CyFun Essential: What Changes From Important and What April 2027 Means

For essential entities in Belgium, 18 April 2026 was the first NIS2 milestone: a verified CyberFundamentals statement at the Basic or Important level, or an ISO 27001 scope and Statement of Applicability submitted to the authorities. Many boards treated that as the finish line.
It was the halfway point. By 18 April 2027, essential entities must hold a certification, not a verification. For organisations on the CyFun track, that means certification at the Essential level, or at the target level their risk assessment designates. The Essential level holds 218 requirements, 85 more than Important, and it scores them more strictly.
This article covers what the law requires by entity type, what actually changes between Important and Essential, how certification differs from verification, and how to work back from the deadline with roughly six months left.
What does April 2027 mean for essential entities?
By 18 April 2027, essential entities in Belgium must hold a formal certification: CyFun certification by an accredited conformity assessment body, or ISO/IEC 27001 certification with a scope covering their essential services. The alternative is the inspection track, with a progress report to the CCB. The deadline sits thirty months after the Belgian NIS2 law entered into force.
What the law requires, by entity type
The obligations come from two texts: the Law of 26 April 2024, which entered into force on 18 October 2024, and its implementing Royal Decree of 9 June 2024. The deadlines count from 18 October 2024, or from the date an entity was identified by the authority.
| Entity and track | By 18 April 2026 (18 months) | By 18 April 2027 (30 months) | Legal basis |
|---|---|---|---|
| Essential entity, CyFun track | Verification by an accredited body at the Basic or Important level | Certification under the CyFun framework | Royal Decree of 9 June 2024, art. 22, § 1, 1° and § 2, 1° |
| Essential entity, ISO 27001 track | Scope and Statement of Applicability submitted | ISO/IEC 27001 certification | Royal Decree of 9 June 2024, art. 22, § 1, 2° and § 2, 2° |
| Essential entity, inspection track | Self-assessment at Basic or Important, or scope and Statement of Applicability, submitted | Progress report on the conformity process submitted to the CCB | Royal Decree of 9 June 2024, art. 23 |
| Important entity | No fixed milestone | No fixed milestone | Supervision after the fact; a voluntary verification at Important gives a presumption of conformity |
Source: Law of 26 April 2024 and Royal Decree of 9 June 2024, Belgian Official Gazette. Article 23, § 3 adds a continuous obligation for all entities to show measurable improvement.
Two misunderstandings come up often. The first is the idea that the 2026 verification completes the obligation for essential entities. It does not; it was the interim step. The second is confusing verification with certification. They are different procedures, and the 2027 milestone asks for the second.
The three CyFun levels at a glance
The CCB published CyberFundamentals 2025 on 24 October 2025. It aligns the framework with NIST CSF 2.0, which adds a Govern function for board oversight, risk governance and supply chain security. The levels are cumulative: Important contains Basic, Essential contains both.
| Basic | Important | Essential | |
|---|---|---|---|
| Requirements (cumulative) | 34 | 133 | 218 |
| Key measures (cumulative) | 13 | 22 | 29 |
| Minimum score per key measure | 2.5 | 3 | 3 |
| Minimum score per category | none | none | 3 |
| Minimum overall average | 2.5 | 3 | 3.5 |
| Assessment for essential entities | Verification | Verification | Certification |
Scores run from 1 to 5 for documentation maturity and for implementation maturity. Source: CyberFundamentals 2025 framework documentation.
CyFun 2023 and CyFun 2025 coexist until 18 April 2027. Statements and certificates issued under CyFun 2023 remain valid until 18 April 2028 at the latest, after which only CyFun 2025 applies. If you start your gap assessment now, start it against 2025.
Where the jump from Important to Essential actually lands
Most published guidance stops at the counts. The counts matter, but the scoring rules matter more.
At Important, an organisation can pass with an overall average of 3 while some categories sit lower, as long as every key measure reaches 3. At Essential, every category must reach 3 on its own, and the overall average must reach 3.5. There is no longer room for a weak area carried by strong ones. Seven additional key measures come on top, and each can block certification by itself: if a single key measure scores below 3, the certificate is not issued until the non-conformity is resolved.
