ISMS Compliance

Maturity Roadmap

Strategic progression from CyFun Basic to ISO 27001 certification

Overview

This roadmap documents our deliberate, multi-year progression through the Belgian CyberFundamentals framework levels toward ISO 27001 certification. Each phase builds on the previous one, scaled to organisational maturity and focused on effective security outcomes.

Strategic Rationale

PhaseFrameworkBusiness OutcomeWhy
1CyFun BasicBaseline hygieneBelgian CCB minimum requirements
2CyFun ImportantCustomer trustDemonstrate maturity to enterprise clients
3CyFun EssentialRegulatory readinessNIST CSF alignment, NIS2 preparedness
4ISO 27001CertificationFormal third-party validation

Current Status

MetricValue
Framework levelCyFun Basic
Total controls34
Controls documented34
Controls implemented0
Controls partial34
ISMS siteOperational

Roadmap Phases

Phase 1: CyFun Basic (2026) — In Progress

Objective: Achieve full CyFun Basic compliance by implementing all 34 controls with supporting policies, evidence, and procedures.

Key Deliverables

DeliverableTargetStatus
ISMS documentation siteQ1 2026Complete
34 control pages documentedQ1 2026Complete
Security policies draftedQ2 2026In Progress
Evidence pages populatedQ2 2026In Progress
Priority controls (key measures) to "implemented"Q4 2026Planned
All 34 controls to "implemented"Q4 2026Planned

Success Criteria

  • All 34 CyFun Basic controls at "implemented" status
  • All policies approved and published with review dates set
  • Evidence pages verified and up to date
  • Incident response plan tested via walkthrough
  • Risk register reviewed quarterly

Dependencies

  • Management commitment (allocated time for security tasks)
  • Tooling decisions finalized (monitoring, access management)

Phase 2: CyFun Important (2027) — Planned

Objective: Extend coverage to CyFun Important level, adding controls for enhanced protection and structured risk management.

Key Deliverables

DeliverableTargetStatus
Gap analysis: Basic → ImportantQ1 2027Planned
Additional Important-level controls documentedQ2 2027Planned
Enhanced access control (MFA everywhere, PAM)Q2 2027Planned
Structured risk assessment methodologyQ3 2027Planned
Incident response tabletop exerciseQ3 2027Planned
Vulnerability management processQ4 2027Planned

Success Criteria

  • All CyFun Important controls at "implemented" status
  • Risk assessment completed with documented methodology
  • At least one IR tabletop exercise conducted and lessons documented
  • Vulnerability scanning running on a scheduled basis
  • Security awareness training completed by all team members

Dependencies

  • Phase 1 (CyFun Basic) fully complete
  • Budget allocation for additional tooling

Phase 3: CyFun Essential (2028) — Planned

Objective: Achieve CyFun Essential compliance with continuous monitoring, supply chain risk management, and security metrics.

Key Deliverables

DeliverableTargetStatus
Gap analysis: Important → EssentialQ1 2028Planned
Continuous monitoring implementationQ2 2028Planned
Supply chain risk management processQ2 2028Planned
Security metrics dashboardQ3 2028Planned
Full NIST CSF alignment verificationQ4 2028Planned

Success Criteria

  • All CyFun Essential controls at "implemented" status
  • Continuous monitoring operational with alerting
  • Supply chain risks documented and mitigated for critical vendors
  • Security metrics reported quarterly to management
  • Full NIST CSF mapping validated

Dependencies

  • Phase 2 (CyFun Important) fully complete
  • Monitoring infrastructure in place

Phase 4: ISO 27001 Certification (2029) — Planned

Objective: Obtain ISO 27001:2022 certification through formal audit by an accredited certification body.

Key Deliverables

DeliverableTargetStatus
Risk assessment per ISO 27005Q1 2029Planned
Statement of Applicability (SoA)Q1 2029Planned
Internal audit program establishedQ2 2029Planned
Management review conductedQ2 2029Planned
Stage 1 audit (documentation review)Q3 2029Planned
Stage 2 audit (implementation assessment)Q4 2029Planned

Success Criteria

  • Statement of Applicability covers all Annex A controls
  • Internal audit completed with findings resolved
  • Management review documented with decisions recorded
  • Stage 1 audit passed without major nonconformities
  • ISO 27001:2022 certificate obtained

Dependencies

  • Phase 3 (CyFun Essential) fully complete
  • Budget for certification body engagement
  • Internal audit competency (training or external auditor)

Phase Dependencies

PhaseEnablesKey Enabler
1. CyFun BasicPhase 2Documented ISMS, baseline controls, operational policies
2. CyFun ImportantPhase 3Structured risk management, enhanced controls, IR capability
3. CyFun EssentialPhase 4Continuous monitoring, metrics, full NIST CSF alignment
4. ISO 27001OngoingCertified ISMS with continual improvement cycle

On this page