Cybersecurity frameworks cannot remain static.
Threats evolve. Technology environments become more distributed. Supply chains become more interconnected. Regulatory expectations continue to increase. As a result, organizations need cybersecurity programs that can move beyond periodic assessments and provide a more structured approach to managing cyber risk.
That is why the evolution often described as CyFun 1.0 vs 2.0 matters.
For organizations already using CyFun—or planning to adopt it—the transition represents more than a change in documentation. It reflects a broader shift toward:
The latest CyFun framework update was designed to align with NIST Cybersecurity Framework 2.0 and relevant European requirements, including NIS2.
CyFun, or CyberFundamentals, is a structured, risk-based cybersecurity framework designed to help organizations organize, implement, and assess cybersecurity measures.
It provides organizations with a practical way to improve cybersecurity maturity while focusing on measures that help reduce cyber risk and improve resilience.
The framework is based significantly on established cybersecurity practices and has evolved alongside changes in the NIST Cybersecurity Framework. The CyFun 2023 version was based on NIST CSF 1.1, while the newer CyFun 2025 version aligns with NIST CSF 2.0.
This evolution is particularly important for organizations trying to manage cybersecurity alongside multiple compliance requirements.
One of the most significant developments in the newer approach is the stronger focus on governance.
Modern cybersecurity is no longer solely an IT responsibility.
Business leaders, boards, risk teams, compliance professionals, and technology teams all have a role in managing cyber risk.
The updated CyFun framework introduces Governance Measures to better align with modern expectations around cybersecurity oversight and organizational accountability.
This reflects a similar evolution in NIST CSF 2.0, which introduced the Govern function to give cybersecurity governance greater visibility across an organization's risk management strategy.
Cybersecurity programs increasingly need to demonstrate:
For compliance teams, this means governance evidence can no longer be treated as an annual audit exercise.
It needs to become part of continuous compliance operations.
The newer CyFun framework aligns with the evolution of NIST CSF 2.0.
NIST CSF 2.0 expanded the framework's emphasis on governance and reorganized several cybersecurity outcomes to better reflect modern risk management needs.
This matters because many organizations already use NIST CSF as a reference point for:
Greater alignment can make it easier for organizations to connect CyFun requirements with broader cybersecurity and compliance programs.
However, framework alignment alone does not eliminate operational complexity.
Organizations still need to answer questions such as:
This is where compliance automation becomes increasingly important.
Modern organizations depend on an increasingly complex ecosystem of:
As a result, cybersecurity risk increasingly extends beyond the organization's own infrastructure.
The updated CyFun framework expands its focus on supply chain security.
A strong internal security posture does not automatically mean an organization has a strong external risk posture.
Organisations need greater visibility into:
The future of compliance management requires organizations to move beyond collecting supplier questionnaires once a year.
Risk needs to be monitored as an ongoing operational process.
The newer CyFun framework also expands its focus on Operational Technology (OT).
This is increasingly important for organizations operating critical or connected environments such as:
IT and OT environments have historically operated differently. However, increased connectivity means cyber risk can now move across systems and operational boundaries.
Organizations therefore need cybersecurity programs that provide a broader view of their overall technology environment.
One of the practical improvements in the newer CyFun framework is a stronger focus on clarity and auditability.
The updated version reformulates controls and guidance, introduces a specific goal for each control, and provides more comprehensive guidance for interpreting requirements.
This is particularly important because compliance teams often face a major challenge:
Understanding a control is not the same as operationalizing it.
A requirement may appear clear in a framework, but organizations still need to determine:
Better control clarity helps reduce interpretation gaps.
But organizations still need systems and workflows capable of managing those controls at scale.
| Area | Earlier CyFun Approach | Newer CyFun Approach |
|---|---|---|
| Framework alignment | NIST CSF 1.1 alignment | Greater alignment with NIST CSF 2.0 |
| Governance | Embedded cybersecurity management activities | Stronger, explicit governance focus |
| Supply chain | More limited emphasis | Expanded supply chain security focus |
| Operational technology | Less extensive focus | Greater attention to OT environments |
| Controls | Earlier control and guidance structure | Improved clarity and auditability |
| Control understanding | General requirements | Specific goals for controls |
| Guidance | Existing implementation guidance | More comprehensive interpretation guidance |
| Board oversight | Less explicit framework focus | Governance Measures supporting stronger oversight |
The specific framework updates include alignment with NIST CSF 2.0, supply chain and OT expansion, clearer controls, specific control goals, expanded guidance, and Governance Measures.
The transition should not be approached as a simple document update.
Organizations should use it as an opportunity to evaluate how cybersecurity compliance is actually being managed.
Identify:
Avoid creating duplicate compliance programs.
Where possible, organizations should identify common controls across frameworks and reuse evidence and activities.
For example, a single security control may contribute to requirements across:
This is where cross-framework control mapping can significantly reduce duplicate work.
Organizations should establish clear accountability for:
Cybersecurity governance should connect technical activities with enterprise risk and leadership decision-making.
Manual evidence collection is one of the biggest obstacles to scalable compliance.
Teams often spend significant time:
A more scalable approach is to connect compliance operations with the technology systems where evidence already exists.
Point-in-time compliance creates a visibility gap.
A control may be compliant during an assessment but drift out of compliance shortly afterward.
Continuous monitoring helps organizations identify changes and control gaps earlier.
Managing CyFun requirements becomes increasingly complex when organizations are also responsible for other security, privacy, and regulatory frameworks.
Quantarra helps organizations centralize and automate their compliance operations through a unified approach to:
Manage controls, policies, risks, tasks, and evidence from one platform.
Map common controls across multiple frameworks to reduce duplicate compliance work.
Connect existing technology systems and streamline the collection and organization of compliance evidence.
Gain greater visibility into control status and potential compliance gaps.
Reduce manual follow-ups and improve accountability across compliance activities.
Maintain organized evidence and reporting to support internal and external assessments.
The objective is simple:
Instead of building separate operational processes for every framework, organizations can build one scalable compliance operating model.
The terminology can be confusing. Official CyFun materials commonly refer to framework versions by year, including CyFun 2023 and CyFun 2025. CyFun 2023 is based on NIST CSF 1.1, while CyFun 2025 aligns with NIST CSF 2.0.
Key changes include stronger governance measures, alignment with NIST CSF 2.0, expanded supply chain and OT coverage, clearer controls, specific control goals, and more comprehensive guidance.
Not necessarily. Organizations should assess their existing controls and map them to updated requirements rather than automatically rebuilding their entire cybersecurity program.
Yes. Organizations can create control mappings across frameworks to reduce duplication and create a more unified compliance program.
The evolution described as CyFun 1.0 vs 2.0 represents a broader shift in cybersecurity compliance.
Organizations are moving away from isolated controls and periodic assessments toward stronger governance, clearer accountability, supply chain awareness, and more resilient cybersecurity operations.
The biggest opportunity is not simply to update a framework.
It is to modernise the way compliance itself is managed.
With the right combination of control mapping, automated evidence collection, continuous monitoring, and centralised workflows, organizations can turn CyFun compliance into part of an ongoing cybersecurity assurance program.
Quantarra helps organizations automate compliance operations, centralise controls and evidence, and build a continuous approach to cybersecurity assurance.
Explore how Quantarra can support your CyFun compliance journey.