Belgian CyberFundamentals Framework (CyFun) 2025
Overview of the Belgian CyberFundamentals Framework (CyFun) 2025
The Belgian CyberFundamentals Framework (CyFun) 2025, published by the Centre for Cybersecurity Belgium (CCB), is Belgium's national cybersecurity framework providing a structured, risk-based approach to building cyber resilience across organizations of all sizes. CyFun translates international best practices into actionable security measures organized across four progressive assurance levels—Small, Basic, Important, and Essential—enabling organizations to select and implement controls appropriate to their risk profile, sector, and regulatory obligations. The 2025 edition represents a significant evolution of the framework, strengthening alignment with the EU NIS2 Directive as transposed into Belgian law in October 2024, while expanding coverage of supply chain security, operational technology (OT), and governance requirements.
CyFun serves as Belgium's primary reference framework for organizations seeking to demonstrate cybersecurity maturity, comply with NIS2 obligations, and obtain the voluntary CyFun label—a recognized attestation of cyber resilience. The framework maps its measures to internationally recognized standards including NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, ISO/IEC 27002:2022, IEC 62443-3-3, and CIS Controls v8.1, enabling organizations to implement controls once while satisfying multiple compliance and assurance requirements. This cross-mapping approach reduces duplication of effort and helps organizations integrate CyFun into existing security programs built on international standards.
The 2025 edition coexists with CyFun 2023 until 18 April 2027, providing organizations with a transition period to migrate from the previous version. During this coexistence period, organizations may continue using CyFun 2023 for existing certifications and assessments, but new CyFun label applications and renewals increasingly reference the 2025 edition. Organizations should plan their transition to CyFun 2025 proactively, particularly those subject to NIS2 requirements, as the updated framework better reflects current regulatory expectations and emerging threat landscapes including supply chain attacks and OT-targeted intrusions.
Framework Applicability and Adoption
CyFun applies to all Belgian organizations regardless of size or sector, from small businesses and non-profits to large enterprises and critical infrastructure operators. The framework's tiered assurance levels make it accessible to organizations with limited cybersecurity resources while providing a clear progression path toward comprehensive security maturity. CyFun is particularly relevant for organizations subject to Belgium's NIS2 transposition, which entered into force in October 2024, as the framework provides a practical implementation pathway for meeting NIS2's risk management, incident reporting, supply chain security, and governance requirements.
Adoption of CyFun has grown significantly since its initial publication, driven by Belgian government recommendations, sector-specific regulatory guidance, and increasing customer and partner expectations for demonstrated cyber resilience. Organizations pursuing the CyFun label benefit from independent third-party assessment validating their security posture, while those implementing CyFun measures without formal certification gain structured guidance for building effective security programs. The CCB actively promotes CyFun adoption through awareness campaigns, sector workshops, and integration with Belgium's broader cybersecurity ecosystem including the Cyber Security Coalition and regional cyber resilience initiatives.
CyFun's mapping to international standards enables Belgian organizations operating globally to demonstrate security capabilities that align with frameworks recognized across European and international markets. Organizations already implementing ISO 27001, NIST CSF, or CIS Controls can leverage existing investments by mapping current controls to CyFun measures, identifying gaps, and implementing additional measures required for their target assurance level. This interoperability makes CyFun valuable for multinational organizations seeking consistent security practices across Belgian operations while maintaining alignment with global standards.
Four Assurance Levels
CyFun organizes cybersecurity measures across four progressive assurance levels, each building upon the previous level with additional controls addressing higher-risk scenarios and more sophisticated threat environments. Organizations select their target level based on risk assessments, sector requirements, regulatory obligations, and business needs, with each level representing a measurable step toward cyber resilience.
