Basic and Important
Verification of the organization’s self-assessment and declared maturity under the CyFun scheme and ISO/IEC 17029. Unsupported scores are reassessed; material misstatements can lead to rejection of the claim.
Portal loginCyFun — coming Q1 2027
CyFun is Belgium’s CyberFundamentals framework. Complade’s service is in preparation and is not yet available.
The Centre for Cybersecurity Belgium’s CyberFundamentals framework provides concrete measures to improve organizational cyber resilience. It is a distinct programme from CyberSecure Canada and ISO/IEC 27001.
Read the official CCB information
You do not need to wait for the European office or the CyFun launch. Complade Canada Inc. accepts international ISO/IEC 27001 audit applications now within its SCC-accredited scope. Scope, language and audit feasibility are confirmed during application review.
CyFun service launch is targeted for Q1 2027, subject to completing readiness steps and applicable approvals. No CyFun service is currently offered.
The route depends on the assurance level. The organization prepares its self-assessment; an independent conformity assessment body evaluates the evidence. The self-assessment guides the work but does not prove conformity on its own.
Verification of the organization’s self-assessment and declared maturity under the CyFun scheme and ISO/IEC 17029. Unsupported scores are reassessed; material misstatements can lead to rejection of the claim.
Certification under the CyFun scheme and ISO/IEC 17021-1. Auditors assess implemented measures, their effectiveness and the evidence behind maturity scores. This is a CyFun audit, with its own requirements and assessment method.
Identify the systems, services, locations and activities covered. Complete the applicable CyFun self-assessment and gather evidence supporting each declared maturity score.
The auditor checks the consistency and support for your scores, documented management controls and available evidence. Findings determine readiness, priorities and the Stage 2 audit plan.
The auditor evaluates how measures operate in practice, including key measures and management controls. Records, interviews and operational evidence must support the self-assessment; policies alone are not enough.
Required maturity thresholds must be met. Major nonconformities must be resolved and closed; action plans for minor nonconformities must be accepted, or the findings closed, before a positive certification decision. A sufficient score alone does not secure certification.
Keep the self-assessment current. Surveillance reviews changes, maturity, key measures and all specified management controls, together with certificate and mark use. Surveillance takes place at the client’s premises. Recertification reviews continued effectiveness and improvement and includes an on-site audit.
Prepare records that show both how controls are defined and how they operate. Examples include:
Complade’s SCC-accredited ISO/IEC 27001 certification audits are available now for international applicants. An implemented ISMS can provide relevant governance, risk, internal audit and management review evidence for a later CyFun assessment. The applicable CyFun measures and maturity requirements still need to be addressed.
The Belgian scheme also provides a route based on an accredited ISO/IEC 27001 certificate, with a suitable scope and Statement of Applicability. Eligibility and acceptance are determined by the CCB under the applicable rules. An ISO certificate does not automatically issue a CyFun certificate or label, and Complade’s ISO 27001 accreditation does not itself authorize CyFun assessment.
After the relevant conformity assessment, eligible organizations apply to the CCB through Safeonweb@work for the CyFun label. The CCB reviews eligibility and issues the label and associated QR code. Complade does not issue the CCB label.
Accredited ISMS certification for organizations operating internationally.
Accredited certification against Canada’s cybersecurity standard.
Planned CyFun service, subject to the required accreditation and scheme authorization. The authorized levels and scope will be confirmed before launch.
Process summary based on the CyFun CAS Clarifications dated 14 September 2026, particularly Topics 2–4. That document forms part of the scheme; newly introduced or amended rules generally apply two months after publication unless otherwise specified. Confirm the applicable scheme version when planning an assessment.
Official CyFun scheme and clarifications · CyFun in Belgium
The flags identify geographic context. CyFun is not presented here as an EU-wide certification or an EU endorsement.
Canada and Europe
We help Canadian organizations operating in Europe and European organizations operating in Canada with independent certification. Accredited ISO/IEC 27001 certification audits are available now, internationally. CyberSecure Canada supports Canadian cybersecurity needs; Complade’s CyFun service is planned for Q1 2027.
Regional office planned in Brussels, Belgium
Planned local audit support in French and Dutch.
CyFun is Belgium’s CyberFundamentals framework. Complade’s service is in preparation and is not yet available.