The first CyFun deadline is behind us. On 18 April 2026, Belgian essential entities had to put initial conformity evidence in front of the CCB. The next one — full certification — falls on 18 April 2027, which is roughly eight months away. And in a communication issued on 7 August 2026, the CCB’s Inspection Service opened a narrow escape hatch: essential entities that cannot reach full Essential certification in time may reach CyFun Important verification by April 2027 instead, provided they file a remediation plan that gets them to Essential by 18 April 2028.
If that paragraph contains three terms you would rather not have to explain to your board, this article is for you. CyberFundamentals is Belgium’s national cybersecurity framework and the practical route to demonstrating you meet your NIS2 obligations. It has four levels, three ways to prove you meet one, and a set of deadlines that are now close enough to matter. Here is the whole journey, from working out which level applies to you through to having a label registered in your name.
What CyFun is, and why the label matters legally
CyberFundamentals (CyFun) is the cybersecurity framework built by the Centre for Cybersecurity Belgium. It takes four international standards — NIST CSF 2.0, ISO/IEC 27001 and 27002, the CIS Critical Security Controls, and IEC 62443 for industrial environments — and turns them into a tiered catalogue of concrete, measurable controls. Belgium co-owns the scheme with Ireland and Romania, which lays the groundwork for mutual recognition across those markets.
The legal weight comes from the Belgian NIS2 law of 26 April 2024, in force since 18 October 2024, and its executing royal decree of 9 June 2024. Article 21 of that law requires essential and important entities to take proportionate technical and organisational measures. Rather than leaving “proportionate” open to argument, the law grants a presumption of conformity to organisations holding a valid CyFun label issued by an accredited body. That reverses the burden of proof: instead of you demonstrating your security was adequate, the supervisory authority must demonstrate it was not.
What the label does not do is equally worth knowing, because this is where organisations get caught out. The presumption covers article 21 risk-management measures only. It does not cover your registration obligation on Safeonweb@Work, it does not cover incident notification — the 24-hour early warning, 72-hour notification and one-month final report still apply in full — and it does not cover the governance duties that sit personally with your management body, including mandatory board-level cybersecurity training. A CyFun label is a strong answer to one question, not a blanket exemption.
The four levels
CyFun has four cumulative assurance levels. Each one contains everything in the level below it, plus more.
| Level | Intended for | Controls | Claimed attack coverage | Maturity threshold |
|---|---|---|---|---|
| Small | Micro-organisations under 10 staff, no dedicated IT | ~7–10 baseline recommendations | Basic hygiene | Implement the recommendations |
| Basic | SMEs and the recommended floor for suppliers to NIS2 entities | 34 controls | 82% of common, automated attacks | Average ≥ 2.5, every key measure ≥ 2.5 |
| Important | Mid-market organisations, statutory target for NIS2 important entities | 133 controls (34 + 99) | 94% of common and targeted attacks | Average ≥ 3.0, every key measure ≥ 3.0 |
| Essential | Critical infrastructure, statutory target for NIS2 essential entities | 218 controls (133 + 85) | 100% theoretical coverage | Average ≥ 3.5, every category ≥ 3.0 |
Note the attack-coverage figures are the CCB’s own modelling against historical incident data, not a guarantee — but they are useful for explaining to a board why Basic is worth doing even when nothing obliges you.
The scoring is where CyFun differs from a tick-box exercise. Every control is scored twice on a five-point CMMI scale: once for documentation maturity (is the policy written, approved and reviewed?) and once for implementation maturity (is the control actually operating?). You cannot compensate for an unimplemented control with excellent paperwork. On top of that, the CCB designates 29 controls as key measures, and every single one must clear the threshold on its own. A single key measure below the floor blocks the label, regardless of your overall average. That mechanism is deliberate: it stops organisations averaging their way past a gaping hole. Which controls those are and how to lift them is covered in our guide to moving from Basic to Important controls.
Three routes to proving it
| Self-assessment | Verification | Certification | |
|---|---|---|---|
| Who does it | Your own team, optionally with an advisor | A BELAC-accredited body under ISO/IEC 17029 | A BELAC-accredited body under ISO/IEC 17021-1 |
| Available for | All levels (as a gap analysis) | Basic and Important | Essential |
| What you get | An internal scorecard, uploadable to Safeonweb@Work | An official “CyFun Verified” label | An official “CyFun Certified” label |
| Effort | The CCB’s assessment workbook | Document review plus on-site audit, minimum 1.5 days | Full multi-day management-system audit |
| Validity | Point in time | 3 years, annual surveillance | 3 years, annual surveillance |
Only bodies accredited by BELAC under scheme document BELAC 2-405 may issue a label; the currently accredited names include Brand Compliance, What a Work (Trust CHECK) and Vinçotte. Verify the current roster before you sign anything, because accreditations are added over time.
