Skip to Content

CyFun: The Framework Belgium Chose for NIS2

Small, Basic, Important, Essential: which level applies to you
September 15, 2026 by
CyFun: The Framework Belgium Chose for NIS2

A Tuesday in November, 8:40 a.m. Your largest client sends over an eleven-page supplier questionnaire. Question 4: "What is your CyFun level?"

Nobody in the company knows what to answer. The IT manager thinks it is connected to NIS2, without being sure. The finance director has never seen the word. The salesperson is certain of one thing: the question is a knockout, and the answer is due Friday.

CyFun is not a marketing label. It is the framework Belgium built to make NIS2 applicable, and it is becoming a condition of access to certain markets.

What is the CyberFundamentals Framework?

CyFun is a set of cybersecurity measures published by the CCB, Belgium's national cybersecurity authority. What sets it apart is that it is operational rather than declarative: it does not ask whether you have a policy, it asks whether the measure is in place, and it scores it.

It follows the structure of the NIST Cybersecurity Framework 2.0 and its six functions — govern, identify, protect, detect, respond, recover — and turns them into concrete measures, each tied to a required level. Every measure maps to the corresponding international standards, so you do not start from scratch if an ISO 27001 programme is already under way.

Three levels: which one applies to you?

CyFun 2025 comes in three cumulative assurance levels: each level fully includes the requirements of the one below it and adds to them.

  • Basic: the baseline expected of every company, built on technology and processes that are generally already available. The realistic entry point for an SME.
  • Important: designed to reduce the risk of targeted attacks by actors with common skills and resources. The level expected of most entities classified as important under NIS2.
  • Essential: the most demanding level, designed to address advanced attacks by actors with extensive skills and resources.

The target level is not a matter of taste: it follows from your NIS2 classification and the risk level of your activity. The CCB provides the selection tools for this, and it is the first thing to settle, before any implementation work.

CyFun 2023 or CyFun 2025?

The CCB has published a 2025 version of the framework, aligned with the NIST Cybersecurity Framework 2.0 and with European legislation, NIS2 included. It notably expands coverage of supply chain security and operational technology (OT), and introduces governance measures aimed at board-level oversight.

The 2023 and 2025 versions coexist during a transition period, after which only the 2025 version will be accepted for self-assessments and third-party conformity assessments. If you are starting today, start on the 2025 version.

Why Belgium built its own framework

NIS2 mandates risk management measures, but the directive does not say what they look like in practice. Without an operational translation, every company interprets, every auditor interprets differently, and nobody knows what is enough.

CyFun adds three things the directive alone could not provide: an explicit list of measures, an assessment scale that produces a score rather than an opinion, and a presumption of conformity for entities that get verified or certified. It turns a vague obligation into a measurable path.

CyFun or ISO 27001: do you have to choose?

They answer different needs and overlap heavily. ISO 27001 is an international management system standard: it certifies that you steer security, not that a given measure is in place. CyFun is a framework of measures, anchored in the Belgian context and directly connected to NIS2.

In practice: if your customers are international and expect a globally recognised certificate, ISO 27001 remains the reference. If your immediate issue is NIS2 compliance in Belgium, CyFun is the shorter path. And they feed each other: a properly documented control serves both. That is exactly the principle we apply at Prism Technology — one control, one piece of evidence, several frameworks covered.

Where it actually goes wrong

Companies that fail almost never fail on the technology. They fail on three organisational points:

  1. The asset inventory. CyFun starts by identifying what you protect: systems, data, suppliers, processes. Most SMEs discover at this stage that no up-to-date list exists.
  2. The evidence. Stating that a measure is in place is not enough: you need something dated, attributable and attached to the measure concerned. The most underestimated workload of the project.
  3. Keeping it alive. A score obtained in March says nothing about October unless periodic reviews are scheduled and recorded.

How we run CyFun inside Odoo

Prism GRC is a native Odoo module built to cover several frameworks with a single set of controls. On a CyFun project, that means:

  • Asset mapping — systems, databases, departments, suppliers, processes — in a hierarchy that mirrors the real organisation, with departments imported from Odoo HR.
  • The framework imported and broken down into requirements, each requirement linked to one or more controls.
  • A compliance rate computed per framework, continuously, so you always know where the gaps are.
  • Shared controls: a measure such as multi-factor authentication on privileged accounts serves CyFun, ISO 27001 and NIS2 without being documented three times.
  • Evidence attached to the tested control, timestamped, with the test result and its author.
  • Scheduled periodic reviews, traced in the Odoo chatter, to demonstrate the system is alive.

Frequently asked questions

Is CyFun mandatory?

No. What is mandatory are the risk management measures set out in the Belgian law transposing NIS2 for entities in scope, along with registration with the CCB. CyFun is the route Belgium provides to demonstrate that compliance, with a presumption of conformity attached. Other routes, including ISO 27001, remain possible depending on your situation.

What is the difference between CyFun verification and certification?

Verification attests the level reached through arrangements matching the target level, while certification involves an accredited conformity assessment body. Which regime applies depends on your classification as an important or essential entity, and the associated deadlines should be checked directly with the CCB.

How long does CyFun compliance take?

For an SME starting from a healthy IT baseline, most of the work fits in a few months, and it is rarely technical: it is inventorying, documenting, testing and proving. The real timeline depends heavily on whether a usable asset inventory exists at the start.

Take action

Prism Technology is an official Odoo partner in Belgium, based in Walloon Brabant. We built Prism GRC, a native Odoo module for managing risks, controls, audits and multi-framework compliance. In 30 minutes, we work out which CyFun level applies to you and what concretely stands between you and the evidence.

👉 Book your 30-minute demo — Contact us

Why We Built Our GRC on Odoo
And Why a Standalone Tool Would Have Been the Wrong Call