Moving from CyberFundamentals Basic to Important is not more of the same, it is a qualitative jump. Important requires 133 measures, of which 22 are key measures, all proven at CMMI maturity level 3 (“Defined”): formally approved, consistently applied, and evidenced on demand, with every key measure scoring at least 3.0. Ad-hoc technical fixes no longer pass. A converged SASE and ZTNA platform centralises and automates the technical evidence for the access, network and monitoring key measures, which is what makes the audit achievable for a lean mid-market team. For a Belgian organisation, a sovereign single platform like Jimber is the strongest way to carry that evidence burden.
Key takeaways
- CyFun Important under the 2025 framework holds 133 measures (34 Basic plus 99), including 22 key measures, versus 34 measures and 13 key measures at Basic.
- The audit tests each measure on two axes, documentation and implementation, on a 1-to-5 CMMI scale.
- Basic needs an average of at least 2.5 and each of its 13 key measures at 2.5; Important needs an average of at least 3.0 and each of its 22 key measures at 3.0. One weak key measure fails the whole verification.
- The auditor does not search your systems: all evidence must be laid out, self-readable, and in the original CCB Excel format.
- A single SASE console produces the access, segmentation, filtering and logging evidence for a large share of the Important key measures directly.
Where Important sits, and what it demands
CyberFundamentals is Belgium’s national cyber standard, built on NIST CSF, ISO 27001/27002 and the CIS Controls. The 2025 edition aligns fully with NIST CSF 2.0, organising measures under six functions instead of five, with Govern added: Govern, Identify, Protect, Detect, Respond and Recover. Under the Belgian NIS2 law, the required level maps to your classification.
| Level | Measures (2025) | NIS2 status in Belgium | Threat coverage |
|---|---|---|---|
| Small | ~10 rules of thumb | Voluntary (micro-organisations) | Baseline hygiene |
| Basic | 34 (13 key) | Recommended minimum for all SMEs | 82% of automated attacks |
| Important | 133 (22 key) | Mandatory for NIS2 important entities | 94% of targeted attacks |
| Essential | 218 (29 key) | Mandatory for NIS2 essential entities | 100% of advanced attacks |
The step to Important is a step in audit strictness, not just count. Basic is 34 relatively simple controls; Important adds 99 more and raises the bar on proof. The 2025 edition also trimmed Important from 140 measures to 133 by consolidating duplicates, and added a new key measure, RS.CO-02.2, which requires a formal, tested process for reporting significant incidents to the authorities within the NIS2 24-hour and 72-hour windows.
The maturity thresholds that decide the audit
Each measure is scored on the CMMI scale from 1 to 5, on documentation (is it written and approved?) and implementation (is it consistently applied, with evidence?). Level 3, Defined, means a formally approved and current policy, consistently followed, with exceptions documented and under 5%, and objective, traceable evidence available.
| Criterion | CyFun Basic | CyFun Important |
|---|---|---|
| Overall average score | At least 2.5 of 5 | At least 3.0 of 5 |
| Score on every key measure | Each of 13 at least 2.5 | Each of 22 at least 3.0 |
For a mid-market organisation this is the crux: at Important you can no longer get by with ad-hoc technical fixes at level 2. Every key measure must reach Defined, which means management-approved policy that is actively followed and can be demonstrated immediately to an external verifier. A single key measure below 3.0 blocks a positive verification statement.
Mapping the network key measures to SASE evidence
Traditional perimeter firewalls and legacy VPNs struggle to produce this proof. A VPN grants broad network access after login, which conflicts with the least-privilege requirement of PR.AC-4, and managing separate firewalls, filters and segments makes evidence-gathering slow and error-prone. A converged SASE and ZTNA platform pulls the technical evidence for a large share of the Important network measures from one console.
| CyFun measure | Evidence at maturity 3 | SASE/ZTNA (Jimber) contribution | Outside SASE |
|---|---|---|---|
| PR.AC-3 (remote access managed) | Telework policy; MFA enforced for all external connections; live list of remote users | ZTNA replaces VPN and enforces MFA and posture on every connection; console reports all sessions | Writing and approving the telework policy |
| PR.AC-4 (least privilege) | RBAC matrix; quarterly access reviews; admin accounts used only for admin | Per-application access instead of network access, blocking lateral movement; SSO integration | Joiner/mover/leaver HR procedures |
| PR.AC-5 / PR.PT (segmentation) | Current network diagram; proof of IT/OT/guest separation | Cloud-managed microsegmentation; the NIAC isolates agentless and OT devices | Physically securing switches and server rooms |
| PR.PT-4 (web/email filtering) | Active URL/email filter configs; logs of blocked sites; documented exceptions | SWG inspects outbound traffic; RBI runs risky web code in an isolated container | SPF, DKIM and DMARC on the mail server |
| DE.CM-1 (continuous monitoring) | Active traffic and security-event logs; alerts on anomalies | SASE is a central inspection point producing converged logs, exportable to SIEM/SOC | The incident-response process behind the alert |
| PR.DS-1/2 (encryption) | Crypto policy; proof all connections use strong encryption (TLS 1.3) | Automatic end-to-end encryption of all traffic between users, endpoints and apps | Local disk encryption (BitLocker, FileVault) on laptops |
Technology covers the heaviest network measures, but not the whole framework. You still write the policies, run HR onboarding and offboarding, secure physical access, test backups, and commission penetration tests. Read the mapping as “this measure is substantially evidenced,” never as “compliant by product.” Our NIS2 measures to SASE controls guide covers the wider directive, and the CyFun self-assessment piece the documentation side.
