Defects found in the CyFun® 2025 self-assessment templates
BASIC & IMPORTANT v2026-02-20 · ESSENTIAL v3.1 (2026-02-25)

Audit of the three templates published by the Centre for Cybersecurity Belgium · BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25) · last reviewed September 2026

Summary

FindingBASICIMPORTANTESSENTIALAffects a scoreCorrected
Requirement text invisible (white on white)GOVERN!F15GOVERN!F19no
Category score ignores four subcategoriesPROTECT!L3yes
N/A dropped instead of counting as 3RECOVER!J4:J7yes
Invisible leftover management-aspect flagPROTECT!B14PROTECT!B34PROTECT!B58no
Management-aspect flag worded two ways7 cellsno
Control identifier not canonical2 cells3 cells2 cellsno
Two controls share one comment cell1 pair2 pairsno
Double space in requirement wording3 cells5 cells6 cellsno
Same control worded differently across levels14 controlsno
Two defects change a maturity score. The converter corrects them in the file it generates, which means that file no longer computes the same numbers as the official template. Because a conformity assessment body may recompute your scores in the official template, the tool always offers a second copy with the CCB template exactly as published, and both copies state in their ConversionLog sheet which one they are. Everything else in the templates is left untouched: every other formula, requirement text and structure is identical to the published file, and an automated test compares all of them on every build.

BASIC

CyFun2025_ Self-Assessment_tool_BASIC_v2026_02_20.xlsx
Tool version 2026-02-20 · SHA-256 0d464cff7228303ef4960206a32736c292ed3ea258089d0ea18d11bef30d9cbc

SeveritySheetCellControlFindingIn this tool
Medium PROTECTB14PR.PS-04.1 Invisible leftover flag in the management-aspects column
The cell contains the text Governance Measure in bold white on a white fill, so it is invisible in Excel. It is the only cell in the column still using the pre-2026 wording; every visible cell was renamed to "Control linked to (the) management aspects". Present in all three levels and in the previous templates.
Effect: The CCB's own mapping document (CyFun2025_mapping 2026-05) does not list PR.PS-04.1 as a Management Aspect, and its counts of management-linked measures (9 at IMPORTANT, 15 at ESSENTIAL) match the visible cells of the templates exactly — so the invisible cell is a leftover, and emptying it aligns the file with the CCB mapping. It changes nothing to the excluded-measure rules either way, because PR.PS-04.1 is a key measure at every level and N/A is forbidden on key measures anyway.
✔ corrected
Low IDENTIFYE5ID.AM-05.1 Control identifier not in the canonical form
Written ID.AM-5.1, without the leading zero used by every other identifier and by the ESSENTIAL file.
Effect: Tools matching controls across the three files have to normalise the identifier.
✔ corrected
Low DETECTE5DE.CM-03.1 Control identifier not in the canonical form
Written DE.CM-03-1, with a dash instead of a dot before the sub-number.
Effect: Tools matching controls across the three files have to normalise the identifier.
✔ corrected
Low PROTECTE3, E15, E16PR.AA-01.1, PR.PS-05.1, PR.IR-01.1 Double space inside the requirement wording
The requirement text contains a run of two or more spaces.
Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone.
✔ corrected

IMPORTANT

CyFun2025_ Self-Assessment_tool_IMPORTANT_v2026_02_20.xlsx
Tool version 2026-02-20 · SHA-256 2d879747d7be4fc46ff5cde768396791a52840e1005e35332a9ae91474ed1260