Small Level (~10 Measures)
The Small level provides foundational cybersecurity hygiene for micro-enterprises, sole proprietors, and very small organizations with limited IT infrastructure and minimal exposure to sophisticated threats. Approximately 10 measures address essential practices including strong password policies, software updates, basic backup procedures, antivirus protection, and awareness of common phishing tactics. The Small level is designed to be achievable with minimal technical expertise and limited budget, providing a practical starting point for organizations taking their first steps toward cyber resilience.
Small-level measures focus on preventing the most common attack vectors affecting small businesses, including credential theft, malware infections, and ransomware delivered through email. Organizations at this level typically operate with consumer-grade or basic business IT setups, making the measures practical and proportionate to their risk environment. While Small-level controls do not satisfy NIS2 requirements for essential or important entities, they establish foundational security awareness and practices that support progression to higher assurance levels.
Basic Level (~50 Measures)
The Basic level targets small to medium-sized organizations with more structured IT environments and moderate exposure to cyber threats. Approximately 50 measures expand upon Small-level foundations with requirements for access control, network segmentation, incident awareness, vendor management basics, and documented security policies. Basic level controls address threats including targeted phishing, credential stuffing, and opportunistic ransomware attacks that affect organizations with internet-facing services and remote access capabilities.
Organizations pursuing Basic level implementation should establish basic governance structures, assign security responsibilities, and maintain documentation of key security processes. Basic level measures align with foundational requirements in NIST CSF 2.0 and CIS Controls, providing a solid baseline for organizations not subject to stringent regulatory requirements but seeking to demonstrate reasonable security diligence to customers, partners, and insurers. Many Belgian SMEs adopt Basic level as their primary cybersecurity target, balancing security investment with operational constraints.
Important Level (~120 Measures)
The Important level addresses organizations with significant cyber exposure, including those handling sensitive data, providing critical services, or operating in sectors with elevated threat profiles. Approximately 120 measures introduce comprehensive governance requirements, formal risk management processes, security monitoring capabilities, incident response planning, and enhanced supply chain security controls. The 2025 edition notably elevates governance requirements at the Important level, reflecting NIS2's emphasis on management body accountability and board-level cybersecurity oversight.
Important level measures align closely with NIS2 requirements for important entities under Belgium's transposition, making this level particularly relevant for organizations classified as important entities under the directive. Controls address advanced threats including supply chain compromises, insider threats, and targeted attacks against operational systems. Organizations at Important level must implement formal security policies, conduct regular risk assessments, maintain incident response capabilities, and demonstrate management commitment to cybersecurity outcomes through documented governance structures.
Essential Level (~200 Measures)
The Essential level represents the highest assurance tier, designed for organizations operating critical infrastructure, essential services, and high-value targets facing sophisticated, persistent threats. Approximately 200 measures provide comprehensive coverage across governance, risk management, technical controls, incident response, business continuity, supply chain security, and operational technology protection. Essential level controls address nation-state actors, advanced persistent threats (APTs), and complex multi-stage attacks targeting critical systems and data.
Essential level aligns with NIS2 requirements for essential entities and incorporates enhanced OT security measures reflecting the 2025 edition's expanded focus on industrial control systems, SCADA environments, and converged IT/OT networks. Organizations at Essential level must implement continuous security monitoring, advanced threat detection, comprehensive supply chain security programs, and robust business continuity capabilities. The Essential level also includes requirements for security testing, penetration testing, and red team exercises validating control effectiveness against realistic attack scenarios.
Key Updates in CyFun 2025
CyFun 2025 introduces significant enhancements over the 2023 edition, reflecting evolving threat landscapes, regulatory changes, and lessons learned from real-world implementations. Understanding these updates helps organizations transitioning from CyFun 2023 or implementing CyFun for the first time.
NIS2 Alignment: The 2025 edition strengthens alignment with the EU NIS2 Directive as transposed into Belgian law in October 2024. Measures addressing governance, risk management, incident reporting, supply chain security, and business continuity have been updated to reflect NIS2's specific requirements, enabling organizations to use CyFun as a primary implementation framework for NIS2 compliance. The mapping between CyFun assurance levels and NIS2 entity classifications provides clear guidance for essential and important entities.
