CyFun® 2025 · The 4-Week CyFun Readiness Assessment

Ireland has named its NIS2 yardstick. Know where you stand against it.

A fixed-scope, four-week assessment of your organisation against the CyberFundamentals (CyFun®) 2025 framework — the framework the NCSC recommends for demonstrating NIS2 security measures in Ireland. You leave with your assurance level, a maturity score for every function and key measure, the gap to your target, and a roadmap your board can act on.

The NCSC recommends CyFun as "a well-recognised, structured, voluntary tool to assist entities in meeting their NIS2 obligations" — and is careful to add that it is a way to organise and evidence controls, not a statutory presumption of compliance.

Quoted from the NCSC's Cyber Fundamentals page. Ireland has joined the CyFun scheme as a co-owner, and the NCSC's own competent authority for public administration proposes to use it as the preferred approach.
National Cyber Security Centre, Ireland
Source: National Cyber Security Centre (Ireland) — Cyber Fundamentalsncsc.gov.ie/CyFun
Trusted expertise in regulated digital resilience
Operating since 2014 CyberPrism on Azure Marketplace Enterprise Ireland-backed technology Partnered with eir business
Awards and accreditations: IRM Global Risk Awards 2016, Bank of Ireland Startup Awards 2017 Fintech Award, HM Government G-Cloud approved supplier, CIR Risk Management Awards winner — Risk Management Specialist Company of the Year

A Belgian framework, now Ireland's preferred route.

CyFun was built by the Centre for Cybersecurity Belgium to turn NIS2's security measures into concrete, assessable requirements. Ireland has adopted it as a scheme co-owner, and the NCSC recommends it as the preferred way to demonstrate compliance. It is voluntary — but it is the measure supervisors will recognise first.

OCT 2025

CyFun 2025 published

The new edition aligns the framework to NIST CSF 2.0 and NIS2, with more weight on supply-chain and OT security and governance measures from the Important level up. CyFun 2023 and 2025 run in parallel for a transition period.

4 LEVELS

Small, Basic, Important, Essential

An entry level and three assurance levels, selected by a risk assessment of your size, sector and exposure. Each level adds key measures, and your maturity is scored against the level you should be at.

CO-OWNED

Ireland is a CyFun scheme co-owner

The NCSC recommends CyFun for NIS2 essential and important entities and proposes it for public administration. A national certification route is being established; entities are encouraged to use the framework now.

CyFun turns "are we NIS2-ready?" into a question with a number attached: which assurance level should we be at, and how mature are we against it?

That is a question a board can be asked, answer, and be held to. CyFun® is a registered trademark of the Centre for Cybersecurity Belgium; CRI is not a conformity assessment body and this assessment is not certification.

What CyFun expects of the board

CyFun 2025 opens with a Govern function and, from the Important level, adds governance measures — the CCB's stated aim being to improve oversight and align cybersecurity with business goals. That is the same ground NIS2 Article 20 puts on management bodies: approve the measures, oversee them, and be trained.

Under the Govern function, the assessment scores the organisation on:

  • Organisational context — mission, stakeholders and legal obligations understood
  • Risk management strategy — appetite and tolerance set and communicated
  • Roles, responsibilities and authorities — documented, authorised and current
  • Policy — established, communicated and enforced
  • Oversight — results reviewed and used to adjust the strategy
  • Cybersecurity supply-chain risk management — contractual requirements for suppliers

Every measure is scored twice — for how well it is documented and for how well it is implemented — so a policy folder cannot stand in for a working control, and a working control cannot stand in for one nobody has written down.

BOARD QUESTIONS

What a management body should be able to answer

  • Which CyFun assurance level should we be at, and who decided?
  • What is our maturity against that level today, function by function?
  • Which key measures are furthest below target, and what would it cost to close them?
  • What do our supplier contracts actually require on cybersecurity?
  • When did we last test detection, response and recovery — and what did we change?
CYFUN 2025 SCORING

What the assessment measures

The framework's own structure, applied to your organisation
  • Six functions — Govern, Identify, Protect, Detect, Respond, Recover
  • Key measures by tier — Basic, Important and Essential, each scored individually
  • Documentation maturity (1–5) — how formally each control is defined and evidenced
  • Implementation maturity (1–5) — how consistently it operates in practice
  • Target maturity level — level 3 is the CyFun baseline; your target is agreed with leadership
  • Gap to target for every function and key measure, colour-coded
  • NIST CSF 2.0 outcome attestation — True, Partial or False for every outcome underneath
  • Remediation roadmap with owners and timeframes
CyberPrism maps every NIST CSF 2.0 outcome to the CyFun 2025 domains and key measures, so the CyFun result and the NIST result come from one set of declarations, not two questionnaires.