SeveritySheetCellControlFindingIn this tool
High GOVERNF15GV.RR-02.1 Requirement text is invisible
The cell uses a white font on a cell with no fill, so the whole requirement is unreadable in Excel. In the previous template (v2025-10-21) the same cell had a red fill with white text, which was readable; the fill was removed in February 2026 and the font colour was not reset.
Effect: A reader of the file cannot see what GV.RR-02.1 requires. Introduced in the February 2026 template.
✔ corrected
High RECOVERJ4:J7RC.RP-05.1, RC.RP-06.1, RC.CO-03.1, RC.CO-04.1 Excluded measures (N/A) are dropped instead of counting as 3
These four implementation subcategories are =H4=H7 (a shared formula whose master is J4), without the N/A substitution their documentation counterparts have — compare I4 = IF(OR($G4="N/A",$H4="N/A"),3,$G4). Row 3 above them is correct, so the four cells are an oversight rather than a design choice. All four controls permit N/A.
Effect: When one of these measures is marked N/A the cell evaluates to the text "N/A", which AVERAGE ignores, so the measure drops out of the category instead of counting as 3 — this inflates the score. Measured with RECOVER at 5/5 and RC.RP-05.1 marked N/A: the template reports 5.00 where the correct value is 4.33. Also present in the previous template.
✔ corrected
Medium PROTECTB34PR.PS-04.1 Invisible leftover flag in the management-aspects column
Same as BASIC.
Effect: Same as BASIC.
✔ corrected
Medium GOVERNM6:M7 / N6:N7GV.OC-04.1 and GV.OC-04.2 Two controls share one comment cell
The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments.
Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy.
✔ corrected
Low GOVERNB9, B10, B12, B15GV.RM-01.1, GV.RM-02.1, GV.RM-03.2, GV.RR-02.1 Management-aspect flag worded two different ways in one file
Seven cells read Control linked to management aspects and two read Control linked to the management aspects (PROTECT!B46, RECOVER!B6). The column header and the ESSENTIAL file both use the form with "the".
Effect: Cosmetic inconsistency within a single file.
✔ corrected
Low IDENTIFYB30, B31, B40ID.RA-05.2, ID.RA-06.1, ID.IM-04.1 Management-aspect flag worded two different ways in one file
Same as above.
Effect: Cosmetic inconsistency within a single file.
✔ corrected
Low IDENTIFYF10ID.AM-03.2 Control identifier not in the canonical form
Written ID.AM-03-2, with a dash instead of a dot. The ESSENTIAL file writes the same control ID.AM-03.2.
Effect: Tools matching controls across the three files have to normalise the identifier.
✔ corrected
Low DETECTF7DE.CM-03.1 Control identifier not in the canonical form
Written DE.CM-03-1, with a dash instead of a dot.
Effect: Tools matching controls across the three files have to normalise the identifier.
✔ corrected
Low RESPONDF9RS.CO-02.2 Stray whitespace in the control identifier
The identifier is followed by a tab character before the colon.
Effect: Breaks a strict identifier match.
✔ corrected
Low GOVERN / IDENTIFY / PROTECTF4, F7, F6, F37, F41GV.OC-03.1, ID.AM-02.2, PR.AA-03.1, PR.PS-05.1, PR.IR-01.1 Double space inside the requirement wording
The requirement text contains a run of two or more spaces.
Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone.
✔ corrected

ESSENTIAL

CyFun2025_Self-Assessment_tool_ESSENTIAL_v3.1.xlsx
Tool version 2026-02-25 · SHA-256 4c55e08d5fedc57040132df0aa8c49463a42d9a84ec0906f7a3f67282f1507a2

SeveritySheetCellControlFindingIn this tool
High GOVERNF19GV.RR-02.1 Requirement text is invisible
Same as the IMPORTANT file: white font on a cell with no fill.
Effect: A reader of the file cannot see what GV.RR-02.1 requires. Introduced in the v3.1 template.
✔ corrected
High PROTECTL3PR.AA (category) Category score ignores four subcategories
The formula is =AVERAGE(J3:J24) while the category is merged over L3:L28. The documentation column next to it is correct: K3 = AVERAGE(I3:I28). The four subcategory anchors in rows 25–28 are therefore left out of the implementation score only.
Effect: The PR.AA implementation category maturity is wrong whenever rows 25–28 differ from the rest. Measured on a test file with rows 3–24 at 1/1 and rows 25–28 at 5/5: the template reports 1.00 where the correct value is 1.67. The previous template had a different but also incorrect range.
✔ corrected
Medium PROTECTB58PR.PS-04.1 Invisible leftover flag in the management-aspects column
Same as BASIC.
Effect: Same as BASIC.
✔ corrected
Medium GOVERNM7:M8 / N7:N8GV.OC-04.1 and GV.OC-04.2 Two controls share one comment cell
The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments.
Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy.
✔ corrected
Medium IDENTIFYM14:M15 / N14:N15ID.AM-04.1 and ID.AM-04.2 Two controls share one comment cell
The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments.
Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy.
✔ corrected
Low RESPONDF14RS.CO-02.2 Stray whitespace in the control identifier
The identifier is followed by a tab character before the colon.
Effect: Breaks a strict identifier match.
✔ corrected
Low PROTECTF27PR.AA-06.3 Stray whitespace in the control identifier
The cell begins with a newline before the identifier.
Effect: Breaks a strict identifier match.
✔ corrected
Low GOVERN / IDENTIFY / PROTECTF5, F34, F8, F10, F63, F69GV.OC-03.1, GV.SC-05.3, ID.AM-02.2, PR.AA-03.1, PR.PS-05.1, PR.IR-01.1 Double space inside the requirement wording
The requirement text contains a run of two or more spaces.
Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone.
✔ corrected
Low variousGV.OC-03.2, GV.RR-02.1, GV.RR-04.1, GV.OC-05.1, GV.PO-01.2, ID.RA-01.3, PR.AA-05.3, PR.PS-04.1 Requirement wording differs from the same control in the IMPORTANT file
Eight controls that exist in both files are worded differently. Six more differ between BASIC and IMPORTANT (GV.RR-04.1, ID.AM-07.1, ID.IM-03.1, DE.AE-03.1, PR.AA-03.1, PR.DS-11.1).
Effect: Not corrected, and possibly intentional.
— reported only

Sources

How the audit was done

Every cell of the three published templates was read programmatically and checked for:

The checks that found nothing are worth stating too: no duplicate or missing control identifiers, no score cell without a dropdown, no dropdown permitting N/A where the CyFun rule forbids it, no NA_Count range that misses a control row, no Summary reference pointing at a non-control row, and no unprotected function sheet.