What is CyFun 2025 Basic, Important and Essential?
The CyberFundamentals Framework, published by the Centre for Cybersecurity Belgium. Ireland's National Cyber Security Centre has adopted it as a national NIS2 assessment and certification scheme. The 2025 edition is defined as a selection of NIST CSF 2.0 subcategories.
Nobody by law in Ireland today — it is voluntary while the National Cyber Security Bill 2024 is pending. In Belgium a certified level carries a legal presumption of conformity with NIS2. Elsewhere in the EU it has no national standing.
The complete CCB Basic list, not a subset.
A strict superset of Basic — measured against both booklets rather than taken from the documentation's claim that the levels are cumulative.
A strict superset of Important in turn, measured the same way.
13 from Basic, plus 9 added at Important and 7 at Essential, across 17 requirements. A further 15 management-aspect controls are reported separately, never netted in.
Basic, Important and Essential — all of them, with every requirement and key measure read from that level's own booklet. This read "3 of 4" until 20 September 2026, counting a starting level called Small as a fourth; see the edition note below for what that was and why it is not one.
Dates that matter
- 1 October 2025The current edition of the Basic, Important and Essential booklets alike, legal depot D/2025/14828/002.
- PendingIreland's scheme remains voluntary until the National Cyber Security Bill 2024 completes.
What people get wrong
The 2025 edition is not the 2023 edition
Basic 2025 has 28 requirements. The widely-quoted figure of 34 is the 2023 edition's, and nine subcategories that edition included are not in Basic 2025 at all — two of them carrying patching and malicious-code detection, which the 2025 booklet folds into key measures elsewhere. Six of those nine turn out to be requirements at a higher level, four at Important and two at Essential, so the older encoding was not inventing them: it was putting a higher level's selection into Basic. If a document says 34, it is describing the older edition. The 2023 edition also carried a starting level called Small, below Basic. It is not a fourth assurance level and never was — that edition's own introduction reads "in addition to the starting level Small, three assurance levels are also provided" — and its booklet is plain-language guidance across seven topics with no CSF subcategory ids, no key measures and no annexes, so there is nothing in it a requirement list could be built from. CyFun's own site now publishes only the three. If you meet Small in older material, that is what it was.
The levels are cumulative, and each booklet lists only what its own level adds
Important's Annex B says so outright — its nine key measures are "in addition to" Basic's thirteen, and Essential's Annex C is in addition to both. Several of the requirements those annexes name are lower-level requirements gaining a further sub-measure, so the effective set at a level is the union across the levels and is not what any single document states. Important and Essential also carry annexes of controls linked to the management aspects, which Basic has no equivalent of.
A requirement id IS a NIST CSF 2.0 subcategory id
That is how the edition is constructed, which is why there is no separate crosswalk to drift. Every id and title here is checked independently against a CSF 2.0 reference verified against NIST CSWP 29 — which is also how three places where the CCB's own booklets print a title or an id differently from each other were found and recorded.
2 Essential requirements are shown as unaddressed, and that is deliberate
Nothing in the assessment asks about capacity planning or programme performance evaluation. Those requirements report as unaddressed rather than being mapped onto the nearest question that is about something else, and both are waiting on the same thing: the ISO control that is their exact home is cited by nothing, so a question could not carry a citation checked against the standard's own text. One of them is also unaddressed at Important. None of them is a Key Measure: the two that were — a maintained record of network communication and data flows, and a route for an outsider to report a vulnerability to you — were closed on 19 September 2026 by adding those two questions, which is the honest way to close one. Seven more left this list on 20 September 2026 the same way. Resourcing adequacy, closed by a question asking whether the people holding security responsibilities have the time, authority and budget to carry them out. A supply-chain risk-management programme, closed by one asking whether there is an agreed written strategy behind the individual supplier decisions. Approved messaging for public recovery updates, closed by one asking whether the channel, the person authorised to speak and the first statement are agreed before an incident rather than during it. And two pairs closed by a single question each, because each pair is one practice rather than two: risk appetite together with strategic risk-response direction, which live in one document, and estimating an incident's impact and scope together with validating that estimate, which are the same judgement made twice as the picture develops. The last two were judgement calls rather than gaps: whether a requirement is a control at all, and whether a smaller organisation can honestly answer one. The security expectations that customers, insurers and investors place on you turned out to be a control, and one the regulatory-obligations question did not reach. Identity assertions turned out to be answerable only in part, so the question asks the half an organisation holds — whether applications sign people in through one central account — and the cryptographic half stays with the platform.
Certification runs through a conformity assessment body
The official method scores every requirement on a 1–5 maturity scale, and a label is issued by a CCB-recognised body. No self-assessment tool, this one included, produces a level or a label.
What Vivid Risk does with CyFun 2025 Basic, Important and Essential
A coverage panel on every EU and Irish report, against the Centre for Cybersecurity Belgium's own published requirement lists — 28 at Basic, 69 at Important and 90 at Essential, read from the 2025 booklets.
Indicative only. The requirements are the CCB's; which of your answers speaks to each one is our mapping, not theirs. This is not a CyFun self-assessment, level, label or certificate — the official method scores every requirement 1–5 and certification runs through a CCB-recognised conformity assessment body.
Indicative only. The requirements below are the CCB's own CyFun 2025 list for the level shown, but which of your answers speaks to each one is our mapping, not the CCB's. This is not a CyFun self-assessment, level, label or certificate — the official method scores every requirement on a 1-5 maturity scale and certification runs through a CCB-recognised conformity assessment body. It does not affect your Vivid Maturity Index. Which assurance level applies to an organisation is the organisation's own determination against its risk profile; nothing here infers one for you.
Questions
Does Vivid Risk give me a CyFun certificate?
No. Certification runs through a CCB-recognised conformity assessment body. Vivid Risk shows indicative coverage against the CCB's published requirement lists so you can see where you stand before you start.
Which assurance level does the report show?
Whichever you select. The panel offers Basic, Important and Essential and defaults to Basic; it does not infer a level from your headcount, your sector or your NIS2 entity class. Which level applies to an organisation is that organisation's own determination against its risk profile, and guessing it would be the sort of claim this product exists not to make.
Why is the coverage called indicative?
The requirements are the CCB's, published and unambiguous. Which of your questionnaire answers speaks to each one is our mapping, and the CCB publishes no mapping to a third-party questionnaire for it to be checked against. So the requirement list is theirs and the join is ours, and the page says so.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.