In short
CyFun (CyberFundamentals) is a voluntary cybersecurity framework the Irish NCSC recommends for organising and evidencing your controls against NIS2. It is built on the NIST Cybersecurity Framework, it scales to three assurance levels (Basic, Important, Essential), and its self-assessment tool is a free spreadsheet. Two versions are live: use CyFun 2025, based on NIST CSF 2.0, because CyFun 2023 is retired on 18 April 2027. CyFun is not proof of NIS2 compliance on its own, and Irish certification does not exist yet; the NCSC expects a national scheme by 2027. Run the Basic self-assessment first: half a day, no cost, and it produces the gap list everything else works from.
CyFun, short for CyberFundamentals, is a cybersecurity framework the Irish National Cyber Security Centre recommends as a way to organise and evidence your security controls against NIS2. It is voluntary, it is built on the NIST Cybersecurity Framework, and its self-assessment tool is free.
It was written by the Centre for Cybersecurity Belgium, which is why the documentation is Belgian and the tool says CCB on it. Ireland adopted it rather than writing its own, which is good news: the framework has years of use behind it and a working set of tools.
This guide covers what CyFun contains, which of the two current versions to use, how to pick your assurance level, and how to run the self-assessment without buying anything.
Why the NCSC points to CyFun
NIS2 tells you to take "appropriate and proportionate" measures. It does not tell you what appropriate looks like for a 40-person food producer in Carlow. That gap is where most compliance projects stall.
CyFun fills it with a control list, scaled to three assurance levels, that you can score yourself against and hand to a customer, an insurer or a regulator. It is a structure for the work and a record that the work happened.
Two limits, stated plainly because they matter:
- CyFun is not proof of NIS2 compliance. The NCSC says so directly. Your sectoral competent authority decides what compliance means in your sector. CyFun is a recognised, credible way to get there and to show your reasoning.
- Irish certification does not exist yet. The NCSC expects a national certification scheme by 2027, which will become Ireland's NIS2 certification route. Until then you self-assess. Self-assessment is still worth doing, because the evidence it produces is what questionnaires ask for.
CyFun 2023 or CyFun 2025: which version to use
There are two live versions, and picking one is the first decision.
| CyFun 2023 | CyFun 2025 | |
|---|---|---|
| Based on | NIST CSF 1.1 | NIST CSF 2.0 |
| Core functions | Five | Six, adding Govern |
| Status | Being retired | Current |
They coexist until 18 April 2027, and you may use either until then. Certificates issued against CyFun 2023 stay valid until 18 April 2028 at the latest, after which only CyFun 2025 is accepted.
Start on CyFun 2025 if you are starting now. Doing the 2023 version in 2026 means doing the transition again inside two years, and the added Govern function is the part boards are being asked about.
The six functions
CyFun 2025 organises every control under the six functions of NIST CSF 2.0.
Govern. Who owns cyber risk, what the organisation's risk appetite is, and how that is decided and reviewed. New in 2.0, and the function that most directly answers the NIS2 requirement for management bodies to approve and be trained on the risk-management measures.
Identify. What you have. Devices, accounts, data, suppliers, and where the important things sit. Nearly every failed assessment fails here first, because you cannot protect an asset register that does not exist.
Protect. Access control, MFA, patching, encryption, backup, awareness training. The bulk of the control count.
Detect. Whether you would notice. Logging, alerting, endpoint detection, and someone whose job it is to look.
Respond. What happens in the first hour. Who declares an incident, who notifies, who talks to customers.
Recover. Getting back to work, and proving you can before you need to. A backup that has never been restored is not a recovery plan.
Which assurance level fits your business
CyFun has three levels. They are not a maturity ladder you climb: you pick the one that matches your risk and stay there.
| Level | Intended for | Roughly what it asks |
|---|---|---|
| Basic | Small businesses with limited exposure | Cyber hygiene: MFA, patching, backup, awareness, an asset list |
| Important | Medium businesses, or anyone holding sensitive data | Everything in Basic, plus monitoring, documented processes and tested response |
| Essential | Critical services and high-impact entities | Everything in Important, plus independent assurance and continual improvement |
The mapping to NIS2 is deliberate. If NIS2 would class you as an important entity, the Important level is the sensible target. If NIS2 does not cover you but your customers keep sending questionnaires, Basic answers most of them.
Running the self-assessment
The tool is a spreadsheet, published free by the CCB. Budget half a day for a first pass, and do it with two people rather than one.
- Download the tool for your chosen version and level. The workbook contains the control list, a scoring sheet and the reporting diagrams. There is nothing to buy and no account to create.