One shortcut is worth knowing: if you already hold an accredited ISO/IEC 27001 certificate, you do not start from scratch. The CCB recognises ISO 27001 as proof of conformity provided you can map every CyFun key measure and level-specific control into your certified Statement of Applicability. We compare the two frameworks on cost, scope and lead time in CyFun versus ISO 27001.
The route from zero to a registered label
1. Register on Safeonweb@Work. Legal entity details, contacts, technical IP ranges and sector, authenticated through the Belgian enterprise register. The registration deadlines have passed — 18 December 2024 for digital-sector entities, 18 March 2025 for everyone else — so if this is still open on your side, it is the first thing to fix. Failure to register carries its own penalty range of €500 to €125,000.
2. Classify and choose a level. The CCB’s scope test and selection tool take headcount, turnover, balance sheet and sub-sector activity and return both your statutory classification (essential or important) and a recommended assurance level. These are two different things and it pays to keep them apart in your own head: the classification is law, the level is how you prove you meet it.
3. Self-assess. Work through the CCB’s assessment workbook, scoring documentation and implementation maturity for each control. This is a genuine gap analysis, not a formality — expect the first pass to be uncomfortable. The output flags exactly which key measures fall short. What you have to be able to show for each one is covered in what Belgian organisations must document after April 2026.
4. Remediate. This is where the real work and most of the budget goes. Typical priorities: enforcing multi-factor authentication across all external and privileged access, moving access control from network location to identity and device posture, centralising logging, and formalising policies, incident runbooks and a supplier register. Legacy systems that cannot be patched need documented compensating controls rather than silence — the approach we set out in managing end-of-life systems under NIS2.
5. Get audited. The accredited body runs a phase 1 document review off-site, then a phase 2 on-site audit — minimum 1.5 person-days with at least a full day on site. Auditors sample live configurations, inspect logs, test backup restoration and interview staff. Our walkthrough of what a CCB conformity assessment actually looks like covers what to expect on the day. If non-conformities surface, you normally get 60 to 90 days to fix them before re-evaluation.
6. Request the label. Upload the verification statement or certification report to Safeonweb@Work; the CCB validates it and registers your entity. From that point the label runs three years, with at least one surveillance audit each year.
What it costs
| CyFun Basic | CyFun Important | ISO/IEC 27001 | |
|---|---|---|---|
| Advisory fees | €3,000 – €7,000 | €8,000 – €15,000 | €15,000 – €25,000 |
| External audit, year 1 | €2,000 – €4,000 | €4,000 – €8,000 | €10,000 – €20,000 |
| Internal effort | 50 – 150 hours | 150 – 350 hours | 400 – 800 hours |
| Lead time | 2 – 4 months | 3 – 6 months | 8 – 14 months |
| First-year total | €8,000 – €15,000 | €18,000 – €32,000 | €30,000 – €60,000 |
| Annual maintenance | €1,500 – €3,000 | €3,000 – €6,000 | €5,000 – €12,000 |
Market benchmark ranges for Belgian mid-market organisations of roughly 50–250 employees, excluding the cost of the technical remediation itself, which varies enormously with your starting point. Verify current quotes before budgeting.
Flemish organisations can reduce the advisory line materially. The KMO-portefeuille covers 45% of external advice for small enterprises and 35% for medium ones, capped at €7,500 a year, and VLAIO’s cybersecurity improvement projects co-fund up to half of eligible advice and remediation packages. Applied to a Basic track, that can bring net first-year advisory spend down to a few thousand euro.
What the label is worth commercially
For a lot of Belgian organisations, the commercial argument now outruns the legal one. Article 21(2)(d) of the NIS2 law obliges regulated entities to manage supply chain risk, which in practice means pushing security requirements down to suppliers — and the CCB explicitly recommends CyFun Basic verification as the baseline for suppliers to in-scope entities. Our analysis of NIS2 supply chain obligations covers how that flows through contracts.
Three practical effects follow. Tender and RFP participation increasingly requires demonstrable framework alignment, and a registered label satisfies that in one document instead of a bespoke evidence pack. Customer security questionnaires shrink or disappear when you can point at a CAB-verified label listed with the CCB. And insurers increasingly factor maturity evidence into underwriting, where a verified label helps on both premium and the exclusion clauses that decide whether a claim gets paid.
There is also a defensive argument for companies sitting just below the thresholds. If your headcount drifts past 50 or a large client designates you as a critical supplier, having Basic already in place turns a compliance emergency into an upgrade.
The objections worth taking seriously
“We’re an important entity under ex-post supervision — self-assessment is enough.” Legally, that is defensible: important entities are supervised reactively, and an internal assessment meets the statutory baseline until something goes wrong. Two things undercut it. Commercially, no enterprise customer bound by article 21(2)(d) will accept your own spreadsheet as evidence. And after an incident, the CCB’s inspectors can challenge your self-scored maturity directly — at which point the presumption of conformity you thought you had was never actually there, with exposure up to €7 million or 1.4% of turnover behind it.
