Skip to content

Evidence request lists

Belgium CyberFundamentals

Evidence request list. 44 controls, 44 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Belgium CyberFundamentals: Detect

BE-CF-12
Network monitoring and defense

Network monitoring and defense. Implements CyFun DE.CM-1: the network is monitored to detect potential cybersecurity events.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BE-CF-17
Continuous monitoring strategy

Continuous monitoring strategy. Implements CyFun DE.CM: the information system and assets are monitored to identify cybersecurity events and verify the effectiveness of protective measures.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BE-CF-28
Audit event logging and storage

Audit event logging and storage. Implements CyFun PR.PT-1: audit and log records are determined, documented, implemented and retained in accordance with policy.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BE-CF-29
Audit record review and analysis

Audit record review and analysis. Implements CyFun DE.AE-2: detected events are analysed to understand attack targets and methods.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BE-CF-30
Time synchronization

Time synchronization. Supports CyFun PR.PT-1: reliable, synchronised time sources underpin audit log integrity and event correlation.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BE-CF-31
Audit log protection and retention

Audit log protection and retention. Implements CyFun PR.PT-1: audit and log records are protected from unauthorised access, modification and deletion, and retained per policy.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs
BE-CF-32
Accountability and non-repudiation

Accountability and non-repudiation. Implements CyFun PR.PT-1 / PR.AC-1: actions are attributable to individual users to provide accountability and non-repudiation.

Artefacts an auditor will ask for
  • Logging standard and event taxonomy
  • SIEM coverage matrix
  • Log retention policy and evidence
  • Time synchronisation configuration
  • Log integrity controls and hash records
Where this commonly fails
  • Critical systems not forwarding logs
  • Retention shorter than regulatory minimum
  • Time drift on legacy systems
  • No tamper-evident protections on logs

Belgium CyberFundamentals: Identify

BE-CF-13
Risk assessment procedures

Risk assessment procedures. Implements CyFun ID.RA: asset vulnerabilities are identified, internal and external threats are identified, and risks (likelihood and impact) are determined.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BE-CF-14
Vulnerability scanning and management

Vulnerability scanning and management. Implements CyFun ID.RA-1 / DE.CM-8: vulnerability scans are performed and identified vulnerabilities are managed to remediation.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BE-CF-15
Security categorization

Security categorization. Implements CyFun ID.AM-5: resources are prioritised based on their classification, criticality and business value.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BE-CF-16
Threat intelligence integration

Threat intelligence integration. Implements CyFun ID.RA-2: cyber threat intelligence is received from information-sharing forums and sources and integrated into risk processes.

Artefacts an auditor will ask for
  • Risk assessment methodology and register
  • Vulnerability scan reports and remediation SLAs
  • Threat intelligence feed inventory
  • Continuous monitoring dashboard and KPI
  • Risk acceptance approvals
Where this commonly fails
  • Risk register not refreshed at defined cadence
  • Critical vulnerabilities exceeding SLA
  • Threat intelligence not integrated into controls
  • Continuous monitoring limited to a subset of systems
BE-CF-26
System component inventory

System component inventory. Implements CyFun ID.AM-1 and ID.AM-2: physical devices, systems and software platforms within the organisation are inventoried.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BE-CF-33
Asset management and data flow mapping

Asset management and data flow mapping. Implements CyFun ID.AM-3 / ID.AM-4: organisational communication and data flows are mapped and external information systems are catalogued.

Artefacts an auditor will ask for
  • Data flow diagrams and network/system topology
  • Catalogue of external information systems and connections
  • Asset register linking data flows to systems and owners
Where this commonly fails
  • Data flows undocumented or outdated
  • External/third-party connections not catalogued
  • No owner assigned to mapped data flows
BE-CF-34
Business environment

Business environment. Implements CyFun ID.BE: the organisation's mission, objectives, stakeholders, role in the supply chain, dependencies and critical functions are identified, communicated and used to inform cybersecurity roles and risk decisions.

