Every requirement text that differs, quoted verbatim from the CCB templates
Reviewed September 2026
CyFun 2025 v2025-10-21 → BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25)
Same measure identifiers, same publisher. 28 descriptions changed, covering 20 distinct measures — a measure worded differently at two levels is listed once per level (17 of the rows change the obligation verb). Every edit here is a small one, so any change of obligation verb is reported.
| Level | Measure | Description |
|---|---|---|
| BASIC | PR.AA-06.1obligation verb changed | Physical access to all organisational assets, including critical zones, Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk. |
| IMPORTANT | GV.OC-03.2 | Legal and regulatory obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied. |
| IMPORTANT | GV.RM-01.1 | Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management. |
| IMPORTANT | GV.RR-02.1 | Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and externally. |
| IMPORTANT | ID.AM-08.8obligation verb changed | The organisation The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems. |
| IMPORTANT | PR.AA-06.1obligation verb changed | Physical access to all organisational assets, including critical zones, Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk. |
| IMPORTANT | PR.AA-06.2obligation verb changed | Physical access controls Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events. |
| IMPORTANT | DE.AE-02.1obligation verb changed | Cybersecurity and information security events Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies. |
| IMPORTANT | DE.AE-06.1obligation verb changed | Information about adverse events Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response. |
| ESSENTIAL | GV.OC-03.2 | Legal, regulatory, and contractual obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, Legal, regulatory, and contractual obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied. |
| ESSENTIAL | GV.RM-01.1 | Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management. |
| ESSENTIAL | GV.RR-04.1 | Personnel with access to the organisation’s most critical information or technology shall be Personnel with access to the organisation’s most critical information or technology shall be authenticated. |
| ESSENTIAL | GV.OV-03.1 | The organisation's cybersecurity risk management performance shall be evaluated, reviewed and The organisation's cybersecurity risk management performance shall be evaluated, reviewed and adjusted when necessary. |
| ESSENTIAL | ID.AM-08.7obligation verb changed | The organisation The organisation shall prevent unauthorised removal of maintenance equipment which contains critical system information of the organisation. |
| ESSENTIAL | ID.AM-08.8obligation verb changed | The organisation The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems. |
| ESSENTIAL | ID.IM-03.1 | The organisation shall conduct The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber resilience. |
| ESSENTIAL | PR.AA-01.3 | System credentials shall be deactivated System credentials shall be deactivated after a specified period of inactivity unless it would compromise the safe operation of (critical) processes. |
| ESSENTIAL | PR.AA-02.2 | The organisation shall ensure that unique credentials are used for each authenticated user, device, and process interacting with the organisation's critical systems. These credentials shall be verified, and the unique identifiers shall be captured during system interactions. Exceptions may be made for emergency access ("break-glass" procedures), provided such access is strictly controlled, logged, and reviewed. |
| ESSENTIAL | PR.AA-04.1obligation verb changed | Identity assertions Identity assertions shall be protected, conveyed, and verified. |
| ESSENTIAL | PR.AA-06.1obligation verb changed | Physical access to all organisational assets, including critical zones, Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk. |
| ESSENTIAL | PR.AA-06.2obligation verb changed | Physical access controls Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events. |
| ESSENTIAL | PR.AA-06.3obligation verb changed | Critical zones Critical zones shall have additional physical access controls beyond those applied to general facilities. |
| ESSENTIAL | PR.AA-06.4obligation verb changed | Assets located within critical zones Assets located within critical zones shall be physically protected against unauthorised access, damage, or interference. |
| ESSENTIAL | PR.PS-06.3obligation verb changed | Secure software development practices shall be integrated into all phases of the software development lifecycle, and their effectiveness Secure software development practices shall be integrated into all phases of the software development lifecycle, and their effectiveness shall be regularly monitored and improved. |
| ESSENTIAL | PR.IR-01.7 | The organisation shall ensure that development and test environments are strictly separated from the production environment, particularly in ICS/OT systems where any crossover could compromise The organisation shall ensure that development and test environments are strictly separated from the production environment, particularly in ICS/OT systems where any crossover could compromise safety, endanger health, or disrupt essential operations. |
| ESSENTIAL | DE.AE-02.1obligation verb changed | Cybersecurity and information security events Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies. |
| ESSENTIAL | DE.AE-06.1obligation verb changed | Information about adverse events Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response. |
| ESSENTIAL | RS.AN-07.1obligation verb changed | Incident data and metadata Incident data and metadata shall be collected and protected to ensure their accuracy, authenticity, and traceability. |
CyFun 2023 self-assessment tool v2025-10-21 → CyFun 2025 BASIC and IMPORTANT v2026-02-20, ESSENTIAL v3.1 (2026-02-25)
Each row pairs a CyFun 2023 measure with the CyFun 2025 measure it becomes. The pairing is the one published by the CCB in Mapping_CyFun2023-CyFun2025 (v2026-02-25): this converter's mapping was compared against that document and the two agree on all 195 pairs and all 24 deleted measures. Of the 195 mapped measures, 174 have a different description (1 change the obligation verb). Measures deleted in 2025 and measures added in 2025 have no counterpart and are not listed here.
