CyFun

Achieve CyFun Compliance Faster and Smarter

CyberFundamentals (CyFun), developed by the Centre for Cybersecurity Belgium (CCB), is the Belgian reference framework for implementing cybersecurity best practices and supporting compliance with the NIS2 Directive. Secrato brings CyFun to life by providing automation, evidence management, real-time monitoring, and cross-framework control mapping, enabling organisations to manage cybersecurity efficiently while demonstrating compliance with confidence.

Accelerate CyFun Compliance with Automation

Secrato simplifies CyFun adoption through automation, pre-mapped controls, and centralised workflows. Designed to eliminate blind spots across your controls, our platform ensures you meet baseline cybersecurity requirements with speed, precision, and audit-ready transparency. Whether you are preparing for NIS2, Cyber Essentials, or ISO 27001, Secrato makes compliance seamless and scalable.

 

Automated Evidence Collection

Automate CyFun compliance tasks with Secrato. Integrations across your IT stack and pre-built controls enable effortless evidence collection in real time. No screenshots or spreadsheets — just a single source of truth for audits and continuous compliance.

Continuous Monitoring and Cross-Mapped Controls

Secrato continuously monitors CyFun controls to provide real-time visibility into your security posture. Already aligned with ISO 27001, SOC 2, GDPR or any other compliance requirement? Our cross-framework mapping eliminates duplication by reusing evidence and controls across frameworks, accelerating compliance and reducing administrative overhead.

Framework Library
Every major framework, ready to use.

Natively supports the frameworks that matter most to European enterprises — ISO 27001, NIS2, CYFUN, GDPR, CRA, and more — with continuous coverage expansion.

Control Management
Define once. Apply across every framework.

Map, tag, group, and manage controls across frameworks in a structured environment — eliminating duplication and keeping governance consistent at scale.

Assessments Engine
Evaluate status, track readiness.

Run Y/N and maturity-based assessments (0–3, 0–5, or custom) across multiple frameworks simultaneously — without managing each one in isolation.

Evidence Management
Attach once, validate everywhere.

Manage evidence through manual uploads and automated API-based collection. Secrato recognises where evidence satisfies requirements across frameworks automatically.

Policy Linking & Versioning
Full traceability from policy to control.

Link policies directly to controls and requirements with version control for full traceability — keeping governance connected from documentation to execution.

API & Integrations
Connect your entire compliance ecosystem.

Connect with internal and external systems — Microsoft 365, cloud platforms, security tools, and more — to support smoother, more reliable evidence automation across all frameworks.

Secrato