Audit of the three templates published by the Centre for Cybersecurity Belgium · BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25) · last reviewed September 2026
| Finding | BASIC | IMPORTANT | ESSENTIAL | Affects a score | Corrected |
|---|---|---|---|---|---|
| Requirement text invisible (white on white) | – | GOVERN!F15 | GOVERN!F19 | no | ✔ |
| Category score ignores four subcategories | – | – | PROTECT!L3 | yes | ✔ |
| N/A dropped instead of counting as 3 | – | RECOVER!J4:J7 | – | yes | ✔ |
| Invisible leftover management-aspect flag | PROTECT!B14 | PROTECT!B34 | PROTECT!B58 | no | ✔ |
| Management-aspect flag worded two ways | – | 7 cells | – | no | ✔ |
| Control identifier not canonical | 2 cells | 3 cells | 2 cells | no | ✔ |
| Two controls share one comment cell | – | 1 pair | 2 pairs | no | ✔ |
| Double space in requirement wording | 3 cells | 5 cells | 6 cells | no | ✔ |
| Same control worded differently across levels | 14 controls | no | — | ||
CyFun2025_ Self-Assessment_tool_BASIC_v2026_02_20.xlsx
Tool version 2026-02-20 · SHA-256 0d464cff7228303ef4960206a32736c292ed3ea258089d0ea18d11bef30d9cbc
| Severity | Sheet | Cell | Control | Finding | In this tool |
|---|---|---|---|---|---|
| Medium | PROTECT | B14 | PR.PS-04.1 | Invisible leftover flag in the management-aspects column The cell contains the text Governance Measure in bold white on a white fill, so it is invisible in Excel. It is the only cell in the column still using the pre-2026 wording; every visible cell was renamed to "Control linked to (the) management aspects". Present in all three levels and in the previous templates.Effect: The CCB's own mapping document (CyFun2025_mapping 2026-05) does not list PR.PS-04.1 as a Management Aspect, and its counts of management-linked measures (9 at IMPORTANT, 15 at ESSENTIAL) match the visible cells of the templates exactly — so the invisible cell is a leftover, and emptying it aligns the file with the CCB mapping. It changes nothing to the excluded-measure rules either way, because PR.PS-04.1 is a key measure at every level and N/A is forbidden on key measures anyway. |
✔ corrected |
| Low | IDENTIFY | E5 | ID.AM-05.1 | Control identifier not in the canonical form Written ID.AM-5.1, without the leading zero used by every other identifier and by the ESSENTIAL file.Effect: Tools matching controls across the three files have to normalise the identifier. |
✔ corrected |
| Low | DETECT | E5 | DE.CM-03.1 | Control identifier not in the canonical form Written DE.CM-03-1, with a dash instead of a dot before the sub-number.Effect: Tools matching controls across the three files have to normalise the identifier. |
✔ corrected |
| Low | PROTECT | E3, E15, E16 | PR.AA-01.1, PR.PS-05.1, PR.IR-01.1 | Double space inside the requirement wording The requirement text contains a run of two or more spaces. Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone. |
✔ corrected |
CyFun2025_ Self-Assessment_tool_IMPORTANT_v2026_02_20.xlsx
Tool version 2026-02-20 · SHA-256 2d879747d7be4fc46ff5cde768396791a52840e1005e35332a9ae91474ed1260
| Severity | Sheet | Cell | Control | Finding | In this tool |
|---|---|---|---|---|---|
| High | GOVERN | F15 | GV.RR-02.1 | Requirement text is invisible The cell uses a white font on a cell with no fill, so the whole requirement is unreadable in Excel. In the previous template (v2025-10-21) the same cell had a red fill with white text, which was readable; the fill was removed in February 2026 and the font colour was not reset. Effect: A reader of the file cannot see what GV.RR-02.1 requires. Introduced in the February 2026 template. |
✔ corrected |
| High | RECOVER | J4:J7 | RC.RP-05.1, RC.RP-06.1, RC.CO-03.1, RC.CO-04.1 | Excluded measures (N/A) are dropped instead of counting as 3 These four implementation subcategories are =H4 … =H7 (a shared formula whose master is J4), without the N/A substitution their documentation counterparts have — compare I4 = IF(OR($G4="N/A",$H4="N/A"),3,$G4). Row 3 above them is correct, so the four cells are an oversight rather than a design choice. All four controls permit N/A.Effect: When one of these measures is marked N/A the cell evaluates to the text "N/A", which AVERAGE ignores, so the measure drops out of the category instead of counting as 3 — this inflates the score. Measured with RECOVER at 5/5 and RC.RP-05.1 marked N/A: the template reports 5.00 where the correct value is 4.33. Also present in the previous template. |
✔ corrected |
| Medium | PROTECT | B34 | PR.PS-04.1 | Invisible leftover flag in the management-aspects column Same as BASIC. Effect: Same as BASIC. |
✔ corrected |
| Medium | GOVERN | M6:M7 / N6:N7 | GV.OC-04.1 and GV.OC-04.2 | Two controls share one comment cell The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments. Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy. |
✔ corrected |
| Low | GOVERN | B9, B10, B12, B15 | GV.RM-01.1, GV.RM-02.1, GV.RM-03.2, GV.RR-02.1 | Management-aspect flag worded two different ways in one file Seven cells read Control linked to management aspects and two read Control linked to the management aspects (PROTECT!B46, RECOVER!B6). The column header and the ESSENTIAL file both use the form with "the".Effect: Cosmetic inconsistency within a single file. |
