The CyberFundamentals (CyFun®) Framework Training is delivered as an intensive one-day programme from 09:00 to 17:00. The programme combines framework knowledge with exercises and a practical implementation workshop, enabling participants to apply the methodology to organisational scope, risks, controls, evidence and priorities.
Module 1 – Understanding the CyberFundamentals Framework
- Introduction to the CyberFundamentals Framework
- Structure of the framework
- Functions, categories and subcategories
- Controls, requirements and implementation guidance
- Positioning CyFun® within the NIS2 context
- Relationship with other cybersecurity frameworks and standards
Outcome: Participants understand how CyFun® is structured and how the framework can be used to translate NIS2 cybersecurity requirements into a practical approach.
Module 2 – Selecting the Appropriate Assurance Level
- Understanding the CyFun® assurance levels
- Basic
- Important
- Essential
- Framework selection
- Organisational scope and risk considerations
- Using the CyFun® selection tools
Outcome: Participants learn how to determine the appropriate CyFun® assurance level based on the organisation's context and cybersecurity requirements.
Module 3 – Controls, Measures & Evidence
- Translating CyFun® controls into technical measures
- Translating CyFun® controls into organisational measures
- Identifying documentation requirements
- Identifying appropriate evidence
- Key measures and implementation expectations
- Using mappings to support implementation
Outcome: Participants learn how to move from framework requirements to concrete measures and how to demonstrate that these measures have actually been implemented.
Module 4 – Self-Assessment & Cybersecurity Maturity
- Using the CyFun® self-assessment tools
- Assessing current cybersecurity maturity
- Understanding maturity scoring
- Identifying gaps
- Interpreting assessment results
- Translating assessment findings into priorities
Outcome: Participants gain the skills to perform a CyFun® self-assessment and use the results to identify and prioritise cybersecurity improvements.
Module 5 – Conformity Assessment & ISO/IEC 27001
- Self-assessment
- External verification
- Certification
- Understanding the differences between assessment approaches
- Role of Conformity Assessment Bodies (CABs)
- Relationship between CyFun® and ISO/IEC 27001
- Preparing the organisation for conformity assessment
Outcome: Participants understand the available approaches for demonstrating conformity and what organisations need to prepare when moving towards external verification or certification.
Module 6 – Building Your CyFun® Implementation Roadmap
- Translating gaps into implementation actions
- Prioritising cybersecurity measures
- Defining practical next steps
- Connecting scope, risks, controls and evidence
- Building a structured implementation roadmap
- Practical implementation workshop
Outcome: Participants leave the training with a methodology for transforming CyFun® assessment results into a realistic and prioritised cybersecurity implementation roadmap.