NIS2 and CyberFundamentals (CyFun)

What is NIS2?

NIS2 is the European cybersecurity law for organisations. Directive (EU) 2022/2555 sets a floor for how companies in listed sectors defend their own networks and systems, how fast they report an incident, and who inside the company answers for it.

The word directive is what trips people up. A regulation like the GDPR applies to your company directly. A directive does not: it obliges each member state to write its own law, so the text that binds a Belgian company is Belgian. Here that is the law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security, in force since 18 October 2024, with a royal decree of 9 June 2024 that names the Centre for Cybersecurity Belgium (CCB) as national cybersecurity authority and national CSIRT. Deadlines, fines and supervision sit in that Belgian text, so a group with a Dutch subsidiary is reading two laws that say roughly the same thing on different dates.

NIS2 looks at your organisation. The Cyber Resilience Act covers the other half of the picture, the security of products you sell.

Who is in scope, and the part that catches people

Three questions decide it: do you provide a service listed in annex I or II of the law, are you big enough, and are you established in Belgium. Annex I holds the highly critical sectors, from energy and health to drinking water, digital infrastructure and B2B ICT service management. Annex II holds the other critical ones, among them waste, chemicals, food, several kinds of manufacturing and research. Check every service you sell rather than your main activity, because one side activity pulls the whole company in.

The size test has two halves and that is where it goes wrong. Under 50 full-time equivalents is small, 50 to 249 medium-sized, 250 and up large. On money you take the lower of turnover and balance sheet total, and above 10 million euros makes you medium-sized. The CCB's own example settles most arguments: a company with 80 people, one million euros of turnover and a 70 million balance sheet is medium-sized and in scope, because the low turnover figure wins on the money side while the headcount already sits in the middle band. Group structure is the second surprise, since the figures of partner and linked enterprises get consolidated. A 30 person subsidiary of a 900 person group does not get to call itself small.

Combine size and sector and you get the labels. A large company in annex I is an essential entity. A medium-sized company in annex I, and anything of either size in annex II, is an important entity. Some categories are in whatever their size, among them DNS and trust service providers, and the CCB can name any organisation regardless of size when it is the sole provider of a service in Belgium.

What the law actually asks for

Risk management measures. Article 21 of the directive names ten areas and the Belgian law lists eleven minimum measures over the same ground: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, secure acquisition and development including vulnerability handling, testing whether your measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. They have to be proportionate to your risk and your size, so a 60 person food producer is not expected to build what a hospital builds.

Incident reporting, on a clock. A significant incident is one that has caused or could cause serious disruption to your listed service or financial loss to you, or significant damage to other people. Reporting to the CCB runs in stages: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours (24 hours for trust service providers), an interim report if the CSIRT asks, and a final report a month after that notification. Notifications go through the CCB notification platform. Where it matters you also warn the customers whose service is affected.

Management accountability. This is what turns NIS2 from an IT project into a board file. The management body approves the measures, oversees implementation, follows training so it can judge them, and is liable when the entity breaches its risk management obligations. The Belgian explanatory memorandum reads the term widely: anyone who can represent the entity, anyone who takes decisions that bind it, anyone with control over who runs it. In a Flemish SME that is the zaakvoerder and the board, not the person who manages the firewall.

An essential entity versus an important entity: how the supervision works

Both carry the same obligations from the same date. What differs is when somebody comes to check.

An essential entity is supervised proactively and reactively. It undergoes a regular conformity assessment and picks one of three routes: a CyberFundamentals verification or certification by a conformity assessment body authorised by the CCB after BELAC accreditation, an ISO/IEC 27001 certification whose scope and Statement of Applicability the CCB accepts, or an inspection by the CCB inspection service. On top of that the inspectors can turn up at any moment. Fines run from 500 euros to 10 million euros or 2 percent of worldwide annual turnover, whichever is higher, and three measures exist only here: a monitoring officer placed in the company, a temporary suspension of a certification, and a temporary ban on a named person exercising managerial functions.

An important entity is supervised after the fact. No standing conformity assessment and nothing to hand the CCB in April 2026. Supervision starts on an incident, or on evidence that the company is not complying. Fines top out at 7 million euros or 1.4 percent of worldwide annual turnover.