✔ corrected |
| Low | IDENTIFY | B30, B31, B40 | ID.RA-05.2, ID.RA-06.1, ID.IM-04.1 | Management-aspect flag worded two different ways in one file Same as above. Effect: Cosmetic inconsistency within a single file. |
✔ corrected |
| Low | IDENTIFY | F10 | ID.AM-03.2 | Control identifier not in the canonical form Written ID.AM-03-2, with a dash instead of a dot. The ESSENTIAL file writes the same control ID.AM-03.2.Effect: Tools matching controls across the three files have to normalise the identifier. |
✔ corrected |
| Low | DETECT | F7 | DE.CM-03.1 | Control identifier not in the canonical form Written DE.CM-03-1, with a dash instead of a dot.Effect: Tools matching controls across the three files have to normalise the identifier. |
✔ corrected |
| Low | RESPOND | F9 | RS.CO-02.2 | Stray whitespace in the control identifier The identifier is followed by a tab character before the colon. Effect: Breaks a strict identifier match. |
✔ corrected |
| Low | GOVERN / IDENTIFY / PROTECT | F4, F7, F6, F37, F41 | GV.OC-03.1, ID.AM-02.2, PR.AA-03.1, PR.PS-05.1, PR.IR-01.1 | Double space inside the requirement wording The requirement text contains a run of two or more spaces. Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone. |
✔ corrected |
CyFun2025_Self-Assessment_tool_ESSENTIAL_v3.1.xlsx
Tool version 2026-02-25 · SHA-256 4c55e08d5fedc57040132df0aa8c49463a42d9a84ec0906f7a3f67282f1507a2
| Severity | Sheet | Cell | Control | Finding | In this tool |
|---|---|---|---|---|---|
| High | GOVERN | F19 | GV.RR-02.1 | Requirement text is invisible Same as the IMPORTANT file: white font on a cell with no fill. Effect: A reader of the file cannot see what GV.RR-02.1 requires. Introduced in the v3.1 template. |
✔ corrected |
| High | PROTECT | L3 | PR.AA (category) | Category score ignores four subcategories The formula is =AVERAGE(J3:J24) while the category is merged over L3:L28. The documentation column next to it is correct: K3 = AVERAGE(I3:I28). The four subcategory anchors in rows 25–28 are therefore left out of the implementation score only.Effect: The PR.AA implementation category maturity is wrong whenever rows 25–28 differ from the rest. Measured on a test file with rows 3–24 at 1/1 and rows 25–28 at 5/5: the template reports 1.00 where the correct value is 1.67. The previous template had a different but also incorrect range. |
✔ corrected |
| Medium | PROTECT | B58 | PR.PS-04.1 | Invisible leftover flag in the management-aspects column Same as BASIC. Effect: Same as BASIC. |
✔ corrected |
| Medium | GOVERN | M7:M8 / N7:N8 | GV.OC-04.1 and GV.OC-04.2 | Two controls share one comment cell The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments. Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy. |
✔ corrected |
| Medium | IDENTIFY | M14:M15 / N14:N15 | ID.AM-04.1 and ID.AM-04.2 | Two controls share one comment cell The comment and assessor-comment cells are merged across the two rows, so the two controls cannot be given separate comments. Effect: Corrected by unmerging the cells so each control keeps its own comment. In the "as published" copy the merge is restored and both texts are written into the shared cell, each prefixed with its identifier, so no comment is lost in either copy. |
✔ corrected |
| Low | RESPOND | F14 | RS.CO-02.2 | Stray whitespace in the control identifier The identifier is followed by a tab character before the colon. Effect: Breaks a strict identifier match. |
✔ corrected |
| Low | PROTECT | F27 | PR.AA-06.3 | Stray whitespace in the control identifier The cell begins with a newline before the identifier. Effect: Breaks a strict identifier match. |
✔ corrected |
| Low | GOVERN / IDENTIFY / PROTECT | F5, F34, F8, F10, F63, F69 | GV.OC-03.1, GV.SC-05.3, ID.AM-02.2, PR.AA-03.1, PR.PS-05.1, PR.IR-01.1 | Double space inside the requirement wording The requirement text contains a run of two or more spaces. Effect: Corrected by collapsing the run to a single space. No word of the requirement is changed, and spacing at the start of a line is left alone. |
✔ corrected |
| Low | various | — | GV.OC-03.2, GV.RR-02.1, GV.RR-04.1, GV.OC-05.1, GV.PO-01.2, ID.RA-01.3, PR.AA-05.3, PR.PS-04.1 | Requirement wording differs from the same control in the IMPORTANT file Eight controls that exist in both files are worded differently. Six more differ between BASIC and IMPORTANT (GV.RR-04.1, ID.AM-07.1, ID.IM-03.1, DE.AE-03.1, PR.AA-03.1, PR.DS-11.1). Effect: Not corrected, and possibly intentional. |
— reported only |
Every cell of the three published templates was read programmatically and checked for:
The checks that found nothing are worth stating too: no duplicate or missing control identifiers, no score cell without a dropdown, no dropdown permitting N/A where the CyFun rule forbids it, no NA_Count range that misses a control row, no Summary reference pointing at a non-control row, and no unprotected function sheet.