How the verification works in Belgium
An official CyFun label comes through a formal, independent process supervised by the Belgian accreditation body BELAC and the CCB. You cannot use any IT provider: the audit must be done by a Conformity Assessment Body accredited under ISO/IEC 17029, such as Brand Compliance or What a Work (Trust CHECK). The path runs in six steps: complete the official, unmodified CCB Excel self-assessment; select an accredited CAB; undergo the audit (a document review plus a mandatory on-site visit, with a regulatory minimum of 1.5 person-days and at least one full day on site); an independent reviewer inside the CAB checks the findings; the CAB issues a verification statement if you meet the thresholds; and you submit the verified self-assessment through Safeonweb@Work, after which the CCB grants the label with a scannable QR code.
What the auditor expects is specific. They will not hunt through your systems, so evidence must be prepared and directly presentable. Each justification must be self-readable and split into documentation (policy page X) and implementation (screenshot Y or log Z). Only the original CCB Excel format is accepted; edited or PDF-exported files are refused. And if the auditor finds a measure overstated, you correct the self-assessment to match their conclusion and resubmit.
Timeline, cost and subsidies
Reaching Basic usually takes two to four months; Important typically takes 6 to 12 months to document policy, implement the technical measures such as SASE/ZTNA, and gather the evidence. Registered important and essential entities had to hold a Basic or Important verification statement by 18 April 2026, and essential entities must reach full Essential certification by 18 April 2027. Missing these is an infringement of the Belgian NIS2 law, with important-entity fines up to €7 million or 1.4% of global turnover and personal director liability. On the upside, Belgian support exists: in Flanders SMEs can use the KMO-portefeuille to hire accredited providers for CyFun guidance, with a subsidy of 45% for small and 35% for medium enterprises, and VLAIO offers dedicated cybersecurity improvement tracks.
Frequently asked questions
Which CyberFundamentals level does our organisation need?
It follows your NIS2 classification. Important entities (usually 50-plus employees or over €10 million turnover in sectors like transport, postal, waste or chemicals) must meet at least Important. Essential entities (energy, drinking water, banking, healthcare) must reach Essential. Organisations outside NIS2 scope can choose Basic voluntarily.
How many measures must we demonstrate for Important under the newest framework?
Under CyFun 2025, Important covers 133 measures in total: you must master the 34 Basic measures plus 99 Important-specific ones. Within those 133, 22 are designated key measures that are tested with priority and a stricter individual pass mark.
What minimum score do we need to pass Important?
An overall average maturity of at least 3.0 of 5 across documentation and implementation, and each of the 22 key measures must also score at least 3.0 individually. If a single key measure scores below 3.0, the verifier cannot issue a positive statement.
What changed between CyFun 2023 and CyFun 2025?
The 2025 version adds a sixth core function, Govern, centralising strategic risk management and board accountability. It reduces Important from 140 to 133 measures by merging duplicates, introduces a 22nd key measure (RS.CO-02.2) for timely incident reporting to the authorities, and strengthens supply-chain requirements (ID.SC).
How long does a Basic-to-Important track take?
It depends on your starting maturity, but a mid-market organisation should plan on 6 to 12 months to document the policies, implement the technical measures such as SASE/ZTNA, and assemble the evidence for the audit, against two to four months for Basic.
Can the implementation and audit be subsidised?
Yes. In Flanders, SMEs can use the KMO-portefeuille to engage accredited providers for CyFun guidance, with 45% support for small and 35% for medium enterprises, and VLAIO provides specific cybersecurity improvement tracks and subsidies to lower the barrier to formal auditing.
Make the evidence produce itself
The hard part of Important is not the technology, it is proving every key measure at maturity 3 on demand. A converged SASE console generates the access, segmentation, filtering and monitoring evidence continuously, so you walk into the audit with it ready. Book a Jimber demo to see how the network key measures map to your CyFun evidence, or start with our NIS2 compliance checklist.