ISMS Compliance

Maturity Roadmap

Strategic progression from CyFun Basic to ISO 27001 certification

Overview

This roadmap documents our accelerated progression through the Belgian CyberFundamentals framework levels toward ISO 27001 certification by Q1 2027. Each phase builds on the previous one, with parallel workstreams to meet the aggressive timeline.

Strategic Rationale

PhaseFrameworkTargetBusiness Outcome
1CyFun BasicQ2 2026Belgian CCB minimum requirements
2CyFun Important + EssentialQ3 2026Customer trust, NIS2 preparedness
3ISO 27001Q1 2027Formal third-party certification

Current Status

MetricValue
Framework levelCyFun Basic
Total controls33
Controls documented33
Controls implemented15
Controls partial16
Controls planned2
ISMS siteOperational

Roadmap Phases

Phase 1: CyFun Basic (Q1–Q2 2026) — In Progress

Objective: Achieve full CyFun Basic compliance by implementing all 33 controls with supporting policies, evidence, and procedures.

Key Deliverables

DeliverableTargetStatus
ISMS documentation siteQ1 2026Complete
33 control pages documentedQ1 2026Complete
Security policies draftedQ2 2026In Progress
Evidence pages populatedQ2 2026In Progress
Priority controls (key measures) to "implemented"Q2 2026In Progress
All 33 controls to "implemented"Q2 2026Planned

Success Criteria

  • All 33 CyFun Basic controls at "implemented" status
  • All policies approved and published with review dates set
  • Evidence pages verified and up to date
  • Incident response plan tested via walkthrough
  • Risk register reviewed quarterly

Dependencies

  • Management commitment (allocated time for security tasks)
  • Tooling decisions finalized (monitoring, access management)

Phase 2: CyFun Important + Essential (Q3–Q4 2026) — Planned

Objective: Extend coverage to CyFun Important and Essential levels in parallel, adding controls for enhanced protection, structured risk management, continuous monitoring, and supply chain security.

Key Deliverables

DeliverableTargetStatus
Gap analysis: Basic → Important + EssentialQ3 2026Planned
Additional controls documented and implementedQ3 2026Planned
Enhanced access control (MFA everywhere, PAM)Q3 2026Planned
Structured risk assessment methodology (ISO 27005)Q3 2026Planned
Continuous monitoring and alertingQ3 2026Planned
Incident response tabletop exerciseQ4 2026Planned
Vulnerability management processQ4 2026Planned
Supply chain risk management processQ4 2026Planned
Security metrics dashboardQ4 2026Planned
Full NIST CSF alignment verificationQ4 2026Planned

Success Criteria

  • All CyFun Important and Essential controls at "implemented" status
  • Risk assessment completed with documented methodology
  • At least one IR tabletop exercise conducted and lessons documented
  • Vulnerability scanning running on a scheduled basis
  • Continuous monitoring operational with alerting
  • Supply chain risks documented and mitigated for critical vendors
  • Security awareness training completed by all team members

Dependencies

  • Phase 1 (CyFun Basic) fully complete
  • Budget allocation for additional tooling and monitoring infrastructure

Phase 3: ISO 27001 Certification (Q1 2027) — Planned

Objective: Obtain ISO 27001:2022 certification through formal audit by an accredited certification body.

Key Deliverables

DeliverableTargetStatus
Statement of Applicability (SoA)Q4 2026Planned
Internal audit program establishedQ4 2026Planned
Management review conductedQ4 2026Planned
Stage 1 audit (documentation review)Q1 2027Planned
Stage 2 audit (implementation assessment)Q1 2027Planned

Success Criteria

  • Statement of Applicability covers all Annex A controls
  • Internal audit completed with findings resolved
  • Management review documented with decisions recorded
  • Stage 1 audit passed without major nonconformities
  • ISO 27001:2022 certificate obtained

Dependencies

  • Phase 2 (CyFun Important + Essential) fully complete
  • Budget for certification body engagement
  • Internal audit competency (training or external auditor)

Phase Dependencies

PhaseEnablesKey Enabler
1. CyFun Basic (Q2 2026)Phase 2Documented ISMS, baseline controls, operational policies
2. CyFun Important + Essential (Q4 2026)Phase 3Risk management, monitoring, full NIST CSF alignment
3. ISO 27001 (Q1 2027)OngoingCertified ISMS with continual improvement cycle