| Level | CyFun 2023 → CyFun 2025 | Description |
|---|---|---|
| BASIC | ID.AM-1.1 → ID.AM-01.1 | An inventory of An inventory of physical and virtual infrastructure assets—such as hardware, network devices, and cloud-hosted environments—that support information processing shall be documented, reviewed, and updated as changes occur. |
| BASIC | ID.AM-2.1 → ID.AM-02.1 | An inventory An inventory of software, digital services, and business systems used within the organisation shall be documented, reviewed, and updated as changes occur. |
| BASIC | ID.AM-3.1 → ID.AM-07.1 | Data that the organisation stores and uses shall be identified. |
| BASIC | ID.AM-5.1 → ID.AM-5.1 | The organisation’s The organisation’s assets shall be prioritised based on classification, criticality, and business value. |
| BASIC | ID.GV-1.1 → GV.PO-01.1 | Policies and procedures for information Policies and procedures for managing information and cybersecurity shall be established, documented, reviewed, approved, updated when changes occur, communicated and enforced. |
| BASIC | ID.GV-3.1 → GV.OC-03.1 | Legal and regulatory requirements regarding Legal and regulatory requirements regarding information and cybersecurity shall be identified and implemented. |
| BASIC | ID.GV-4.1 → GV.RM-03.1 | As part of the As part of the organisation-wide risk management strategy, a comprehensive strategy to manage information and cybersecurity risks shall be developed and updated when changes occur. |
| BASIC | ID.RA-1.1 → ID.RA-01.1 | Threats and vulnerabilities shall be Threats and vulnerabilities shall be identified in all relevant assets, including software, network and system architectures, and facilities that house critical computing assets. |
| BASIC | ID.RA-5.1 → ID.RA-05.1 | The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and impact on business processes and assets. The organisation shall conduct risk assessments in which risk is determined by threats, vulnerabilities and the impact on business processes and assets. |
| BASIC | PR.AC-1.1 → PR.AA-01.1 | Identities and credentials for authorised Identities and credentials for authorised users, services, and hardware shall be managed. |
| BASIC | PR.AC-2.1 → PR.AA-06.1 | Physical access to Physical access to all organisational assets, including critical zones, shall be managed, monitored, and enforced based on risk. |
| BASIC | PR.AC-3.1 → PR.AA-03.1 | All wireless access points used by the organisation, including those providing guest access, shall be securely configured, managed, and monitored to prevent unauthorised access and ensure network integrity. |
| BASIC | PR.AC-3.2 → PR.AA-03.2 | Multi-Factor Authentication (MFA) shall be required to access the organisation's networks remotely. |
| BASIC | PR.AC-4.1 → PR.AA-05.1 | Access Access permissions, rights, and authorisations shall be defined, managed, enforced and reviewed. |
| BASIC | PR.AC-4.2 → PR.AA-05.2 | It shall be It shall be determined who needs access to the organisation's business-critical information and technology and the means to gain access. |
| BASIC | PR.AC-4.3 → PR.AA-05.3 | Access rights, privileges and authorisations shall be restricted to the systems and specific information needed to perform the tasks (the principle of Least Privilege). |
| BASIC | PR.AC-4.4 → PR.AA-05.4 | No-one shall have administrative privileges for routine day-to-day tasks. |
| BASIC | PR.AC-5.1 → PR.IR-01.1 | Firewalls shall be Firewalls shall be installed, configured, and actively maintained on all networks used by the organisation to protect against unauthorised access and cyber threats. |
| BASIC | PR.AC-5.2 → PR.IR-01.2 | To safeguard critical systems, organisations shall implement network segmentation and segregation aligned with trust boundaries and asset criticality, thereby limiting threat propagation and enforcing strict access control. |
| BASIC | PR.AT-1.1 → PR.AT-01.1 | The organisation shall establish and maintain a cybersecurity awareness and training programme to ensure that all personnel understand how to perform their tasks securely and responsibly. |
| BASIC | PR.DS-3.1 → PR.DS-01.9 | Enterprise assets shall be disposed of safely. |
