← Back to Insights
By Gilberto Torres, Gforce Networks · Frameworks

ISO 27001 vs CyFun: Which Framework Is Right for Your Belgian SME?

If you are navigating NIS2 compliance as a Belgian SME, you have likely encountered two framework names: ISO 27001 and CyFun. Both are legitimate paths to demonstrating cybersecurity maturity. Both are referenced in Belgian regulatory guidance. But they are not interchangeable — and choosing the wrong one can cost you time, money, and credibility.

Here is an honest comparison from someone who has implemented both.

What Is ISO 27001?

ISO 27001 is the international standard for information security management systems (ISMS). Published by ISO and IEC, it is recognised globally — from Belgium to the UAE to Singapore. Certification requires an accredited third-party audit and is renewed every three years with annual surveillance audits.

ISO 27001:2022 (the current version) covers 93 controls across four themes: organisational, people, physical, and technological. It is rigorous, well-documented, and broadly understood by clients, partners, and insurers worldwide.

Best for: Organisations with international clients, regulated sector obligations, or ambitions beyond the Belgian market. Also the stronger signal for enterprise procurement processes and cyber insurance underwriters.

What Is CyFun?

CyFun (Cybersecurity Framework) is the Belgian national cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It is directly aligned with the NIST Cybersecurity Framework and structured around five functions: Identify, Protect, Detect, Respond, Recover.

CyFun operates at four maturity levels (Basic, Important, Essential, and Large), which correspond directly to the NIS2 entity categories. The CCB has explicitly linked CyFun compliance to NIS2 obligations — making it the most direct path to demonstrating regulatory compliance in Belgium.

Unlike ISO 27001, CyFun does not (currently) require mandatory third-party certification for most SMEs — though the CCB is expected to tighten this over time.

Best for: Belgian SMEs whose primary obligation is NIS2 compliance with the CCB, and who need a structured, achievable framework without the overhead of full ISO 27001 certification.

Key Differences at a Glance

DimensionISO 27001CyFun
OriginInternational (ISO/IEC)Belgian national (CCB)
RecognitionGlobalBelgium / EU
CertificationMandatory third-party auditSelf-assessment (for most)
NIS2 alignmentIndirectly (via equivalence)Directly mapped
Effort to achieveHigher (6–18 months typical)Lower (3–9 months)
CostHigher (audit + consultant fees)Lower (internal + advisory)
Market signalStrong internationallyStrong in Belgium/EU public sector

When to Choose ISO 27001

Choose ISO 27001 if your clients or prospects require it contractually, if you operate in a regulated sector (healthcare, finance, critical infrastructure) where ISO 27001 is the expected standard, or if you are targeting international markets where the standard is well-recognised. Also consider it if you are planning to pursue cyber insurance — ISO 27001 certification often directly influences premium pricing.

When to Choose CyFun

Choose CyFun if your primary driver is NIS2 compliance with the CCB, if you need a structured framework quickly and at lower cost, or if you are a Belgian public sector supplier where CyFun Basic or Essential is referenced in tender requirements. CyFun is also an excellent first step — many organisations use it to build foundational maturity before pursuing ISO 27001 certification.

Can You Do Both?

Yes, and the overlap is significant. ISO 27001:2022 and CyFun share many controls. An organisation that has implemented ISO 27001 can map those controls to CyFun maturity levels with relatively modest additional effort. The reverse is also true: a CyFun Essential assessment builds most of the documented evidence base needed for ISO 27001 certification.

At Gforce, we typically recommend starting with a CyFun gap assessment to establish your baseline, prioritise remediation, and meet your immediate NIS2 obligations — then pursuing ISO 27001 certification as a second phase if your client base or sector demands it.

Get the Right Guidance for Your Situation

The right framework depends on your sector, client base, regulatory obligations, and resources. There is no universal answer — but there is always a right answer for your specific context.

Gforce Networks offers a free NIS2 readiness consultation that includes a framework recommendation tailored to your organisation. We work with Belgian SMEs of 10 to 250 employees and will give you a clear, actionable recommendation — not a sales pitch.

Book your free consultation at gforcenetworks.be →

Gilberto Torres is founder of Gforce Networks, a certified Data Protection Officer (DPO) and fractional CISO. He has guided Belgian and international SMEs through ISO 27001 and NIS2 compliance programmes.