NIS2 Self-Certification: Does It Exist? Belgium Says Yes — Most of the EU Says No
Short answer: no, not at EU level. Nothing in Directive (EU) 2022/2555 lets an organisation sign a form, tick a box, and call itself “NIS2 self-certified.” But that answer is less useful than it sounds, because the directive deliberately left the door open for member states to build their own evidence schemes — and one of them, Belgium, walked through it. This article separates what NIS2 actually requires from what compliance vendors market as “self-certification,” and maps the real options: Belgium’s CyFun, ISO 27001, the EU’s still-unfinished cloud certification scheme, and what’s coming next.
Does NIS2 Have an Official Self-Certification Scheme?
Article 21 of the directive — the operative provision that actually obliges essential and important entities to act — never mentions certification, self-certification, or any form of formal sign-off. It requires “appropriate and proportionate” technical, operational, and organisational measures across ten categories: risk analysis, incident handling, business continuity, supply chain security, secure development, effectiveness assessment, cyber hygiene and training, cryptography, access control, and multi-factor authentication.[1] Compliance is demonstrated through documentation and, when a competent authority asks, an audit — not through a certificate you obtain once and file away.
Certification enters the picture in a different article. Article 24 says member states may require entities to use ICT products, services, or processes that are certified under a European cybersecurity certification scheme — and separately, that member states shall encourage (not require) the use of qualified trust services.[2] That “may,” not “shall,” is the whole story: certification is a tool national governments are permitted to reach for, not a baseline every entity must clear. The European Commission can eventually make it mandatory for specific entity categories through a delegated act, but only after it identifies “insufficient levels of cybersecurity” in a sector — and any such act must include an implementation period before it bites.[2] No such delegated act has been issued as of this writing.
Self-Assessment, Self-Certification, and Third-Party Certification Are Not the Same Thing
Search “NIS2 self-assessment” and you’ll land on a dozen vendor tools — free quizzes that estimate whether you’re in scope. Search “NIS2 self-certification” and most of those same vendors reuse the term loosely, as if filling out their questionnaire were equivalent to a compliance claim a regulator would accept. It isn’t, and conflating the two is the single most common error we see in how this topic gets covered. Three distinct things share the word “self”:
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
- Self-identification (scoping) — determining whether you’re an essential or important entity at all. This is a prerequisite, not evidence of compliance.
- Self-assessment against a control framework — evaluating your own maturity against a published set of controls and documenting the result. This produces internal evidence, but its weight depends entirely on whether a competent authority or scheme recognises the framework you used.
- Third-party certification — an accredited external body verifies your controls and issues a certificate. This is what most people mean by “certification” in every other regulatory context, and it’s what ISO 27001 and the EU’s adopted cybersecurity schemes actually are.
“Self-certification” in the strict sense — a self-assessment that a government body formally accepts as sufficient evidence, with no external verification required at the entry tier — turns out to be rare. In reviewing the frameworks published by four of the largest implementing states, we found exactly one that runs this way end to end.
Belgium’s CyFun: The EU’s Clearest Self-Assessment Pathway
The Centre for Cybersecurity Belgium (CCB) runs CyberFundamentals (CyFun) — a tiered control framework aligned to NIST CSF 2.0, restructured in its 2025 update into six functions, 22 categories, and 106 subcategories.[6] It is, as far as we could establish, the only framework in the EU where a government cybersecurity authority has built a formal, tiered self-assessment pathway and explicitly recognises the output as evidence toward NIS2 obligations.
| Assurance level | Approx. control count | Typical fit | Verification required? |
|---|---|---|---|
| Small | Lightweight baseline | Micro-organisations, no dedicated IT staff | Self-assessment only |
| Basic | 34 controls | Lower-risk important entities | Self-assessment; verification optional |
| Important | ~133 controls (cumulative) | Standard important entities | Self-assessment, verification often expected |
| Essential | ~217 controls (cumulative) | Essential entities, critical infrastructure | Verification/certification by an accredited body |
The process runs in three steps: a selection tool assigns the appropriate level based on sector and risk exposure, a self-assessment against that level’s control set follows, and — depending on the level and entity type — a verification or certification step by an accredited Conformity Assessment Body closes it out.[6] For essential entities, the CCB’s expectation is Basic or Important level implementation by April 2026, with full Essential-level coverage by April 2027.[6] Holding an ISO 27001 certificate doesn’t force you to start from zero, either: the CCB accepts ISO 27001 evidence for a CyFun label where the controls are properly mapped.[6][5] What CyFun does not do is act as a complete substitute for NIS2 compliance on its own — incident notification procedures under the 24-hour/72-hour/one-month timeline still have to be built and documented separately, label or no label.[6]
Why France and Germany Don’t Offer the Same Thing
It’s tempting to assume every member state runs something CyFun-shaped, since France and Germany both use language like “self-assessment” in their onboarding guidance. They don’t — and the difference matters if you operate across borders.
