Cybersecurity
DETAIL

Belgium CyFun — Cybersecurity Framework

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

Belgium CyFun is a national cybersecurity framework that guides organizations in strengthening their cyber resilience and safeguarding digital assets across Belgian public and private sectors. The framework provides a structured approach to managing cybersecurity risks and aligns organizations with best practices for data protection and regulatory compliance.

CyFun is published by the Centre for Cybersecurity Belgium (CCB) and serves as a foundational resource for Belgian organizations seeking to assess and improve their cybersecurity posture. It is applicable to a wide range of sectors, covering areas such as security controls, risk management, privacy governance, and incident response. The framework aligns with international standards and complements established frameworks like NIST and ISO 27001.

Organizations leverage Belgium CyFun by conducting risk assessments, implementing security controls, and integrating its requirements into existing cybersecurity and compliance programs. Adoption supports audit readiness, ongoing regulatory compliance, and the development of mature security governance in line with both national and international expectations.

Why it Matters

Belgium CyFunestablishes a national baseline for cybersecurity, enablingorganizations to proactively address evolving threats and regulatoryrequirements across sectors.

Key benefits include:

  • Strengthen cybersecurity governance

Support the creation of robustpolicies and procedures that embed security responsibilitiesthroughout organizational structures.

  • Enhance regulatory alignment

Align security programs with Belgianand international standards, streamlining compliance with legal andsector-specific obligations.

  • Improve incident management

Enable organizations to detect,respond to, and recover from cyber incidents with greater speed andefficiency.

  • Protect sensitive digital assets

Implement comprehensive dataprotection measures to safeguard critical information againstunauthorized access, manipulation, or loss.

  • Increase audit readiness

Facilitate the documentation andevidence collection needed to demonstrate ongoing compliance duringaudits and regulatory reviews.

How it Works

The BelgiumCyFun — Cybersecurity Framework is structured around controlfamilies and governance domains, combined with a risk managementlifecycle and an embedded maturity model. It outlines regulatoryrequirements and cross-industry security safeguards, enablingorganizations to map controls to specific threats, assets, andcompliance obligations relevant to the Belgian context.

Organizationsapply the framework by conducting risk assessments, selecting andimplementing security controls, and integrating those controls intoexisting governance and compliance programs. Teams use the frameworkto define monitoring requirements, operate incident responseprocesses, perform compliance assessments, and track maturity overtime, translating policy into practical security practices andcontinual improvement cycles.

WithinSmartSuite, teams operationalize Belgium CyFun by importing controllibraries, maintaining a centralized risk register, and governingpolicies with versioned documentation. SmartSuite supports evidencecollection, compliance tracking, remediation workflows, auditreadiness, and reporting dashboards that tie controls to risks andmonitoring metrics, enabling coordinated governance and ongoingsecurity posture visibility.

Key Elements

  • Security Governance Structure

Defines organizational roles,responsibilities, and overarching policies to ensure consistentcybersecurity management across entities.

  • Risk Assessment Process

Describes systematic procedures forevaluating, prioritizing, and addressing cybersecurity risksthroughout the organization.

  • Protective Control Families

Organizes technical, physical, andadministrative controls to mitigate threats and safeguard digitalassets.

  • Incident Response Management

Outlines coordinated steps andmechanisms for detecting, reporting, and resolving cybersecurityincidents.

  • Privacy and Data Protection Domains

Establishes standards for thehandling, processing, and storage of sensitive personal and businessdata.

  • Compliance Alignment Layer

Specifies integration points withnational regulations and international security standards to supportlegal adherence.

  • Continuous Monitoring Capabilities

Provides structured approaches forongoing assessment of systems, networks, and emerging threats toensure resilience.

Framework Scope

Belgium CyFun iscommonly adopted by entities operating in both public and privatesectors that oversee information systems, digital assets, or criticalinfrastructure. The framework covers cybersecurity controls, privacymanagement, and incident response, and is typically utilized whenintegrating data protection measures, addressing audit requirements,or enhancing cybersecurity programs to support assurance initiatives.

Framework Objectives

Belgium CyFunprovides organizations with a comprehensive framework to enhancecybersecurity risk management and regulatory compliance.

Strengthen resilience against evolving cybersecurity threats anddigital asset vulnerabilities

Improve governance and oversight of security controls and riskmanagement practices

Ensure compliance with Belgian and international data protection andprivacy regulations

Enhance operational resilience through effective incident responseand recovery measures

Support demonstrated audit readiness and ongoing regulatorycompliance obligations

Promote adoption of best practices for holistic cybersecurity andprivacy governance Belgium CyFun is a national cybersecurityframework that maps to EU and international standards—often alignedwith DORA and the NIS Directive and cross-referenced with ISO/IEC27001 or NIST CSF. Organizations implement it for regulatorycompliance (DORA/NIS), security governance, certification efforts,and to drive operational security improvements.

Framework in Context

Belgium CyFun is a nationalcybersecurity framework that maps to EU and internationalstandards—often aligned with DORA and the NIS Directive andcross-referenced with ISO/IEC 27001 or NIST CSF. Organizationsimplement it for regulatory compliance (DORA/NIS), securitygovernance, certification efforts, and to drive operational securityimprovements.

