The 22 CyberFundamentals Control Categories Explained
CyberFundamentals 2025 organises security measures into 22 control categories across six functions. How many apply depends on your level: 17 at Basic, 20 at Important, 22 at Essential. Each category addresses a specific aspect of cybersecurity. Here's what they cover and why they matter.
The NIST Framework Structure
CyberFundamentals 2025 follows the six core functions of NIST CSF 2.0. GOVERN is the one CSF 1.1 did not have, and it carries 40 of the 218 controls at Essential level: Learn more about what CyberFundamentals is and how it works.
The 22 Categories
Organisational Context
1 Basic / 6 Important / 9 Essential
What the business actually does, and which legal duties come with it.
Why it matters: Without it you cannot say which systems are critical, so every control spend becomes arguable.
Examples:
- • A written mission and the services it depends on
- • The legal and regulatory obligations you are subject to
- • The critical systems whose failure stops the business
Risk Management Strategy
1 Basic / 6 Important / 6 Essential
How the organisation decides which risks it accepts, and who signs that off.
Why it matters: An auditor asks what your risk appetite is. Without a written answer, every later decision looks arbitrary.
Examples:
- • A risk appetite statement approved by management
- • A documented risk management process
- • Risks recorded with an owner and a treatment
Roles, Responsibilities and Authorities
1 Basic / 5 Important / 7 Essential
Who is accountable for security, and what they are allowed to decide.
Why it matters: Under NIS2 management is personally accountable, so the names have to be written down.
Examples:
- • A named security owner, not a role in the abstract
- • Security duties in job descriptions
- • A joiner, mover and leaver process
Policy
1 Basic / 2 Important / 2 Essential
The written security policy, approved, current, and actually circulated.
Why it matters: A policy nobody approved or read scores as a draft, which is to say as nothing.
Examples:
- • A policy with an approval date and an approver
- • Evidence it was communicated to staff
- • A review cycle that has actually run
Oversight
- Basic / - Important / 2 Essential
Management checking that the security strategy still matches the risks.
Why it matters: Essential level only. It is the difference between having a strategy and steering by it.
Examples:
- • Management review minutes with decisions
- • Security performance reported to the board
- • Strategy adjusted after a review
Cybersecurity Supply Chain Risk Management
- Basic / 4 Important / 14 Essential
What you require of suppliers, in writing, and how you check they deliver it.
Why it matters: The largest category at Essential, with 14 controls, and where NIS2 pushes obligations down the chain.
Examples:
- • Security requirements written into contracts
- • A supplier register with a risk rating
- • Breach notification clauses you can point to
Asset Management
5 Basic / 19 Important / 28 Essential
A current list of the hardware, software, services and data you actually run.
Why it matters: You cannot protect what you have not written down, and auditors start here.
Examples:
- • Hardware and software inventories that are dated
- • A list of every external service you use
- • Owners assigned to critical assets
Risk Assessment
2 Basic / 11 Important / 15 Essential
Finding the weaknesses that matter, and deciding what to do about each.
Why it matters: This is where your CyFun level comes from, so it is the one you cannot skip.
Examples:
- • Vulnerability scans with dated results
- • A risk register linked to assets
- • Remediation decisions with deadlines
Improvement
1 Basic / 8 Important / 12 Essential
What you learned last time, actually changing how you work.
Why it matters: New in CSF 2.0. It is what separates a live management system from a folder of documents.
Examples:
- • A tabletop exercise with a written outcome
- • Lessons learned after a real incident
- • Tests run together with suppliers
Identity Management, Authentication and Access Control
8 Basic / 15 Important / 26 Essential
Who can get in, and whether you can prove you took it away again.
Why it matters: The biggest category at Basic, with 8 of its 34 controls, and the first thing an auditor asks for.
Examples:
- • MFA on remote access and critical systems
- • No administrative rights for daily work
- • Timestamped proof that leavers lost access
Awareness and Training
1 Basic / 6 Important / 7 Essential
Making sure people know what is expected of them, and proving they were told.
Why it matters: Training without an attendance record is not evidence, it is an intention.
Examples:
- • Training records showing who completed what
- • Phishing simulations with results
- • Signed acknowledgement of the policy
Data Security
2 Basic / 7 Important / 15 Essential
Data stays private and unaltered, at rest and in transit.
Why it matters: Backups live here, and a backup you have never restored is a theory.
Examples:
- • Encryption at rest and in transit
- • Backups that have been restore-tested
- • A record of where sensitive data lives
Platform Security
2 Basic / 10 Important / 18 Essential
Systems hardened and patched, with logging switched on.
Why it matters: Logging sits here, and logs are the evidence every other control leans on.
