ISO 27001 or CyFun? What most Belgian SMEs get wrong about NIS2
A question I hear often from Belgian SME owners: “Do I need ISO 27001 to comply with NIS2?”
The honest answer, for most of them, is no. The fuller answer depends on your situation, and this post walks through how to tell which situation you are in.
I covered the baseline NIS2 obligations in my readiness checklist post. This one is more opinionated. I am Gilberto Torres, founder of Gforce Networks, with DPO experience including roles at Essensium and Mind OSS, and 15 plus years in IT. Gforce Networks also published a more neutral comparison of ISO 27001 and CyFun; this post is the personal, direct version of that argument.
Where I stand
For most Belgian SMEs, treating ISO 27001 certification as the default path to NIS2 compliance is the wrong starting point. Certification is expensive, slow, and often aimed at proving a management system exists rather than reducing your actual risk fastest.
CyFun, the Belgian Cyber Fundamentals framework published by the CCB, is the better starting point for most of these organisations. It gives you a tiered set of controls that scales with your risk profile and maps directly onto NIS2 expectations, and it does not require an external certification audit to get started.
That does not make ISO 27001 pointless. It makes it conditional. Consider it when:
- A customer, tender or contract explicitly requires it
- You operate in a sector where certification is the recognised norm (finance, health data processing, defence supply chains)
- You need it to enter a specific market or qualify as a supplier
- You have already built solid practices through CyFun and certification is the next logical step, not the first one
I am not against ISO 27001. I am against treating it as the default answer when it is usually not the fastest or cheapest way to the same outcome.
NIS2 does not mandate a certification
NIS2 asks for risk-management measures that are appropriate and proportionate to your size and the risks you actually face. It does not name ISO 27001, or any other specific standard, as mandatory. You can demonstrate compliance through documented policies, implemented controls, and evidence that you manage risk on an ongoing basis, with or without a certificate on the wall.
CyFun was built with this in mind. The CCB designed it specifically for the Belgian market, as a practical framework that smaller organisations can start using without hiring an external certification body from day one.
The real difference between the two paths
CyFun is a controls framework published by the CCB. You work through the controls that match your risk profile and can show evidence of implementation. It is designed to scale with your organisation rather than demand a fixed audit process from day one.
ISO 27001 is a certified management system. It requires you to build and maintain an Information Security Management System (ISMS), pass an external audit, and go through annual surveillance audits to keep the certificate. It proves, to an external party, that your management system meets an international standard, which matters a great deal when a contract or a market specifically asks for that proof.
Neither path is inherently “more secure.” A well-implemented CyFun programme can protect an organisation better than a box-ticking ISO 27001 certificate pursued only to win a tender. The question is not which framework is superior. It is which one matches what your business actually needs right now.
What the two paths actually involve
It helps to be concrete about what each path asks of your organisation, beyond the labels.
Starting with CyFun typically looks like this: pick the level that matches your risk and sector, work through the control list against what you already have, close the gaps that matter most first, and document what you did. There is no mandatory external audit at the entry level, which means your first results come from implementation, not from paperwork prepared for an assessor.
Pursuing ISO 27001 certification means building a full Information Security Management System: a defined scope, a risk assessment methodology, a Statement of Applicability against the standard’s Annex A controls, internal audits, a management review cycle, and then an external certification audit by an accredited body. Once certified, you keep the certificate through annual surveillance audits and a recertification audit roughly every three years. This is a real, recurring commitment of staff time and external fees, which is exactly why it should be triggered by a genuine business need rather than taken on as a default.
Neither of these descriptions should be read as a cost estimate. Actual costs vary widely by organisation size, scope, and the certification body you choose, and I am not going to put a number on it here that I cannot stand behind. Get a quote from an accredited certification body for your specific scope before you budget for it.
When CyFun is the right call
If none of your contracts or markets require ISO 27001 by name, and you are building security maturity from a limited base, start with CyFun. It lets you:
- Prioritise controls against your real risks instead of a generic standard’s full scope
- Move faster, since there is no external certification audit gating your first results
- Scale your tier up as your risk profile grows, without restarting a certification process
A small logistics company whose main risks are phishing, ransomware and a dependency on a handful of SaaS tools gains more, faster, from implementing the CyFun controls that match its risk profile than from spending a year preparing for an ISO audit that was never going to be asked for.
When ISO 27001 is the right call
Certification earns its cost back when it unlocks something CyFun cannot:
- A specific tender or contract names ISO 27001 as a hard requirement
- You operate in a sector (banking, critical infrastructure, defence supply chains) where the certificate is the expected proof of maturity
- A strategic customer or investor requires third-party certified evidence, not a self-assessment
- You have already matured through CyFun and the next step for your business is external certification, not foundational controls
In those cases, the certification cost is a market-access cost, not a pure security cost, and it should be budgeted and evaluated as such.
Two situations, worked through
Situation one: a 40-person software company builds internal tools for Belgian retailers. No current contract names ISO 27001. The founders worry about ransomware and about a departing employee walking out with customer data. Here, CyFun is the clear answer: implement access control, backups, and an incident response plan against the risk tier that matches the business, and use that work directly to meet NIS2 obligations. Certification would not reduce either of the two actual risks faster than the controls themselves.
Situation two: a 90-person manufacturing supplier wants to qualify for a tender from a larger original equipment manufacturer, and the tender documents explicitly list ISO 27001 certification as a qualifying requirement. Here, the decision is not really about security strategy. It is about whether the contract is worth the certification cost. If it is, certification is the right call, and CyFun controls are a sensible foundation to build the ISMS on top of rather than a competing option.
The difference between the two situations is not the sector or the size. It is whether a named requirement exists. That is the test to apply to your own organisation before assuming either path is the default.
A simple way to decide
Ask these questions, in order:
- Does a current or prospective contract name ISO 27001 explicitly? If yes, you likely need it regardless of the other answers.
- Does your sector treat it as the expected norm? If yes, weigh it seriously even without a named requirement.
- Have you implemented CyFun’s controls for your risk tier yet? If not, do that first. It is the faster route to actually reducing risk and to meeting NIS2’s risk-management expectations.
- Would certification open a market or a customer segment you cannot reach otherwise? If yes, that is a legitimate business case for certification, separate from compliance.
If the answer to all four is no, CyFun is very likely your answer, now and for the foreseeable future.