NIS2CyFUNComplianceKMO

NIS2 and CyFUN: what do these rules concretely mean for your SME or non-profit?

NIS2 and CyFUN keep coming up, but what do they actually involve? A clear explanation of the law, who it applies to, and how CyFUN gives your IT security a practical shape.

Brian

Brian

Co-Founder & CEO

21 August 20266 min read
Illustration of a balance scale, NIS2 and CyFUN theme

The terms NIS2 and CyFUN have been popping up everywhere lately: in newsletters, in client questionnaires, sometimes in an email from your insurer. For many owner-managers of an SME or board members of a non-profit it stays abstract. What exactly is it, does it apply to me, and what is then expected of me? Below is a level-headed explanation without exaggeration, because panic helps nobody move forward.

What is NIS2?

NIS2 is a European cybersecurity directive. It obliges organisations in certain sectors to get their IT security in order and to report incidents. A European directive does not apply directly: each country transposes it into its own legislation. In Belgium that has happened, and oversight lies with the Centre for Cybersecurity Belgium (CCB).

The core of NIS2 is not complicated. Those covered must take appropriate measures to manage cyber risks, report serious incidents in good time, and can be audited on this. An important detail that often gets forgotten: the directors are themselves responsible. With NIS2, cybersecurity has explicitly become a matter for management, not something you can fully hand off to IT.

Who is covered?

NIS2 distinguishes between two groups: essential entities and important entities. They get the same kind of obligations, but oversight is stricter for essential entities. Whether you are covered depends on your sector and your size.

  • Do you operate in a listed sector (think energy, drinking water, transport, healthcare, digital services, certain government and research institutions)?
  • Are you a medium or large organisation? In practice: from around 50 employees or more than 10 million euros in turnover.
  • Are you a supplier to an organisation that is itself covered by NIS2? Then that client can require through the contract that you take equivalent measures, even if you are not legally covered.

That last point affects many SMEs and non-profits that assume they stay out of range. You may not fall directly under the law, but you do fall under the requirements of a client who does. The effect feels the same: you have to demonstrate that your security is in order.

And what is CyFUN then?

Here comes the reassuring part. NIS2 says you must take appropriate measures, but not in detail how. CyFUN, in full the CyberFundamentals framework of the CCB, fills that gap. It is a practical framework that translates the vague obligation of the law into concrete, achievable steps, specifically usable for smaller organisations.

CyFUN works with levels (Small, Basic, Important, Essential), so you start at a level that fits your risk and size. You do not have to do everything at once. The framework leans on well-known standards but is written in understandable language and ordered so you know where to begin. For an SME or non-profit, CyFUN is therefore often the most usable starting point: it gives structure without the weight of a full ISO certification.

Concrete first steps

You do not have to solve everything at once. But it is wise to know where you stand before a client, insurer or regulator asks you.

  1. Check your scope. See whether your sector and size bring you under NIS2, and whether there are clients in your portfolio who are covered themselves.
  2. Look at CyFUN Small or Basic. Work through the accompanying self-assessment document from the CCB. That gives you an honest picture of your current IT security in half a day.
  3. Note the biggest gaps. MFA on important accounts, tested back-ups and a basic incident plan are often the first gaps, and immediately the most rewarding to tackle.
  4. Book a call. Not for an expensive quote, but to sharpen your blind spot and map out a realistic path.

Want to know whether NIS2 applies to you and what CyFUN concretely means for you? On our NIS2 page for SMEs we explain it calmly, and you can book a no-obligation call to review your situation.