Who it is for

CyFun is written for any organisation, but it matters most to the ones a supervisor will ask.

Entities in scope of NIS2

Where CyFun is the recognised route
  • Essential and important entities across the NIS2 sectors — energy, transport, health, water, digital infrastructure, manufacturing, food and more
  • Public administration bodies, where the NCSC's competent authority proposes CyFun as the preferred approach
  • Organisations that expect to be designated once Ireland's national legislation is enacted, and want a defensible baseline before then
  • Groups with Belgian or other EU operations already working to CyFun

Organisations asked to prove it

Where the label is a business enabler
  • Suppliers to NIS2 entities being asked for evidence of their own security measures
  • Mid-sized businesses whose customers, insurers or banks want a recognised standard, not a bespoke questionnaire
  • ISO 27001-certified organisations that want the NIS2-specific view the certificate does not give
  • Boards that want to know which assurance level they should be at before committing to a certification path
CyFun 2025 — the entry level Small and the three assurance levels Basic, Important and Essential, rising with exposure
Your assurance level is selected by risk, not preference. Which level applies to you is settled in week one.

The six functions — and what each asks of you

CyFun 2025 follows the NIST CSF 2.0 structure. The assessment scores every key measure under all six, and reports the maturity of each function against your target.

GOVERN

Strategy, policy and oversight

Organisational context, risk strategy, roles and authorities, policy, oversight and supply-chain risk management — including the contractual requirements you place on suppliers.

IDENTIFY

Assets, risks and improvement

Asset management — including maintenance tools and portable media — risk assessment, vulnerability management and the improvement loop that learns from incidents and tests.

PROTECT

Safeguards

Identity and access control, awareness and training, data security, platform security and technology infrastructure resilience — boundary protection, segmentation, firewalls, patching and backups.

DETECT

Finding what is happening

Continuous monitoring of critical systems and adverse-event analysis — logging enabled, retained and actually reviewed.

RESPOND

Acting on an incident

Incident management, analysis, reporting and communication within the timeframes in your plan and the law, and mitigation.

RECOVER

Restoring and learning

Recovery plan execution and recovery communication — restoring services and telling stakeholders what happened.

Illustrative CyFun maturity scale from 1 Initial to 5 Optimised, with level 3 as the CyFun baseline and level 4 as an example target
Every key measure is scored on this scale for documentation and for implementation. Level 3 is the CyFun baseline; the gap to your target is the roadmap.

Most organisations cannot yet say which CyFun level they should be at — let alone whether they would pass it.

Policies, a firewall, backups and an awareness course are not an assurance level. An assurance level is a risk-based selection, a maturity score against every key measure it demands, and a plan to close the gaps. Four weeks is enough to establish all three.

The CyFun Readiness Assessment

Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

WEEK 1

Onboarding and level selection

Establish where you start from
  • Capture business context, NIS2 status and critical services
  • Risk-based selection of your CyFun assurance level — Basic, Important or Essential
  • Target maturity level proposed for leadership to agree
WEEK 2

Assessment

Declare and evidence every measure
  • Structured working sessions across all six functions — your team answers, we structure
  • Documentation and implementation maturity declared for every key measure
  • Evidence gathered as you go
WEEK 3

Gap analysis and dashboards

Maturity against target
  • Live dashboards by function and by Basic, Important and Essential key measures
  • Target maturity level confirmed with leadership
  • NIS2 and NIST CSF 2.0 views generated from the same declarations
WEEK 4

Board and roadmap

Decide what happens next
  • CyFun Executive Guidance Report delivered
  • Prioritised remediation roadmap to the target level
  • Board or executive briefing in person
Paul C Dwyer, CEO of Cyber Risk International

"CyFun is the first time an Irish board has been handed a NIS2 measuring stick it can actually read. Level, score, gap. Once you can say those three numbers out loud, the compliance conversation becomes a management conversation."

Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk Leadership

What you receive

Every deliverable is written for the management body NIS2 holds accountable — and the report is the artefact it signs off.

