Skip to content

CyFun 1.0 vs 2.0: What's Changed and What It Means for Your Cybersecurity Program

by Deepak Xavier, chief product officer on

CyFun 1.0 vs 2.0: Why the Evolution Matters

Cybersecurity frameworks cannot remain static.

Threats evolve. Technology environments become more distributed. Supply chains become more interconnected. Regulatory expectations continue to increase. As a result, organizations need cybersecurity programs that can move beyond periodic assessments and provide a more structured approach to managing cyber risk.

That is why the evolution often described as CyFun 1.0 vs 2.0 matters.

For organizations already using CyFun—or planning to adopt it—the transition represents more than a change in documentation. It reflects a broader shift toward:

  • Stronger cybersecurity governance
  • Greater board-level accountability
  • Improved supply chain risk management
  • Better coverage of operational technology
  • Clearer and more auditable controls
  • More practical implementation guidance
  • Greater alignment with modern cybersecurity frameworks and regulations

The latest CyFun framework update was designed to align with NIST Cybersecurity Framework 2.0 and relevant European requirements, including NIS2.

What Is CyFun?

CyFun, or CyberFundamentals, is a structured, risk-based cybersecurity framework designed to help organizations organize, implement, and assess cybersecurity measures.

It provides organizations with a practical way to improve cybersecurity maturity while focusing on measures that help reduce cyber risk and improve resilience.

The framework is based significantly on established cybersecurity practices and has evolved alongside changes in the NIST Cybersecurity Framework. The CyFun 2023 version was based on NIST CSF 1.1, while the newer CyFun 2025 version aligns with NIST CSF 2.0.

This evolution is particularly important for organizations trying to manage cybersecurity alongside multiple compliance requirements.

CyFun 1.0 vs 2.0: The Key Differences

1. Greater Emphasis on Cybersecurity Governance

One of the most significant developments in the newer approach is the stronger focus on governance.

Modern cybersecurity is no longer solely an IT responsibility.

Business leaders, boards, risk teams, compliance professionals, and technology teams all have a role in managing cyber risk.

The updated CyFun framework introduces Governance Measures to better align with modern expectations around cybersecurity oversight and organizational accountability.

This reflects a similar evolution in NIST CSF 2.0, which introduced the Govern function to give cybersecurity governance greater visibility across an organization's risk management strategy.

What this means for organizations

Cybersecurity programs increasingly need to demonstrate:

  • Who owns cyber risk
  • How cybersecurity responsibilities are assigned
  • How risk decisions are governed
  • How policies are communicated
  • How cybersecurity performance is monitored
  • How leadership receives visibility into cyber risk

For compliance teams, this means governance evidence can no longer be treated as an annual audit exercise.

It needs to become part of continuous compliance operations.

2. Better Alignment With NIST CSF 2.0

The newer CyFun framework aligns with the evolution of NIST CSF 2.0.

NIST CSF 2.0 expanded the framework's emphasis on governance and reorganized several cybersecurity outcomes to better reflect modern risk management needs.

This matters because many organizations already use NIST CSF as a reference point for:

  • Cybersecurity strategy
  • Risk management
  • Security controls
  • Supplier risk
  • Incident response
  • Business resilience

Greater alignment can make it easier for organizations to connect CyFun requirements with broader cybersecurity and compliance programs.

The compliance challenge

However, framework alignment alone does not eliminate operational complexity.

Organizations still need to answer questions such as:

  • Which controls satisfy multiple requirements?
  • Where is the evidence for each control?
  • Who owns remediation?
  • Which controls are continuously monitored?
  • What changed since the last assessment?

This is where compliance automation becomes increasingly important.

3. Expanded Focus on Supply Chain Security

Modern organizations depend on an increasingly complex ecosystem of:

  • Cloud providers
  • SaaS applications
  • Managed service providers
  • Technology vendors
  • Third-party developers
  • Data processors
  • Operational partners

As a result, cybersecurity risk increasingly extends beyond the organization's own infrastructure.

The updated CyFun framework expands its focus on supply chain security.

Why this matters

A strong internal security posture does not automatically mean an organization has a strong external risk posture.

Organisations need greater visibility into:

  • Third-party cybersecurity requirements
  • Supplier risk
  • Vendor controls
  • Shared responsibilities
  • Evidence of compliance
  • Ongoing risk changes

The future of compliance management requires organizations to move beyond collecting supplier questionnaires once a year.

Risk needs to be monitored as an ongoing operational process.

4. Increased Attention to Operational Technology

The newer CyFun framework also expands its focus on Operational Technology (OT).

This is increasingly important for organizations operating critical or connected environments such as:

  • Manufacturing
  • Energy
  • Transportation
  • Healthcare infrastructure
  • Government services
  • Critical infrastructure

IT and OT environments have historically operated differently. However, increased connectivity means cyber risk can now move across systems and operational boundaries.

Organizations therefore need cybersecurity programs that provide a broader view of their overall technology environment.

5. Clearer Controls and Better Auditability

One of the practical improvements in the newer CyFun framework is a stronger focus on clarity and auditability.

The updated version reformulates controls and guidance, introduces a specific goal for each control, and provides more comprehensive guidance for interpreting requirements.

This is particularly important because compliance teams often face a major challenge:

Understanding a control is not the same as operationalizing it.