Artefacts an auditor will ask for
  • Documented mission, critical business functions and dependencies
  • Identification of the organisation's role in the supply chain
  • Resilience requirements for critical services (normal and stress)
Where this commonly fails
  • Critical functions and dependencies not identified
  • Resilience requirements not defined for critical services
  • Business context not feeding cybersecurity risk decisions
BE-CF-35
Cybersecurity governance and policy

Cybersecurity governance and policy. Implements CyFun ID.GV: an organisational cybersecurity policy is established and communicated, cybersecurity roles and responsibilities are coordinated, legal and regulatory requirements are understood and managed, and governance and risk management processes address cybersecurity risks.

Artefacts an auditor will ask for
  • Board-approved cybersecurity policy and supporting standards
  • Register of legal, regulatory and contractual cybersecurity requirements (including NIS2 and privacy)
  • Defined cybersecurity roles, responsibilities and governance forums
  • Evidence of management review of the cybersecurity programme
Where this commonly fails
  • Policy not approved/communicated at leadership level
  • Legal/regulatory obligations not tracked
  • Governance forums not evidenced or not reviewing cyber risk
BE-CF-36
Supply chain risk management

Supply chain risk management. Implements CyFun ID.SC: cyber supply chain risk management processes are identified, established and agreed; suppliers and third-party partners are assessed against contractual obligations; and supplier compliance is routinely monitored, audited and tested.

Artefacts an auditor will ask for
  • Supply chain risk management policy and supplier risk register
  • Security requirements embedded in supplier contracts
  • Supplier assessments, audits and performance monitoring records
  • Incident-response and exit provisions for critical suppliers
Where this commonly fails
  • Critical suppliers not risk-assessed
  • Security requirements absent from contracts
  • No ongoing monitoring or testing of supplier controls

Belgium CyberFundamentals: Protect

BE-CF-01
Account management and provisioning

Account management and provisioning. Implements CyFun PR.AC-1: identities and credentials for authorised devices, users and processes are issued, managed, verified, revoked and audited.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-02
Access enforcement and least privilege

Access enforcement and least privilege. Implements CyFun PR.AC-4: access permissions and authorisations are managed, incorporating the principles of least privilege and separation of duties.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-03
Multi-factor authentication requirements

Multi-factor authentication requirements. Implements CyFun PR.AC-7: users, devices and other assets are authenticated commensurate with the risk of the transaction, including multi-factor authentication.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-04
Remote access controls

Remote access controls. Implements CyFun PR.AC-3: remote access to organisational systems is managed and secured.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-05
Wireless access restrictions

Wireless access restrictions. Implements CyFun PR.AC-3 / PR.PT-4: wireless access is managed and communications and control networks are protected.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-06
Identity proofing and verification

Identity proofing and verification. Implements CyFun PR.AC-6: identities are proofed and bound to credentials and asserted in interactions.

Artefacts an auditor will ask for
  • Access control policy and standard
  • Joiner/mover/leaver workflow records
  • Role and entitlement matrix
  • Quarterly access review attestations
  • MFA enrolment and exception register
Where this commonly fails
  • Stale or dormant accounts not deprovisioned
  • Shared or generic accounts retained
  • MFA not enforced for privileged or remote access
  • Access reviews skipped or rubber-stamped
BE-CF-07
Boundary protection and segmentation

Boundary protection and segmentation. Implements CyFun PR.AC-5 / PR.PT-4: network integrity is protected through network segregation and segmentation, and communications networks are protected.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BE-CF-08
Cryptographic protection of data

Cryptographic protection of data. Implements CyFun PR.DS-1 and PR.DS-2: data-at-rest and data-in-transit are protected using cryptography.

Artefacts an auditor will ask for
  • Cryptographic standards and algorithm catalogue
  • Key management policy and KMS configuration
  • TLS configuration and inventory
  • Encryption at rest evidence per system
  • Key rotation and escrow records
Where this commonly fails
  • Use of deprecated ciphers or self-signed certificates
  • Keys stored alongside encrypted data
  • No documented rotation schedule
  • Inconsistent encryption coverage across data stores
BE-CF-09
Denial-of-service protection

Denial-of-service protection. Implements CyFun PR.DS-4 / PR.PT-4: adequate capacity to ensure availability is maintained and communications networks are protected against denial-of-service.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BE-CF-10
Transmission confidentiality and integrity

Transmission confidentiality and integrity. Implements CyFun PR.DS-2: data-in-transit is protected for confidentiality and integrity.

