The NIS2 directive has been in force since October 2024. The CyFun framework from the CCB is the Belgian implementation standard. Canvos helps your organisation comply with both.
The NIS2 directive is the successor to the original NIS directive and sets stricter cybersecurity requirements for a broader range of organisations in the EU.
The CyFun framework was developed by the Centre for Cybersecurity Belgium (CCB) and is the Belgian standard for cybersecurity measures, based on the internationally recognised NIST Cybersecurity Framework.
Developed by the Centre for Cybersecurity Belgium, the national authority for cybersecurity.
Built on the NIST Cybersecurity Framework, internationally the gold standard for cybersecurity.
Small, Basic and Important/Essential — each level builds on the previous with stricter measures.
Mandatory for NIS2-obligated organisations in Belgium. The CyFun framework is the official instrument through which Belgian organisations demonstrate their NIS2 compliance.
For each pillar of the CyFun framework, Canvos offers concrete features that support your compliance.
Article 21 of the NIS2 directive specifies 10 risk management measures. Below you will find how Canvos supports each requirement.
| NIS2 Requirement (Art. 21) | Canvos Implementation |
|---|---|
| Risk analysis and security policy | Governance Center with configurable security policy per organisation, data classification at 4 levels for risk-based approach. |
| Incident handling | Audit logging on 130+ routes, real-time alerts on suspicious activity, built-in phishing reporting, structured event logging for rapid analysis. |
| Business continuity | PM2 auto-restart on process failures, health endpoint monitoring, availability probes every minute, platform watch every 20 minutes. |
| Supply chain security | 100% open-source stack — full transparency on every component. No dependency on US cloud providers, no hidden sub-processors. |
| Security in acquisition and development | Fully auditable source code, 100% European hosting in Datacenter United (Ghent, Belgium), no proprietary black-box components. |
| Effectiveness assessment | Monthly compliance reporting per organisation, audit export in JSON/CSV/CEF, governance event log for periodic evaluation. |
| Cyber hygiene and training | Security onboarding tour for new users, phishing awareness via built-in reporting, clear warnings on risky behaviour. |
| Cryptography and encryption | TLS 1.3 for all in-transit communication, AES-256 encryption at rest, mandatory TLS enforcement for email. |
| Access policy and asset management | Multi-factor authentication (TOTP 2FA), role-based access control, session management, IP and geo-blocking, time-based access. |
| Multi-factor authentication | TOTP 2FA built in, conditional access policies, mandatory MFA enforceable per organisation via Governance Center. |
Let our team perform a compliance assessment and discover how Canvos helps your organisation comply with NIS2 and CyFun.
No obligation. We discuss your situation and show concretely how Canvos helps.