Your NIS2 journey
Have your measures assessed at the selected CyFun® level. The applicable level depends on your circumstances and risk assessment.
CYBERFUNDAMENTALS · BASIC & IMPORTANT
Have your cybersecurity maturity independently verified against CyberFundamentals. What a Work carries out CyFun® Basic and Important audits as part of your NIS2 compliance journey or a voluntary assessment.
Audits and reports in French, English and Dutch.
YOUR NEEDS
Independent verification for organisations seeking an assessment of their cybersecurity measures.
Have your measures assessed at the selected CyFun® level. The applicable level depends on your circumstances and risk assessment.
Provide an independent verification outcome to customers and partners requesting evidence about your cybersecurity.
Have your maturity level verified even if your organisation does not fall directly within the scope of NIS2.
THE PROCESS
We review your scope, intended level and the feasibility of the engagement.
We agree on the audit plan and the evidence to be provided.
We examine your documents and evidence of implemented measures.
An independent review precedes the decision and communication of the conclusions.
FAQ
NIS2, certification, verification: find useful explanations in our FAQ.
Read the full FAQNIS2 is an EU directive strengthening cybersecurity requirements for certain organisations. In Belgium, its transposition includes risk-management measures, incident reporting and management responsibilities. The obligations depend on the organisation’s circumstances.
Directive (EU) 2022/2555 — NIS2 CCB — NIS2 Direct linkUnder the CyFun® scheme, Basic and Important are subject to verification, while Essential is subject to certification. What a Work offers Basic and Important verification. A verification statement issued following a favourable decision must not be presented as an Essential certificate.
CyberFundamentals — CyFun® CyFun® — Authorised conformity assessment bodies Direct linkIt helps demonstrate the measures assessed, but does not cover every NIS2 obligation by itself. Incident reporting, governance and other applicable duties still need to be met. The assurance level must match your circumstances; Basic verification does not replace Essential certification where required.
Directive (EU) 2022/2555 — NIS2 CCB — NIS2 Direct linkWHAT A WORK
Tell us your intended level, scope and preferred language. We will review your request.