| BASIC | PR.IP-11.1 → GV.RR-04.1 | Personnel Personnel with access to the organisation’s most critical information or technology shall be authenticated. |
| BASIC | PR.IP-4.1 → PR.DS-11.1 | Backups for organisation's business-critical data shall be Backups for the organisation's business-critical data shall be performed and stored on a different system from the device on which the original data resides. |
| BASIC | PR.MA-1.1 → ID.AM-08.2 | Patches and security updates for Patches and security updates for operating systems and critical system components shall be installed. |
| BASIC | PR.PT-1.1 → PR.PS-04.1 | Logs shall be maintained, documented, and Logs shall be maintained, documented, and monitored. |
| BASIC | DE.AE-3.1 → DE.AE-03.1 | The The logging functionality of protection and detection tools shall be enabled. Logs shall be backed up and kept for a predefined period, and regularly reviewed to identify unusual or potentially harmful activity. |
| BASIC | DE.CM-1.1 → DE.CM-01.1 | Firewalls shall be installed and operated Firewalls shall be installed and operated at the network boundaries, including endpoint firewalls. |
| BASIC | DE.CM-3.1 → DE.CM-03-1 | End point and network protection tools to monitor end-user behaviour for dangerous activity shall be implemented. |
| BASIC | DE.CM-4.1 → DE.CM-01.2 | Anti-virus, Anti-virus, -spyware, and other -malware programs shall be installed and updated. |
| BASIC | RS.CO-3.1 → RS.CO-02.1 | Information about cybersecurity incidents shall be communicated to employees in a way that is clear and easy to understand. |
| BASIC | RS.IM-1.1 → ID.IM-03.1 | The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its The organisation shall conduct post-incident evaluations to analyse lessons learned from incident response and recovery, and consequently improve processes / procedures / technologies to enhance its cyber-resilience. |
| BASIC | RS.RP-1.1 → RS.MA-01.1 | An incident response An incident response plan, including defined roles, responsibilities, and authorities, shall be executed during or after a cybersecurity event affecting the organisation's critical systems. |
| BASIC | RC.RP-1.1 → RC.RP-01.1 | A recovery process for disasters and information/cybersecurity incidents shall be developed and A recovery process for disasters and information/cybersecurity incidents shall be developed and executed. |
| IMPORTANT | ID.BE-2.1 → GV.OC-01.1 | The The organisation's mission shall be established, communicated and shall form the basis for information and cybersecurity risk management. |
| IMPORTANT | ID.GV-3.2 → GV.OC-03.2 | Legal and regulatory Legal and regulatory obligations related to information and cybersecurity shall be continuously managed to ensure they remain accurate, up to date, and effectively applied. |
| IMPORTANT | ID.BE-4.1 → GV.OC-04.1 | The organisation shall identify, document, and communicate the critical objectives, capabilities, and services relied upon by external stakeholders, prioritise them based on criticality, and integrate this prioritisation into the risk assessment process. |
| IMPORTANT | ID.BE-5.1 → GV.OC-04.2 | The organisation shall define and document cybersecurity requirements for essential operations, validate them through testing and audits, keep records of results and corrective actions, and regularly update requirements based on evolving risks. |
| IMPORTANT | ID.BE-1.1 → GV.OC-05.1 | The The organisation shall identify, document, and communicate its role in the supply chain, including the external capabilities, services, and dependencies it relies on (upstream), as well as its interactions with downstream stakeholders.. |
| IMPORTANT | ID.GV-1.2 → GV.PO-01.2 | Organisational-wide information and cybersecurity policies and procedures shall include the use of cryptography and, where appropriate, encryption, reflect changes in requirements, threats, technology and organisational roles, and be approved by senior management, who oversee implementation. |
| IMPORTANT | ID.RM-1.1 → GV.RM-01.1 | Information and cybersecurity objectives shall be coherently established throughout the organisation and approved by senior management. |