France’s ANSSI runs registration through the MesServicesCyber platform. An entity self-assesses whether it falls into scope — essential or important, based on sector and size thresholds — and registers accordingly.[7] That’s a scoping exercise, not a compliance self-certification. Ongoing compliance is demonstrated through an internal “conformity analysis” per information system, reviewed and updated over time, that ANSSI can inspect through supervisory audits — there’s no submitted self-certification document that closes the loop the way a CyFun label does.[7]
Germany’s amended BSI Act works the same way. Registration opened via the BSI’s new portal on 6 January 2026, and — in the BSI’s own framing — “there is no individual notification by the authorities; entities must determine and document their status themselves.”[8] Beyond that self-determined scoping, entities must be able to demonstrate their risk analyses, implemented measures, and the effectiveness of those measures on request.[8] Again: audit-readiness, not a self-certification submission.
The Netherlands sits in between. A privately run “NIS2 Quality Mark” (QM10/QM20/QM30) has emerged from the compliance-services market — not a government scheme — and it combines a self-assessment (a documented basic risk analysis) with a mandatory remote audit by a certified third-party auditor before the mark is issued.[9] That third-party step is exactly the piece CyFun’s Small and Basic tiers let you skip.
ISO 27001: The De Facto Evidence Auditors Actually Accept
One practical detail gets missed in most compliance guidance: an ISO 27001 certificate is only as strong as the accreditation body behind it. National accreditation bodies (UKAS, DAkkS, COFRAC and their equivalents) publish registers of accredited certification bodies — a certificate issued by a body outside that register carries far less weight with a competent authority than one that is. Before treating an existing ISO 27001 certificate as your NIS2 evidence base, confirm the certifying body appears on your national accreditation register, not just that the certificate exists.
Outside Belgium’s specific framework, ISO/IEC 27001 certification is the closest thing to a universally recognised compliance signal across NIS2 jurisdictions — not because the directive names it, but because auditors and national authorities consistently treat a current ISO 27001 certificate as strong supporting evidence for Article 21’s risk-management and access-control measures. Practitioner analysis puts the overlap at roughly 60–80% of NIS2’s requirements.[5] The gap sits in three places: NIS2’s 24-hour/72-hour incident notification timeline has no equivalent in ISO 27001’s incident-management clause; Article 20’s requirement that the management body itself approve and oversee cybersecurity measures needs its own documented sign-off trail, which a generic ISMS certificate doesn’t automatically produce; and NIS2 audits increasingly expect current, continuously updated evidence rather than the point-in-time snapshot an annual ISO surveillance audit provides.[5] A few national authorities — ANSSI in France and BaFin in Germany among them — layer additional local-language documentation requirements on top of an ISO certificate rather than accepting it as-is.[5] Treat ISO 27001 as a strong accelerant, not a finish line.
The Cloud Wildcard: EUCS Isn’t Live Yet
If your organisation is evaluating a cloud provider’s security posture, you may have been told to look for an “EUCS certificate.” As of 2026, you won’t find one that means anything under EU law. The European Cybersecurity Certification Scheme for Cloud Services (EUCS) — the scheme meant to give cloud providers an EU-recognised way to certify security levels (basic, substantial, high) under the Cybersecurity Act — remains in candidate/draft status.[4] It was first drafted in 2020 and has stalled repeatedly over disputes about data-sovereignty requirements for non-EU cloud providers.[4] The only EU cybersecurity certification scheme formally adopted to date is EUCC, approved in January 2024 — and it covers ICT hardware and software products (chips, smartcards, components), not cloud services at all.[3] If a vendor markets an “EUCS-certified” cloud offering today, ask precisely which scheme they mean; there is currently nothing to certify against at EU level.