What costs money is how important entities read ex post. It does not mean later, it means unannounced. The measures and the 24 hour clock have applied since 18 October 2024, and after an incident the CCB can ask you to prove they were already in place. An important entity may also volunteer for the essential regime and hold the same presumption of conformity as its bigger neighbours.

CyberFundamentals and the presumption of conformity

CyberFundamentals, or CyFun, is the CCB's own framework and the reason NIS2 is workable for a Belgian SME. It is free, it comes with tools, and it turns eleven legal phrases into controls you can tick off. It is assembled from NIST CSF, ISO/IEC 27001 and 27002, IEC 62443 and the CIS Critical Security Controls, and which control belongs at which level was decided using anonymised data on attacks that actually happened in Belgium.

There are four levels. Small is a starting self-assessment for micro-organisations with little technical knowledge. Basic holds 34 controls, Important adds 99 against targeted attacks by ordinary attackers, Essential another 85 against attackers with serious means. The CCB puts coverage figures next to them: 82 percent of the attacks in its own attack profiles at Basic, 94 at Important, 100 at Essential. A new version launched in October 2025 and both CyFun 2023 and CyFun 2025 stay valid until 18 April 2027, so you pick.

A selection tool walks you through a risk assessment and lands on a level. An Excel self-assessment then scores every control twice on a scale of 1 to 5, once for policy maturity (written down, approved, current) and once for implementation maturity (it happens day to day), and shows in red what falls under the thresholds of the Conformity Assessment Scheme. Basic and Important are then verified by a conformity assessment body, Essential is certified, and you request the label on the Safeonweb@work portal.

The payoff is legal rather than decorative. A validated implementation gives you a presumption of conformity: until proven otherwise you are presumed to have met your obligations under the law.

If you already hold ISO/IEC 27001:2022 you do not start over, since that is one of the three accepted routes. The CCB inspection service reads your Statement of Applicability against the equivalent CyFun level and looks hardest at the CyFun key measures, so the work is a mapping exercise plus evidence that the controls are effective, not a second management system. For essential entities the calendar is fixed: a CyFun Basic or Important verification statement by 18 April 2026, and the Essential certification or the ISO certificate by 18 April 2027. CyFun is not only Belgian any more either: Romania, Ireland, Malta and Cyprus have joined the group that owns the scheme.

In scope because your customer is

Most Flemish SMEs meet NIS2 through a contract rather than through the law, because supply chain security is one of the eleven measures and entities in scope have to manage the risk their direct suppliers bring.

Take an electrical installer near Genk, 22 people, who programmes and maintains the PLCs in the pumping stations of a drinking water company. Drinking water is annex I and the utility is large, so it is an essential entity. The installer sits in no annex sector and has 22 people, so the law does not touch it directly.

At contract renewal a security annex arrives: multi-factor authentication on every remote connection into the utility network, no shared accounts on the maintenance laptops, a named contact reachable within 24 hours, notification of any incident that could affect the utility, and a CyFun Basic verification inside twelve months. None of that comes from the law reaching the installer. It comes from the utility having to show its own inspection service how it manages supplier risk, and the CCB advises precisely this: an organisation that may sit in the supply chain of a NIS2 entity should meet at least CyFun Basic.

The arithmetic is friendly to the installer. Basic is 34 controls and a company that already runs backups, patches and per-person accounts is closer than it thinks, the same annex will arrive from the next customer in a listed sector, and the second time the answers are on file. Saying no is the expensive option: a supplier who does not answer security questions is one the utility has to write up as a risk it cannot manage.

What to do first

  1. Settle the scope question on paper. Every service against annexes I and II, headcount and financials with group consolidation applied, and the conclusion written down with a date.

  2. Register on Safeonweb@work if you are in. The deadline was 18 December 2024 for the digital sectors and 18 March 2025 for everyone else. If you missed it, register now, because the CCB works from that list.

  3. Run the CyFun selection tool and the self-assessment. Both are free, and the gap list they produce is also the answer to the next customer questionnaire.

  4. Fix the reporting route before you need it. Who decides an incident is significant, who files the early warning inside 24 hours, and where the credentials for the notification platform live.

Last Updated: September 4, 2026 Back to Dictionary
Keywords
nis2 cyberfundamentals cyfun ccb cyber resilience act ai incident market surveillance authority iso 27001 gdpr audit trail least privilege regulation