Supply Chain Security: CyFun 2025 significantly expands supply chain security requirements across Important and Essential levels, addressing third-party risk management, vendor security assessments, software supply chain integrity, and contractual security obligations. These enhancements reflect the growing recognition that supply chain attacks represent a primary threat vector, particularly for organizations with complex vendor ecosystems and reliance on third-party software and services.
Operational Technology (OT) Focus: The 2025 edition introduces dedicated OT security measures addressing industrial control systems, SCADA environments, building management systems, and other operational technology increasingly targeted by attackers. OT measures draw from IEC 62443-3-3 security requirements and address network segmentation between IT and OT, OT-specific monitoring, patch management challenges in OT environments, and incident response considerations for operational systems where availability constraints limit traditional security approaches.
Governance at Important Level: CyFun 2025 elevates governance requirements to the Important level, previously concentrated at Essential level. Organizations at Important level must now demonstrate management body accountability, board-level cybersecurity reporting, and formal assignment of cybersecurity responsibilities to senior management. This change reflects NIS2's governance requirements and ensures that organizations with moderate to high cyber exposure maintain appropriate executive oversight of security programs.
Updated International Mappings: The 2025 edition updates cross-references to NIST CSF 2.0, ISO 27001:2022, ISO 27002:2022, IEC 62443, and CIS Controls v8.1, ensuring that CyFun measures remain aligned with current international best practices. Organizations can leverage updated mapping tables to demonstrate equivalence between CyFun implementation and other framework certifications.
Relationship to NIS2 and Other Frameworks
CyFun 2025 exists within a broader ecosystem of European and international cybersecurity frameworks, with important relationships that enable comprehensive security program development. Understanding these relationships helps organizations integrate CyFun effectively with existing compliance obligations and security investments.
CyFun serves as Belgium's recommended implementation framework for organizations subject to the EU NIS2 Directive, transposed into Belgian national law in October 2024. The CCB designed CyFun 2025 specifically to help organizations meet NIS2's risk management, governance, incident reporting, supply chain security, and business continuity requirements. Organizations classified as essential or important entities under NIS2 can use CyFun assurance levels as implementation targets, with Important level addressing important entity requirements and Essential level addressing essential entity requirements.
The framework maps comprehensively to NIST Cybersecurity Framework 2.0, enabling organizations familiar with NIST CSF to understand CyFun measures within a recognized functional structure. CyFun measures align with NIST CSF 2.0's six functions—Govern, Identify, Protect, Detect, Respond, and Recover—providing a familiar organizational framework for implementing Belgian-specific requirements. Organizations can use NIST CSF 2.0 as an overlay for communicating CyFun implementation status to international stakeholders.
CyFun measures map to ISO/IEC 27001:2022 and ISO/IEC 27002:2022 controls, enabling organizations pursuing ISO 27001 certification to leverage CyFun as a gap assessment and implementation guide. The mapping demonstrates which CyFun measures satisfy ISO 27001 Annex A control requirements, helping organizations achieve dual compliance efficiently. Organizations with existing ISO 27001 certifications can assess their current control implementation against CyFun measures to identify additional requirements for their target assurance level.
For organizations operating industrial and operational technology environments, CyFun 2025's OT measures align with IEC 62443-3-3 system security requirements, providing a pathway for OT security compliance within the broader CyFun framework. Similarly, CyFun measures map to CIS Controls v8.1, enabling organizations implementing CIS Controls to understand how their existing controls contribute to CyFun assurance level achievement.
Implementation Strategies and Best Practices
Successfully implementing CyFun 2025 requires organizations to understand their target assurance level, assess current security practices, and implement measures systematically. Organizations should begin with comprehensive gap assessments comparing current security practices against CyFun requirements for their selected assurance level, identifying strengths, weaknesses, and prioritization opportunities.
