NIS2 created the Pressure. CyFun® creates the path. NIS Institute leads the way.

Discover how CyFun® translates NIS2 obligations into practical controls, maturity targets, evidence requirements and a clear cybersecurity roadmap. NIS2 establishes what organisations must achieve. CyFun® provides a structured way to decide what to implement, assess progress and demonstrate that cybersecurity measures are working.
How to turn cybersecurity obligations into controls, evidence and measurable progress?
Knowing that your organisation must improve its cybersecurity is not the same as knowing what to do next. NIS2 has increased the attention given to cybersecurity governance, riskmanagement and organisational resilience. But once the initial legal analysis is complete, organisations still face a series of practical questions:
- Which cybersecurity measures should we implement?
- What is the right level of security for our organisation?
- How do we assess our current maturity?
- Which gaps should we address first?
- What evidence do we need? How do we demonstrate measurable progress?
- How do we demonstrate measurable progress?
This is where the CyberFundamentals Framework, better known as CyFun®, becomes particularly valuable.
What is the CyberFundamentals Framework?
CyFun® is a cybersecurity framework developed and owned by the Centre for Cybersecurity Belgium (CCB). It provides organisations with concrete measures and a structured, step-by-step approach to protecting data, reducing exposure to common cyberattacks and improving cyber resilience.
The current CyFun® 2025 edition was updated to align with the NIST Cybersecurity Framework 2.0 and alligns with national and European legislation, including the NIS2 Directive. It also places
emphasis on governance, supply-chain security, operational technology and clearer, more auditable controls.
The framework organises cybersecurity outcomes around six functions:
- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
For organisations that require a formal assurance approach, CyFun® distinguishes between the Basic, Important and Essential assurance levels. Each level reflects a different risk and maturity profile. The objective is not to apply the same measures to every organisation, but to select a proportionate level based on its context, exposure and potential impact.
NIS2 defines the expectations. CyFun® helps organise the work.
Legislation describes obligations and expected outcomes. It does not manage your assets, assign control owners, configure your systems, test your backups or collect evidence for you. Those activities require a working method. CyFun® helps organisations translate broad cybersecurity expectations into:
- Defined controls;
- Technical and organisational measures;
- Clear responsibilities;
- Maturity objectives;
- Supporting documentation;
- Implementation evidence;
- Prioritised improvement actions.
This creates a common language between management, IT, cybersecurity, risk, compliance, internal audit and external assessors. Instead of treating NIS2 as one large compliance project an organisation can divide the work into manageable decisions. That structure is essential. Without it organisations can spend significant time producing policies, purchasing tools or launching disconnected initiatives without knowing whether those investments address the most important risks.
Cybersecurity on paper is not enough.
- A control may be described in a policy without being consistently implemented.
- A security tool may be installed without clear ownership, monitoring or periodic review.
- A backup may exist without being adequately protected or tested.
- An incident response plan may have been approved without ever being exercised.
This is why evidence and maturity matter. CyFun® supports organisations in looking beyond the simple question of whether a control exists. It helps them examine how consistently that control is documented, implemented, monitored and improved. The framework’s self-assessment tools can support maturity scoring, gap identification and management reporting. The results can then be used to define priorities and build an implementation roadmap rather than becoming another static compliance spreadsheet. Demonstrating progress requires more than checking “implemented” in a questionnaire. The purpose of evidence is not to create unnecessary administration. It is to demonstrate that an organisation understands its risks, has selected appropriate measures and can show that those measures are operating in practice. Good evidence also improves decision-making. It allows management to distinguish between controls that are genuinely effective and controls that merely appear complete on paper.
A practical CyFun® training. Not another general NIS2 overview.
At NIS Institute we believe that cybersecurity training must lead to usable decisions and practical action. NIS Institute is therefore organising a one-day, live-online training on the CyberFundamentals Framework on 23 September 2026. The course is designed for professionals who already have a basic understanding of NIS2 and now need to translate that knowledge into implementation, assessment and evidence. The course does not repeat the general principles of the NIS2 Directive in detail. Instead, it focuses on how CyFun® can be applied in practice.
Training details
https://nisinstitute.eu/training/cyberfundamentals-cyfun-framework/
Date: Wednesday, 23 September 2026
Format: One full day, live online
Training provider: NIS Institute, the specialised training division of CyberMinute
Prior knowledge: Basic knowledge of NIS2 is recommended
Certificate: Participants receive a certificate of attendance
Practical focus: Controls, assurance levels, maturity, evidence, conformity assessment and implementation roadmapping
Participants who want to continue towards an internationally recognised PECB qualification can also choose an optional PECB Pack. This includes either the PECB NIS 2 Directive Foundation or Lead Implementer self-study materials, access to the corresponding examination and one free retake. The PECB Pack is optional and separate from the CyFun® certificate of attendance.
The CyFun® Framework is a registered trademark owned by the Centre for Cybersecurity Belgium (CCB). NIS Institute is responsible for the content and delivery of this training. Reference to CyFun® does not, by itself, imply certification or endorsement of the training by the CCB.