Skip to main content
CCB CyberFundamentals CyFun

CyberFundamentals (CyFun®)

The Centre for Cybersecurity Belgium (CCB) CyberFundamentals Framework, version 2023-03-01 — a practical, risk-based framework with Basic, Important, and Essential assurance levels, aligned with NIS2. Available on the Premium plan.

A practical route to
cybersecurity maturity and NIS2 readiness

CyFun® was developed by the Centre for Cybersecurity Belgium (CCB) on top of recognised standards — NIST CSF, ISO/IEC 27001, IEC 62443, and CIS Controls. It organises measures under the five NIS functions Identify, Protect, Detect, Respond, and Recover, and scales them to the organisation's risk profile.

The framework is used well beyond the Belgian government. It is the reference for NIS2 conformity in Belgium and has also been adopted in Romania and drawn on by other EU member states, making it a recognisable baseline for organisations operating across the EU.

Organisations can use CyFun for self-assessment or for conformity assessment by an accredited body. In Unicis, you track every measure, link tasks as evidence, and report on progress per assurance level.

3
Assurance levels
5
NIS functions
2023
Version 2023-03-01
EN · FR
Languages

Get CyFun-ready with Unicis

Track Basic, Important, or Essential measures with evidence, guidance, and cross-framework mapping.

Five functions, three assurance levels

CyFun measures are grouped by the NIS functions and scaled to the assurance level that fits your risk.

ID

Identify

Asset management, business environment, governance, risk assessment, and risk management strategy.

PR

Protect

Identity and access management, awareness and training, data security, protective processes, maintenance, and protective technology.

DE

Detect

Anomalies and events, continuous security monitoring, and detection processes.

RS

Respond

Response planning, communications, analysis, mitigation, and improvements.

RC

Recover

Recovery planning, improvements, and recovery communications.

B/I/E

Basic, Important, Essential

Assurance levels set the depth of measures. Basic provides small-organisation hygiene; Important and Essential add increasingly rigorous controls, and key measures mark the priority actions.

Why teams choose CyFun

Scales to your risk

Pick the assurance level that matches your risk profile and grow into higher levels over time.

Recognised across the EU

Used in Belgium and Romania, and referenced by other EU member states as a path to NIS2 readiness.

Mapped to other frameworks

Mappings to NIS2, ISO 27001, NIST CSF, and CIS let you reuse evidence across frameworks.

Maturity levels mapped to Unicis Platform

CyFun assesses both policy maturity (is it documented, approved, and governed?) and implementation maturity (is it applied, evidenced, and measured?) on five levels. Unicis maps each level to a control status, so your CyFun score follows directly from the statuses you set on controls.

CyFun levelWhat is expected (policy and implementation)Unicis statusStatus meaning
1 · InitialPolicy and process are informal or ad hoc, with little documentation, no formal approval, and no consistent evidence of implementation.Performed InformallyDevelopment has barely started and will require significant work to fulfill the requirements
2 · RepeatablePolicy is documented but not yet formally approved. The process is partly implemented and exceptions are handled case by case. Evidence exists but is incomplete.PlannedProgressing nicely but not yet complete
3 · DefinedPolicy is documented, approved, and communicated, and exceptions follow a defined process. The process is described and implemented consistently, though not yet fully enforced or measured.Well DefinedDevelopment is more or less complete, although detail is lacking and/or it is not yet implemented, enforced and actively supported by top management
4 · ManagedPolicy is enforced with managed exceptions. The process is implemented and operating, with evidence of implementation and metrics collected and monitored.Quantitatively ControlledDevelopment is complete, the process/control has been implemented and recently started operating
5 · OptimizingPolicy and process are reviewed regularly and improved based on metrics. Implementation is consistent across the organisation, with substantial evidence for auditors.Continuously ImprovingThe requirement is fully satisfied, is operating fully as expected, is being actively monitored and improved, and there is substantial evidence to prove all that to the auditors

Statuses outside the five levels

  • Unknown
    Has not even been checked yet
  • Not Applicable
    Management can ignore them
  • Not Performed
    Complete lack of recognizable policy, procedure, control etc.

Who should use CyFun?

Organisations of any size that want a structured, risk-based baseline — especially NIS2 entities in Belgium and Romania, their suppliers, and companies serving customers who ask for CyFun conformity.

NIS2 Essential EntitiesNIS2 Important EntitiesSMEsPublic SectorSuppliers & Service ProvidersCritical Infrastructure

Multi-Framework Support

13 Compliance Frameworks Supported

From the minimum viable security baseline to enterprise-grade standards — coverage for every compliance requirement.

Community (Free) Premium Ultimate

Start your CyFun journey with Unicis

Track CyberFundamentals measures with evidence, guidance, and cross-framework mapping. Available on the Premium plan.