Artefacts an auditor will ask for
  • Cryptographic standards and algorithm catalogue
  • Key management policy and KMS configuration
  • TLS configuration and inventory
  • Encryption at rest evidence per system
  • Key rotation and escrow records
Where this commonly fails
  • Use of deprecated ciphers or self-signed certificates
  • Keys stored alongside encrypted data
  • No documented rotation schedule
  • Inconsistent encryption coverage across data stores
BE-CF-11
Session management controls

Session management controls. Implements CyFun PR.AC-7 / PR.PT-4: sessions are authenticated and managed to protect confidentiality and integrity.

Artefacts an auditor will ask for
  • Network architecture and segmentation diagram
  • Firewall rule review evidence
  • IDS/IPS tuning records
  • Session timeout configuration
  • DoS mitigation runbooks
Where this commonly fails
  • Flat networks with limited segmentation
  • Stale firewall rules and any-any allows
  • Session timeouts too long or inconsistent
  • DoS protections untested
BE-CF-23
Baseline configuration establishment

Baseline configuration establishment. Implements CyFun PR.IP-1: a baseline configuration of information technology and control systems is created and maintained, incorporating security principles.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BE-CF-24
Configuration change control

Configuration change control. Implements CyFun PR.IP-3: configuration change control processes are established and applied.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BE-CF-25
Security impact analysis

Security impact analysis. Implements CyFun PR.IP-3: changes are assessed for security impact before implementation under configuration change control.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BE-CF-27
Software usage restrictions

Software usage restrictions. Implements CyFun PR.IP-1 / PR.DS-6: authorised software usage is governed and integrity-checking mechanisms are used.

Artefacts an auditor will ask for
  • Secure configuration baselines per platform
  • Change advisory board minutes
  • CMDB extracts
  • Configuration drift reports
  • Software allow-list and usage records
Where this commonly fails
  • Baselines missing for newer platforms
  • Emergency changes bypassing CAB
  • CMDB out of sync with reality
  • No automated drift detection
BE-CF-37
Awareness and training

Awareness and training. Implements CyFun PR.AT: all users are informed and trained, and privileged users, third-party stakeholders, senior executives and physical/information security personnel understand their roles and responsibilities.

Artefacts an auditor will ask for
  • Security awareness programme and completion records
  • Role-based training for privileged users and administrators
  • Phishing simulation and awareness campaign results
  • Training for senior leadership and third-party stakeholders
Where this commonly fails
  • Awareness training not completed by all users
  • No role-based training for privileged/administrative users
  • Effectiveness of awareness not measured
BE-CF-38
System maintenance

System maintenance. Implements CyFun PR.MA: maintenance and repair of organisational assets are performed and logged with approved and controlled tools, and remote maintenance is approved, logged and performed in a manner that prevents unauthorised access.

Artefacts an auditor will ask for
  • Maintenance policy, schedule and maintenance logs
  • Approval and logging records for remote maintenance sessions
  • Control of maintenance tools and media
Where this commonly fails
  • Maintenance not logged or approved
  • Remote maintenance performed without approval or monitoring
  • Maintenance tools not controlled
BE-CF-39
Data security lifecycle management

Data security lifecycle management. Implements CyFun PR.DS-3 / PR.DS-5: assets are formally managed throughout removal, transfer and disposition, and protections against data leaks are implemented.

Artefacts an auditor will ask for
  • Asset disposal/sanitisation records and procedures
  • Data leakage prevention controls and monitoring
  • Media handling, transfer and disposition policy
Where this commonly fails
  • Media not sanitised before disposal or reuse
  • No data-leak protections for sensitive data
  • Asset transfers not tracked

Belgium CyberFundamentals: Recover

BE-CF-40
Recovery planning

Recovery planning. Implements CyFun RC.RP-1: a recovery plan is maintained and executed during or after a cybersecurity incident to restore systems and assets affected.

