Belgium CyberFundamentals
Belgian Centre for Cybersecurity CyberFundamentals Framework
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (13)
Belgium CyberFundamentals: Access Control & Identity
Managing access to information systems (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-01 | Account management and provisioning |
| BE-CF-02 | Access enforcement and least privilege |
| BE-CF-03 | Multi-factor authentication requirements |
| BE-CF-04 | Remote access controls |
| BE-CF-05 | Wireless access restrictions |
| BE-CF-06 | Identity proofing and verification |
Belgium CyberFundamentals: Audit & Accountability
Audit logging and accountability measures (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-28 | Audit event logging and storage |
| BE-CF-29 | Audit record review and analysis |
| BE-CF-30 | Time synchronization |
| BE-CF-31 | Audit log protection and retention |
| BE-CF-32 | Accountability and non-repudiation |
Belgium CyberFundamentals: Configuration Management
Managing system configurations securely (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-23 | Baseline configuration establishment |
| BE-CF-24 | Configuration change control |
| BE-CF-25 | Security impact analysis |
| BE-CF-26 | System component inventory |
| BE-CF-27 | Software usage restrictions |
Belgium CyberFundamentals: Incident Response
Detecting and responding to security incidents (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-18 | Incident response planning and testing |
| BE-CF-19 | Incident handling and containment |
| BE-CF-20 | Incident reporting and notification |
| BE-CF-21 | Forensic analysis capabilities |
| BE-CF-22 | Lessons learned and improvement |
Belgium CyberFundamentals: Risk Assessment & Management
Identifying and managing cybersecurity risks (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-13 | Risk assessment procedures |
| BE-CF-14 | Vulnerability scanning and management |
| BE-CF-15 | Security categorization |
| BE-CF-16 | Threat intelligence integration |
| BE-CF-17 | Continuous monitoring strategy |
Belgium CyberFundamentals: System & Communications Protection
Protecting systems and communications (Belgium CyberFundamentals)
| Code | Title |
|---|---|
| BE-CF-07 | Boundary protection and segmentation |
| BE-CF-08 | Cryptographic protection of data |
| BE-CF-09 | Denial-of-service protection |
| BE-CF-10 | Transmission confidentiality and integrity |
| BE-CF-11 | Session management controls |
| BE-CF-12 | Network monitoring and defense |
Detect
| Code | Title |
|---|---|
| CYFUN-13 | Anomalies and Events Detection |
| CYFUN-14 | Continuous Monitoring |
| CYFUN-15 | Detection Processes |
Identify
| Code | Title |
|---|---|
| CYFUN-2 | Asset Inventory |
| CYFUN-3 | Business Environment and Governance |
| CYFUN-4 | Risk Assessment |
| CYFUN-5 | Supply Chain Risk Management |
Protect
| Code | Title |
|---|---|
| CYFUN-10 | Information Protection Processes |
| CYFUN-11 | Maintenance |
| CYFUN-12 | Protective Technology |
| CYFUN-6 | Identity Management and Access Control |
| CYFUN-7 | Multi-Factor Authentication |
| CYFUN-8 | Awareness and Training |
| CYFUN-9 | Data Security |
Recover
| Code | Title |
|---|---|
| CYFUN-21 | Recovery Planning |
| CYFUN-22 | Recovery Improvements |
| CYFUN-23 | Recovery Communications |
Regulatory
| Code | Title |
|---|---|
| CYFUN-24 | NIS2 Alignment |
Respond
| Code | Title |
|---|---|
| CYFUN-16 | Response Planning |
| CYFUN-17 | Response Communications |
| CYFUN-18 | Analysis |
| CYFUN-19 | Mitigation |
| CYFUN-20 | Improvements from Incidents |
Scoping
| Code | Title |
|---|---|
| CYFUN-1 | Assurance Level Selection |
Your Compliance Coverage
If you comply with Belgium CyberFundamentals, you already cover:
ANSSI Cybersecurity Framework
36%
20 controls mapped
Compare →NIST SP 800-171
36%
20 controls mapped
Compare →DoD Zero Trust Reference Architecture
36%
20 controls mapped
Compare →+ 534 more: NIST SP 800-172 (36%), BSI IT-Grundschutz (36%)
See all 537 mapped frameworks ↓Maps to 537 other frameworks
Frequently Asked Questions
What is Belgium CyberFundamentals?
Belgium CyberFundamentals is a compliance framework from Belgium with 13 domains and 56 controls. Belgian Centre for Cybersecurity CyberFundamentals Framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Belgium CyberFundamentals have?
Belgium CyberFundamentals has 56 controls organised across 13 domains. The largest domains are Protect (7 controls), Belgium CyberFundamentals: Access Control & Identity (6 controls), Belgium CyberFundamentals: System & Communications Protection (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Belgium CyberFundamentals map to?
Belgium CyberFundamentals maps to 537 other compliance frameworks. The top mapping partners are ANSSI Cybersecurity Framework (36% coverage), NIST SP 800-171 (36% coverage), DoD Zero Trust Reference Architecture (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Belgium CyberFundamentals compliance?
Start your Belgium CyberFundamentals compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Belgium CyberFundamentals requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 56 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required