| IMPORTANT | ID.RM-2.1 → GV.RM-02.1 | Risk appetite and risk tolerance statements shall be defined, documented, approved by senior management, communicated, and maintained. |
| IMPORTANT | ID.GV-4.2 → GV.RM-03.2 | Information Information and cybersecurity risks shall be documented, as part of the enterprise risk management processes, formally approved by senior management, and updated when changes occur. |
| IMPORTANT | ID.AM-6.1 → GV.RR-02.1 | Information security and Information security and cyber security roles, responsibilities and authorities for employees, suppliers, customers, and partners shall be documented, reviewed, authorised, kept up-to-date, communicated, and coordinated internally and externally. |
| IMPORTANT | ID.SC-3.1 → GV.SC-05.1 | Requirements for addressing cybersecurity risks and the sharing of sensitive information in supply chains shall be established, prioritised, integrated into contracts and other types of formal agreements, and enforced. |
| IMPORTANT | ID.SC-2.1 → GV.SC-07.1 | The The risks posed by a supplier, its products and services and other third parties shall be identified, documented, prioritised, mitigated and assessed at least annually and when changes occur during the relationship. |
| IMPORTANT | ID.SC-5.1 → GV.SC-08.1 | The organisation shall identify and document key personnel from suppliers and The organisation shall identify and document key personnel from relevant suppliers and other third parties to include them in incident planning, response, and recovery activities. |
| IMPORTANT | ID.AM-1.2 → ID.AM-01.2 | The inventory of assets associated with information and information processing facilities shall reflect changes in the organisation’s context and include all information necessary for effective accountability. The inventory of enterprise assets associated with information and information processing facilities shall reflect changes in the organisation’s context and include all information necessary for effective accountability. |
| IMPORTANT | ID.AM-2.2 → ID.AM-02.2 | The inventory The inventory reflecting which software, services and systems are used in the organisation shall reflect changes in the organisation’s context and include all information necessary for effective accountability. |
| IMPORTANT | ID.AM-2.3 → ID.AM-02.3 | The people responsible and accountable for managing software platforms and applications within the organisation shall be formally identified. |
| IMPORTANT | ID.AM-3.2 → ID.AM-03-2 | The organisation's network communication and internal data flows shall be mapped, documented, authorised, and updated when changes occur. |
| IMPORTANT | ID.AM-4.1 → ID.AM-04.1 | Organisations shall keep a clear and up-to-date list of all external services it uses, including how they connect to their systems. These services shall be reviewed and approved before use, and the list shall be updated whenever changes happen. |
| IMPORTANT | ID.RA-1.2 → ID.RA-01.2 | A process shall be established to monitor, identify, and document vulnerabilities of the organisation's A process shall be established to continuously monitor, identify, and document vulnerabilities of the organisation's business critical systems. |
| IMPORTANT | ID.RA-5.2 → ID.RA-05.2 | The organisation shall conduct and document risk assessments in which risk is determined by threats, vulnerabilities, impact on business processes and assets, and The organisation shall conduct and document risk assessments in which risk is determined by threats, vulnerabilities, impact on business processes and assets, and likelihood of their occurrence. |
| IMPORTANT | ID.RA-6.1 → ID.RA-06.1 | Risk responses shall be identified, prioritised, planned, tracked and communicated. |
| IMPORTANT | PR.IP-11.2 → GV.RR-04.2 | A cybersecurity process for human resources shall be developed and maintained applicable at recruitment, during employment and at termination of employment. |
| IMPORTANT | PR.AT-3.2 → GV.SC-02.1 | Third-party providers shall Third-party providers shall notify any transfer, termination or transition of personnel with physical or logical access to business-critical system elements of the organisation. |
