CyberFundamentals (CyFun®)
The Centre for Cybersecurity Belgium (CCB) CyberFundamentals Framework, version 2023-03-01 — a practical, risk-based framework with Basic, Important, and Essential assurance levels, aligned with NIS2. Available on the Premium plan.
A practical route to
cybersecurity maturity and NIS2 readiness
CyFun® was developed by the Centre for Cybersecurity Belgium (CCB) on top of recognised standards — NIST CSF, ISO/IEC 27001, IEC 62443, and CIS Controls. It organises measures under the five NIS functions Identify, Protect, Detect, Respond, and Recover, and scales them to the organisation's risk profile.
The framework is used well beyond the Belgian government. It is the reference for NIS2 conformity in Belgium and has also been adopted in Romania and drawn on by other EU member states, making it a recognisable baseline for organisations operating across the EU.
Organisations can use CyFun for self-assessment or for conformity assessment by an accredited body. In Unicis, you track every measure, link tasks as evidence, and report on progress per assurance level.
Get CyFun-ready with Unicis
Track Basic, Important, or Essential measures with evidence, guidance, and cross-framework mapping.
Five functions, three assurance levels
CyFun measures are grouped by the NIS functions and scaled to the assurance level that fits your risk.
Identify
Asset management, business environment, governance, risk assessment, and risk management strategy.
Protect
Identity and access management, awareness and training, data security, protective processes, maintenance, and protective technology.
Detect
Anomalies and events, continuous security monitoring, and detection processes.
Respond
Response planning, communications, analysis, mitigation, and improvements.
Recover
Recovery planning, improvements, and recovery communications.
Basic, Important, Essential
Assurance levels set the depth of measures. Basic provides small-organisation hygiene; Important and Essential add increasingly rigorous controls, and key measures mark the priority actions.
Why teams choose CyFun
Scales to your risk
Pick the assurance level that matches your risk profile and grow into higher levels over time.
Recognised across the EU
Used in Belgium and Romania, and referenced by other EU member states as a path to NIS2 readiness.
Mapped to other frameworks
Mappings to NIS2, ISO 27001, NIST CSF, and CIS let you reuse evidence across frameworks.
Maturity levels mapped to Unicis Platform
CyFun assesses both policy maturity (is it documented, approved, and governed?) and implementation maturity (is it applied, evidenced, and measured?) on five levels. Unicis maps each level to a control status, so your CyFun score follows directly from the statuses you set on controls.
| CyFun level | What is expected (policy and implementation) | Unicis status | Status meaning |
|---|---|---|---|
| 1 · Initial | Policy and process are informal or ad hoc, with little documentation, no formal approval, and no consistent evidence of implementation. | Performed Informally | Development has barely started and will require significant work to fulfill the requirements |
| 2 · Repeatable | Policy is documented but not yet formally approved. The process is partly implemented and exceptions are handled case by case. Evidence exists but is incomplete. | Planned | Progressing nicely but not yet complete |
| 3 · Defined | Policy is documented, approved, and communicated, and exceptions follow a defined process. The process is described and implemented consistently, though not yet fully enforced or measured. | Well Defined | Development is more or less complete, although detail is lacking and/or it is not yet implemented, enforced and actively supported by top management |
| 4 · Managed | Policy is enforced with managed exceptions. The process is implemented and operating, with evidence of implementation and metrics collected and monitored. | Quantitatively Controlled | Development is complete, the process/control has been implemented and recently started operating |
| 5 · Optimizing | Policy and process are reviewed regularly and improved based on metrics. Implementation is consistent across the organisation, with substantial evidence for auditors. | Continuously Improving | The requirement is fully satisfied, is operating fully as expected, is being actively monitored and improved, and there is substantial evidence to prove all that to the auditors |
Statuses outside the five levels
- UnknownHas not even been checked yet
- Not ApplicableManagement can ignore them
- Not PerformedComplete lack of recognizable policy, procedure, control etc.
How Unicis covers CyFun®
Unicis Platform Modules
Who should use CyFun?
Organisations of any size that want a structured, risk-based baseline — especially NIS2 entities in Belgium and Romania, their suppliers, and companies serving customers who ask for CyFun conformity.
Multi-Framework Support
13 Compliance Frameworks Supported
From the minimum viable security baseline to enterprise-grade standards — coverage for every compliance requirement.
Start your CyFun journey with Unicis
Track CyberFundamentals measures with evidence, guidance, and cross-framework mapping. Available on the Premium plan.
Record of Processing Activities
Transfer Impact Assessment
Privacy Impact Assessment
Cybersecurity Controls
Cybersecurity Risk Management
Asset Inventory Management
Interactive Awareness Program