through the workbook scoring rubric against your collected evidence, by someone who did not collect it. The mock run finds the holes a CAB will find.

What you ship this week

  • Workbook completed end-to-end with the CCB 1–5 maturity score per control on both Documentation and Implementation axes.
  • Gap list: every control scored below the BASIC threshold, with target remediation dates and owners.
  • Internal review by a second pair of eyes (a colleague, an MSP, or a peer compliance lead) who challenges every score.
  • Updated risk register entries for any gap that materially raises a documented risk.
Week 8

Submission: Workbook + Roadmap

Goal. Hand off the workbook. For an essential entity on the CyFun route, this is the CAB engagement kickoff; under CCB inspection, it is the self-assessment for the inspection service. An important entity has nothing to file: the workbook is its evidence if the CCB asks, and the basis for a voluntary CAB assessment.

What you ship this week

  • Final CCB CyberFundamentals workbook (the Excel file the CCB publishes and the CAB expects).
  • Remediation roadmap: every gap from W7 with target date, owner, and dependency.
  • Scope statement and asset inventory attached.
  • If you missed the April 2026 step: a cover note documenting the catch-up timeline and current state.

After Submission: What Happens Next

For a self-assessment submission, the CCB does not return a verdict in the way a CAB does. The submission goes on the record and supports any subsequent supervisory review. For a CAB audit, the auditor returns a marked-up workbook with findings the organization must address.

Either way, the workbook is the working artifact. If you self-assessed, plan a quarterly review cycle to keep the evidence current. If you went through a CAB, the marked-up workbook becomes the next remediation roadmap, same structure, different starting state.

April 18, 2027 is the next date for essential entities, and it has not moved: an ESSENTIAL-level assessment on the CAB and ISO routes, a progress report on the CCB-inspection route (Royal Decree, Art. 22 and 23). The CCB Inspection Service asks essential entities that cannot hold an ESSENTIAL-level conformity assessment by that date for a remediation plan. That plan should preferably consist of a CyFun IMPORTANT certificate plus the measures planned to reach ESSENTIAL by April 18, 2028 (letter of 11 August 2026, ref. NCCA/JK/INS/2026-002). A lower level is also possible where the entity's own risk assessment justifies it (Royal Decree, Art. 7), provided it shows by April 18, 2027 that it meets that level. An important entity that opts for a voluntary assessment does so at IMPORTANT or higher (Royal Decree, Art. 11).

Run the 8 Weeks in ECP Instead of in Sharepoint

Every artifact in this plan (scope statement, asset inventory, risk register, the four policies, evidence per control, mock-run scoring, remediation roadmap, the CCB-compatible Excel workbook) is a first-class object in Easy Cyber Protection. You work the plan; the platform produces the workbook.

  • CyFun-mapped templates for every BASIC, IMPORTANT, and ESSENTIAL control.
  • Live integrations (Microsoft Graph, Sophos, Bitdefender, others) feed evidence into the right control automatically.
  • CCB-compatible Excel export and CAB auditor reimport (shipped April 2026).
  • Audit Readiness Snapshot: the one-page artifact you hand the W7 reviewer.

Frequently Asked Questions

Is 8 weeks realistic for a CyFun BASIC audit-readiness?

For an organization with reasonable existing security hygiene (MFA, EDR, backups, some documentation), yes. For an organization starting from zero documentation, 12–16 weeks is more realistic. The security work itself takes time, and the workbook cannot evidence what does not exist. The 8-week plan assumes the controls are roughly in place; the work is documenting them and collecting evidence.

Do I need a CAB audit, or is a self-assessment enough?

Important entities had no administrative formality with the CCB by April 18, 2026. They must implement the NIS2 measures, and the CCB can ask for evidence, for example after an incident. A voluntary CyFun assessment is a self-assessment verified by a CAB at IMPORTANT level or higher (Royal Decree of 9 June 2024, Art. 11). Essential entities need a CyFun ESSENTIAL certificate, ISO/IEC 27001 with equivalent measures, or a CCB inspection by April 18, 2027. Their own risk assessment may justify a lower level, which they must show they meet by that date (Art. 7). An essential entity that will not reach ESSENTIAL in time is requested to submit a remediation plan to the CCB Inspection Service: preferably a certificate at CyFun IMPORTANT level plus the measures planned to reach ESSENTIAL by April 18, 2028. Some important entities choose a voluntary CAB audit because enterprise clients ask for an external certificate.

What if my mock run in W7 surfaces serious gaps?

Submit anyway in W8 with the remediation roadmap. A workbook that scores honestly with target dates per gap is a stronger position than a wall of green that does not survive a CAB review.

Can I use this plan if my deadline already passed?

Yes. The April 18, 2026 step applied to essential entities, and the sources we read describe no late procedure for it, so ask the CCB inspection service how to regularise your position. Work the 8-week plan so your workbook is ready for the April 18, 2027 date, which has not moved. There is a separate catch-up route for that 2027 date. An essential entity that cannot hold an ESSENTIAL-equivalent conformity assessment by then is requested to submit a remediation plan to the CCB Inspection Service. The plan should preferably prove compliance at CyFun IMPORTANT level and describe the measures planned to reach ESSENTIAL by April 18, 2028 (letter ref. NCCA/JK/INS/2026-002, 11 August 2026). No remediation plan is needed if you have fully implemented ESSENTIAL-equivalent measures by April 18, 2027, or if your own risk analysis under Art. 7 of the NIS2 Royal Decree justifies a lower CyFun assurance level and you demonstrate by that same date that you comply with it. See the missed-deadline article for the routes and the remediation plan.

How does this plan map to IMPORTANT or ESSENTIAL tier?

The structure (scope → risk register → policies → evidence → mock run → submission) is the same. The volume changes: IMPORTANT tier covers 133 controls (vs 34 for BASIC), ESSENTIAL covers 218. Allow 16–24 weeks for IMPORTANT and 24–36 for ESSENTIAL with the same week-by-week structure scaled to fit. The CAB audit cycle adds another 4–8 weeks on top.

What does the CCB CyberFundamentals workbook actually look like?

It is the official Excel file maintained by the Centre for Cybersecurity Belgium (CCB), downloadable from the Safeonweb @work portal. Each control has rows for Documentation maturity (1–5) and Implementation maturity (1–5), a column for comments or additional information, and a column for the assessor's comments. There is no evidence column, so keep your own index of the document, screenshot or log sample behind each score. The same file is what a CAB receives, marks up, and returns.

Related Articles

Sources

  1. CCB CyberFundamentals Framework + Workbook
  2. Directive (EU) 2022/2555 (NIS2)
  3. Belgian NIS2 Law of 26 April 2024
  4. Centre for Cybersecurity Belgium (CCB)
  5. BELAC: Belgian Accreditation Body
  6. CCB: FAQ NIS2 and CyberFundamentals
  7. Royal Decree of 9 June 2024 (NIS2, French text)