What is CyFun?
CyberFundamentals (CyFun®) is published by the Centre for Cybersecurity Belgium (CCB) to translate NIS2 obligations into concrete, measurable requirements. The 2025 edition is structured on the six NIST CSF 2.0 functions and maps onto ISO/IEC 27001/27002, CIS Controls v8.1 and IEC 62443.
CyFun 2025 holds 218 requirements across 22 categories and 90 subcategories, split into three cumulative assurance levels: Basic (34 requirements), Important (133) and Essential (218). Twenty-nine of them are key measures, each carrying its own conformity threshold.
Every requirement is scored on two dimensions — documentation maturity and implementation maturity, each 1 to 5. Conformity is then judged against three rules: every key measure at or above the level's floor, every category at or above 3 at Essential, and an overall average of 2.5, 3 or 3.5 depending on the level.
CyFun 2025 structure
Govern (GV)
Identify (ID)
Protect (PR)
Detect (DE)
Respond (RS)
Recover (RC)
CyFun with ResiPlan
ResiPlan ships the official CyFun® 2025 catalogue and reproduces the CCB self-assessment method: dual documentation/implementation scoring, key-measure and category thresholds, and a conformity verdict per assurance level. The result exports as a workbook laid out like the CCB's own tool.
Cross-mapping uses the CCB's own correspondence tables to ISO/IEC 27002:2022 and the NIS2 Directive — assess once, satisfy your CyFun and NIS2 obligations together.
ResiPlan is not affiliated with, endorsed by or accredited by the CCB. A self-assessment prepares you for a conformity assessment by an accredited body; it is not a certification.
Frequently asked questions
What is CyFun?
CyberFundamentals (CyFun®) is the Belgian CCB framework that operationalises NIS2 with concrete requirements at three cumulative assurance levels: Basic, Important and Essential. The 2025 edition holds 218 requirements over the six NIST CSF 2.0 functions.
Which CyFun level do I need?
It depends on your risk profile and NIS2 classification; important and essential entities typically target the Important or Essential level.
Is CyFun mapped to NIS2 and ISO 27001?
Yes, and by the publisher itself: the CCB issues correspondence tables to ISO/IEC 27001/27002:2022, CIS Controls v8.1, IEC 62443 and the NIS2 Directive. ResiPlan uses those official tables rather than a mapping of its own.
How is CyFun conformity calculated?
Each requirement carries a documentation score and an implementation score from 1 to 5. Requirement scores roll up to subcategories, subcategories to categories, and categories to the overall average. Conformity requires every key measure to reach the level's threshold (2.5 at Basic, 3 at Important and Essential), every category to reach 3 at Essential, and an overall average of 2.5, 3 or 3.5 respectively.
Does ResiPlan issue a CyFun certificate?
No. ResiPlan implements the published self-assessment method so you can measure and evidence your position. A CyFun conformity assessment is delivered by an accredited conformity assessment body under the CCB scheme.