ClearSecurity VISION
EN / RO
← All articles

Regulation · 18 June 2026 · 5 min read

CyberFundamentals 2025 (CyFun): the framework behind NIS2 self-assessment

Romania's official NIS2 self-assessment is built on the CyberFundamentals framework. What the 6 functions and assurance levels are, and how they map to NIS2 obligations.

ClearSecurity Vision

If you’ve opened Romania’s official NIS2 self-assessment platform (DNSC’s SecureRO) and run into terms like “CyberFundamentals”, “the 6 functions” or “Small / Basic / Important / Essential level” — and it felt like another language — this article is for you.

You don’t need to be a cybersecurity specialist to understand what’s being asked of you. Here is the framework, explained clearly and without unnecessary jargon.

What CyberFundamentals actually is

CyberFundamentals (or CyFun for short) is a set of security best practices created by the Centre for Cybersecurity Belgium (CCB). In short: a structured list of things an organisation should do to protect itself against the most common cyber-attacks.

What makes it useful is that it doesn’t reinvent the wheel. CyFun pulls together the best-known international security standards — NIST, ISO 27001, IEC 62443, CIS — and translates them into a clear, step-by-step path. Instead of reading hundreds of pages of standards, you get a single, logically organised list.

Romania chose this framework as the basis for its NIS2 self-assessment: DNSC’s SecureRO platform asks you exactly these questions.

The 6 functions, at a glance

CyFun organises everything around 6 big questions about your organisation. If this is all you remember from the article, it’s enough:

  • GovernWho is responsible for security, and what rules have you set? Security isn’t just “the IT team’s job” — it’s a leadership decision: who decides, what policies you have, who you report to.

  • IdentifyWhat exactly do you need to protect? Which systems, which data, which devices, which suppliers. You can’t defend something you don’t even know you have.

  • ProtectWhat have you put in place so a disaster doesn’t happen? Strong passwords, access control, backups, staff training.

  • DetectCan you tell quickly when something is wrong? An attack spotted in 10 minutes does far less damage than one discovered three months later.

  • RespondWhat do you do in the first hours when an incident actually happens? Who calls whom, how you limit the damage, who you report to.

  • RecoverHow do you get back to normal after an incident — and what do you learn from it? You restore systems and make sure it doesn’t happen again.

These same 6 functions show up in your NIS2 obligations. In practice, if you tick these off, you’re very close to compliance.

The levels: how strict, based on how critical you are

CyFun doesn’t ask the same of everyone. It has four tiers, from simple to advanced:

  1. Small — a starting point, for very small organisations or those with no technical knowledge. A quick first check.
  2. Basic — the baseline measures, valid for any organisation. Reasonable protection using means you likely already have.
  3. Important — for higher-risk organisations that need to withstand targeted attacks.
  4. Essential — the top level, for critical infrastructure that must be protected against advanced attacks.

The higher you go, the more measures apply: a few dozen at Basic, over a hundred at Important, and 218 at Essential. You pick the level that matches how critical your activity is — usually tied to your NIS2 entity type (important or essential).

”Key measures”: not everything weighs the same

Not all requirements carry the same weight. CyFun marks some of them as key measures — the ones that stop the most common types of attacks. They are mandatory at that level. It’s a helpful filter: it tells you where to start if you can’t do everything at once.

How scoring works: “on paper” and “in reality”

This is the part many people miss. For each measure, CyFun asks you to rate yourself on two dimensions:

  • Documentationhave you written it down? Is there a policy, a procedure, a clear rule?
  • Implementationdo you actually do it? Is it applied in practice, with evidence?

You can have a beautiful policy on paper that nobody follows — or the opposite, you do the right thing but never documented it. Real compliance needs both. Each dimension gets a score from 1 to 5 (documentation separate from implementation), and to be “compliant” at a level you must pass a minimum threshold.

So what do you do with this?

The good news: the official self-assessment is free on DNSC’s SecureRO platform. We recommend using it — it’s the official tool and gives you a clear picture of where you stand.

The less comfortable news: knowing where your gaps are doesn’t mean you’ve closed them. The self-assessment gives you a score and a list of problems. The real work starts then — writing the policies, implementing the measures, gathering evidence, meeting the DNSC reporting deadlines, and preparing for the audit.

That’s where CERTO, our NIS2 compliance platform, comes in: it generates the documents you need, tracks your incidents and legal deadlines (OUG 155/2024), and prepares your file for the DNSC-attested auditor. DNSC tells you where you are; CERTO helps you get where you need to be — and stay there.


This article is informational and explains the CCB’s public CyberFundamentals 2025 framework and its link to NIS2 / OUG 155/2024. It is not legal or technical advice. Your specific obligations depend on your organisation’s sector, size, and activities.


Want a clear picture of where you stand against NIS2 and a concrete compliance plan? Start with CERTO or talk to us.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.