IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →

CyberFundamentals Certification: How It Works

CyberFundamentals certification provides official validation that your organization meets CCB security standards. Here's everything you need to know about getting certified.

CyberFundamentals certification medal - official recognition
CyberFundamentals certification demonstrates officially recognized cybersecurity

Why Get Certified?

Certification isn't mandatory for most organizations, but the trend is clear: the CCB reported in November 2025 that 75% of registered NIS2 entities in Belgium had already selected a security framework, a majority of them CyberFundamentals. Certification offers significant benefits: Not sure what CyberFundamentals is? Start with our introduction guide.

Prove compliance : Show customers and partners you meet recognized standards
Win contracts : Many tenders now require security certification
Reduce insurance costs : Cyber insurers often offer discounts for certified organizations
NIS2 evidence : Certification demonstrates compliance with NIS2 requirements
Identify gaps : The audit process reveals areas for improvement
Build trust : Independent verification carries more weight than self-assessment

Certification Levels

CyberFundamentals offers certification at three levels: Compare all three levels in detail.

LevelControlsTypical ForAudit Complexity
Basic 34 Entry level, set by your risk analysis Moderate
Important 133 NIS2 important entities Comprehensive
Essential 218 NIS2 essential entities Extensive

The Certification Process

1

Self-Assessment

2-8 weeks

Evaluate your current security posture against your target level's controls. Identify and close any gaps before engaging an auditor.

2

Choose an Auditor

1-2 weeks

Select a CCB-authorised conformity assessment body (CAB). The CCB publishes the list of authorised bodies. Compare quotes and availability.

3

Document Preparation

2-4 weeks

Gather evidence for all required controls: policies, procedures, configurations, logs, training records, etc.

4

Stage 1 Audit

1-2 days

The auditor reviews your documentation to verify completeness. They identify any issues to address before Stage 2.

5

Stage 2 Audit

1-5 days

On-site (or remote) verification that controls are actually implemented and effective. Includes interviews and testing.

6

Certificate Issued

2-4 weeks

If you pass, you receive your CyberFundamentals certificate. If not, you get specific findings to address.

Finding an Auditor

Only authorised conformity assessment bodies (CABs) can verify or certify CyberFundamentals. On the CCB list dated 7 September 2026, five bodies are authorised for CyFun verification at Basic and Important level: Brand Compliance België, CertUp, DNV Business Assurance, Vinçotte and What a Work SRL. DNV is authorised for CyFun 2023 only; the other four cover CyFun 2023 and CyFun 2025. The list names no body for CyFun Essential certification. Fifteen bodies are authorised for ISO/IEC 27001:2022 certification, and a sixteenth is listed as suspended. An essential entity has three routes to its Essential-level assessment: CyFun certification, ISO/IEC 27001, or supervision by the CCB inspection service (Royal Decree of 9 June 2024, Art. 23). Both CyFun 2023 and CyFun 2025 are accepted until 18 April 2027. Learn more about the role of the CCB in overseeing certifications.

  • Check the current CCB list before you plan, authorisations change
  • Ask about their experience with your industry
  • Understand what's included in the price
  • Ask about remote vs on-site audit options
View CCB-authorised CABs →

Certification Costs

Costs vary by level, auditor, and your organization's complexity:

Basic €2,500 - €5,000 Estimate for a standard SME verification
Important €5,000 - €25,000 Estimate for a first verification, same range as our CAB audit cost guide
Essential No CAB authorised yet CCB list, 7 September 2026: no body certifies CyFun Essential yet

These are estimates. Get quotes from auditors for accurate pricing.

Maintaining Certification

Certification isn't a one-time event:

Validity period 3 years from certificate date
Annual surveillance Lighter audit to verify continued compliance
Recertification Full audit required every 3 years
Major changes Notify auditor of significant organizational changes

Preparing for Success

Maximize your chances of passing: Make sure you understand the 22 control categories you'll be assessed on.

  • Don't rush into audit - ensure you're truly ready
  • Conduct an internal audit first
  • Organize evidence in advance, don't scramble during audit
  • Ensure staff can explain their responsibilities
  • Address any known issues before the audit
  • Have a compliance management system (even a spreadsheet)

Get Certification-Ready with Easy Cyber Protection

We help you prepare for successful certification:

Gap assessment : Know exactly what's missing before you engage an auditor
Evidence management : Organized documentation ready for review
Control implementation : Guided implementation of required controls
Audit preparation : Pre-audit checklist and readiness review

Frequently Asked Questions

Is CyberFundamentals certification mandatory?

Not for important entities. An essential entity needs an Essential-level conformity assessment by 18 April 2027 (CyFun certification, ISO 27001 or CCB inspection), or a lower level its own risk assessment justifies. Outside NIS2, it is voluntary.

How long does certification take?

From decision to certificate: typically 3-6 months. This includes preparation, auditor scheduling, and the audit itself. Well-prepared organizations can move faster.

Can I fail the audit?

Yes. If significant non-conformities are found, you won't receive certification until they're addressed. Minor issues may be noted but won't prevent certification.

What if my organization changes after certification?

Significant changes (mergers, new locations, major IT changes) should be reported to your certification body. They'll advise if additional assessment is needed.

Does certification guarantee I'm secure?

Certification means you meet specific control requirements at a point in time. It's not a guarantee against all attacks, but it significantly reduces your risk.

Sources

  1. CCB: FAQ NIS2 and CyberFundamentals
  2. CCB: One year of NIS2 in Belgium (28 November 2025)
  3. CCB list of authorised CABs (version 7 September 2026)
  4. Royal Decree of 9 June 2024 (NIS2, French text), Art. 6, 7, 11, 22 and 23

Related Articles