Home › Frameworks › CyFun

Reach your CyFun level, and prove it.

Dazr turns the CCB’s CyberFundamentals into recurring controls with owners, evidence and reminders. Pick your version and level, keep every key measure on track and walk into your verification ready. Included from Pro, €99 a month.

At a glance

  • Versions: CyFun 2023 and CyFun 2025, both accepted until 18 April 2027.
  • Levels: Basic, Important and Essential, with Small as an entry level.
  • Controls: 27, from the version and level to the six functions Govern, Identify, Protect, Detect, Respond and Recover.
  • Plan: included from Pro, €99 a month.

On this page

  1. What is CyFun?
  2. Levels and who needs which
  3. What you get in Dazr
  4. One set of evidence for CyFun, NIS2 and ISO 27001
  5. How Dazr helps with CyFun

What is CyFun?

CyberFundamentals (CyFun®) is the cybersecurity framework of the Centre for Cybersecurity Belgium (CCB). It is the route the CCB recommends to the risk-management measures of the Belgian NIS2 law of 26 April 2024. CyFun 2025, published on 1 October 2025, follows the NIST Cybersecurity Framework 2.0; CyFun 2023 follows NIST CSF 1.1.

Levels and who needs which

  • Basic, Important and Essential are cumulative assurance levels, with Small as an entry level. Each level adds requirements and asks for more maturity.
  • Key measures are the requirements that stop the most common attacks. They must reach the required maturity at every level.
  • Your level follows from the CCB risk-assessment tool. An essential entity may justify a lower level with a documented risk analysis; its NIS2 classification stays the same.
  • Essential entities are assessed regularly: a CyFun certification (Essential) or verification (Important or Basic), an ISO/IEC 27001 certification, or an inspection by the CCB. Important entities may opt in.
  • A verification or certification by a body accredited by BELAC and authorised by the CCB gives you a presumption of conformity.

Deadlines depend on your level and route. For essential entities a first milestone fell on 18 April 2026; check the CCB’s current communication for yours.

What you get in Dazr

ProgrammeVersion and level, scope, key measures, self-assessment and the conformity assessment, each a control with an owner.
Govern and IdentifyContext, risk strategy, roles, policy, oversight, the supply chain, assets, risk assessment and improvement.
Protect and DetectAccess and MFA, awareness, data and backups, platform security, network resilience, monitoring and event analysis.
Respond and RecoverIncident management, analysis, reporting to the CCB, mitigation, recovery and communication.

One set of evidence for CyFun, NIS2 and ISO 27001

Every CyFun control in Dazr names the NIS2 measure and the ISO 27001 controls it maps to. Turn on CyFun next to NIS2 or ISO 27001 and link the same evidence to both.

CyFun functionNIS2ISO 27001:2022
GovernArt. 20; Art. 21(2)(a) and (d)Clauses 4 to 6 and 9.3; A.5.1 to A.5.4, A.5.19 to A.5.23
IdentifyArt. 21(2)(a), (e) and (f)6.1, 8.2, 10; A.5.9 to A.5.12, A.8.8
ProtectArt. 21(2)(c), (e), (g), (h), (i) and (j)A.5.15 to A.5.18, A.6.3, A.8.5, A.8.13, A.8.24
DetectArt. 21(2)(b)A.5.25, A.8.15, A.8.16
RespondArt. 21(2)(b); Art. 23A.5.24 to A.5.28
RecoverArt. 21(2)(c)A.5.29, A.5.30

How Dazr helps with CyFun

With Dazr Compliance you can:

  • Record the version, level and scope you chose, with management approval on file
  • Keep every key measure in view, with its owner, evidence and next check
  • Run the 27 CyFun controls on schedule, with reminders, evidence expiry dates and a weekly overdue chaser
  • Report significant incidents on time: the incident register counts down the 24-hour, 72-hour and one-month NIS2 milestones
  • Give your conformity assessment body a time-limited, read-only login, or hand over a PDF audit trail
Incident register with a GDPR notification countdown and a NIS2 incident-notification milestone
The register with a GDPR notification countdown and the next NIS2 milestone.

Sources: CCB, CyberFundamentals Framework, CCB, CyFun® 2025 is here, CCB, FAQ on NIS2 and CyberFundamentals, CCB, conformity assessment bodies, CCB, the 18 April 2026 deadline for essential entities.

CyFun questions, answered.

Does Dazr give us a CyFun certificate?

No. Only a conformity assessment body authorised by the CCB can verify or certify you. Dazr keeps the work and the evidence that body asks for in one place.

CyFun 2023 or CyFun 2025?

Both are accepted until 18 April 2027. CyFun 2025 follows NIST CSF 2.0, adds governance measures from the Important level and puts more weight on the supply chain and operational technology. The controls in Dazr follow the 2025 categories and name the 2023 categories they replace, so they work for either version.

We already work towards ISO 27001. Do we need CyFun too?

In Belgium an ISO/IEC 27001 certification with the right scope is also a route to NIS2 conformity. CyFun is free to use and is the framework the CCB recommends. In Dazr you can run both and link the same evidence to both.

Which plan do we need?

CyFun is included from Pro, €99 a month for up to five users and five frameworks, and in Enterprise. Try Pro free for 14 days.

Ready for your CyFun assessment?