Select the Appropriate Assurance Level: Organizations must select an assurance level appropriate to their risk profile, sector requirements, and regulatory obligations. Risk assessments should consider data sensitivity, service criticality, threat exposure, and regulatory classification under NIS2. Organizations subject to NIS2 should align their CyFun target level with their entity classification, selecting Important level for important entities and Essential level for essential entities.
Leverage Existing Framework Investments: Organizations already implementing ISO 27001, NIST CSF, or CIS Controls should map existing controls to CyFun measures before implementing additional requirements. This approach minimizes duplication and accelerates CyFun implementation by building upon established security capabilities. Use CyFun's published mapping tables to identify gaps requiring new implementation efforts.
Plan the Transition from CyFun 2023: Organizations currently certified or implementing CyFun 2023 should develop transition plans addressing the 18 April 2027 coexistence deadline. Transition planning should include gap assessments comparing 2023 and 2025 requirements, prioritization of new measures introduced in 2025, and scheduling of reassessment activities. Organizations should begin transition early to avoid last-minute compliance pressures.
Address Governance Requirements Early: The 2025 edition's elevated governance requirements at Important level require management commitment and organizational change. Organizations should secure executive sponsorship, establish cybersecurity governance structures, and assign clear accountability for CyFun implementation before addressing technical controls. Governance foundations support sustainable security program development and demonstrate NIS2 compliance.
Implement Supply Chain and OT Controls Progressively: New supply chain and OT security requirements may require significant organizational changes. Organizations should assess current supply chain and OT security postures, prioritize high-risk vendors and critical OT systems, and implement enhanced controls progressively. Engage OT engineering teams early in OT security planning to balance security requirements with operational availability constraints.
Common Challenges and Solutions
Organizations implementing CyFun 2025 frequently encounter similar challenges related to assurance level selection, resource constraints, and integration with existing security programs. Understanding these common challenges helps organizations plan proactively and implement CyFun effectively.
Determining the Right Assurance Level: Organizations may struggle to select an appropriate assurance level, either underestimating their risk exposure or over-implementing controls beyond their needs. Solutions include conducting formal risk assessments, consulting CCB guidance on sector-specific recommendations, and considering NIS2 entity classifications where applicable. Organizations should select levels based on objective risk analysis rather than aspirational targets that exceed practical implementation capacity.
Resource Constraints for SMEs: Small and medium organizations may lack dedicated cybersecurity personnel and budgets required for higher assurance levels. Solutions include prioritizing measures based on risk, leveraging managed security service providers, implementing controls progressively over multi-year roadmaps, and starting with Small or Basic levels before advancing. The tiered structure enables organizations to build capabilities incrementally rather than attempting comprehensive implementation immediately.
Integrating CyFun with ISO 27001 Programs: Organizations with existing ISO 27001 certifications may find gaps between ISO 27001 scope and CyFun requirements, particularly for supply chain and OT measures. Solutions include extending ISO 27001 scope to cover CyFun-identified gaps, using CyFun gap assessments to inform ISO 27001 continuous improvement activities, and maintaining integrated documentation demonstrating compliance with both frameworks.
OT Security Implementation: Organizations with operational technology environments face unique challenges implementing OT security measures without disrupting production systems. Solutions include conducting OT-specific risk assessments, implementing network segmentation between IT and OT, deploying OT-aware monitoring solutions, and engaging OT vendors in security planning. Organizations should balance security improvements with operational availability requirements, implementing controls during planned maintenance windows.
Transitioning from CyFun 2023 to CyFun 2025: Organizations certified under CyFun 2023 must plan migration before the 18 April 2027 coexistence deadline. Solutions include conducting gap analyses between 2023 and 2025 editions, prioritizing new supply chain and OT requirements, updating governance documentation for Important and Essential levels, and scheduling reassessment against the 2025 framework. The CCB provides transition guidance and self-assessment tools on the official CyFun portal to support organizations through this migration period.