“It’s a paper exercise that doesn’t improve security.” This is true of plenty of compliance regimes and false of this one, for a structural reason: the dual scoring weights implementation as heavily as documentation, and the on-site audit samples live configurations, logs and restore tests. You cannot pass on policy binders. Whether the underlying controls are worth doing is a separate question, and the answer is yes — the Basic set is essentially the list of things that stop commodity attacks.
“We already have ISO 27001.” Then you are most of the way there and should use the mapping route rather than starting again. The one thing to check carefully is scope: ISO 27001 lets you draw the Statement of Applicability around a department or a location, while NIS2 expects coverage of everything supporting the in-scope service. If your certificate covers a subset, the gap is real.
“The cost is disproportionate for a 90-person company.” At €8,000–€15,000 for Basic before subsidies, against a fine ceiling of €7 million and the risk of exclusion from tenders, the arithmetic does not favour waiting. The stronger version of this objection is about time rather than money — 50 to 150 internal hours is real for a two-person IT team — and the honest answer is to start with Basic and a phased roadmap rather than aiming straight at Important.
Where to start, eight months out
If you are an essential entity, April 2027 is now inside your planning horizon and the August 2026 fallback communication is worth reading properly — it is a route to a remediation plan, not an extension. If you are an important entity, the question is less about the deadline and more about the first customer who asks for a label. Either way the first move is the same: run the CCB scope test, complete the self-assessment workbook honestly, and find out how far the 29 key measures are from where you need them.
Most of the technical gaps that assessment surfaces cluster in the same places — multi-factor authentication on every external access path, access based on identity and device posture instead of network location, segmentation of systems that cannot be patched, and central logging. That is precisely the ground a single SASE platform covers, and it is why Jimber’s ZTNA network isolation, secure web gateway and firewall-as-a-service tend to close several key measures at once rather than one at a time, from one EU-sovereign platform. Book a demo and bring your self-assessment output; we will map it against what the platform covers. Preparing for the audit itself? Start with our NIS2 compliance checklist for IT managers.
Frequently asked questions
What is the CyberFundamentals (CyFun) framework?
CyFun is Belgium’s national cybersecurity framework, developed by the Centre for Cybersecurity Belgium. It translates NIST CSF 2.0, ISO/IEC 27001, the CIS Controls and IEC 62443 into a tiered catalogue of measurable controls across four assurance levels, and provides the practical route to demonstrating compliance with the Belgian NIS2 law.
Is CyFun mandatory for Belgian companies under NIS2?
CyFun itself is not mandatory, but NIS2 entities must demonstrate their security measures somehow — in practice through CyFun or ISO/IEC 27001. Holding a valid CyFun label grants a legal presumption of conformity with article 21 of the Belgian NIS2 law, shifting the burden of proof onto the supervisory authority.
What are the four CyFun levels?
Small covers roughly seven baseline recommendations for micro-organisations. Basic has 34 controls and is claimed to counter 82% of common automated attacks. Important has 133 controls and 94% coverage, and is the target for NIS2 important entities. Essential has 218 controls and is the target for essential entities.
What is the difference between CyFun verification and certification?
Verification applies to the Basic and Important levels and is performed under ISO/IEC 17029, resulting in a “CyFun Verified” label. Certification applies to the Essential level under ISO/IEC 17021-1 and results in a “CyFun Certified” label. Both must be performed by a BELAC-accredited conformity assessment body.
How long is a CyFun label valid?
Three years from issuance. To keep it valid, the organisation must undergo at least one surveillance audit each year, in which the accredited body confirms the controls are still operating and the documentation has been maintained. Letting a surveillance audit lapse invalidates the label before its three-year term ends.
How much does CyFun cost for a mid-market company?
First-year totals typically run €8,000 to €15,000 for Basic and €18,000 to €32,000 for Important, including advisory support, internal effort and the audit itself, but excluding technical remediation. That is roughly 40% to 60% below comparable ISO 27001 costs. Flemish SMEs can offset part of the advisory spend through VLAIO subsidies.
What are the NIS2 deadlines for Belgian entities?
Registration on Safeonweb@Work closed on 18 March 2025 for most sectors. Essential entities had to submit initial conformity evidence by 18 April 2026 and must hold full certification by 18 April 2027, with a documented remediation route to 18 April 2028 available under the CCB’s August 2026 guidance.
Does a CyFun label cover all NIS2 obligations?
No. The presumption of conformity covers article 21 risk-management measures only. Registration on Safeonweb@Work, the incident notification timeline of 24 hours, 72 hours and one month, and the governance duties resting personally on your management body all remain separate obligations that a label does not satisfy.