Examples:
- • A patch process with timing targets
- • Hardened baseline configurations
- • Logs kept, reviewed and retained
Technology Infrastructure Resilience
2 Basic / 6 Important / 13 Essential
Network and physical protections, and the capacity to keep running.
Why it matters: Firewalls and segmentation live here, and segmentation is where audits commonly find gaps.
Examples:
- • Firewalls installed and actively maintained
- • Network segmentation for critical systems
- • Physical access controls to server rooms
Adverse Event Analysis
1 Basic / 5 Important / 8 Essential
Turning raw signals into a judgement about whether something is actually wrong.
Why it matters: Alerts nobody correlates are noise, and noise is what auditors treat as no detection at all.
Examples:
- • Logging enabled on protection tools
- • Events correlated across sources
- • A defined threshold for declaring an incident
Continuous Monitoring
3 Basic / 9 Important / 14 Essential
Watching for trouble across networks, endpoints and the suppliers you depend on.
Why it matters: Anti-malware and endpoint monitoring are Basic-level controls, not advanced ones.
Examples:
- • Anti-malware deployed and updated
- • Endpoint and network monitoring in place
- • External service providers monitored too
Incident Management
1 Basic / 5 Important / 6 Essential
Running the incident response plan when something actually happens.
Why it matters: NIS2 sets reporting clocks, so the plan has to name who starts them.
Examples:
- • An incident response plan with named roles
- • Incidents categorised and prioritised
- • Evidence the plan was executed
Incident Analysis
- Basic / - Important / 4 Essential
Working out what happened, and keeping the proof intact while you do.
Why it matters: Essential level only, and the part most organisations discover they cannot do mid-incident.
Examples:
- • Forensic evidence preserved with integrity
- • Root cause established and recorded
- • Incident records kept for the retention period
Incident Response Reporting and Communication
1 Basic / 2 Important / 2 Essential
Telling the people and authorities who have to be told, on time.
Why it matters: This is where the NIS2 24-hour early warning obligation actually lands.
Examples:
- • A contact list for authorities and customers
- • Reporting deadlines written into the plan
- • Proof a notification was actually sent
Incident Mitigation
- Basic / 2 Important / 2 Essential
Stopping the spread.
Why it matters: Two controls, and the ones that decide whether an incident stays small.
Examples:
- • A documented containment step
- • Isolation of affected systems
- • Eradication confirmed before recovery
Incident Recovery Plan Execution
1 Basic / 3 Important / 4 Essential
Getting back to normal operation, in a known order, from clean backups.
Why it matters: Recovery is the control most often assumed and least often tested.
Examples:
- • A recovery plan with restoration order
- • Restores verified before going live
- • Recovery time objectives that are written down
Incident Recovery Communication
- Basic / 2 Important / 4 Essential
Telling staff, customers and authorities that service is back, and what happened.
Why it matters: The final NIS2 report closes here, and a missed final report is a reportable failure.
Examples:
- • A communication plan for recovery
- • The NIS2 final report submitted
- • Stakeholders told service is restored
Controls by Tier
Each tier builds on the previous one: See the full level comparison.
Implementation Approach
Work through categories systematically: These controls map directly to NIS2 requirements, and successful implementation can lead to official certification.
- 1 Start with the Basic tier controls - they're foundational
- 2 Within each category, implement basic controls first
- 3 Build evidence and documentation as you go
- 4 Progress to advanced controls as resources allow
- 5 Review and improve continuously
Need Help with Implementation?
Easy Cyber Protection guides you through each control category with clear tasks, evidence templates, and progress tracking.
Frequently Asked Questions
Do I need to implement all categories?
Not at Basic. Basic has controls in 17 of the 22 categories. Supply Chain Risk Management (GV.SC), Incident Mitigation (RS.MI) and Incident Recovery Communication (RC.CO) start at Important (20 categories). Oversight (GV.OV) and Incident Analysis (RS.AN) start at Essential (all 22). Within each category, the depth grows with the level.
Which categories are most important?
At Basic, the framework puts the most controls in Identity Management, Authentication and Access Control (PR.AA, 8 of the 34) and Asset Management (ID.AM, 5). But all categories work together: a gap in one area can undermine the others.
How do categories relate to NIS2 requirements?
CyberFundamentals categories map directly to NIS2 Article 21 requirements. Implementing CyberFundamentals at the appropriate tier demonstrates NIS2 compliance.
Can I focus on certain categories first?
Yes. Start where Basic puts most of its controls: PR.AA (8), ID.AM (5) and Continuous Monitoring (DE.CM, 3). Together they hold 16 of the 34 Basic controls.
How are controls within categories prioritized?
The CCB framework assigns controls to tiers based on importance and effort. Basic tier has the foundational controls. Each subsequent tier adds more advanced measures.