The CyberFundamentals Framework is a set of concrete measures to protect your data, significantly reduce the risk of the most common cyber-attacks and increase your organisation's cyber resilience. The framework is based on;

  • Four commonly used cybersecurity frameworks (NIST CSF, ISO 27001 / ISO 27002, CIS Controls and IEC 62443); and,
  • Anonymized historical data of successful cyber-attacks. Through retro-fitting, we are able to assess what percentage of past attacks the measures of the Framework will protect you against.

To respond to the severity of the threat an organisation is exposed to, in addition to the starting level Small, 3 assurance levels are provided: Basic, Important and Essential

The levels and key measures

CyFun Small cover

Small

The starting level Small allows an organisation to make an initial assessment. It is intended for micro-organisations or organisations with limited technical knowledge.

pdf
Download
CyFun Basic Cover

Basic

The assurance level Basic contains the standard information security measures for all enterprises. These provide an effective security value with technology and processes that are generally already available. Where justified, the measures are tailored and refined.

pdf
Download
CyFun Important cover

Important

The assurance level Important is designed to minimise the risks of targeted cyber-attacks by actors with common skills and resources in addition to known cyber security risks.

pdf
Download
CyFun Essential cover

Essential

The assurance level Essential goes one step further and is designed to address the risk of advanced cyber-attacks by actors with extensive skills and resources.

pdf
Download

CyberFundamentals Toolbox

The CyberFundamentals Toolbox contains all the tools and resources that will help you achieve conformity with the CyberFundamentals Framework.

Access the CyFun Toolbox

Get your CyberFundamentals Label

Obtaining the CyberFundamentals label provides significant advantages for any organisation, primarily in enhancing its cybersecurity posture and gaining a competitive edge in the marketplace. The label indicates that the organisation has met a recognised standard of cybersecurity practices, ensuring the implementation of essential security controls to protect its systems and data. 

The conformity assessment process not only helps in mitigating risks associated with cyber threats but also demonstrates to stakeholders, clients, and partners that the organisation is committed to maintaining robust cybersecurity measures. As a result, it fosters trust and confidence among clients and partners, potentially leading to increased business opportunities and partnerships.

Additional tools and explanation to help you get your label are available in the CyFun Toolbox.

1. Perform a risk assesment to select your assurance level

The CyFun Selection Tool is a tool for Risk Assessment resulting in a well-informed selection of the appropriate CyberFundamentals Assurance Level.

Download the CyFun Selection tool

2. Complete your Self-Assessment and implement corrective measures

The CyFun Self-Assessment tool is a MS Excel format tool to prepare self-assessment and includes spider diagrams to support management reporting.

Download the Self-Assessment Tool

3. Select an authorised Conformity Assessment Body and have them verify on certify your self-assessment

Get in touch with a Conformity Assessment Body (CAB) to have them assess your Self-Assessment and your implementation of mitigating measures.

Download the list of authorised CABs

4. Request your label on the Safeonweb@work portal

Once the Conformity Assessment process is finalised with your CAB, request your CyFun label in the Safeonweb@work portal.

Access the Safeonweb@work portal

FAQ

  • Do the CyFun® controls need to be included in the ISO/IEC 27001 Statement of Applicability to serve as an aid in establishing presumption of conformity under Belgian NIS legislation (this is the scenario where the NIS 2 entity chooses the ISO path instead

    The certification authority of the CCB (NCCA) will verify if the substantiated statement of applicability (SoA) has the same level as the relevant CyFun® assurance level. The inclusion of CyFun® controls in the ISO/IEC 27001 Statement of Applicability remains a decision of the entity concerned.

    In relation to the above the certification authority of the CCB (NCCA) will apply the deadlines set out in Art 22 of the RD of 09 June 2024:

    • Within 18 months of the entry into force of the NIS2 law or the date of the identification referred to in Article 11 of the NIS2 law the scope of the ISMS and a substantiated statement of applicability (SoA) of the same level as stipulated in CyFun® Basic or CyFun® Important and
    • Within 30 months an ISO/IEC 27001:2022 certification where the substantiated SoA has the same level as defined in CyFun® Important or Essential, depending on whether the entity is Important or Essential.
  • What is meant by a “substantiated” statement of applicability (SoA)?

    The definition of “substantiated” is as in ISO/IEC 27006-1:2024 clause 9.3.2.2 (f); the substantiation of the Statement of Applicability (SoA) has to allow the assessment of the effective implementation of the controls. Or in other words: There must be evidence that a control is implemented and is effective.

  • What does it mean in practice when it is stated that "a substantiated SoA has the same level as defined by CyFun © Basic, Important, or Essential"?

    The aim is to create a level playing field for all entities registered in Belgium, whether they choose CyFun® or ISO/IEC 27001:2022. Given the specificity of CyFun® that has been endorsed by various stakeholders, the NCCA uses the measures identified in the respective assurance level of CyFun® to review the Statement of Applicability of an ISO/IEC 27001:2022 certified entity to ensure that equivalent controls are defined and implemented effectively. Here the NCCA will pay specific attention to the key measures defined in CyFun® as these measures are directly derived from cyber attacks taking place in Belgium.

    As supervising authority, we are not allowed to advise on how the relationship between the relevant assurance level of CyberFundamentals and the ISO/IEC 2700:2022 SoA is made.

  • Are ‘exclusions’ possible in CyFun®?

    Exclusions in CyFun® could be specific CyFun® requirements where it is not feasible for the organisation to meet those CyFun® requirements. Because The premise of CyFun® is that one can fill in controls proportionally based on risk management, a conscious decision was made not to provide the possibility in the CyFun® self-assessment tool taking into account the unlikeliness of these motivated exclusions.

    The non-application of a control is an ‘exception’ (‘exception’) as provided in the CyFun® Maturity Level Description (CyFun® Toolbox).

    Documentation should verify that the exclusion is properly motivated,  documented and authorised by the organisation's senior management.

    Implementation should verify that there is sufficient evidence of due diligence to demonstrate that the exclusion of a CyFun® control does not compromise compliance with specific legal, regulatory and/or contractual obligations.

Getting a CyFun label with an ISO27001 certification

It is also possible to obtain a CyFun label by using your exisiting ISO27001 certification with the correct scope. Get in touch with your selected CAB to have them verify the scope of your certificate.

Reuse of the CyFun Framework

The CyberFundamentals Framework is a framework owned by the Centre for Cybersecurity Belgium (CCB), operating under the authority of the Prime Minister of Belgium. 

The acronym “CyFun” stands for “CyberFundamentals Framework” and is a registered trademark owned by the CCB.

The CyFun Framework and the CyberFundamentals Conformity Assessment Scheme (CAS) are available on www.cyfun.be.

The use of the acronym “CyFun” and/or parts of this document are authorised, as long as the source is clearly mentioned.

Any commercial use of CyFun is subject to a prior agreement with the CCB.

Conformity Assessment Bodies

 A dedicated page is available for Conformity Assessment Bodies that aim to become accredited and authorised for the CyberFundamentals Framework.

Access the page for Conformity Assessment Bodies