Guide · Sectors

Public sector and local government: demonstrating NIS2 and CyberFundamentals with Canvos

Municipalities, welfare offices, inter-municipal bodies and agencies must not only work securely under NIS2 and the CyberFundamentals framework, but prove it. Canvos delivers the measures and the evidence in one workplace: access control with 2FA, logging, encrypted backups, mobile policy, and an evidence chain that exports as CEF to your SIEM.

Canvos · Sectors7 min readPublic sector · NIS2 · CyberFundamentals · CCB

Since NIS2 took effect in Belgium, many public entities are 'important' or 'essential' entities, with a registration duty at the Centre for Cybersecurity Belgium, an incident notification duty and a mandatory conformity assessment based on CyberFundamentals. The practical question for an administration without a large IT team is: how do we show at an audit that access, logging, backup and data protection are in order? In this guide An, responsible for a small administration, walks through the places in Canvos where those measures live and where the evidence comes from. Note: the administration screens are currently shown in Dutch; the captions translate every step.

Watch in 60 seconds · Compliance score, 2FA, login log, backup, CEF export, mobile policy and retention in one minute, without sound.

Step by stepSeven steps

1. The compliance score as starting point 2. Access control: two-factor authentication 3. Detection: the login log 4. Recovery: encrypted backups 5. Reporting: evidence chain to your SIEM 6. Mobile policy 7. Retention according to archive law

1

The compliance score as starting point

Open the Governance Center, tab Compliance. The score is computed from facts, control by control: data classification active, DLP rules, public links controlled, blocked file types, email policy, retention executed, audit log at least one year, chain intact, sync and worker healthy, alerts configured, mobile screen protection. Each control shows what is missing. This is your internal baseline for CyFun.

The compliance score with the list of controls and their status
2

Access control: two-factor authentication

CyberFundamentals asks for strong authentication for access to systems. In Canvos every user activates an authenticator app or a hardware key (FIDO2) under Settings, tab 2FA. The secret stays on your own server; no external identity service is needed. See the two-factor guide for the steps.

The 2FA settings with authenticator app and hardware key
3

Detection: the login log

Under Beveiliging (security) every sign-in is listed with user, IP address, country, browser and result. Repeated failed attempts lead to a temporary lockout; a login from an unexpected country is flagged as suspicious and may require approval. This is the logging and monitoring NIS2 expects under 'incident handling', without a separate tool.

The login log with IP, country and result per sign-in
4

Recovery: encrypted backups

Under Backup you enable daily AES-256 encrypted backups of files, email, calendars, contacts, chat and the governance logs, with retention for daily and weekly copies. Only you know the key. You restore yourself, without a vendor: that is the business continuity the framework asks for, and which you must also be able to test.

The backup configuration with frequency, data types and encryption key
5

Reporting: evidence chain to your SIEM

Under Gebeurtenissen (events) is every policy action, hash-chained and anchored daily. Export as CEF for your SIEM or that of your inter-municipal body, or as CSV and JSON for the auditor or the CCB. In an incident you reconstruct in minutes who did what, which NIS2 expects within 24 hours for the early warning and within 72 hours for the notification.

The event log with the export buttons CEF, CSV and JSON
6

Mobile policy

Under Mobiel (mobile) you define what the Canvos app does on employees' phones and tablets. Today screen protection is enforced: no screenshots or screen recordings of your data. Biometric unlock, copy-and-paste restriction and automatic locking are already passed to the app and will be enforced in a next version of the app. The policy is fetched at sign-in and also applies on private devices.

The mobile policy with screen protection and biometric unlock
7

Retention according to archive law

Under Retentiebeleid (retention policy) you set how long email, recycle bin, versions and the audit log are kept. For public bodies the archive decree and selection lists apply; keep the audit log at least one year, preferably two, so last year's incident can still be reconstructed. Retention runs automatically and is itself logged.

The retention policy with the retention period for the audit log
What this means for you. NIS2 and CyberFundamentals are not an IT project but a burden of proof. Canvos puts the framework's basic measures in one workplace, on by default, and produces the evidence while you work: a score, a log, a chain, an export. Because everything runs on a European server of a Belgian provider, you also meet the sovereignty expectation that the CCB and the Flemish and federal governments state ever more explicitly. And because no separate tools are needed, it is feasible for an administration with half an IT person.

FAQFrequently asked questions

Does Canvos replace a CyberFundamentals certification?

No. CyFun Basic, Important and Essential are frameworks with a self-assessment or verification by an accredited body. Canvos covers a large part of the technical measures for your office environment and delivers the evidence; policy, awareness and the rest of your IT landscape remain your responsibility.

How does this help with the 24 and 72 hour notification duty?

The evidence chain and the login log give you the facts within minutes: which accounts, which files, which actions. That is exactly what you need for the early warning within 24 hours and the incident notification within 72 hours to the CCB.

Can our inter-municipal body or IT partner collect the logs centrally?

Yes. The CEF export connects to common SIEM solutions. Real-time alerts and the monthly report go to the addresses you set, also outside your organisation.

Where is the data?

On infrastructure in Europe, managed by Canvos from Belgium, without a US parent company. There is no route through which a foreign government can force access via the CLOUD Act.

Is this also suitable for a small welfare office or a school?

Yes. The measures are on by default and require no own servers or security specialist. The guide for SMEs without an IT department shows the same workplace from that perspective.

Related guidesRelated guides

Want to try it yourself?

Book a 20-minute demo, or set up your workspace today.

Book a demo