In practice, consultants, conformity assessment bodies and Belgian industry groups report the same friction points when organisations move towards Essential.
| Area | Why it gets harder at Essential | Evidence an assessor typically asks to see |
|---|---|---|
| Network architecture and segmentation | Flat networks and legacy applications make it hard to show that critical systems are separated | Firewall and segmentation configuration, network diagrams, rule reviews |
| Remote and third-party access | VPN concentrators give broad network access that is difficult to restrict and evidence per user and per application | Access policies, MFA enforcement logs, access reviews |
| Logging and monitoring | Assessors look for controls that have operated over time, not configurations switched on the week before | SIEM ingestion, alert handling records, retention settings |
| Supply chain | The Govern function in CyFun 2025 expands expectations around suppliers | Supplier risk register, contract clauses, supplier assessments |
| Governance | Board oversight becomes a scored area, not a formality | Board decisions, risk reviews, roles and responsibilities |
For the exact control texts, work from the CyFun 2025 Essential documentation itself. The pattern above explains where the effort tends to go, not what each control says.
The operating-history point deserves emphasis. Several of these areas are not a configuration you can finish in a week before the audit. If monitoring or access reviews start in March 2027, an assessor in April will see weeks of records, not months.
Verification versus certification
A verification is an assessment by an accredited conformity assessment body that results in a verification statement for the Basic or Important level. It leads to a CyFun label through Safeonweb@work. For important entities, a verification at Important gives a presumption of conformity.
A certification is a full certification cycle by a conformity assessment body accredited by BELAC and authorised by the CCB, under ISO/IEC 17021-1 or ISO/IEC 17065. It checks that controls work over time, handles non-conformities formally and includes surveillance audits during a three-year cycle. This is what essential entities on the CyFun track need by April 2027.
Accreditation for CyFun work runs through BELAC’s scheme document BELAC 2-405. Practitioners and industry associations such as Beltug report pressure on the capacity of accredited bodies as the deadline approaches. The practical conclusion is simple: contact assessment bodies now, not when your preparation feels finished.
The ISO 27001 route
The Royal Decree accepts ISO/IEC 27001 certification as an alternative, under two conditions set out by the CCB. The certified scope must cover all networks, information systems and processes that support the essential services; a certificate for one application or one data centre does not qualify. And the Statement of Applicability must map the implemented controls to the corresponding CyFun measures, with evidence that they operate.
Which route fits depends on your organisation more than on the framework. CyFun is prescriptive and built for Belgian NIS2 compliance, which helps organisations that want a clear list. ISO 27001 is a management system standard recognised internationally, which helps organisations that already hold it or whose customers and partners abroad ask for it. The comparison is covered in more detail in CyFun versus ISO 27001.
What happens if you miss it
The CCB’s inspection service can carry out inspections, request configurations and logs, and in serious cases appoint a supervising officer inside the entity at the entity’s cost. Administrative fines for essential entities reach up to €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities the ceiling is €7 million or 1.4%. In addition, members of management can be temporarily suspended from their functions. The enforcement practice so far is covered in what NIS2 enforcement looks like in Belgium.
The fines are not the most useful reason to act, though. A certification that slips past April 2027 because no assessor was available is an avoidable problem, and it is the one most organisations can still prevent this month.
Working back from 18 April 2027
With roughly six months left, the order of the work matters more than its volume. The phases below follow what assessors and consultants describe as the longest items, from last to first.
- The certification audit itself (February to April 2027). Stage 1 and stage 2, followed by closing any non-conformities. Plan buffer here: a single key measure below 3 delays the certificate.
- Evidence and pre-audit (January to February 2027). An internal pre-audit against the full Essential scope, a central evidence repository, and the remaining fixes. Freeze major architectural changes during this phase.
- Controls that need operating history (from now). Segmentation, access control for remote and third-party users, logging and monitoring. These are the items that take months to implement and months to accumulate evidence, so they start first.
- Scope, target level and assessor (now). Confirm your entity status and target level, run the gap assessment against CyFun 2025, choose between the CyFun and ISO 27001 routes, and book an accredited assessment body.
If your organisation completed a verification at Important in the spring, the gap assessment is shorter than it sounds. The step from Basic to Important and the way CCB conformity assessments run are good reference points for what assessors already saw.