A requirement may appear clear in a framework, but organizations still need to determine:

  • What activities must be performed?
  • Which team owns them?
  • What evidence proves implementation?
  • How frequently should the control operate?
  • How should exceptions be handled?
  • How can auditors validate it?

Better control clarity helps reduce interpretation gaps.

But organizations still need systems and workflows capable of managing those controls at scale.

CyFun 1.0 vs 2.0: A Practical Comparison

Area Earlier CyFun Approach Newer CyFun Approach
Framework alignment NIST CSF 1.1 alignment Greater alignment with NIST CSF 2.0
Governance Embedded cybersecurity management activities Stronger, explicit governance focus
Supply chain More limited emphasis Expanded supply chain security focus
Operational technology Less extensive focus Greater attention to OT environments
Controls Earlier control and guidance structure Improved clarity and auditability
Control understanding General requirements Specific goals for controls
Guidance Existing implementation guidance More comprehensive interpretation guidance
Board oversight Less explicit framework focus Governance Measures supporting stronger oversight

The specific framework updates include alignment with NIST CSF 2.0, supply chain and OT expansion, clearer controls, specific control goals, expanded guidance, and Governance Measures.

What Does the Transition Mean for Compliance Teams?

The transition should not be approached as a simple document update.

Organizations should use it as an opportunity to evaluate how cybersecurity compliance is actually being managed.

Step 1: Review Existing Controls

Identify:

  • Current CyFun controls
  • Control owners
  • Existing evidence
  • Technology dependencies
  • Gaps between implemented and documented controls

Step 2: Map Existing Controls to Updated Requirements

Avoid creating duplicate compliance programs.

Where possible, organizations should identify common controls across frameworks and reuse evidence and activities.

For example, a single security control may contribute to requirements across:

  • CyFun
  • ISO 27001
  • NIST CSF
  • SOC 2
  • Privacy requirements
  • Internal security policies

This is where cross-framework control mapping can significantly reduce duplicate work.

Step 3: Strengthen Governance

Organizations should establish clear accountability for:

  • Cybersecurity risk
  • Policy management
  • Control ownership
  • Risk acceptance
  • Remediation
  • Executive reporting

Cybersecurity governance should connect technical activities with enterprise risk and leadership decision-making.

Step 4: Improve Evidence Collection

Manual evidence collection is one of the biggest obstacles to scalable compliance.

Teams often spend significant time:

  • Taking screenshots
  • Downloading logs
  • Updating spreadsheets
  • Chasing system owners
  • Preparing evidence folders

A more scalable approach is to connect compliance operations with the technology systems where evidence already exists.

Step 5: Move Toward Continuous Monitoring

Point-in-time compliance creates a visibility gap.

A control may be compliant during an assessment but drift out of compliance shortly afterward.

Continuous monitoring helps organizations identify changes and control gaps earlier.

How Quantarra Helps Organizations Manage CyFun Compliance

Managing CyFun requirements becomes increasingly complex when organizations are also responsible for other security, privacy, and regulatory frameworks.

Quantarra helps organizations centralize and automate their compliance operations through a unified approach to:

Centralized Control Management

Manage controls, policies, risks, tasks, and evidence from one platform.

Cross-Framework Mapping

Map common controls across multiple frameworks to reduce duplicate compliance work.

Automated Evidence Collection

Connect existing technology systems and streamline the collection and organization of compliance evidence.

Continuous Control Monitoring

Gain greater visibility into control status and potential compliance gaps.

Automated Workflows

Reduce manual follow-ups and improve accountability across compliance activities.

Audit Readiness

Maintain organized evidence and reporting to support internal and external assessments.

The objective is simple:

Instead of building separate operational processes for every framework, organizations can build one scalable compliance operating model.

CyFun 1.0 vs 2.0: Frequently Asked Questions

Q. Is CyFun 1.0 the same as CyFun 2023?

The terminology can be confusing. Official CyFun materials commonly refer to framework versions by year, including CyFun 2023 and CyFun 2025. CyFun 2023 is based on NIST CSF 1.1, while CyFun 2025 aligns with NIST CSF 2.0.

Q. What is the biggest change in the newer CyFun framework?

Key changes include stronger governance measures, alignment with NIST CSF 2.0, expanded supply chain and OT coverage, clearer controls, specific control goals, and more comprehensive guidance.

Q. Does moving to the newer framework require starting again?

Not necessarily. Organizations should assess their existing controls and map them to updated requirements rather than automatically rebuilding their entire cybersecurity program.

Q. Can CyFun controls be mapped to other frameworks?

Yes. Organizations can create control mappings across frameworks to reduce duplication and create a more unified compliance program.

Conclusion

The evolution described as CyFun 1.0 vs 2.0 represents a broader shift in cybersecurity compliance.

Organizations are moving away from isolated controls and periodic assessments toward stronger governance, clearer accountability, supply chain awareness, and more resilient cybersecurity operations.

The biggest opportunity is not simply to update a framework.

It is to modernise the way compliance itself is managed.

With the right combination of control mapping, automated evidence collection, continuous monitoring, and centralised workflows, organizations can turn CyFun compliance into part of an ongoing cybersecurity assurance program.

Ready to simplify CyFun compliance?

Quantarra helps organizations automate compliance operations, centralise controls and evidence, and build a continuous approach to cybersecurity assurance.

Explore how Quantarra can support your CyFun compliance journey.