CyFun 2025 For MSPs And
MSSPs — And Their Clients

Deliver scalable, CyFun-aligned cybersecurity services with Cynomi’s AI-powered vCISO platform. Automate assessments across assurance levels, generate policies, and help Belgian clients build resilience and demonstrate NIS2 conformity.

Book a demo Or Watch Full Demo

See Cynomi’s Automated vCISO Platform in Action

By clicking submit I consent to the use of my personal data by Cynomi in accordance with Cynomi’s Privacy Policy

What is CyFun 2025 and Why
Does It Matter for MSPs and MSSPs?

Diagram of the four CyFun assurance levels as nested frames, with Small enclosed by Basic, Important and Essential

What Organizations Does
CyFun 2025 Apply To?

CyFun is designed for organizations of any size that want to strengthen resilience, and it carries particular weight for entities regulated under Belgium’s NIS2 law. It is especially relevant for:

Essential and Important Entities Under Belgium’s NIS2 Law

Small and mid-sized business premises icon

Small and Mid-Sized Businesses Building a Security Baseline

Chemical manufacturing and processing plant icon

Manufacturing and Industrial Companies

Healthcare, Energy, and Transport Operators

Clearing and market infrastructure network icon

Suppliers and Service Providers to Regulated Entities

MSPs and MSSPs Serving Belgian Clients

Why MSPs and MSSPs
Should Align With CyFun 2025

Aligning with CyFun enables providers to deliver right-sized, regulation-backed security programs across the Belgian market.

Deliver standardized services with a framework that scales from SMEs to essential entities

Help clients demonstrate NIS2 conformity through a recognized national mechanism

Turn assurance-level progression into a natural upsell path as clients mature

Support cross-mapping to NIST CSF, ISO 27001, and CIS Controls without duplicate work

How MSPs and MSSPs Can Comply with
CyFun 2025 and Help Clients Do the Same

Cynomi guides you step by step through managing cybersecurity and compliance.

step 1

Assess & Identify

Launch CyFun-Aligned Assessments at the Right Level

  • Conduct automated assessments aligned with the client’s assurance level
  • Identify gaps against the framework’s concrete measures
  • Generate risk scores and prioritized findings for each client
step 2

Establish and Plan

Build Programs That Progress Through the Levels

  • Auto-generate policies and remediation plans mapped to CyFun requirements
  • Map owners, timelines, and priorities appropriate to each client’s level
  • Plan the path from baseline levels toward higher assurance as clients mature
step 3

Optimize and Track Progress

Maintain Conformity and Demonstrate It

  • Track progress across all Belgian clients in one dashboard
  • Maintain documentation and evidence to support verification and labeling
  • Deliver executive-ready reports that show resilience improving over time

Framework FAQs

No. CyFun is voluntary, but in Belgium it serves as a recognized way to demonstrate conformity with the NIS2 law — which is mandatory for essential and important entities.

The Centre for Cybersecurity Belgium (CCB), the national authority for cybersecurity, which also oversees Belgium’s NIS2 implementation.

The framework defines progressive assurance levels — Small, Basic, Important, and Essential — so organizations implement measures proportionate to their size and risk exposure. Each level builds on the previous one: Basic covers essential hygiene controls, while Important and Essential add progressively more advanced measures for higher-risk and critical entities.

Its measures are drawn from and mapped to NIST CSF, ISO 27001, CIS Controls, and IEC 62443, so work done for CyFun translates directly to other frameworks clients may need.

Cynomi automates CyFun-aligned assessments, generates policies, tracks remediation, and maintains the documentation clients need for self-assessment or verification — enabling MSPs and MSSPs to deliver the framework at scale.

Interested In How Cynomi Can Help With
CyFun 2025?