What’s Coming: A Proposed EU-Wide “Basic” Self-Assessment Tier
A revision to the Cybersecurity Act currently under discussion would formalise three assurance levels across future EU certification schemes — basic, substantial, and high — with “basic” conformity assessable through self-assessment for lower-complexity cases, while substantial and high levels would still require an accredited Conformity Assessment Body.[10] The same proposal floats letting certified essential entities skip some targeted security audits.[10] This is not adopted law, and no timeline for entry into force has been confirmed — treat it as a signal of direction, not a compliance option you can rely on today. If it proceeds broadly as proposed, it would effectively extend a CyFun-style entry tier EU-wide rather than leaving Belgium as the outlier.
Decision Tree: Which Path Fits Your Organisation
Cut through the options with four questions, in order:
- Are you established and registered in Belgium? If yes, CyFun is the most direct path — start with the Selection Tool to determine your assurance level, and lean on an existing ISO 27001 certificate if you have one to shortcut the mapping.
- Do you already hold, or are you pursuing, ISO 27001 certification? If yes, treat it as your evidence backbone everywhere else in the EU, then close the three gaps above — incident-notification timelines, Article 20 board sign-off, and continuous (not annual) evidence — with NIS2-specific documentation.
- Are you a cloud service provider, or evaluating one? Don’t wait for EUCS. Build your evidence trail against Article 21 directly; treat any current “EUCS” marketing claim with scepticism until the scheme is formally adopted.
- None of the above? Start with your national competent authority’s registration/scoping process (equivalent to France’s MesServicesCyber or Germany’s BSI portal), then build a documented risk assessment, treatment plan, and management-body approval record — the same evidentiary core every scheme above ultimately asks for, self-certified or not.
Frequently Asked Questions
Can I just fill out a form and call my company “NIS2 self-certified”?
No. There is no EU-recognised self-certification form. What you can do is complete a documented self-assessment against a recognised framework — CyFun in Belgium, or ISO 27001 more broadly — and keep the evidence ready for when a competent authority asks.
Does an ISO 27001 certificate mean I’m NIS2-compliant?
No, though it covers a substantial share of the ground. It’s strong supporting evidence, not a substitute for NIS2’s specific incident-notification timelines and management-body accountability documentation.[5]
Is CyFun only for Belgian companies?
The framework and its control set are published in the open, so any organisation can use it as a self-assessment structure. Formal recognition as NIS2 evidence, however, is a Belgian mechanism run by the CCB — check with your own competent authority before assuming it carries the same weight elsewhere.[6]
Should I wait for the proposed EU-wide “basic” self-assessment tier?
No. It is a proposal under discussion, not adopted law, with no confirmed entry-into-force date.[10] Build your compliance evidence now against Article 21 and, where relevant, ISO 27001 or CyFun — you can layer a future scheme on top later.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS 2 Directive, Article 21 — Cybersecurity risk-management measures. nis2resources.eu
- NIS 2 Directive, Article 24 — Use of European cybersecurity certification schemes. nis-2-directive.com
- ENISA — An EU Prime! EU adopts first Cybersecurity Certification Scheme (EUCC, 31 Jan 2024). certification.enisa.europa.eu
- ENISA — EUCS: Cloud Services Scheme (candidate status). enisa.europa.eu
- ISMS.online — Does ISO 27001 Certification Guarantee NIS 2 Compliance? Evidence vs. Assurance. isms.online
- NIS Institute — CyFun 2025: Belgium’s Updated Framework for NIS2 Readiness. nisinstitute.eu
- ANSSI — NIS 2 registration, MesServicesCyber (official French competent authority). messervices.cyber.gouv.fr
- NISD2.eu — NIS2 in Germany: Deadlines, Fines & BSIG Guide. nisd2.eu
- Normsupport — NIS2 QM10 Quality Mark. normsupport.nl
- Reed Smith — Proposed amendments to NIS2: Cybersecurity certification schemes. reedsmith.com
Related reading: NIS2 vs ISO 27001 · NIS2 readiness check · Belgium NIS2 penalties and enforcement · Does NIS2 apply to me?
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