| IMPORTANT | PR.MA-2.1 → ID.AM-08.11 | Remote maintenance Remote maintenance and diagnostic activities of organisational assets shall be pre-approved and the performance logged. |
| IMPORTANT | PR.MA-2.2 → ID.AM-08.12 | Setting up non-local maintenance and diagnostic sessions over remote network connections shall require strong authenticators and these connections shall be terminated when non-local maintenance is completed. |
| IMPORTANT | PR.DS-3.2 → ID.AM-08.3 | The organisation shall enforce accountability for all its business-critical assets throughout the system The organisation shall enforce accountability for all its business-critical assets throughout the system lifecycle, including removal, transfers, and disposal. |
| IMPORTANT | PR.MA-1.2 → ID.AM-08.6 | The organisation shall plan, The organisation shall plan, perform and document preventive maintenance and repairs on its critical system components according to approved processes and tools. |
| IMPORTANT | PR.MA-1.3 → ID.AM-08.8 | The organisation shall The organisation shall pre-approve, monitor and enforce maintenance tools for use on its critical systems. |
| IMPORTANT | PR.IP-7.1 → ID.IM-03.3 | The organisation shall The organisation shall identify improvements derived from the monitoring, measurements, assessments, and lessons learned and consequently translate this into improved processes / procedures / technologies to enhance its cyber resilience (continuous improvement). |
| IMPORTANT | PR.IP-8.1 → ID.IM-03.4 | The organisation shall collaborate and share information about security incidents and mitigation measures The organisation shall collaborate and share information about its critical system's related security incidents and mitigation measures with designated partners. |
| IMPORTANT | PR.IP-8.2 → ID.IM-03.5 | Communication Communication of effectiveness of protection technologies shall be shared with relevant stakeholders. |
| IMPORTANT | PR.IP-8.3 → ID.IM-03.6 | The organisation shall implement, where feasible, automated mechanisms to The organisation shall implement, where feasible, automated mechanisms to facilitate the process of information sharing and collaboration. |
| IMPORTANT | PR.IP-9.1 → ID.IM-04.1 | Contingency and continuity plans shall be established, communicated, maintained, tested, validated, and improved. |
| IMPORTANT | PR.IP-12.1 → ID.RA-01.3 | The organisation shall establish and maintain a documented process that The organisation shall establish and maintain a documented process that enables continuous review, analysis and remediation of vulnerabilities and provides for information sharing where applicable. |
| IMPORTANT | PR.AC-1.2 → PR.AA-01.2 | Identities and credentials for authorised Identities and credentials for authorised users, services and hardware shall be managed through automated mechanisms whenever feasible. |
| IMPORTANT | PR.AC-3.3 → PR.AA-03.3 | The organisation shall define, document, and implement usage restrictions, connection requirements, and authorisation procedures for remote access to its critical systems. These controls shall ensure that only approved users can connect, using secure methods, with access limited to what is necessary for their role. |
| IMPORTANT | PR.AC-4.5 → PR.AA-05.5 | Where Where technically, operationally, and economically feasible—without compromising system integrity, safety, or compliance—automated mechanisms shall be implemented to manage user accounts on critical ICT and OT systems. Feasibility shall be determined based on system capabilities, integration potential, risk assessment, and business impact. |
| IMPORTANT | PR.AC-2.2 → PR.AA-06.2 | Physical access controls shall include specific procedures for emergency situations, ensuring continued protection of critical and non-critical assets during such events. |
| IMPORTANT | PR.AT-1.2 → PR.AT-01.2 | The organisation shall The organisation shall include insider threat awareness and reporting in its cybersecurity training to help personnel recognise and respond to potential internal risks. |
