CyFun (Cyber Fundamentals): Assess Your Readiness at Basic, Important or Essential Level
The Cyber Fundamentals Framework, known as CyFun, is a practical cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It gives organisations a concrete, prioritised set of measures to protect against the most common cyber attacks, and it is increasingly recognised across the EU as a structured route to demonstrating NIS2 conformity.
ShieldIQ lets you assess your organisation against CyFun and choose the assurance level that matches your risk and regulatory exposure. It is one framework with three cumulative levels, not three separate assessments.
What Is the Cyber Fundamentals Framework?
CyFun is built on the internationally recognised NIST Cybersecurity Framework and maps to ISO 27001, IEC 62443 and the CIS Controls. Rather than leaving an organisation to interpret a standard from scratch, CyFun translates good practice into a defined set of key measures, each assigned to an assurance level. This makes it an ideal starting point for small and mid-sized organisations that need a credible programme quickly and without a dedicated security team.
Because CyFun is derived from NIST CSF, work you do here carries directly into your other frameworks on ShieldIQ, so your compliance effort is additive, not duplicated.
The Three CyFun Assurance Levels
CyFun defines three levels of assurance. They are cumulative: each level includes everything in the level below it and adds further measures. On ShieldIQ you simply pick your level when you start, and the assessment shows the right set of questions.
Basic covers the foundational cyber hygiene every organisation should have in place. It concentrates on the measures that stop the large majority of common attacks: knowing your assets, controlling access with multi-factor authentication, keeping systems patched, protecting data with backups and encryption, training staff, and being able to respond to and recover from an incident.
Important builds on Basic and adds the rigour expected of organisations with a higher risk profile or regulatory exposure. It introduces structured risk assessment, supply-chain security, vulnerability management, network segmentation, active detection and alerting, and defined incident reporting, including the regulatory notification timelines that NIS2 introduces.
Essential is the most demanding level, aligned to the expectations placed on essential entities. On top of Important, it adds board-level governance and accountability for cyber risk, a formal risk-management strategy and risk appetite, continuous supplier assurance, privileged-access management, continuous monitoring enriched with threat intelligence, and a culture of exercising and continuous improvement across response and recovery.
CyFun and NIS2
The NIS2 Directive requires essential and important entities to put appropriate and proportionate security measures in place, and it makes senior management accountable for doing so. CyFun gives you a recognised, concrete way to demonstrate that proportionality: an organisation that meets the CyFun level appropriate to its category has a defensible, evidence-backed answer to the regulator's core question. ShieldIQ maps your CyFun results to the NIS2 obligations and produces the documentation and evidence trail supervisory authorities expect.
Start your CyFun assessment, no card required →
How ShieldIQ Delivers CyFun
Every CyFun function maps to a capability in the ShieldIQ platform, so an assessment is the beginning of a live programme, not a one-off report:
Your assessment produces per-function and per-category scores across Identify, Protect, Detect, Respond and Recover, AI-written analysis of your gaps, and a prioritised remediation plan. From there, the risk register, controls, policies, asset and vendor management, incident and evidence modules let you close those gaps and stay continuously ready, with cross-framework mapping so the same evidence satisfies NIS2, ISO 27001 and NIST CSF at the same time.
Frequently Asked Questions
Which CyFun level should we target?
It depends on your risk profile and your status under NIS2. Smaller organisations and those outside NIS2 scope often start at Basic. Organisations that qualify as important entities under NIS2 typically target Important, and those classed as essential entities target Essential. Because the levels are cumulative on ShieldIQ, you can start at Basic and progress upward as you mature, reusing all the work you have already done.
Is CyFun only relevant in Belgium?
CyFun originated with the Centre for Cybersecurity Belgium, but because it is built on the NIST Cybersecurity Framework and maps to ISO 27001, it is widely applicable and increasingly referenced across the EU as a pragmatic route to NIS2 conformity. It is a strong fit for any EU small or mid-sized organisation that wants a concrete, level-based programme.
How long does the assessment take?
About 15 minutes for the Basic level, a little longer for Important and Essential as more measures are assessed. Your answers save automatically, so you can pause and continue on any device.
Do we need a security team to use it?
No. CyFun and ShieldIQ are designed for organisations without a dedicated CISO. The questions are in plain language, the AI explains each gap, and the platform gives you the remediation steps, policies and evidence tracking to act on the results.