Frequently Asked Questions
What is CyFun?
CyFun (CyberFundamentals Framework) is Belgium's national cybersecurity framework published by the Centre for Cybersecurity Belgium (CCB). It provides a structured set of security measures organized across four assurance levels—Small, Basic, Important, and Essential—enabling organizations to build cyber resilience appropriate to their risk profile. CyFun maps to international standards including NIST CSF 2.0, ISO 27001/27002, IEC 62443, and CIS Controls, and serves as Belgium's recommended framework for NIS2 compliance and the voluntary CyFun label certification.
What are the four CyFun assurance levels?
CyFun defines four progressive assurance levels: Small (~10 measures) for micro-enterprises and sole proprietors; Basic (~50 measures) for small to medium organizations; Important (~120 measures) for organizations with significant cyber exposure and NIS2 important entity obligations; and Essential (~200 measures) for critical infrastructure operators and NIS2 essential entities. Each level builds upon the previous level with additional controls addressing higher-risk scenarios and more sophisticated threats.
How does CyFun relate to NIS2?
CyFun 2025 is explicitly aligned with the EU NIS2 Directive as transposed into Belgian law in October 2024. The CCB designed CyFun as Belgium's primary implementation framework for NIS2, with Important level addressing requirements for important entities and Essential level addressing requirements for essential entities. Organizations subject to NIS2 can use CyFun measures to demonstrate compliance with risk management, governance, incident reporting, supply chain security, and business continuity obligations.
How does CyFun compare to ISO 27001?
CyFun and ISO 27001 serve complementary but distinct purposes. ISO 27001 is an international certifiable standard for Information Security Management Systems (ISMS), while CyFun is Belgium's national framework providing prescriptive security measures with a voluntary label program. CyFun maps its measures to ISO 27001:2022 and ISO 27002:2022 controls, enabling organizations to use CyFun as an implementation guide for ISO 27001 or to demonstrate equivalence between CyFun certification and ISO 27001 compliance. Organizations may pursue both CyFun label and ISO 27001 certification, leveraging overlapping controls to reduce implementation effort.
How do organizations obtain the CyFun label?
Organizations obtain the CyFun label through independent third-party assessment by CCB-accredited auditors who evaluate implementation of CyFun measures at the organization's selected assurance level. The certification process includes documentation review, control testing, and on-site assessment verifying that security measures are implemented and operating effectively. Organizations must maintain their CyFun label through periodic reassessment, typically annually, demonstrating continued compliance with CyFun requirements. The CCB maintains a registry of CyFun-certified organizations and provides guidance on selecting accredited assessment bodies through the official CyFun portal.
Conclusion
The Belgian CyberFundamentals Framework (CyFun) 2025 provides a comprehensive, tiered approach to building cyber resilience for organizations across Belgium. With four assurance levels addressing organizations from micro-enterprises to critical infrastructure operators, CyFun enables proportional security investment while providing clear progression paths toward comprehensive security maturity. The 2025 edition's enhanced NIS2 alignment, supply chain security requirements, OT focus, and elevated governance expectations reflect current regulatory and threat landscapes.
Successful CyFun implementation requires organizations to select appropriate assurance levels, leverage existing framework investments through cross-mapping, and implement measures systematically based on risk priorities. Organizations transitioning from CyFun 2023 should plan proactively for the 18 April 2027 coexistence deadline, while new implementers can use CyFun as a primary framework for NIS2 compliance and voluntary CyFun label certification.
By following CyFun 2025 guidance, maintaining comprehensive documentation, and pursuing independent assessment where appropriate, organizations can establish security programs that effectively protect against evolving threats, demonstrate compliance with Belgian and EU requirements, and build trust with customers, partners, and regulators. CyFun's integration with international standards ensures that Belgian organizations can achieve local compliance while maintaining alignment with globally recognized security practices.