Common Framework Mappings

Organizationsmap Belgium CyFun to widely used security and regulatory frameworksto align controls, demonstrate compliance, and streamline riskmanagement across EU and international programs.

Mapped frameworks include:

CIS CriticalSecurity Controls

DigitalOperational Resilience Act (DORA)

EU General DataProtection Regulation (GDPR)

ISO/IEC 27001

ISO/IEC 27002

MITRE ATT&CK

NIS Directive /NIS2

NISTCybersecurity Framework

At a Glance
Belgium Cybersecurity Framework (CyFun)
  • checklist
    Classification
    Category
    info
    Cybersecurity
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Framework
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Europe
    Region Detail
    info
    Belgium
    Publisher
    info
    CyFun
  • published_with_changes
    Versioning
    Version
    info
    Current CyFun Framework
    Effective Date
    info
    2023
    Issue Date
    info
    2019
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The Belgium Cybersecurity Framework (CyFun) is published by the Belgian Centre for Cybersecurity and is publicly available through official government resources.

Official Resources
Belgium CyFun Framework Overview
Provides an overview of the Belgium CyFun framework focusing on cybersecurity resilience practices.
chevron_forward
Centre for Cybersecurity Belgium - CyFun Guidance
Outlines guidance for implementing the CyFun cybersecurity practices in organizations.
chevron_forward
CyFun Security Controls Documentation
Defines specific security controls within the Belgium CyFun framework for organizational compliance.
chevron_forward
CyFun Risk Management Framework
Describes the risk management strategies within the Belgium CyFun framework for enhanced cybersecurity.
chevron_forward
CyFun Incident Response Guidelines
Outlines incident response procedures aligned with CyFun to enhance organizational readiness.
chevron_forward
SMARTSUITE

How SmartSuite Supports Belgium CyFun

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Initiative-to-Control Mapping

Translate CyFun guidance into operational controls with clear ownership.

Readiness Assessments and Gap Tracking

Run assessments, document gaps, and build a prioritized improvement roadmap.

Awareness and Training Programs

Manage awareness initiatives, completion tracking, and supporting evidence.

Incident Preparedness and Exercises

Schedule incident exercises, capture outcomes, and track corrective actions.

Partner and Stakeholder Coordination

Coordinate collaboration tasks, shared responsibilities, and evidence across groups.

Reporting and Continuous Improvement

Report posture, open actions, and improvements over time.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
EU DORA

DORA is an EU regulation requiring financial firms to manage ICT risks, report incidents, test security, and oversee third-party providers.

Learn More
arrow_forward
GDPR

GDPR is an EU regulation that protects individuals' personal data and strengthens organizations' accountability for privacy.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
MITRE ATT&CK

MITRE ATT&CK is a knowledge framework documenting adversary tactics and techniques to help organizations detect, analyze, and respond to attacks.

Learn More
arrow_forward
NIS2 (EU 2022/2555)

NIS2 establishes mandatory cybersecurity and incident-reporting requirements to strengthen resilience across essential and important EU organizations.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For Belgium CyFun (Cybersecurity Framework)

What is Belgium CyFun used for?

Belgium CyFun is used to help organizations identify, assess, and manage cybersecurity risks, while aligning with Belgian regulatory requirements and international best practices. It guides the implementation of security controls and governance measures to strengthen cyber resilience and protect digital assets.

Is Belgium CyFun mandatory or certifiable?

Belgium CyFun is not a mandated or certifiable standard, but it serves as a recommended framework published by the Centre for Cybersecurity Belgium (CCB). Organizations adopt it to demonstrate due diligence, regulatory alignment, and readiness for audits across Belgium’s public and private sectors.

What organizations should use Belgium CyFun?

Belgium CyFun is applicable to all Belgian organizations, including those in public administration, critical infrastructure, and private industry. Its flexible approach allows organizations of various sizes and sectors to tailor cybersecurity controls and processes to their specific risk environments.

What are the key components of Belgium CyFun?

The framework is structured around control families, governance domains, a risk management lifecycle, and an embedded maturity model. It requires organizations to map controls to threats, assets, and compliance obligations relevant to their business context.

How do organizations implement Belgium CyFun?

Implementation is based on conducting cybersecurity risk assessments, selecting and applying necessary security controls, and embedding requirements into existing governance and compliance programs. Continual monitoring, incident response planning, and maturity tracking are critical for effective implementation.

How does Belgium CyFun relate to frameworks like NIST or ISO 27001?

Belgium CyFun is designed to align with international frameworks such as NIST Cybersecurity Framework and ISO 27001, providing a Belgian perspective and regulatory context. Organizations can use it alongside these frameworks to create a comprehensive cybersecurity governance program.

What are the ongoing compliance requirements for Belgium CyFun?

Maintaining compliance with Belgium CyFun requires regular risk reviews, continual control monitoring, policy updates, incident response testing, and internal or external compliance assessments. Organizations should document processes and demonstrate continual improvement in their cybersecurity maturity.

How would SmartSuite support Belgium CyFun?

SmartSuite supports Belgium CyFun by enabling organizations to import control libraries, maintain a centralized risk register, and systematically manage policies and controls. The platform streamlines compliance through built-in evidence collection, compliance tracking, remediation workflows, audit preparation, and reporting dashboards, ensuring continuous oversight and governance of security posture.

Operationalize CyFun with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward