The short verdict: a Belgian mid-market organisation serving mostly domestic customers should choose CyberFundamentals — it delivers NIS2 presumption of conformity at 40–60% lower cost than ISO 27001. A Belgian SaaS or export firm selling to international enterprises needs ISO 27001, because global procurement asks for it by name. And since the two overlap on 70–80% of their technical controls, the smartest long-term play is often both, in that order. Here is the full comparison behind that verdict.
Key takeaways
- Both routes are legally recognised: under the Belgian NIS2 law, CyFun verification/certification AND accredited ISO 27001 certification grant presumption of conformity — ISO only if the scope and Statement of Applicability map to the CCB’s key measures.
- The cost gap is real: first-year CyFun Basic/Important runs €8,000–€32,000 against €30,000–€60,000 for ISO 27001 at mid-market size, with Flemish VLAIO subsidies covering up to 45% of advisory costs.
- The philosophies differ: CyFun prescribes technical “definitions of done” against verified Belgian attack data (82% attack coverage at Basic, 94% at Important, 100% at Essential); ISO 27001 builds a risk-driven management system.
- The deadlines are statutory: essential entities had to file their SoA or CyFun self-assessment with the CCB by 18 April 2026, must report progress by 18 April 2027, and complete full certification within 30 months.
- Effort transfers: 70–80% control overlap means CyFun-first organisations reuse most of the work when international customers later demand ISO.
What each framework actually is
CyberFundamentals (CyFun® 2025, released 1 October 2025) is the CCB’s national framework, rebuilt on NIST CSF 2.0 with six functions — Govern, Identify, Protect, Detect, Respond, Recover — across 22 categories and 106 subcategories. It ships in four assurance levels: Small (7–10 hygiene rules for micro-organisations), Basic (34 controls), Important (133 total) and Essential (218 total). Scoring uses CMMI maturity thresholds: 2.5/5 to pass Basic verification, 3.0 for Important, 3.5 for Essential. Its defining feature is prescriptiveness — controls are retro-fitted against actual Belgian incident data, which is where the attack-coverage percentages come from.
ISO/IEC 27001:2022 is the international management-system standard: clauses 4–10 govern context, leadership, risk planning, operations, evaluation and improvement, while Annex A supplies 93 controls in four themes, selected per your own risk assessment and documented in a Statement of Applicability. Certification runs on a three-year cycle — two-stage initial audit, annual surveillance, recertification — under ISO/IEC 17021-1 accredited bodies. Where CyFun says exactly what “done” looks like, ISO asks you to prove your management system decides that soundly.
| Parameter | CyFun Basic | CyFun Important | CyFun Essential | ISO/IEC 27001:2022 |
|---|---|---|---|---|
| Controls | 34 | 133 | 218 | 93 Annex A + clauses 4–10 |
| Attack coverage (CCB analysis) | 82% | 94% | 100% | Depends on risk assessment |
| Pass criterion | CMMI 2.5 | CMMI 3.0 | CMMI 3.5 | Pass/fail conformity audit |
| Audit regime | Verification (ISO/IEC 17029) | Certification (ISO/IEC 17021-1) | Certification (ISO/IEC 17021-1) | |
| Typical timeline | 2–4 months | 6–12 months | 12+ months | 8–14 months (50–250 FTE) |
The NIS2 recognition question, answered precisely
The Belgian NIS2 law recognises three routes to presumption of conformity: CyFun verification at Basic or Important, CyFun certification at Essential, and accredited ISO 27001 certification — the last one with a condition that trips people up: the ISMS scope must cover the regulated services, and the Statement of Applicability must demonstrably implement measures equivalent to your applicable CyFun level, mapped via the CCB’s official sheets. An ISO certificate scoped to “the IT department” does not cover a logistics operation. The statutory calendar applies either way: SoA or self-assessment filed with the CCB by 18 April 2026 (passed — late filers should regularise now), progress report by 18 April 2027, full certification within 30 months. Essential entities face ex-ante inspections; important entities are checked reactively, after incidents — the supervision split covered in the NIS2 scope check.
What does each route cost?
| Metric | CyFun Basic | CyFun Important | ISO 27001 (50–250 FTE) |
|---|---|---|---|
| Advisory fees | €3,000–€7,000 | €8,000–€15,000 | €15,000–€25,000 (30–55 days) |
| External audit (CAB/CB) | €2,000–€4,000 | €4,000–€8,000 | €10,000–€20,000 |
| Internal hours | 50–150 | 150–350 | 400–800 |
| Total year 1 | €8,000–€15,000 | €18,000–€32,000 | €30,000–€60,000 |
| Annual maintenance | €1,500–€3,000 | €3,000–€6,000 | €5,000–€12,000 |
Three cost notes. The CCB’s self-assessment tooling is free. Flemish SMEs can offset advisory fees through the VLAIO KMO-portefeuille (45% subsidy for small, 35% for medium enterprises, capped at €7,500/year) and cybersecurity improvement grants up to 50% co-funding. And the ISO delta buys the management system, not better firewalls — the technical controls largely coincide.