- Score each control on maturity and on documentation, separately. This is the part people get wrong. CyFun scores whether a control exists and works, and separately whether it is written down. A control you do reliably but have never documented scores well on one axis and badly on the other, and questionnaires ask about the second.
- Be honest about partials. The temptation is to score "we mostly do that". The output is only useful if it tells you where you actually are, and a self-assessment nobody will ever audit is the one place where honesty is free.
- Read the spider diagram, not the total. The workbook plots your score per function. A low Detect score next to a high Protect score is the common Irish SME shape: good locks, nobody watching. That picture is more useful to a board than a percentage.
- Turn the gaps into a dated list with costs. Anything unscored becomes an action with an owner and a date. This list is the deliverable, not the spreadsheet.
- Keep the evidence. Screenshots of the MFA policy, the patch report, the restore test log. Evidence is what turns a self-assessment into something you can hand over.
The four gaps that set the level
Four gaps decide whether a small business scores Basic or Important, and all four sit in Detect and Recover:
- Backups that run but have never been restore-tested.
- Logging that exists on the devices but is not collected anywhere, so nobody could reconstruct an incident.
- MFA on email but not on the VPN, the remote desktop, or the line-of-business application.
- No named person who declares an incident, which is the gap that turns a 24-hour reporting clock into a missed one.
None of the four is expensive to close. All four are the difference between a Basic score and an Important one.
CyFun, NIS2 and NIST: how the three fit
Three different things, often used as if they were one.
- NIS2 is the law. It says what outcomes you must achieve. See our NIS2 guide for scope and obligations.
- NIST CSF is the international structure underneath. It supplies the six functions and the vocabulary.
- CyFun is the practical layer on top: a scaled control list, a scoring method and a free tool, recommended by the NCSC.
If you already hold ISO 27001, you do not need CyFun. ISO remains a valid route, and the controls overlap heavily. CyFun is the lighter option for a business that has never certified anything and needs to show a customer something credible this quarter.
What to do next
Run the self-assessment at Basic level this month, even if you think you need Important. It takes half a day, it costs nothing, and it produces the gap list that everything else works from. Then decide whether to move up a level.
Related reading
- Does NIS2 apply to my Irish business, and what does it require?
- What is a SOC, and does a small Irish business need one?
- How should an Irish SME choose between managed IT providers?
Related services
Want it done with you
We run the CyFun self-assessment as a working session: two hours with your team, the scoring done live, and a prioritised gap list with costs against each item by the end of the week. Offices in Cork and Kilkenny, working with SMEs across Ireland.
What is CyFun?
CyFun, short for CyberFundamentals, is a cybersecurity framework written by the Centre for Cybersecurity Belgium and recommended by the Irish National Cyber Security Centre as a way to organise and evidence your security controls against NIS2. It is voluntary and free to self-assess against. It is built on the NIST Cybersecurity Framework and scales to three assurance levels so a small business is not asked to build what a bank builds.
Is CyFun mandatory in Ireland?
No. CyFun is voluntary. The NCSC recommends it as a recognised and credible way to demonstrate that you have organised your controls, but other frameworks including ISO 27001 remain valid. Your sectoral competent authority decides what NIS2 compliance means in your sector, so CyFun on its own is not proof of compliance.
Should I use CyFun 2023 or CyFun 2025?
CyFun 2025, if you are starting now. CyFun 2023 is built on NIST CSF 1.1 and has five core functions. CyFun 2025 is built on NIST CSF 2.0 and adds a sixth, Govern, which covers who owns cyber risk and how that is decided. The two versions coexist until 18 April 2027, and certificates against CyFun 2023 remain valid until 18 April 2028 at the latest. Starting on 2023 now means repeating the transition inside two years.
How much does the CyFun self-assessment cost?
Nothing. The self-assessment tool is a spreadsheet the CCB publishes free, containing the control list, the scoring sheet and the reporting diagrams. There is no account to create and nothing to buy. Formal certification will carry a fee once a scheme exists, but Irish certification is not yet available: the NCSC expects a national scheme by 2027.
Which CyFun assurance level do I need?
Match the level to your risk, not your ambition. Basic suits small businesses with limited exposure and covers cyber hygiene: MFA, patching, backup, awareness and an asset list. Important suits medium businesses and anyone holding sensitive data, adding monitoring, documented processes and tested response. Essential is for critical services and adds independent assurance. If NIS2 would class you as an important entity, target the Important level.
We already have ISO 27001. Do we need CyFun as well?
No. ISO 27001 remains a valid route and the controls overlap heavily. CyFun is the lighter option for a business that has never certified anything and needs to show a customer something credible quickly. Doing both duplicates effort without adding assurance.