What technology can and cannot evidence
A large part of CyFun Essential is organisational: board oversight, risk management, supplier management, training, crisis exercises, incident procedures. No product delivers those, and no product should claim to.
A network security platform can contribute to a narrower set of controls: segmentation between systems, identity-based access for users and third parties instead of broad VPN access, web security, and the logs that show these controls operate. That is the part where Jimber, as a European single SASE platform, helps organisations produce evidence an assessor can check. It covers part of the technical controls and none of the governance ones.
The case against rushing into certification
Three objections come up in board rooms, and each has a reasonable core.
“Use the inspection track and keep the audit budget.” Article 23 does offer a route through the CCB inspection service with a self-assessment and a progress report, and a CFO will point out that the CCB’s inspection capacity is limited. That is true. It also moves the timing of the assessment out of your hands and does not reduce the work, since the inspection service can still request the same configurations and logs. The route suits some organisations. It does not remove the need to reach the level.
“ISO 27001 travels further than a Belgian scheme.” For organisations with international customers, this is often right, and the Royal Decree accepts ISO 27001 with the correct scope and CyFun mapping. The mapping is the catch: the Statement of Applicability must still show CyFun Essential coverage. It is a different route to the same controls, not a shortcut around them.
“Essential is over-engineered for a mid-sized organisation.” Some requirements feel heavy for a 300-person company, and poorly planned segmentation of legacy systems can cause outages. The law does not offer a lighter tier for essential entities, though. The practical answer is sequencing: start with the controls that reduce the most risk and need the longest history, and avoid architecture changes close to the audit.
Where to start this week
Three actions fit in one week: confirm your entity classification and CyFun target level, request availability and a quote from two accredited assessment bodies, and list the controls in your gap assessment that need months of operating history. Those three steps decide whether April 2027 is a schedule or a risk.
If network segmentation and remote access are on that list, book a demo and we will walk through which CyFun controls the platform helps you evidence. If you prefer to test first, try Jimber free.
Frequently asked questions
What is the CyFun Essential deadline for essential entities in Belgium?
18 April 2027. By then, essential entities must hold a CyFun certification, an ISO/IEC 27001 certification with a scope covering their essential services, or, on the inspection track, have submitted a progress report to the CCB. The deadline follows from article 22 of the Royal Decree of 9 June 2024.
What was required by 18 April 2026?
Essential entities on the CyFun track needed a verification by an accredited body at the Basic or Important level. On the ISO route, they had to submit their scope and Statement of Applicability. On the inspection track, a self-assessment or the ISO scope documents.
What is the difference between CyFun verification and certification?
A verification results in a verification statement for the Basic or Important level and leads to a CyFun label. A certification is a full cycle under ISO/IEC 17021-1 or 17065 by an accredited body, with formal handling of non-conformities and surveillance audits. Essential entities need certification by April 2027.
How many requirements does CyFun Essential have?
Under CyFun 2025, the Essential level contains 218 requirements, including 29 key measures. That is 85 requirements and 7 key measures more than Important. Essential also requires every category to score at least 3 and an overall average of at least 3.5.
Can we use ISO 27001 instead of CyFun Essential?
Yes, if the certified scope covers all networks, systems and processes that support your essential services, and your Statement of Applicability maps the controls to CyFun with evidence that they operate. A certificate for a single application or site does not qualify.
Do important entities need CyFun Essential certification?
No. Important entities are supervised after the fact and have no fixed certification deadline. A voluntary verification at the Important level gives them a presumption of conformity under Belgian law.
Which CyFun version should we assess against?
CyFun 2025, published on 24 October 2025. CyFun 2023 and 2025 coexist until 18 April 2027, and CyFun 2023 statements and certificates remain valid until 18 April 2028 at the latest. A new gap assessment is best done against the 2025 version.
What happens if one key measure fails in the audit?
The certificate is not issued while any key measure scores below 3, even if the overall average is high enough. The assessment body records a non-conformity that must be resolved first, which is why a buffer before the deadline matters.
What are the fines for essential entities under the Belgian NIS2 law?
Up to €10 million or 2% of worldwide annual turnover, whichever is higher. Members of management can also be temporarily suspended from their functions. For important entities the ceiling is €7 million or 1.4% of turnover.