Artefacts an auditor will ask for
  • Recovery plan and IT disaster-recovery procedures
  • Recovery time and recovery point objectives (RTO/RPO)
  • Recovery plan test results and restoration records
Where this commonly fails
  • Recovery plan untested
  • RTO/RPO not defined or not met in tests
  • Backups not validated for restorability
BE-CF-41
Recovery improvements

Recovery improvements. Implements CyFun RC.IM: recovery planning and processes are improved by incorporating lessons learned into future activities, and recovery strategies are updated.

Artefacts an auditor will ask for
  • Post-recovery review reports and lessons-learned register
  • Updates to recovery plans and strategies following incidents/tests
  • Tracking of recovery improvement actions to closure
Where this commonly fails
  • Lessons learned not captured after recovery events
  • Recovery plans not updated following tests/incidents
  • Improvement actions not tracked
BE-CF-42
Recovery communications

Recovery communications. Implements CyFun RC.CO: public relations are managed, reputation is repaired after an incident, and recovery activities are communicated to internal and external stakeholders and executive and management teams.

Artefacts an auditor will ask for
  • Crisis communication plan and stakeholder contact lists
  • Records of recovery communications to internal/external parties
  • Public-relations and reputation-management procedures
Where this commonly fails
  • No crisis communication plan
  • Stakeholders not informed during recovery
  • Regulatory/customer notification obligations missed

Belgium CyberFundamentals: Respond

BE-CF-18
Incident response planning and testing

Incident response planning and testing. Implements CyFun RS.RP-1: a response plan is maintained, tested and executed during or after a cybersecurity incident.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BE-CF-19
Incident handling and containment

Incident handling and containment. Implements CyFun RS.MI-1 / RS.MI-2: incidents are contained and mitigated.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BE-CF-20
Incident reporting and notification

Incident reporting and notification. Implements CyFun RS.CO-2 / RS.CO-3: incidents are reported consistent with established criteria and information is shared with internal and external stakeholders.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BE-CF-21
Forensic analysis capabilities

Forensic analysis capabilities. Implements CyFun RS.AN-1 / RS.AN-3: detection notifications are investigated and forensic analysis is performed.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out
BE-CF-22
Lessons learned and improvement

Lessons learned and improvement. Implements CyFun RS.IM-1 / RS.IM-2: response activities incorporate lessons learned and response strategies are updated.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out

Belgium CyberFundamentals: Scoping and Regulatory Alignment

BE-CF-43
Assurance level selection and scoping

Assurance level selection and scoping. Core to CyFun: the organisation selects the appropriate assurance level (BASIC, IMPORTANT or ESSENTIAL) proportionate to the cyber risk of its activities and defines the scope of the systems and processes to which the key measures apply.

Artefacts an auditor will ask for
  • Documented selection and justification of the CyFun assurance level
  • Defined assessment scope (systems, processes, locations)
  • Risk rationale linking activity criticality to the chosen level
Where this commonly fails
  • Assurance level not justified against risk
  • Scope undefined or inconsistent with the assessment
  • Critical systems excluded from scope
BE-CF-44
NIS2 alignment

NIS2 alignment. Core to CyFun: the CyberFundamentals key measures are mapped to the obligations of the NIS2 Directive (as transposed in Belgian law), and the CCB recognises attainment of CyFun assurance levels as a means to demonstrate compliance with NIS2 risk-management and reporting obligations.

Artefacts an auditor will ask for
  • Mapping of implemented CyFun key measures to NIS2 obligations
  • Evidence of NIS2 incident-notification readiness and timelines
  • Management body approval and oversight of cybersecurity risk-management measures (NIS2 governance)
Where this commonly fails
  • CyFun implementation not mapped to NIS2 obligations
  • Incident-notification process not aligned to NIS2 timelines
  • Management-body accountability for NIS2 not evidenced
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.