There are many cybersecurity frameworks out there. But CyFun® (CyberFundamentals Framework) has one characteristic that we find particularly interesting.
It takes a widely recognised framework, the NIST Cybersecurity Framework, and turns it into something much more directly assessable and, importantly, auditable.
For anyone working in GRC, that distinction matters.
Building on NIST CSF without simply copying it
The relationship between the two frameworks is clear.
CyFun® largely follows the structure and logic of the NIST CSF, using Functions, Categories and Subcategories. The 2025 version is now aligned with NIST CSF 2.0.
But CyFun® is not simply a copy of NIST CSF.
The framework has been adapted and complemented with elements from other recognised standards and good practices, including ISO 27001/27002, CIS Critical Security Controls (ETSI TR 103 305-1) and IEC 62443.
Some elements have been added, others reformulated or reorganised. CyFun® 2025 also strengthens areas such as governance, supply-chain security and OT, while explicitly improving the clarity and auditability of its controls.
And this is where, in our view, CyFun® becomes particularly interesting.
From a reference framework to an auditable framework
NIST CSF is primarily designed to help organisations understand and improve how they manage cybersecurity risk.
It provides an excellent structure for defining cybersecurity outcomes and organising a cybersecurity programme.
CyFun® keeps that logic but adds a much more concrete assessment mechanism.
The question is no longer simply:
“Have we addressed this?”
It also becomes:
“How well have we documented it?”
and:
“How well have we actually implemented it?”
CyFun® therefore distinguishes between two important dimensions:
Policy Maturity — to what extent do the organisation’s documented policies, rules and procedures address the requirement?
Implementation Maturity — to what extent is the requirement actually implemented in the organisation’s day-to-day practices?
This may sound like a relatively simple distinction.
But it makes a significant difference.
An organisation can have a beautifully written policy that nobody actually follows.
Conversely, it can have very good operational practices that depend on the knowledge and habits of a few individuals, without those practices being properly documented or institutionalised.
CyFun® makes the gap between what is written and what is actually done visible.
And the calculation remains deliberately simple
Another aspect we like is that CyFun® does not hide the assessment behind an overly complex scoring formula.
Each control can be assigned a maturity score from 1 to 5, for both Policy Maturity and Implementation Maturity.
The five levels range from:
1 — Initial
to
5 — Optimizing
At Subcategory level, the scores of the underlying controls can then be averaged separately for Policy and Implementation maturity.
Those results can in turn be aggregated to provide a broader view at Category level.
In other words, behind the dashboards and visualisations, the basic principle remains remarkably straightforward:
add the scores and divide by the number of assessed elements.
Simple.
Transparent.
Easy to understand for both the auditor and the auditee.
And structured enough to turn an assessment into something measurable and repeatable.
That is probably what I like most about CyFun®
CyFun® does not try to reinvent cybersecurity.
It starts with an extremely solid foundation (NIST CSF) adapts it, and complements it with other recognised standards and good practices.
But more importantly, it adds something essential:
a way to move from a framework describing what an organisation should do to a framework that can assess what the organisation is actually doing - and how mature that implementation is.
And the approach goes beyond self-assessment. CyFun® also has a Conformity Assessment Scheme, creating a path towards independent verification and certification.
That progression is what we find particularly compelling:
Framework → Assessment → Audit
Because ultimately, in cybersecurity and GRC, knowing what you should be doing is one thing.
Being able to demonstrate what you are actually doing is another.
