A fixed-scope, four-week assessment of your organisation against the CyberFundamentals (CyFun®) 2025 framework — the framework the NCSC recommends for demonstrating NIS2 security measures in Ireland. You leave with your assurance level, a maturity score for every function and key measure, the gap to your target, and a roadmap your board can act on.
The NCSC recommends CyFun as "a well-recognised, structured, voluntary tool to assist entities in meeting their NIS2 obligations" — and is careful to add that it is a way to organise and evidence controls, not a statutory presumption of compliance.
Quoted from the NCSC's Cyber Fundamentals page. Ireland has joined the CyFun scheme as a co-owner, and the NCSC's own competent authority for public administration proposes to use it as the preferred approach.
CyFun was built by the Centre for Cybersecurity Belgium to turn NIS2's security measures into concrete, assessable requirements. Ireland has adopted it as a scheme co-owner, and the NCSC recommends it as the preferred way to demonstrate compliance. It is voluntary — but it is the measure supervisors will recognise first.
The new edition aligns the framework to NIST CSF 2.0 and NIS2, with more weight on supply-chain and OT security and governance measures from the Important level up. CyFun 2023 and 2025 run in parallel for a transition period.
An entry level and three assurance levels, selected by a risk assessment of your size, sector and exposure. Each level adds key measures, and your maturity is scored against the level you should be at.
The NCSC recommends CyFun for NIS2 essential and important entities and proposes it for public administration. A national certification route is being established; entities are encouraged to use the framework now.
CyFun turns "are we NIS2-ready?" into a question with a number attached: which assurance level should we be at, and how mature are we against it?
That is a question a board can be asked, answer, and be held to. CyFun® is a registered trademark of the Centre for Cybersecurity Belgium; CRI is not a conformity assessment body and this assessment is not certification.CyFun 2025 opens with a Govern function and, from the Important level, adds governance measures — the CCB's stated aim being to improve oversight and align cybersecurity with business goals. That is the same ground NIS2 Article 20 puts on management bodies: approve the measures, oversee them, and be trained.
Under the Govern function, the assessment scores the organisation on:
Every measure is scored twice — for how well it is documented and for how well it is implemented — so a policy folder cannot stand in for a working control, and a working control cannot stand in for one nobody has written down.
CyFun is written for any organisation, but it matters most to the ones a supervisor will ask.
CyFun 2025 follows the NIST CSF 2.0 structure. The assessment scores every key measure under all six, and reports the maturity of each function against your target.
Organisational context, risk strategy, roles and authorities, policy, oversight and supply-chain risk management — including the contractual requirements you place on suppliers.
Asset management — including maintenance tools and portable media — risk assessment, vulnerability management and the improvement loop that learns from incidents and tests.
Identity and access control, awareness and training, data security, platform security and technology infrastructure resilience — boundary protection, segmentation, firewalls, patching and backups.
Continuous monitoring of critical systems and adverse-event analysis — logging enabled, retained and actually reviewed.
Incident management, analysis, reporting and communication within the timeframes in your plan and the law, and mitigation.
Recovery plan execution and recovery communication — restoring services and telling stakeholders what happened.
Policies, a firewall, backups and an awareness course are not an assurance level. An assurance level is a risk-based selection, a maturity score against every key measure it demands, and a plan to close the gaps. Four weeks is enough to establish all three.
Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.
"CyFun is the first time an Irish board has been handed a NIS2 measuring stick it can actually read. Level, score, gap. Once you can say those three numbers out loud, the compliance conversation becomes a management conversation."
Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk LeadershipEvery deliverable is written for the management body NIS2 holds accountable — and the report is the artefact it signs off.
A risk-based, documented rationale for the CyFun level you should be at — Basic, Important or Essential — that you can show a supervisor.
What the organisation relies on, where it is exposed, and what an incident would mean for it.
Govern to Recover, each with documentation and implementation maturity and the gap to target.
Every Basic, Important and Essential key measure scored individually, so the weakest controls are named, not averaged away.
Written for a board, not an IT department. Where you stand against your level, what matters most, and what closing the gap will take.
Actions ordered by gap and exposure, with owners and timeframes, to move from current to target maturity.
The same evidence read through NIS2 and the underlying NIST framework, ready for whichever question comes first.
A session with your board or executive team, with ThreatLens tying current threat activity to where you are weakest.
CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.
CyFun 2025 is a native module. CyberPrism maps every NIST CSF 2.0 outcome to the CyFun domains and key measures, so your CyFun score, your NIS2 view and your NIST baseline all come from one set of declarations — and re-assessing later means updating, not starting again.
The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.
Keep your CyberPrism environment live. Track remediation toward your target level, re-assess quarterly, receive ongoing threat intelligence, and give your board a standing CyFun view — with the evidence base ready when a conformity assessment or a supervisor calls for it.
Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it — including a conformity assessment body if you pursue the label.
No. The NCSC is clear that certification or self-assessment under CyFun is optional, and that NIS2 compliance is always determined by the relevant national competent authority. It is, however, the framework the NCSC recommends and the one it proposes as the preferred approach for public administration. If you have to demonstrate NIS2 security measures to an Irish supervisor, CyFun is the most direct way to do it.
No. The label is issued through a conformity assessment by an authorised body, and Ireland's national certification arrangements are still being established. This assessment gives you what that process needs: a risk-based level selection, a self-assessment against every key measure with evidence behind it, and the corrective measures prioritised. CRI is not a conformity assessment body.
CyFun answers this with a risk assessment rather than a preference — size, sector, exposure and the impact of an incident. We run that selection with you in week one and document the rationale, so the level you assess against is one you can defend. Most NIS2 entities land at Important or Essential; the entry level Small exists for micro-organisations making a first check.
ISO 27001 certifies that a management system exists and is operated; CyFun measures specific key measures against a NIS2-aligned assurance level, with a maturity score for each. The two are complementary, and the CCB itself allows an ISO 27001 certificate with the right scope to support a CyFun label. The assessment credits your certification wherever it applies and shows you where CyFun asks for more.
Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.
The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.
Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups, multi-site operators or organisations assessing at the Essential level with significant OT may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.
A 30-minute scoping call is enough to confirm whether NIS2 reaches you, which assurance level is likely, what the four weeks would cover, and when it could start.