Many organisations have invested in cybersecurity over the years. Tools are in place, policies exist, and responsibilities are assigned. Yet when asked simple questions — Are we doing enough? Are we focusing on the right risks? Can we prove it? — answers are often unclear.
This gap is not caused by a lack of effort, but by a lack of structure, prioritisation, and measurable maturity.
Cyber Fundamentals (CyFun) addresses this gap by turning cybersecurity into a structured, risk-based, and auditable system.
From effort to structure
CyFun is a risk-based cybersecurity framework, originally developed in Belgium and now adopted by Ireland, Romania, and Malta. It provides organisations with a practical way to organise, implement, and demonstrate their cybersecurity measures.
In simple terms, CyFun is a practical framework that helps organisations understand what cybersecurity measures they need, how well they are implemented, and how to improve them over time.
However, there is still a lot of confusion around CyFun in Belgium, so let’s keep it simple.
For organizations classified as essential entities under Belgian NIS2 law, a formal conformity assessment is mandatory. These organizations must demonstrate compliance by choosing between:
- The CyberFundamentals (CyFun) framework
- Or an ISO/IEC 27001 certification with an appropriate scope and Statement of Applicability
So no, CyFun is not universally mandatory. But for essential entities, doing nothing is not an option. You must choose one of the two recognized routes.
At the same time, it’s important not to overestimate what CyFun does. It:
- Does not replace NIS2 obligations
- Does not guarantee compliance
Ultimately, the Belgian authority will still assess whether your security measures are appropriate and proportionate to your risks, regardless of the framework you choose.
A maturity model that reflects reality
A key strength of CyFun is its proportional approach.
Not every organisation requires the same level of security. CyFun introduces three levels of maturity:
- Basic – Foundational controls and initial risk awareness
- Important – Structured processes and managed security practices
- Essential – Advanced governance, monitoring, and high assurance
This classification is based on:
- Organisational size and complexity
- Sector and regulatory exposure
- Risk profile and potential impact of incidents
This approach ensures that cybersecurity investments are aligned with actual risk, avoiding both under-protection and unnecessary complexity.
Built on NIST — Strengthened by governance
CyFun is grounded in the NIST Cybersecurity Framework, transitioning to version 2.0, which places stronger emphasis on governance and accountability.
It is structured around six core functions:
- Govern – Strategy, policies, roles, and oversight
- Identify – Assets, risks, and vulnerabilities
- Protect – Preventive safeguards
- Detect – Monitoring and threat identification
- Respond – Incident handling and mitigation
- Recover – Resilience and business continuity
These functions form a continuous cycle, not isolated actions. They enable organisations to move from reactive measures to ongoing risk management and improvement.
What makes CyFun particularly valuable is how these functions are applied:
- Through documented processes
- Supported by evidence and traceability
- Designed to be assessable and auditable
How CyFun works in practice
In practice, CyFun is not implemented all at once. It follows a structured path:
- First, organisations assess their current maturity level
- Then, they identify gaps between current and required controls
- Next, priorities are defined based on risk and impact
- Finally, controls are implemented, documented, and continuously improved
This step-by-step approach ensures that cybersecurity evolves in a controlled and realistic way, rather than through isolated or reactive efforts.
Turning NIS2 into action
NIS2 introduces clear expectations around risk management and security measures, especially for essential and important entities. However, it does not prescribe exactly how organisations should implement them.
This creates uncertainty.
CyFun translates these expectations into:
- Structured processes
- Practical controls
- Measurable maturity levels
It aligns closely with Risk Management Measures (RMM), which define the baseline of what organisations must achieve.
At the same time, CyFun remains flexible. It can be used alongside:
- ISO 27001
- ISO 62443
- COBIT
- Existing internal frameworks
This allows organisations to integrate CyFun into their current environment, rather than replacing what already works.
Start with self-assessment: understanding where you stand
Before improving cybersecurity, organisations need a clear view of their current position.
Self-assessment is often the first and most critical step. It helps answer key questions:
- Do we know our critical assets and risks?
- Are our controls formally defined or applied ad hoc?
- Can we demonstrate what we have implemented?
- Are responsibilities and governance clearly assigned?
CyFun supports this process by providing a structured way to evaluate your maturity level across its core functions.
This is not about achieving perfection from the start. It is about creating visibility.
Even a simple, honest assessment can:
- Reveal hidden gaps
- Highlight quick wins
- Provide direction for investment
Without this step, organisations often invest in cybersecurity blindly — reacting to incidents instead of managing risk proactively.
From controls to assurance
A major shift in cybersecurity is moving from implementation to assurance.
It is no longer sufficient to say:
- “We have controls in place”
Organisations are expected to demonstrate:
- Controls are well designed
- Controls are properly implemented
- Controls are consistently operating
CyFun supports this by enabling:
- Clear mapping between risks and controls
- Consistent documentation and evidence
- External validation through certification (optional)
While CyFun does not follow a traditional certification cycle, it does require annual verification for organisations classified as essential entities.
This verification must be performed by an approved Conformity Assessment Body (CAB), with the official list maintained by the Belgian Centre for Cybersecurity (CCB).
Why starting early matters
Even if organisations do not go for formal verification of their CyFun implementation, they still benefit from adopting the framework early.
It allows them to:
- Assess their current maturity level
- Identify and prioritise gaps
- Strengthen governance and accountability
- Prepare for future regulatory reviews
Delaying action often leads to reactive decisions, fragmented implementations, and higher costs.
A structured approach, on the other hand, builds clarity, consistency, and long-term resilience.
Practical first steps
For organisations starting with CyFun, a few initial actions can create immediate impact:
- Map your critical systems and data
- Define clear ownership for cybersecurity responsibilities
- Document existing controls — even if they are informal
- Identify your top 3–5 risks and focus there first
- Ensure basic incident response procedures are in place
These steps create a foundation that can be expanded into a more mature and structured cybersecurity approach over time.
Final perspective
CyFun brings these elements together into a coherent, measurable, and auditable system.
It does not add complexity, it removes ambiguity.
And in a landscape where organisations are increasingly expected to prove their security, not just assume it, that clarity becomes a competitive advantage.If you want to understand where your organisation stands and how to structure your path toward NIS2:
👉 Dadir helps you assess your maturity, prioritise what matters, and turn CyFun into a practical, business-aligned roadmap.
Contact us for more information: https://dadir.be/