Where the market pulls each way
ISO 27001 is the answer international procurement expects: cross-border SaaS deals, Tier-1 supply chains, DORA-adjacent finance and TISAX-adjacent automotive all ask for the certificate by name, and Belgium counts 347 valid ISO/IEC 27001 certificates in the official ISO Survey. CyFun owns the home field: Belgian public tenders prefer it, domestic B2B chains accept it, Belgian cyber insurers increasingly price risk on CMMI maturity scores, and the framework is spreading — co-owned with Ireland and Romania, observed by France, Portugal and Croatia. The decision rule is customer geography: who has to believe your paperwork?
The overlap: why “both, in order” works
The CCB publishes official mappings between CyFun and ISO 27001/27002, NIST CSF 2.0, CIS Controls and IEC 62443, and the technical overlap at Important/Essential level exceeds 70–80%: MFA, access management, vulnerability scanning, segmentation, incident workflows, backup testing, logging — the same list mapped control-by-control in NIS2 measures translated to SASE controls. The difference is grain: where ISO Annex A states access-control principles, CyFun mandates specific MFA enforcement on administrative endpoints and air-gapped backup validation schedules. So the phased path is genuinely efficient: implement CyFun Important first (fast compliance, hard technical controls, lower cost — building on the work described in CyFun Basic to Important and the self-assessment guide), then bolt ISO’s clauses 4–10 around the running control set when export customers ask. Existing ISO holders travel the other way in days, not months: map the SoA to CyFun’s key measures and verify the prescriptive gaps.
Who audits what
BELAC, under the FPS Economy, is Belgium’s sole accreditation body. CyFun verification (Basic/Important) runs under ISO/IEC 17029 — Brand Compliance België obtained BELAC accreditation on 4 September 2025 — while CyFun Essential and ISO 27001 certification run under ISO/IEC 17021-1 through bodies like DEKRA, Bureau Veritas and TÜV. The CyFun workflow is five steps: level selection with the CCB tool, self-assessment against the CMMI thresholds, CAB engagement, external audit against the conformity scheme, and attestation registered with the CCB — what that audit feels like in practice is described in what CCB conformity assessments actually look like.
Decide by customer, implement once
Choose CyFun if your revenue is Belgian and your deadline is regulatory. Choose ISO 27001 if your customers are international and their procurement portals say so. Plan both, CyFun first, if export growth is on a two-to-three-year horizon. And notice what stays constant across every branch of that tree: the technical control set — MFA-enforced access, segmentation, logging, web protection, backup discipline. That is where platform choice quietly decides your audit workload, because one system that enforces MFA on every access, segments users to applications and produces identity-aware logs evidences a long list of CyFun key measures and Annex A controls at once. For EU mid-market teams, Jimber is that consolidation: one EU-sovereign platform generating the evidence both auditors ask for, at a flat cost that fits either compliance budget. Whichever framework you file under, book a demo to see how much of your control list one platform closes before the consultants start counting days.
Frequently asked questions
Does an ISO 27001 certificate automatically satisfy Belgian NIS2?
Not automatically. It grants presumption of conformity only if the ISMS scope explicitly covers your regulated services and the Statement of Applicability demonstrates measures equivalent to your applicable CyFun level, using the CCB’s mapping.
Which framework is cheaper for a 100-person Belgian company?
CyFun, clearly: €8,000–€32,000 in year one for Basic or Important versus €30,000–€60,000 for ISO 27001 — roughly 40–60% lower, because CyFun skips most management-system documentation overhead.
What are the hard NIS2 deadlines in Belgium?
SoA or CyFun self-assessment filed with the CCB by 18 April 2026, a progress report by 18 April 2027, and full certification within 30 months of the law’s entry into force. The first deadline has passed — regularise immediately if you missed it.
Can Flemish companies get subsidies for this?
Yes. The VLAIO KMO-portefeuille covers up to 45% of cybersecurity advisory costs for small enterprises (35% for medium), capped at €7,500 per year, and VLAIO improvement grants co-fund implementation projects up to 50%.
What is the difference between CyFun verification and certification?
Verification applies to Basic and Important under ISO/IEC 17029 and yields a “Verified” statement; certification applies to Essential (and ISO 27001) under ISO/IEC 17021-1 with fuller audits and an accredited certificate.
Is CyFun recognised outside Belgium?
Increasingly: Ireland and Romania co-own the framework for NIS2 implementation, with France, Portugal and Croatia observing or partially adopting. For global procurement outside the EU, ISO 27001 remains the expected standard.
We already hold ISO 27001 — how much extra work is CyFun alignment?
Little. Map your existing SoA to CyFun’s key measures with the official CCB sheets and verify the prescriptive technical requirements — exact MFA configurations, backup validation schedules — are actually met.
Which framework do Belgian cyber insurers prefer?
Both are accepted, but insurers increasingly favour CyFun because CMMI maturity scores give them verified technical risk data about resilience against the attack vectors that actually drive claims.