CyberFundamentals (CyFun) has four levels: Small, Basic, Important and Essential. Basic is the level the CCB recommends for every organisation and the minimum for many NIS2 entities. It follows the five functions of the NIST framework: identify, protect, detect, respond and recover. Below is, per function, what Basic concretely asks and whether Canvos handles it for you. Three labels: built in is on by default or done with one setting, partly needs a choice or addition from you, your policy lies outside the workplace and remains your responsibility. Print the PDF and tick.
Step by stepThe five functions
1. Identify: know what you have 2. Protect: access, data, backup, awareness 3. Detect: see what happens 4. Respond: when things go wrong 5. Recover: back to work
Identify: know what you have
- Inventory of users and access built in
The user list in organisation management shows every account with role, status, storage and mailbox. Export as CSV for your inventory. - Inventory of devices partly
Active sessions show device and browser per user. Laptops and phones themselves you keep in your own register. - Inventory of software and cloud services partly
Canvos replaces mail, files, office suite, chat, meetings and password vault: one supplier on the list instead of six. Other software you keep inventorying yourself. - Policy and legal requirements your policy
An information security policy, GDPR processing register and NIS2 registration at the CCB. See the checklist for the processing register. - Supplier risk built in
Canvos runs in Europe with a Belgian provider, without a US parent company; the processing agreement and the location of the data are fixed.
Protect: access, data, backup, awareness
- Identities and strong authentication (MFA) built in
Two-factor authentication with authenticator app or hardware key per user; one login for all modules. - Least privilege and roles built in
Roles & Apps decide who sees which module; company folders give rights per group. - Remote and mobile access built in
Mobile policy with screen protection (biometric unlock and automatic locking follow in the app). Sessions can be ended remotely. - Data protected at rest and in transit built in
TLS everywhere, encrypted backups (AES-256), data classification with labels, DLP on national register numbers and IBANs, sharing policy with password and expiry. - Backups made, kept and tested partly
Daily encrypted backups with retention are one setting. The yearly restore test you plan and document yourself. - Secure baseline configuration and patching built in
Servers, updates and security patches are managed by Canvos; executable files and attachments are blocked by default. - Removing access on departure built in
Disabling one account closes mail, files, calendar, chat and vault at once; sessions expire. - Awareness and training your policy
A yearly session on phishing and passwords remains necessary. The guides on this site can serve as training material. - Logs kept built in
Login log and governance events, hashed and anchored daily, kept according to the retention policy.
Detect: see what happens
- Events collected and correlated built in
Every policy action in the evidence chain; export as CEF to a SIEM, or CSV and JSON. - Suspicious sign-ins built in
New country or new IP is flagged, repeated failed attempts lock temporarily, approval may be required. - Malicious code partly
Executable files and attachments are blocked and mail is filtered for spam and malware. Endpoint protection on laptops remains your choice. - Alerts to the right people built in
Real-time alerts and a monthly compliance report to the addresses you set.
Respond: when things go wrong
- Incident plan your policy
Who calls whom, what is reported to the CCB within 24 and 72 hours. One page suffices for Basic; keep it in the vault. - Analysis: what happened built in
Login log plus evidence chain reconstruct in minutes who shared or opened which file. - Containment built in
End sessions, disable account, reset password, legal hold on affected files. - Communication and notification partly
The export delivers the facts for the notification; the notifying itself and communication with those affected is yours.
Recover: back to work
- Restore from backup built in
Restorable yourself with your own key, without a ticket to a vendor. - Recovery plan and test partly
Document who restores, where the key is and how long it may take. Test at least yearly. - Lessons and improvement your policy
After an incident: what do we change in policy and settings? The compliance score shows the effect immediately.
FAQFrequently asked questions
Is this an official CyFun assessment?
No. This is a practical translation of the Basic level to an office on Canvos. The official self-assessment is done in the CCB's CyFun portal; for Important and Essential, verification by an accredited body is required.
Does my organisation have to do this?
NIS2 entities must have a conformity assessment carried out; CyFun is the Belgian reference framework for it. Other organisations use Basic voluntarily as evidence for customers, insurers or tenders.
How long does it take to reach Basic with Canvos?
The technical measures are largely in place after setting up Canvos. Policy, training and the device inventory usually take a few days of work, spread over a few weeks.
Where do I find the evidence for the auditor?
Compliance report, login log and the export of the evidence chain in the Governance Center, plus the backup history. Everything can be downloaded and dated.