Regulation · 18 June 2026 · 5 min read
CyberFundamentals 2025 (CyFun): the framework behind NIS2 self-assessment
Romania's official NIS2 self-assessment is built on the CyberFundamentals framework. What the 6 functions and assurance levels are, and how they map to NIS2 obligations.
ClearSecurity Vision
If you’ve opened Romania’s official NIS2 self-assessment platform (DNSC’s SecureRO) and run into terms like “CyberFundamentals”, “the 6 functions” or “Small / Basic / Important / Essential level” — and it felt like another language — this article is for you.
You don’t need to be a cybersecurity specialist to understand what’s being asked of you. Here is the framework, explained clearly and without unnecessary jargon.
What CyberFundamentals actually is
CyberFundamentals (or CyFun for short) is a set of security best practices created by the Centre for Cybersecurity Belgium (CCB). In short: a structured list of things an organisation should do to protect itself against the most common cyber-attacks.
What makes it useful is that it doesn’t reinvent the wheel. CyFun pulls together the best-known international security standards — NIST, ISO 27001, IEC 62443, CIS — and translates them into a clear, step-by-step path. Instead of reading hundreds of pages of standards, you get a single, logically organised list.
Romania chose this framework as the basis for its NIS2 self-assessment: DNSC’s SecureRO platform asks you exactly these questions.
The 6 functions, at a glance
CyFun organises everything around 6 big questions about your organisation. If this is all you remember from the article, it’s enough:
-
Govern — Who is responsible for security, and what rules have you set? Security isn’t just “the IT team’s job” — it’s a leadership decision: who decides, what policies you have, who you report to.
-
Identify — What exactly do you need to protect? Which systems, which data, which devices, which suppliers. You can’t defend something you don’t even know you have.
-
Protect — What have you put in place so a disaster doesn’t happen? Strong passwords, access control, backups, staff training.
-
Detect — Can you tell quickly when something is wrong? An attack spotted in 10 minutes does far less damage than one discovered three months later.
-
Respond — What do you do in the first hours when an incident actually happens? Who calls whom, how you limit the damage, who you report to.
-
Recover — How do you get back to normal after an incident — and what do you learn from it? You restore systems and make sure it doesn’t happen again.
These same 6 functions show up in your NIS2 obligations. In practice, if you tick these off, you’re very close to compliance.
The levels: how strict, based on how critical you are
CyFun doesn’t ask the same of everyone. It has four tiers, from simple to advanced:
- Small — a starting point, for very small organisations or those with no technical knowledge. A quick first check.
- Basic — the baseline measures, valid for any organisation. Reasonable protection using means you likely already have.
- Important — for higher-risk organisations that need to withstand targeted attacks.
- Essential — the top level, for critical infrastructure that must be protected against advanced attacks.
The higher you go, the more measures apply: a few dozen at Basic, over a hundred at Important, and 218 at Essential. You pick the level that matches how critical your activity is — usually tied to your NIS2 entity type (important or essential).
”Key measures”: not everything weighs the same
Not all requirements carry the same weight. CyFun marks some of them as key measures — the ones that stop the most common types of attacks. They are mandatory at that level. It’s a helpful filter: it tells you where to start if you can’t do everything at once.
How scoring works: “on paper” and “in reality”
This is the part many people miss. For each measure, CyFun asks you to rate yourself on two dimensions:
- Documentation — have you written it down? Is there a policy, a procedure, a clear rule?
- Implementation — do you actually do it? Is it applied in practice, with evidence?
You can have a beautiful policy on paper that nobody follows — or the opposite, you do the right thing but never documented it. Real compliance needs both. Each dimension gets a score from 1 to 5 (documentation separate from implementation), and to be “compliant” at a level you must pass a minimum threshold.
So what do you do with this?
The good news: the official self-assessment is free on DNSC’s SecureRO platform. We recommend using it — it’s the official tool and gives you a clear picture of where you stand.
The less comfortable news: knowing where your gaps are doesn’t mean you’ve closed them. The self-assessment gives you a score and a list of problems. The real work starts then — writing the policies, implementing the measures, gathering evidence, meeting the DNSC reporting deadlines, and preparing for the audit.
That’s where CERTO, our NIS2 compliance platform, comes in: it generates the documents you need, tracks your incidents and legal deadlines (OUG 155/2024), and prepares your file for the DNSC-attested auditor. DNSC tells you where you are; CERTO helps you get where you need to be — and stay there.
This article is informational and explains the CCB’s public CyberFundamentals 2025 framework and its link to NIS2 / OUG 155/2024. It is not legal or technical advice. Your specific obligations depend on your organisation’s sector, size, and activities.
Want a clear picture of where you stand against NIS2 and a concrete compliance plan? Start with CERTO or talk to us.
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.