IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

CyFun for MSPs: Belgium's Cyber Framework Explained

Your client just received a letter from the CCB asking about CyFun compliance. Do you know what to say? CyberFundamentals (CyFun) is the Belgian framework that maps directly to NIS2. It is what thousands of your clients will need to prove before a CAB auditor. Here is what every MSP needs to know.

MSP discussing CyFun compliance framework with client on laptop

The CyberFundamentals framework is the CCB's answer to a simple question: how does a Belgian organisation know if it is cybersecurity-ready? And how does it prove that to an auditor? As an MSP, you are the bridge between the NIS2 requirements and your client's audit readiness.

What Is CyFun?

CyberFundamentals (CyFun) is the cybersecurity framework published by Belgium's Centre for Cybersecurity Belgium (CCB). It gives organisations a structured, measurable path to cybersecurity compliance. The framework maps to international standards including NIS2, ISO 27001, and NIST CSF, but is specifically adapted for the Belgian regulatory context.

CyFun Basic

34 controls

The entry level, and the standard tier for most SME clients. Required for organisations in the NIS2 supply chain. Covers all critical security domains.

CyFun Important

Extended controls

For organisations classified as Important Entities under NIS2. Requires more rigorous implementation and evidence.

CyFun Essential

Full controls

For Essential Entities: critical infrastructure, large public sector. Full framework implementation and mandatory CAB audit.

Why CyFun Matters for Your MSP Clients

NIS2 created two categories of regulated entities in Belgium: Important and Essential. About 4,000 organisations had registered with the CCB by November 2025. But the real impact on your client base comes from Article 21 of the directive, which requires NIS2-regulated organisations to manage cybersecurity risk in their supply chains.

That means: if your client supplies services or products to an NIS2-registered entity (a hospital, a municipality, a utility), that customer will ask your client to prove basic cybersecurity hygiene. CyFun Basic is the standard they will be measured against. This is already happening.

About 4,000

Belgian entities registered with the CCB under NIS2 (CCB, Nov 2025)

25,000+

estimated organisations affected by supply chain requirements

5

CyFun verification bodies for Basic and Important (CCB list, 7 September 2026)

34

controls required for CyFun Basic certification

The Auditor Bottleneck Your Clients Need to Know About

On the CCB list dated 7 September 2026, five bodies are authorised for CyFun verification at Basic and Important level: Brand Compliance België, CertUp, DNV Business Assurance, Vinçotte and What a Work SRL. DNV is authorised for CyFun 2023 only; the other four cover CyFun 2023 and CyFun 2025. The list names no body for CyFun Essential certification. Fifteen bodies are authorised for ISO/IEC 27001:2022 certification, and a sixteenth is listed as suspended. An essential entity has three routes to its Essential-level assessment: CyFun certification, ISO/IEC 27001, or supervision by the CCB inspection service (Royal Decree of 9 June 2024, Art. 23). Check the current list before advising a client, because authorisations are still changing.

How MSPs Deliver CyFun Compliance

MSP delivery of CyFun compliance follows a repeatable process. You do not need compliance certifications. You need a process and the right tooling.

Isometric illustration of the 5-step CyFun compliance process for MSPs
1

Run the CyFun assessment

Map the client's current state against all 34 CyFun Basic controls. Score each control on documentation and implementation maturity. This produces a gap report: the foundation of everything that follows.

2

Prioritise quick wins

Not all 34 controls are equal. Identify the 5-8 controls with the biggest compliance gap and the lowest effort to close. Start there. Early wins build momentum and client confidence.

3

Generate policies and evidence

CyFun requires documented policies, not just technical controls. Generate or adapt security policy documents, access control procedures, backup policies, and incident response plans. Collect evidence that each control is implemented.

4

Build the audit dossier

Consolidate all evidence into a structured audit pack: control status, policy documents, screenshots, logs, test results. This is what the CAB auditor will review. The cleaner the dossier, the faster the audit.

5

Schedule the CAB audit

Once the client is audit-ready, help them book with a CCB-authorised CAB (accredited by BELAC for CyFun). Given the current bottleneck, booking early matters. Your job is done when the client walks into the audit room prepared.

VLAIO Subsidies: Removing the Cost Objection

The Flemish kmo-portefeuille subsidy covers up to 45% of cybersecurity advisory costs (up to €7,500 per year for SMEs). As an MSP registered with VLAIO as a cybersecurity advisor, your compliance services qualify. This means a client paying €100/month for managed CyFun compliance gets up to €45/month reimbursed. Their net cost drops to around €55/month.

The Fastest Way to Start Offering CyFun Services

Easy Cyber Protection gives MSPs a multi-tenant CyFun platform with assessment tools, policy generation, evidence collection, and branded audit-ready reports: one fee per client per month, by the client's size in employees: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request, no monthly base. Partners buy below the published rate; the partner rate card is on request. A one-time €400 MSP onboarding (a guided session) applies when you start. Every client gets the full feature set: AI assistance and integrations included from day one. No compliance expertise required: you prepare the clients, the CAB auditors certify them.

Ready to offer CyFun as a recurring service? Our free Launch Kit shows you how to package and sell it.

Frequently Asked Questions

Does every SME need CyFun?

Not every SME is directly in scope for NIS2. But the supply chain effect means many SMEs will be asked to demonstrate CyFun Basic readiness by their larger clients or partners. Cyber insurers are also increasingly asking for evidence of a security framework. For most SMEs, CyFun Basic is the practical answer.

What is the difference between CyFun Basic and Important?

CyFun Basic has 34 controls; Important builds on it with 133. Which level a client needs depends on its NIS2 class and its own risk assessment. An essential entity defaults to CyFun Essential and may go lower only when its risk assessment justifies it, and must show by 18 April 2027 that it meets that level. An important entity picks its level with the CCB's CyFun Selection Tool, a risk assessment; a voluntary CyFun assessment is at least at Important level (Royal Decree of 9 June 2024, Art. 11). If you are unsure, start with Basic: every higher level builds on it.

Do MSPs need to be accredited to deliver CyFun services?

No. MSPs help clients become audit-ready: that means mapping controls, generating documentation, and collecting evidence. The audit itself is performed by a CAB that BELAC accredited for CyFun and the CCB authorised. Think of the MSP as the bookkeeper and the auditor as the external accountant.

How long does CyFun Basic implementation take?

It depends entirely on the client's starting position. A well-equipped client (M365 with MFA enforced, EDR, immutable backup, written acceptable-use policy) reaches Basic audit-ready in 1 to 3 months. Most of the work is documentation and evidence collection, not technical controls. A client with measurable gaps (missing MFA, consumer-grade backup, no EDR everywhere) needs 4 to 6 months because each gap is its own implementation project. A greenfield client is 6 to 9 months or more. The security work itself takes time, and the workbook cannot evidence what does not exist. Higher tiers (Important, Essential) are multi-year arcs because each tier carries more controls and more evidence to build. See the scoping guide for the full per-tier and multi-year breakdown.

Can we use VLAIO subsidies for CyFun compliance work?

Yes, if you are registered as a VLAIO-approved cybersecurity advisor. The kmo-portefeuille covers up to 45% of cybersecurity advisory costs. This makes the compliance service significantly more affordable for Flemish SME clients and removes one of the most common objections.

Sources for the level rule: CCB, FAQ NIS2 and CyberFundamentals; CCB CyFun Selection Tool; CCB, One year of NIS2 in Belgium (28 November 2025); CCB list of authorised CABs (version 7 September 2026); Royal Decree of 9 June 2024 (French text)

Related Articles