ISO 27001 vs CyFun: Which Framework Is Right for Your Belgian SME?
If you are navigating NIS2 compliance as a Belgian SME, you have likely encountered two framework names: ISO 27001 and CyFun. Both are legitimate paths to demonstrating cybersecurity maturity. Both are referenced in Belgian regulatory guidance. But they are not interchangeable — and choosing the wrong one can cost you time, money, and credibility.
Here is an honest comparison from someone who has implemented both.
What Is ISO 27001?
ISO 27001 is the international standard for information security management systems (ISMS). Published by ISO and IEC, it is recognised globally — from Belgium to the UAE to Singapore. Certification requires an accredited third-party audit and is renewed every three years with annual surveillance audits.
ISO 27001:2022 (the current version) covers 93 controls across four themes: organisational, people, physical, and technological. It is rigorous, well-documented, and broadly understood by clients, partners, and insurers worldwide.
Best for: Organisations with international clients, regulated sector obligations, or ambitions beyond the Belgian market. Also the stronger signal for enterprise procurement processes and cyber insurance underwriters.
What Is CyFun?
CyFun (Cybersecurity Framework) is the Belgian national cybersecurity framework developed by the Centre for Cybersecurity Belgium (CCB). It is directly aligned with the NIST Cybersecurity Framework and structured around five functions: Identify, Protect, Detect, Respond, Recover.
CyFun operates at four maturity levels (Basic, Important, Essential, and Large), which correspond directly to the NIS2 entity categories. The CCB has explicitly linked CyFun compliance to NIS2 obligations — making it the most direct path to demonstrating regulatory compliance in Belgium.
Unlike ISO 27001, CyFun does not (currently) require mandatory third-party certification for most SMEs — though the CCB is expected to tighten this over time.
Best for: Belgian SMEs whose primary obligation is NIS2 compliance with the CCB, and who need a structured, achievable framework without the overhead of full ISO 27001 certification.
Key Differences at a Glance
| Dimension | ISO 27001 | CyFun |
|---|---|---|
| Origin | International (ISO/IEC) | Belgian national (CCB) |
| Recognition | Global | Belgium / EU |
| Certification | Mandatory third-party audit | Self-assessment (for most) |
| NIS2 alignment | Indirectly (via equivalence) | Directly mapped |
| Effort to achieve | Higher (6–18 months typical) | Lower (3–9 months) |
| Cost | Higher (audit + consultant fees) | Lower (internal + advisory) |
| Market signal | Strong internationally | Strong in Belgium/EU public sector |
When to Choose ISO 27001
Choose ISO 27001 if your clients or prospects require it contractually, if you operate in a regulated sector (healthcare, finance, critical infrastructure) where ISO 27001 is the expected standard, or if you are targeting international markets where the standard is well-recognised. Also consider it if you are planning to pursue cyber insurance — ISO 27001 certification often directly influences premium pricing.
When to Choose CyFun
Choose CyFun if your primary driver is NIS2 compliance with the CCB, if you need a structured framework quickly and at lower cost, or if you are a Belgian public sector supplier where CyFun Basic or Essential is referenced in tender requirements. CyFun is also an excellent first step — many organisations use it to build foundational maturity before pursuing ISO 27001 certification.
Can You Do Both?
Yes, and the overlap is significant. ISO 27001:2022 and CyFun share many controls. An organisation that has implemented ISO 27001 can map those controls to CyFun maturity levels with relatively modest additional effort. The reverse is also true: a CyFun Essential assessment builds most of the documented evidence base needed for ISO 27001 certification.
At Gforce, we typically recommend starting with a CyFun gap assessment to establish your baseline, prioritise remediation, and meet your immediate NIS2 obligations — then pursuing ISO 27001 certification as a second phase if your client base or sector demands it.
Get the Right Guidance for Your Situation
The right framework depends on your sector, client base, regulatory obligations, and resources. There is no universal answer — but there is always a right answer for your specific context.
Gforce Networks offers a free NIS2 readiness consultation that includes a framework recommendation tailored to your organisation. We work with Belgian SMEs of 10 to 250 employees and will give you a clear, actionable recommendation — not a sales pitch.