NIS2 Certification: CyberFundamentals & ISO 27001 Paths
NIS2 does not create a "NIS2 certificate." Instead, Belgium uses the CyberFundamentals (CyFun) framework as its compliance path, with ISO 27001 as the alternative. This guide explains both paths, what certification actually means, and how to get audit-ready.
Is NIS2 Certification Required?
Not directly. NIS2 is a European directive. It does not issue certificates. Each member state decides how to verify compliance. In Belgium, the Centre for Cybersecurity Belgium (CCB) chose the CyberFundamentals framework as the primary compliance mechanism. Organizations can also demonstrate compliance through ISO 27001 certification.
CyberFundamentals Certification Tiers
CyFun has three cumulative levels. Your level depends on your NIS2 class and your own risk assessment.
Basic
Important
Essential
CyFun vs ISO 27001
| Aspect | CyberFundamentals | ISO 27001 |
|---|---|---|
| Framework cost | Free | Standard purchase required |
| Belgian NIS2 accepted | Yes (primary path) | Yes (alternative path) |
| Audit required | Important & Essential tiers | Always (for certification) |
| International recognition | Belgium only | Globally recognized |
| Typical audit cost | Lower | Higher |
| Maintenance | Annual reassessment | Annual surveillance audits |
| Best for | Belgian-focused organizations | International organizations |
ISO 27001 as Alternative
In November 2025 the CCB reported that 75% of entities had already selected a security framework, a majority of them CyFun. ISO 27001 is internationally recognized and may be preferred if you already hold the certification or operate across borders. The CCB accepts it provided it finds your scope and Statement of Applicability acceptable.
- ✓ ISO 27001 certification is typically more expensive than CyFun audits
- ✓ It requires annual surveillance audits and triennial recertification
- ✓ If you already have ISO 27001, the CCB still has to accept your scope and Statement of Applicability
- ✓ ISO 27001 covers a broader scope than CyFun
How Certification Works
For CyFun Important and Essential tiers, a Conformity Assessment Body (CAB) conducts the audit. The CCB publishes the current list of authorised bodies. Here is the process:
- 1 Register with the CCB and determine your classification
- 2 Choose your path: CyberFundamentals or ISO 27001
- 3 Implement the required controls and document evidence
- 4 On the CCB-inspection route (essential entities): the self-assessment went to the CCB by April 2026; a progress report follows (Royal Decree, Art. 23)
- 5 On the CAB route: engage an authorised CAB for verification or certification
- 6 Receive your certification and maintain it annually
Certification vs Self-Assessment
Not every organization needs a full third-party audit. The requirements depend on your NIS2 classification:
Self-assessment
Who: Essential entities that chose supervision by the CCB inspection service (Royal Decree, Art. 23)
Deadline: April 2026
What: Submit a CyFun Basic or Important self-assessment to the CCB. Important entities have no mandatory assessment; a voluntary one is CAB-verified (Art. 11)
Third-party audit
Who: Essential entities on the CAB route
Deadline: April 18, 2027
What: Engage an authorised CAB to verify your controls and evidence. An essential entity that cannot obtain a CyFun Essential certificate by then is requested to submit a remediation plan to the CCB Inspection Service. The plan should preferably consist of a CyFun Important certificate plus the measures planned to reach Essential by April 18, 2028 (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). An entity whose own risk assessment justifies a lower CyFun level may choose it instead, without prior CCB approval but at its own responsibility. It must then show by 18 April 2027 that it meets that level (on the CyFun route, through a CAB verification).
Cost Considerations
Getting audit-ready does not have to be expensive.
- ✓ The CyFun framework itself is completely free
- ✓ On the CCB-inspection route, the CCB bills its inspection work at €150 per hour, indexed yearly; public-sector entities are exempt unless they are listed in Article 1 of the Royal Decree of 4 May 2016 (Royal Decree, Art. 20 §5)
- ✓ Third-party CyFun audits vary by organization size (typically lower than ISO)
- ✓ ISO 27001 certification costs EUR 5,000-30,000+ depending on scope
- ✓ The biggest cost is implementation time, not the audit itself
How Easy Cyber Protection Helps
We make your organization audit-ready. That means you walk into your assessment or audit with confidence.
- ✓ Guided implementation of CyFun controls at your tier
- ✓ Evidence collection and documentation templates
- ✓ Gap analysis showing exactly what is missing
- ✓ Progress tracking across all required controls
- ✓ Clear guidance on what auditors expect to see
Also check our NIS2 compliance checklist and the implementation steps to get started.
Get Audit-Ready
Easy Cyber Protection guides you through every CyberFundamentals control with clear evidence requirements. Know exactly where you stand before the auditor arrives.
Frequently Asked Questions
Is there a NIS2 certificate I can get?
No. NIS2 is a directive, not a certification scheme. In Belgium, you demonstrate NIS2 compliance through CyberFundamentals certification or ISO 27001. These are the accepted proof of compliance.
What is a CAB and how do I find one?
A CAB (Conformity Assessment Body) is an organisation that conducts third-party audits. For CyFun, BELAC accredits the CABs; the ISO 27001 CABs on the CCB list are accredited by national bodies such as BELAC, RvA, DAkkS, ACCREDIA, INAB, OLAS and COFRAC. The CCB authorises them for NIS2 and publishes the list. On the list dated 7 September 2026, five bodies are authorised for verification at Basic and Important level, and none is authorised for Essential certification yet.
Can I use ISO 27001 instead of CyberFundamentals?
Yes. The CCB accepts ISO 27001 as an alternative compliance path for NIS2, provided it finds your scope and Statement of Applicability acceptable. If you already have ISO 27001, check that your scope covers all your networks and information systems.
What happens if we missed the April 2026 step?
The April 18, 2026 step for essential entities was a CAB verification, a self-assessment on the CCB-inspection route, or the ISO 27001 scope and Statement of Applicability. The sources we read (the CCB FAQ, the inspection service letter of 11 August 2026 and the Royal Decree) describe no late procedure, grace period or fine for it. Ask the CCB inspection service (inspection@ccb.belgium.be) how to regularise your position. The next date is April 18, 2027.
How long does it take to get CyFun certified?
For CyFun Basic, 1 to 9 months depending on your starting position: well-equipped organisations 1-3 months, with-gaps 4-6 months, greenfield 6-9 months or more. For Important and Essential, verified or certified by an authorised CAB, the realistic outline is multi-year. Important contains every Basic control and Essential every Important control, so many build them in that order, although the Royal Decree allows an Important verification at the first step (Art. 22 §1). Essential entities cannot wait for a year-3 Essential: they need an Essential-level assessment by 18 April 2027, or Important now plus a plan to reach Essential by 18 April 2028. Each audit cycle also surfaces remediation work that takes 2-3 months to close before the next tier opens.
Sources
- CCB: FAQ NIS2 and CyberFundamentals
- CCB: One year of NIS2 in Belgium (28 November 2025)
- CCB list of authorised CABs (version 7 September 2026)
- CyFun: CABs in Belgium
- CCB Inspection Service letter, ref. NCCA/JK/INS/2026-002 (11 August 2026)
- Royal Decree of 9 June 2024 (NIS2, French text), Art. 7, 11, 20, 22 and 23