CONTEXT
NIS2 & CyFun: what you need to know
The NIS2 Directive
The EU NIS2 Directive (2022/2555) entered into force on 16 January 2023 and was transposed into Belgian law on 26 April 2024. It significantly broadens the scope of cybersecurity obligations, covering essential and important entities across 18 sectors. Affected organisations must implement appropriate security measures and may face audits or certifications.
The CyFun® Framework
CyberFundamentals (CyFun®) is the cybersecurity framework published by the Belgian Centre for Cybersecurity (CCB). Rooted in the NIST Cybersecurity Framework, it defines 218 requirements across 6 functions — Identify, Protect, Detect, Respond and Recover — at three assurance levels: Basic, Important and Essential. CyFun compliance is the recognised path for Belgian organisations to meet their NIS2 obligations.