IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

What is CyberFundamentals? Belgium's Cybersecurity Framework

CyberFundamentals is Belgium's official cybersecurity framework, created by the Centre for Cybersecurity Belgium (CCB). It provides a clear, structured approach to protecting your business, in three levels that build on each other: from 34 basic controls to 218 at the highest level.

CyberFundamentals framework visualization
CyberFundamentals: Belgian cybersecurity in 3 tiers

What is CyberFundamentals?

CyberFundamentals (often called CyFun) is the official Belgian cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It provides organizations with a structured, risk-based approach to cybersecurity. It was developed by the Centre for Cybersecurity Belgium (CCB).

  • Based on international standards: NIST CSF 2.0, ISO 27001, and CIS Controls
  • Tiered approach: Start small, grow as needed
  • Designed for all organizations: From micro-businesses to critical infrastructure
  • NIS2 aligned: Meets European cybersecurity requirements

The 6 Core Functions

CyberFundamentals organizes security measures into six functions, following the NIST Cybersecurity Framework structure: Each function contains specific control categories that organizations must implement.

GV

Govern

Establish cybersecurity governance, policies, and risk strategy

ID

Identify

Know your assets, risks, and business environment

PR

Protect

Implement safeguards: access control, training, data security, backups

DE

Detect

Monitor for anomalies and security events

RS

Respond

Take action when incidents occur

RC

Recover

Restore operations and learn from incidents

Why CyberFundamentals Matters

Many businesses know they need cybersecurity but don't know where to start. CyberFundamentals solves this by providing:

Clear guidance

No guessing what to do - the framework tells you exactly which controls to implement

Right-sized security

Start with the 34 controls of the Basic tier and expand only when you need to

NIS2 compliance

For organizations in NIS2 scope, CyberFundamentals is the recognized path to compliance in Belgium

Proof for stakeholders

Demonstrate to customers, insurers, and auditors that you take security seriously

The 3 Security Tiers

CyberFundamentals uses a tiered approach, allowing you to start simple and grow: See the detailed level comparison.

Tier Controls Coverage Best For
Basic 34 82% Entry level, set by risk analysis
Important 133 94% SMEs in NIS2 scope
Essential 218 100% Critical infrastructure

Coverage percentage indicates share of attack types defended against

Where the Basic Tier Starts

Basic is the entry level, 34 controls in total. It starts with the absolute basics every organization should have:

1

Multi-Factor Authentication

Add a second verification step to all important accounts

2

Security Updates

Keep software and systems up to date

3

Antivirus

Use antivirus software on all devices

4

Network Security

Secure your network with firewalls and proper configuration

5

Backups

Regular backups of critical data, tested for recovery

6

Admin Rights

Limit administrator privileges to those who need them

7

Physical Security

Protect physical access to devices and data

How to Get Started

Getting started with CyberFundamentals is straightforward:

1

Assess your current state

Use a self-assessment tool to see where you stand on the 34 Basic tier controls.

2

Start with the Basic tier

Implement the 34 controls of the entry level. It gives you a solid foundation.

3

Document your progress

Keep records of what you've implemented - this is your compliance evidence.

4

Grow when needed

If you're in NIS2 scope or want better protection, move to the Important or Essential tier.

CyberFundamentals and NIS2

If your organization falls under the NIS2 directive, CyberFundamentals is your implementation path in Belgium. The CCB has designed the framework to map directly to NIS2 requirements.

  • Important entities: Important tier (133 controls) or higher if you opt for an assessment (Royal Decree, Art. 11)
  • Essential entities: Essential tier (218 controls) by default, lower only where your risk assessment justifies it (Art. 7)
  • The framework provides the specific controls needed to meet NIS2 obligations

Which CyberFundamentals level applies to your organisation follows from your NIS2 class and your own risk assessment: essential entities default to Essential. Our free in-scope checker gives you a rough estimate on screen in five questions, no email required. Want scope, level and prioritized control list signed on paper afterwards? The written report is €395 flat (ex VAT), delivered in 48 hours.

How Easy Cyber Protection Helps

We make CyberFundamentals implementation simple:

Guided implementation : Step-by-step tasks walk you through each control
Progress tracking : See your compliance percentage at a glance
Evidence collection : Built-in documentation for audits and stakeholders

Frequently Asked Questions

Is CyberFundamentals mandatory?

For organizations in NIS2 scope (essential and important entities), using a recognized framework like CyberFundamentals is effectively mandatory in Belgium. For others, it's voluntary but highly recommended.

How much does CyberFundamentals cost?

The framework itself is free - it's published by the CCB. Implementation costs depend on your current state and chosen tier.

Can I get certified?

Yes, you can get CyberFundamentals certification through CCB-authorised auditors. This provides external validation of your security posture.

How long does implementation take?

Basic tier typically takes a few months. Important and Essential tiers are ongoing programs that may take 6-12 months to fully implement.

Do I need an IT department?

No. The Basic tier is designed to be implementable by any organization. For higher tiers, you may want IT support, but many SMEs work with their existing IT partner.

What's the difference between CyberFundamentals and ISO 27001?

CyberFundamentals is built on ISO 27001 (among other standards) but is tailored for the Belgian context and specifically aligned with NIS2. It's generally more accessible for SMEs than a full ISO 27001 implementation.

Related Articles

Sources

  1. CCB CyberFundamentals Framework : Official CCB documentation
  2. NIS2 Directive (EU) 2022/2555 : European cybersecurity directive
  3. NIST Cybersecurity Framework : Foundation for CyberFundamentals structure