CyberFundamentals Certification: How It Works
CyberFundamentals certification provides official validation that your organization meets CCB security standards. Here's everything you need to know about getting certified.
Why Get Certified?
Certification isn't mandatory for most organizations, but the trend is clear: the CCB reported in November 2025 that 75% of registered NIS2 entities in Belgium had already selected a security framework, a majority of them CyberFundamentals. Certification offers significant benefits: Not sure what CyberFundamentals is? Start with our introduction guide.
Certification Levels
CyberFundamentals offers certification at three levels: Compare all three levels in detail.
| Level | Controls | Typical For | Audit Complexity |
|---|---|---|---|
| Basic | 34 | Entry level, set by your risk analysis | Moderate |
| Important | 133 | NIS2 important entities | Comprehensive |
| Essential | 218 | NIS2 essential entities | Extensive |
The Certification Process
Self-Assessment
2-8 weeksEvaluate your current security posture against your target level's controls. Identify and close any gaps before engaging an auditor.
Choose an Auditor
1-2 weeksSelect a CCB-authorised conformity assessment body (CAB). The CCB publishes the list of authorised bodies. Compare quotes and availability.
Document Preparation
2-4 weeksGather evidence for all required controls: policies, procedures, configurations, logs, training records, etc.
Stage 1 Audit
1-2 daysThe auditor reviews your documentation to verify completeness. They identify any issues to address before Stage 2.
Stage 2 Audit
1-5 daysOn-site (or remote) verification that controls are actually implemented and effective. Includes interviews and testing.
Certificate Issued
2-4 weeksIf you pass, you receive your CyberFundamentals certificate. If not, you get specific findings to address.
Finding an Auditor
Only authorised conformity assessment bodies (CABs) can verify or certify CyberFundamentals. On the CCB list dated 7 September 2026, five bodies are authorised for CyFun verification at Basic and Important level: Brand Compliance België, CertUp, DNV Business Assurance, Vinçotte and What a Work SRL. DNV is authorised for CyFun 2023 only; the other four cover CyFun 2023 and CyFun 2025. The list names no body for CyFun Essential certification. Fifteen bodies are authorised for ISO/IEC 27001:2022 certification, and a sixteenth is listed as suspended. An essential entity has three routes to its Essential-level assessment: CyFun certification, ISO/IEC 27001, or supervision by the CCB inspection service (Royal Decree of 9 June 2024, Art. 23). Both CyFun 2023 and CyFun 2025 are accepted until 18 April 2027. Learn more about the role of the CCB in overseeing certifications.
- Check the current CCB list before you plan, authorisations change
- Ask about their experience with your industry
- Understand what's included in the price
- Ask about remote vs on-site audit options
Certification Costs
Costs vary by level, auditor, and your organization's complexity:
These are estimates. Get quotes from auditors for accurate pricing.
Maintaining Certification
Certification isn't a one-time event:
Preparing for Success
Maximize your chances of passing: Make sure you understand the 22 control categories you'll be assessed on.
- Don't rush into audit - ensure you're truly ready
- Conduct an internal audit first
- Organize evidence in advance, don't scramble during audit
- Ensure staff can explain their responsibilities
- Address any known issues before the audit
- Have a compliance management system (even a spreadsheet)
Get Certification-Ready with Easy Cyber Protection
We help you prepare for successful certification:
Frequently Asked Questions
Is CyberFundamentals certification mandatory?
Not for important entities. An essential entity needs an Essential-level conformity assessment by 18 April 2027 (CyFun certification, ISO 27001 or CCB inspection), or a lower level its own risk assessment justifies. Outside NIS2, it is voluntary.
How long does certification take?
From decision to certificate: typically 3-6 months. This includes preparation, auditor scheduling, and the audit itself. Well-prepared organizations can move faster.
Can I fail the audit?
Yes. If significant non-conformities are found, you won't receive certification until they're addressed. Minor issues may be noted but won't prevent certification.
What if my organization changes after certification?
Significant changes (mergers, new locations, major IT changes) should be reported to your certification body. They'll advise if additional assessment is needed.
Does certification guarantee I'm secure?
Certification means you meet specific control requirements at a point in time. It's not a guarantee against all attacks, but it significantly reduces your risk.