The European NIS2 Directive requires ‘essential’ and ‘important’ entities to implement appropriate and proportionate security measures and to be able to demonstrate that they have done so.
NIS2 stands for the second European Network and Information Security Directive. In Belgium, this is the legal framework designed to enhance the cyber resilience of society and the economy and to limit the impact of cyber incidents.
With the introduction of the NIS2 Directive in Belgium (since April 2024), organisations in 18 sectors are legally obliged to strengthen their cyber security. The CCB (Centre for Cyber Security Belgium) recognises two approaches for this: CyFun® and ISO/IEC 27001.
Vinçotte offers both.
The CCB allows organisations to choose for themselves how they demonstrate their cyber resilience: via the Belgian CyFun® framework, or via the international ISO/IEC 27001 standard. Both routes carry equal weight in establishing presumption of compliance. Which approach you choose depends on your context, not on a mandatory sequence.
The CCB’s Belgian framework
CyFun® operates with three progressive levels of security, as not every company has the same risk profile. The three levels are Basic – Important – Essential.
The global standard for information security management (ISMS).
A single certification process, suitable for every NIS2 level (including Essential), provided that the scope and Statement of Applicability are accepted by the CCB.
More about ISO/IEC 27001 CertificationThere is no one-size-fits-all answer when choosing between CyFun® and ISO/IEC 27001: the most suitable approach depends on your organisation’s structure, risks and ambitions, and warrants a thorough analysis, particularly for larger groups with multiple legal entities or overseas branches.
Please contact our experts to discuss your situation, or find out more about this choice through Vinçotte Academy’s specialised Framework Exploration course.
| CyFun® (Vinçotte-verification) | |
|---|---|
Starting Point | Belgian and structured in a step-by-step manner |
Recognition | National — specifically designed around NIS2 and the CCB |
| ISO/IEC 27001 (Vinçotte-certification) | |
|---|---|
Starting Point | International management system standard |
Recognition | Globally recognised, additionally validated by the CCB for NIS2 |
Together, we determine your entity type (essential/important), the relevant sector and the desired level.
A one-day standard training course on ISO/IEC 27001 and CyFun®, focusing on the interaction with other frameworks and legislation such as IEC 62443 (OT/ICS), TISAX and the Cyber Resilience Act (CRA).
A thorough analysis against CyFun® or ISO/IEC 27001 shows exactly where you stand today and what still needs to be done.
Our experts independently assess documentation, processes and implementation on the shop floor.
You will receive your CyFun® label or ISO/IEC 27001 certificate, with follow-up through periodic surveillance audits.
Orange Cyberdefense (Wijnegem) is the very first cybersecurity company in Belgium to be officially certified according to the strict European NIS2 directive.
>> Certified by Vinçotte. Read here to find out how we went about it <<Please contact us using the form below or get in touch directly with our cybersecurity expert, Christian Kitooto to plan a meeting with him.