Assurance level selection

A risk-based, documented rationale for the CyFun level you should be at — Basic, Important or Essential — that you can show a supervisor.

Inherent risk profile

What the organisation relies on, where it is exposed, and what an incident would mean for it.

Maturity scores by function

Govern to Recover, each with documentation and implementation maturity and the gap to target.

Key measure scores by tier

Every Basic, Important and Essential key measure scored individually, so the weakest controls are named, not averaged away.

CyFun Executive Guidance Report

Written for a board, not an IT department. Where you stand against your level, what matters most, and what closing the gap will take.

Prioritised remediation roadmap

Actions ordered by gap and exposure, with owners and timeframes, to move from current to target maturity.

NIS2 and NIST CSF 2.0 views

The same evidence read through NIS2 and the underlying NIST framework, ready for whichever question comes first.

Board briefing and threat context

A session with your board or executive team, with ThreatLens tying current threat activity to where you are weakest.

The CyberPrism CyFun Executive Guidance Report: cover, results summary and the Essential Measures radar chart
The CyFun Report — Executive Guidance Report, sample pages
INSIDE THE REPORT

What your board will read

  • Summary of results — target maturity level, overall maturity, overall gap and status at a glance
  • Maturity levels explained — the 1–5 scale, why level 3 is the CyFun baseline, and levels 3 to 5 outlined
  • Methodology — NIST CSF 2.0 outcome attestation and CyFun documentation and implementation maturity, mapped and aggregated
  • Maturity scores by function — Govern, Identify, Protect, Detect, Respond and Recover, key measure by key measure
  • Radar chart — the Essential Measures profile: target, category, documentation and implementation scores on one view
  • Key measures by tier — Essential, Important and Basic, each with its score and gap to target
6 functions3 assurance tiersMaturity 1–5Gap to target

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

CyFun 2025 is a native module. CyberPrism maps every NIST CSF 2.0 outcome to the CyFun domains and key measures, so your CyFun score, your NIS2 view and your NIST baseline all come from one set of declarations — and re-assessing later means updating, not starting again.

CyFunNIS2NIST CSF 2.0DORAEU AI ActThreatLens
CyFun Cyber Fundamentals executive summary with maturity radar and priority actions
CyFun — Cyber Fundamentals maturity by function, against your target level.Click to enlarge

After the four weeks

The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation toward your target level, re-assess quarterly, receive ongoing threat intelligence, and give your board a standing CyFun view — with the evidence base ready when a conformity assessment or a supervisor calls for it.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it — including a conformity assessment body if you pursue the label.

Board meeting in progress
An assurance level is something a board maintains, not something it receives once.

Common questions

Is CyFun mandatory in Ireland?

No. The NCSC is clear that certification or self-assessment under CyFun is optional, and that NIS2 compliance is always determined by the relevant national competent authority. It is, however, the framework the NCSC recommends and the one it proposes as the preferred approach for public administration. If you have to demonstrate NIS2 security measures to an Irish supervisor, CyFun is the most direct way to do it.

Does this give us the CyFun label?

No. The label is issued through a conformity assessment by an authorised body, and Ireland's national certification arrangements are still being established. This assessment gives you what that process needs: a risk-based level selection, a self-assessment against every key measure with evidence behind it, and the corrective measures prioritised. CRI is not a conformity assessment body.

Which assurance level should we be at?

CyFun answers this with a risk assessment rather than a preference — size, sector, exposure and the impact of an incident. We run that selection with you in week one and document the rationale, so the level you assess against is one you can defend. Most NIS2 entities land at Important or Essential; the entry level Small exists for micro-organisations making a first check.

We are ISO 27001 certified. What does this add?

ISO 27001 certifies that a management system exists and is operated; CyFun measures specific key measures against a NIS2-aligned assurance level, with a maturity score for each. The two are complementary, and the CCB itself allows an ISO 27001 certificate with the right scope to support a CyFun label. The assessment credits your certification wherever it applies and shows you where CyFun asks for more.

How much of our team's time does it take?

Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, operations, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

What if four weeks is not enough for us?

Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups, multi-site operators or organisations assessing at the Essential level with significant OT may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.

Know your CyFun level before a supervisor asks for it.

A 30-minute scoping call is enough to confirm whether NIS2 reaches you, which assurance level is likely, what the four weeks would cover, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.