| IMPORTANT | PR.AT-4.1 → PR.AT-02.1 | Members of management bodies shall be able to demonstrate that they have completed training that gives them a solid understanding of information and cybersecurity and risk management so that they can assess information and cyber security risks and their consequences and propose the necessary risk mitigation, considering their roles, responsibilities and authorities. |
| IMPORTANT | PR.AT-5.1 → PR.AT-02.2 | Individuals in specialised roles shall be provided with awareness and training before privileges are granted, so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind. |
| IMPORTANT | PR.AT-2.1 → PR.AT-02.3 | Privileged users shall be qualified before privileges are granted, and these users shall be able to demonstrate Privileged users shall be qualified before privileges are granted, and these users shall be able to demonstrate the understanding of their roles, responsibilities, and authorities. |
| IMPORTANT | PR.DS-6.1 → PR.DS-01.1 | The organisation shall implement software, firmware, and information integrity checks to detect unauthorised changes to its critical system components during storage, transport, start-up and The organisation shall implement software, firmware, and information integrity checks to detect unauthorised changes to its critical system components during storage, transport, start-up and when determined necessary. |
| IMPORTANT | PR.PT-2.1 → PR.DS-01.4 | The The organisation shall define and enforce clear policies and practical safeguards to manage and restrict the use of portable storage media, in order to reduce the risk of data leakage, unauthorised access, and malware introduction. |
| IMPORTANT | PR.PT-2.2 → PR.DS-01.5obligation verb changed | The organisation The organisation shall only allow the use of removable media when absolutely necessary, and shall put technical measures in place to block automatic execution of files from these devices. |
| IMPORTANT | PR.IP-4.2 → PR.DS-11.2 | The reliability and integrity of backups shall be verified and tested The reliability and integrity of backups shall be verified and tested regularly. |
| IMPORTANT | PR.IP-4.3 → PR.DS-11.3 | The organisation shall maintain secure backups of business-critical data in a separate storage location to ensure data availability in case of system failure or data loss. Backup storage shall apply equivalent security controls as the primary environment. |
| IMPORTANT | PR.AC-5.3 → PR.IR-01.3 | To ensure operational stability and security, the organisation shall, without exception, identify, document, and control connections between components of its critical systems. |
| IMPORTANT | PR.AC-5.4 → PR.IR-01.4 | The organisation shall monitor and control The organisation shall implement appropriate boundary protection measures to monitor and control communications at external and key internal boundaries of its critical systems, across both IT and OT environments, to ensure secure and reliable operations. |
| IMPORTANT | PR.IP-5.1 → PR.IR-02.1 | The organisation shall define, The organisation shall define, implement and maintain policies and procedures related to emergency and safety systems, fire protection systems and environmental controls for its critical systems. |
| IMPORTANT | PR.DS-4.1 → PR.IR-04.1 | Adequate resource capacity planning shall ensure that availability of organisation's critical system information processing, networking, telecommunications, and data storage is maintained. |
| IMPORTANT | PR.MA-1.4 → PR.PS-03.1 | Hardware used in business-critical environments shall be maintained, replaced, or removed based on its associated security and operational risk. |
| IMPORTANT | PR.PT-1.2 → PR.PS-04.2 | The organisation shall ensure that The organisation shall ensure that logbook records contain an authoritative time source or internal clock time stamp that is compared and synchronised with an authoritative time source. |
| IMPORTANT | PR.IP-2.1 → PR.PS-06.1 | Security shall be considered throughout the lifecycle of systems and applications, whether developed internally or acquired externally. |
| IMPORTANT | PR.IP-3.1 → PR.PS-06.2 | Changes shall be tested and validated before being implemented into operational systems. Changes and exceptions shall be tested and validated before being implemented into operational systems. |
