IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

NIS2 Certification: CyberFundamentals & ISO 27001 Paths

NIS2 does not create a "NIS2 certificate." Instead, Belgium uses the CyberFundamentals (CyFun) framework as its compliance path, with ISO 27001 as the alternative. This guide explains both paths, what certification actually means, and how to get audit-ready.

NIS2 certification paths in Belgium

Is NIS2 Certification Required?

Not directly. NIS2 is a European directive. It does not issue certificates. Each member state decides how to verify compliance. In Belgium, the Centre for Cybersecurity Belgium (CCB) chose the CyberFundamentals framework as the primary compliance mechanism. Organizations can also demonstrate compliance through ISO 27001 certification.

CyberFundamentals Certification Tiers

CyFun has three cumulative levels. Your level depends on your NIS2 class and your own risk assessment.

Basic

Controls: 34 controls
Assessment: CAB verification (a self-assessment only on the CCB-inspection route)
Cost: Verification fee; on the CCB-inspection route, the CCB bills its inspection by the hour (Royal Decree, Art. 20)
Audience: Essential entities in their April 2026 step, or where Art. 7 justifies it

Important

Controls: 133 controls
Assessment: CAB verification
Cost: Audit fees apply
Audience: Important entities that opt in (minimum level, Art. 11); essential entities in their April 2026 step

Essential

Controls: 218 controls
Assessment: CAB certification
Cost: Audit fees apply
Audience: Essential entities (the default level)

Learn more about CyberFundamentals

CyFun vs ISO 27001

AspectCyberFundamentalsISO 27001
Framework cost Free Standard purchase required
Belgian NIS2 accepted Yes (primary path) Yes (alternative path)
Audit required Important & Essential tiers Always (for certification)
International recognition Belgium only Globally recognized
Typical audit cost Lower Higher
Maintenance Annual reassessment Annual surveillance audits
Best for Belgian-focused organizations International organizations

ISO 27001 as Alternative

In November 2025 the CCB reported that 75% of entities had already selected a security framework, a majority of them CyFun. ISO 27001 is internationally recognized and may be preferred if you already hold the certification or operate across borders. The CCB accepts it provided it finds your scope and Statement of Applicability acceptable.

  • ✓ ISO 27001 certification is typically more expensive than CyFun audits
  • ✓ It requires annual surveillance audits and triennial recertification
  • ✓ If you already have ISO 27001, the CCB still has to accept your scope and Statement of Applicability
  • ✓ ISO 27001 covers a broader scope than CyFun

How Certification Works

For CyFun Important and Essential tiers, a Conformity Assessment Body (CAB) conducts the audit. The CCB publishes the current list of authorised bodies. Here is the process:

  1. 1 Register with the CCB and determine your classification
  2. 2 Choose your path: CyberFundamentals or ISO 27001
  3. 3 Implement the required controls and document evidence
  4. 4 On the CCB-inspection route (essential entities): the self-assessment went to the CCB by April 2026; a progress report follows (Royal Decree, Art. 23)
  5. 5 On the CAB route: engage an authorised CAB for verification or certification
  6. 6 Receive your certification and maintain it annually

Certification vs Self-Assessment

Not every organization needs a full third-party audit. The requirements depend on your NIS2 classification:

Self-assessment

Who: Essential entities that chose supervision by the CCB inspection service (Royal Decree, Art. 23)

Deadline: April 2026

What: Submit a CyFun Basic or Important self-assessment to the CCB. Important entities have no mandatory assessment; a voluntary one is CAB-verified (Art. 11)

Third-party audit

Who: Essential entities on the CAB route

Deadline: April 18, 2027

What: Engage an authorised CAB to verify your controls and evidence. An essential entity that cannot obtain a CyFun Essential certificate by then is requested to submit a remediation plan to the CCB Inspection Service. The plan should preferably consist of a CyFun Important certificate plus the measures planned to reach Essential by April 18, 2028 (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). An entity whose own risk assessment justifies a lower CyFun level may choose it instead, without prior CCB approval but at its own responsibility. It must then show by 18 April 2027 that it meets that level (on the CyFun route, through a CAB verification).

