IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

CyberFundamentals Levels: Basic, Important, Essential

CyberFundamentals offers three security levels, each building on the previous one. Which tier applies follows from your NIS2 class and your own risk assessment: essential entities default to Essential. Here's how to decide.

Understanding the Tiers

The CCB The CCB designed CyberFundamentals with a progressive approach. You start where you are and grow as needed. Each tier is a complete level - not a partial implementation of a higher tier.

Tier-by-Tier Comparison

Tier Controls Coverage Best For
Basic 34 82% Entry level, set by risk analysis
Important 133 94% Where your risk assessment points to it
Essential 218 100% Default for essential NIS2 entities

Coverage = percentage of common attack types defended against. Which tier applies comes from your NIS2 class and your risk assessment. Essential entities default to Essential and may go lower only when their own assessment justifies it, and must show by 18 April 2027 that they meet that level (CCB FAQ).

Each level contains specific control categories that must be implemented.

Basic Tier: Solid Protection

34 controls 82% attack coverage

Basic tier provides real protection against the majority of threats. For many small businesses, this is the sweet spot - good security without overwhelming complexity.

Ideal for:

  • Organisations whose risk analysis points here
  • Organisations the CCB Selection Tool points to Basic
  • Companies with limited IT resources
  • Organizations wanting insurance benefits

What Basic covers:

  • Asset inventory and management
  • Security awareness training
  • Incident response procedures
  • Secure configuration standards
  • Email security controls
  • Mobile device management basics

Important Tier: Broader Coverage

Often the outcome for organizations in scope of the NIS2 directive. For an important entity, its risk assessment decides.

133 controls 94% attack coverage

The Important tier is designed for organizations that need comprehensive protection - either because of NIS2 requirements or because they handle sensitive data and can't afford significant security gaps.

Ideal for:

  • Organisations the CCB Selection Tool points to Important
  • Important entities whose risk assessment points here
  • Organizations handling sensitive customer data
  • Businesses where a breach would be very costly

Additions from Basic:

  • Risk management framework
  • Third-party/vendor security
  • Advanced access controls
  • Security monitoring and logging
  • Business continuity planning
  • Vulnerability management program

Essential Tier: Maximum Protection

218 controls 100% attack coverage

Essential tier provides the highest level of protection in the CyberFundamentals framework. It's designed for organizations where security failures could have widespread societal impact.

Ideal for:

  • Organisations the CCB Selection Tool points to Essential
  • Essential NIS2 entities: this is their default level
  • Companies with the highest risk tolerance requirements

Additions from Important:

  • Advanced threat detection
  • Security Operations Center (SOC) capabilities
  • Comprehensive supply chain security
  • Detailed incident forensics
  • Regulatory compliance documentation

How to Choose Your Tier

The right tier depends on three factors:

NIS2 Classification

An essential entity that uses CyFun defaults to Essential: a certificate by 18 April 2027, or an Important verification statement plus a plan to reach Essential by 18 April 2028. It may choose a lower tier only when its own risk assessment justifies it (Art. 7, Royal Decree of 9 June 2024), and must show by 18 April 2027 that it meets that tier through a CAB verification. No prior CCB approval is needed, but the choice is its own responsibility and the CCB can check it. The 18 April 2027 date counts from the law's entry into force; for an entity identified later, it counts from its identification date (Art. 22 of the same Royal Decree). The 18 April 2028 date comes from the CCB Inspection Service letter of 11 August 2026. An important entity picks its tier with the CCB Selection Tool, which covers sector, size, and the impact and likelihood of attacks. It has no mandatory assessment; a voluntary CyFun assessment is at least at Important level (Art. 11 of the same Royal Decree).

Business Risk

What would a security incident cost you? Not just direct costs - think reputation, customer trust, legal liability. Higher risk = higher tier.

Resources

Can you implement and maintain the controls? Higher tiers require more ongoing effort. Be realistic about what your team can sustain.

Quick Decision Guide

Use this simple decision tree:

Are you in scope for NIS2?

→ Essential entity: Essential by default. Important entity: run the CCB Selection Tool

Are you an Essential Entity?

→ A periodic conformity assessment is mandatory

Are you an Important Entity?

→ Supervision is after the fact, assessment is voluntary, and a CyFun assessment is at Important level at least (Royal Decree, Art. 11)

Are you a small business, not in scope?

→ Start with Basic, upgrade as needed

Not sure which level applies to you? Take the free NIS2 scope determination in five on-screen questions, no email required. Want that decision in writing afterwards, signed, with a prioritized control list attached? The written report is €395 flat (ex VAT), delivered within 48 hours of payment.

Can You Upgrade Later?

Yes, absolutely. CyberFundamentals is designed for progression: Once you reach the desired level, you can pursue official CyberFundamentals certification.

  • Each tier builds on the previous one - your work isn't wasted
  • You can upgrade at your own pace as your needs or resources change
  • Many organizations start with Basic and move to Important within 12-18 months
  • Evidence and documentation from lower tiers carries forward

Get Started with Easy Cyber Protection

We guide you through whichever tier is right for you:

Tier assessment : We help you determine the right level
Progressive implementation : Work through controls at your pace
Compliance tracking : See your progress toward any tier

Frequently Asked Questions

Can I get certified at any tier?

Not the way most people mean it. Basic and Important are verification routes; only Essential is certification. On the CCB list dated 7 September 2026, five bodies are authorised for verification at Basic and Important, and none is authorised for Essential certification yet. Is it mandatory? Not for important entities. An essential entity needs an Essential-level conformity assessment by 18 April 2027 (CyFun certification, ISO 27001 or CCB inspection), or a lower level its own risk assessment justifies. Outside NIS2, it is voluntary.

What if I'm not sure about my NIS2 status?

Check our "Who Must Comply" article for detailed criteria. Generally, if you're in one of the 18 critical sectors and are medium-sized or larger (50+ staff, or both turnover and balance sheet above €10 million, Recommendation 2003/361/EC), you're likely in scope. Some providers are in scope regardless of size, among them providers of public electronic communications networks and services, DNS services and trust services. When in doubt, consult the CCB or a compliance expert.

Is Basic tier enough if I'm not in NIS2 scope?

For most small businesses, Basic tier provides excellent protection (82% of attack types). It's a great choice if you want solid security without the overhead of higher tiers. Being in scope does not rule Basic out either. An important entity whose risk assessment points to Basic can implement Basic, though a voluntary CyFun assessment would have to be at Important level or higher (Royal Decree, Art. 11). An essential entity can go below Essential only when its own risk assessment justifies it, and must show by 18 April 2027 that it meets that level. You can always upgrade if your situation changes.

How long does each tier take to implement?

Basic tier: 1-3 months. Important tier: 3-6 months. Essential tier: 6-12 months. These are typical ranges - your timeline depends on your current security posture and available resources.

What's the cost difference between tiers?

Cost increases with each tier due to more controls, tools, and documentation requirements. However, the cost of a breach typically far exceeds the cost of implementation at any tier.

Related Articles

Sources

  1. CCB CyberFundamentals Framework : Official tier documentation
  2. Centre for Cybersecurity Belgium (CCB) : Belgian authority
  3. NIS2 Directive (EU) 2022/2555 : Scope and obligations
  4. CCB CyFun Selection Tool : Risk assessment for choosing your tier
  5. CCB: FAQ NIS2 and CyberFundamentals : What essential and important entities must provide
  6. Royal Decree of 9 June 2024 (NIS2, French text) : Art. 6 and 7 (essential entities), Art. 11 (voluntary assessment of important entities)