| IMPORTANT | PR.DS-5.1 → RS.MI-01.2 | The organisation shall take appropriate The organisation shall detect unauthorised access or data leakage and take appropriate mitigation actions, including monitoring of critical systems at external boundaries and key internal points. |
| IMPORTANT | DE.AE-2.1 → DE.AE-02.1 | Cybersecurity and information security events shall be reviewed and analysed to identify potential attack targets and methods, in accordance with applicable laws, regulations, standards, and policies. |
| IMPORTANT | DE.AE-3.2 → DE.AE-03.2 | The organisation shall ensure that event data The organisation shall ensure that event data from critical systems is collected and correlated using information from multiple relevant sources. |
| IMPORTANT | DE.DP-4.1 → DE.AE-06.1 | Information about adverse events shall be promptly delivered to authorised personnel and systems to enable timely detection, investigation, and response. |
| IMPORTANT | DE.AE-5.1 → DE.AE-08.1 | Incidents shall be reported when adverse events meet defined and documented incident criteria. |
| IMPORTANT | DE.CM-1.2 → DE.CM-01.3 | The organisation shall monitor and identify unauthorised use of its business-critical systems The organisation shall monitor and identify unauthorised use of its business-critical systems through the detection of unauthorised local connections, network connections and remote connections. |
| IMPORTANT | DE.CM-2.1 → DE.CM-02.1 | The physical environment The physical environment shall be monitored to find potentially adverse events. |
| IMPORTANT | DE.CM-3.2 → DE.CM-03.2 | End point and network protection tools that monitor end-user behaviour for dangerous activity shall be managed. |
| IMPORTANT | DE.CM-6.1 → DE.CM-06.1 | External service provider activities and services shall be secured and monitored to find potentially adverse events. |
| IMPORTANT | DE.CM-5.1 → DE.CM-09.1 | The organisation shall The organisation shall monitor computing hardware, software, runtime environments, and their data to detect potentially adverse events. |
| IMPORTANT | DE.CM-8.1 → ID.RA-01.5 | Vulnerability scanning shall not adversely impact system functions. |
| IMPORTANT | DE.CM-3.3 → PR.PS-02.1 | The organisation shall enforce restrictions on software usage and installation, and ensure that software is maintained, replaced, or removed based on its associated risk. |
| IMPORTANT | RS.IM-2.1 → GV.RR-03.2 | The organisation shall The organisation shall assign roles and responsibilities for reviewing and updating response and recovery plans, ensuring they reflect changes in the risk environment and remain effective. |
| IMPORTANT | RS.AN-5.1 → ID.RA-08.1 | The organisation shall implement vulnerability management The organisation shall establish and implement a vulnerability management plan to identify, analyse, assess, mitigate and communicate all types of vulnerabilities including in the form of a Coordinated Vulnerability Disclosure (CVD) according to applicable legal modalities. |
| IMPORTANT | RS.CO-1.1 → PR.AT-01.3 | Personnel shall receive training to understand their specific roles, responsibilities, and priorities during a cybersecurity or information security incident, including the steps they need to follow to respond effectively. |
| IMPORTANT | RS.CO-3.2 → RS.CO-02.2 | Cybersecurity incidents shall be shared with relevant external stakeholders within the timeframes defined in the Incident Response Plan, including reporting significant incidents to authorities as required by law. |
| IMPORTANT | RS.AN-1.1 → RS.MA-02.1 | Information/cybersecurity incident reports shall be triaged and validated in accordance with the organisation’s incident response procedures. |
| IMPORTANT | RS.AN-2.1 → RS.MA-03.1 | Information/cybersecurity incidents shall be categorised, prioritised and escalated as specified in the incident response plan. |
| IMPORTANT | RS.MI-1.1 → RS.MI-01.1 | Cybersecurity incidents shall be contained and eliminated. Any decision to accept and retain certain cybersecurity risks shall be formally documented. |