Cost Considerations

Getting audit-ready does not have to be expensive.

  • ✓ The CyFun framework itself is completely free
  • ✓ On the CCB-inspection route, the CCB bills its inspection work at €150 per hour, indexed yearly; public-sector entities are exempt unless they are listed in Article 1 of the Royal Decree of 4 May 2016 (Royal Decree, Art. 20 §5)
  • ✓ Third-party CyFun audits vary by organization size (typically lower than ISO)
  • ✓ ISO 27001 certification costs EUR 5,000-30,000+ depending on scope
  • ✓ The biggest cost is implementation time, not the audit itself

How Easy Cyber Protection Helps

We make your organization audit-ready. That means you walk into your assessment or audit with confidence.

  • ✓ Guided implementation of CyFun controls at your tier
  • ✓ Evidence collection and documentation templates
  • ✓ Gap analysis showing exactly what is missing
  • ✓ Progress tracking across all required controls
  • ✓ Clear guidance on what auditors expect to see

Also check our NIS2 compliance checklist and the implementation steps to get started.

Get Audit-Ready

Easy Cyber Protection guides you through every CyberFundamentals control with clear evidence requirements. Know exactly where you stand before the auditor arrives.

Frequently Asked Questions

Is there a NIS2 certificate I can get?

No. NIS2 is a directive, not a certification scheme. In Belgium, you demonstrate NIS2 compliance through CyberFundamentals certification or ISO 27001. These are the accepted proof of compliance.

What is a CAB and how do I find one?

A CAB (Conformity Assessment Body) is an organisation that conducts third-party audits. For CyFun, BELAC accredits the CABs; the ISO 27001 CABs on the CCB list are accredited by national bodies such as BELAC, RvA, DAkkS, ACCREDIA, INAB, OLAS and COFRAC. The CCB authorises them for NIS2 and publishes the list. On the list dated 7 September 2026, five bodies are authorised for verification at Basic and Important level, and none is authorised for Essential certification yet.

Can I use ISO 27001 instead of CyberFundamentals?

Yes. The CCB accepts ISO 27001 as an alternative compliance path for NIS2, provided it finds your scope and Statement of Applicability acceptable. If you already have ISO 27001, check that your scope covers all your networks and information systems.

What happens if we missed the April 2026 step?

The April 18, 2026 step for essential entities was a CAB verification, a self-assessment on the CCB-inspection route, or the ISO 27001 scope and Statement of Applicability. The sources we read (the CCB FAQ, the inspection service letter of 11 August 2026 and the Royal Decree) describe no late procedure, grace period or fine for it. Ask the CCB inspection service (inspection@ccb.belgium.be) how to regularise your position. The next date is April 18, 2027.

How long does it take to get CyFun certified?

For CyFun Basic, 1 to 9 months depending on your starting position: well-equipped organisations 1-3 months, with-gaps 4-6 months, greenfield 6-9 months or more. For Important and Essential, verified or certified by an authorised CAB, the realistic outline is multi-year. Important contains every Basic control and Essential every Important control, so many build them in that order, although the Royal Decree allows an Important verification at the first step (Art. 22 §1). Essential entities cannot wait for a year-3 Essential: they need an Essential-level assessment by 18 April 2027, or Important now plus a plan to reach Essential by 18 April 2028. Each audit cycle also surfaces remediation work that takes 2-3 months to close before the next tier opens.

Sources

  1. CCB: FAQ NIS2 and CyberFundamentals
  2. CCB: One year of NIS2 in Belgium (28 November 2025)
  3. CCB list of authorised CABs (version 7 September 2026)
  4. CyFun: CABs in Belgium
  5. CCB Inspection Service letter, ref. NCCA/JK/INS/2026-002 (11 August 2026)
  6. Royal Decree of 9 June 2024 (NIS2, French text), Art. 7, 11, 20, 22 and 23

Related Articles