| IMPORTANT | RC.IM-1.1 → ID.IM-03.2 | The organisation shall incorporate lessons learned from incident The organisation shall incorporate lessons learned from incident handling activities into updated or new incident handling processes and/or procedures that are framed by appropriate training after review, approval and testing. |
| IMPORTANT | RC.CO-3.1 → RC.CO-03.1 | Recovery activities and progress in restoring operational capabilities shall be communicated to designated internal and external stakeholders in accordance with established communication procedures. |
| IMPORTANT | RC.CO-1.1 → RC.CO-04.1 | Public updates on incident recovery shall be shared using approved communication methods and messaging, in accordance with established procedures. |
| ESSENTIAL | ID.AM-1.4 → ID.AM-01.4 | Mechanisms for detecting the presence of unauthorised hardware and firmware components within the Mechanisms for detecting the presence of unauthorised hardware and firmware components within the organisation’s ICT/OT environment shall be identified. |
| ESSENTIAL | ID.AM-3.3 → ID.AM-03.3 | The The organisation's network communication and external data flows shall be mapped, documented , authorised, and updated when changes occur. |
| ESSENTIAL | ID.AM-4.2 → ID.AM-04.2 | The flow of information to/from external systems The organisation shall map, document and authorise the flow of information to/from external systems and update the flow when changes occur. |
| ESSENTIAL | ID.AM-6.2 → GV.RR-02.2 | The organisation shall appoint The organisation shall appoint a senior-level executive information security officer. |
| ESSENTIAL | ID.BE-1.2 → GV.SC-01.1 | A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes shall be documented, reviewed, updated when changes occur, and approved by organisational stakeholders. |
| ESSENTIAL | ID.BE-5.2 → GV.OC-04.3 | Redundancy shall be implemented to meet availability requirements as defined by the organisation, legislation and/or regulations. |
| ESSENTIAL | ID.BE-5.3 → GV.OC-04.4 | Recovery time and recovery point objectives for the Recovery time and recovery point objectives for the resumption of essential ICT/OT system processes shall be defined and monitored. |
| ESSENTIAL | ID.RA-1.3 → ID.RA-01.4 | To ensure that organisation's operations are not adversely To ensure that organisation's operations are not adversely affected by the testing process, performance/load testing and penetration testing on the organisation’s systems shall be carried out with care. |
| ESSENTIAL | ID.RA-2.2 → ID.RA-02.2 | Automated mechanisms shall be implemented to disseminate security alerts and advisories to relevant organisation stakeholders. |
| ESSENTIAL | ID.SC-2.2 → GV.SC-07.2 | A documented list of all A documented list of all critical suppliers, vendors and partners of the organisation that may be involved in a major incident shall be established, kept up-to-date and made available online and off-line with due regard to confidentiality and security. |
| ESSENTIAL | ID.SC-3.2 → GV.SC-05.2 | Contractual Contractual information/cybersecurity requirements for suppliers and external partners shall be implemented to ensure a verifiable flaw resolution process and to ensure that deficiencies identified during information/cybersecurity testing and evaluation are remedied. |
| ESSENTIAL | ID.SC-3.3 → GV.SC-05.3 | The organisation shall establish contractual requirements permitting the organisation to review the The organisation shall establish contractual requirements permitting the organisation to review the information/cybersecurity programmes implemented by suppliers and third-party partners. |
| ESSENTIAL | ID.SC-4.2 → GV.SC-07.4 | The organisation shall The organisation shall ensure conformity with information/cybersecurity contractual obligations by suppliers and third-party partners through regular reviews of independent audits, assessments, and third party evaluations. |
| ESSENTIAL | PR.AC-1.3 → PR.AA-01.3 | System credentials shall be deactivated after a specified period of inactivity unless it would compromise the safe operation of (critical) System credentials shall be deactivated after a specified period of inactivity unless it would compromise the safe operation of (critical) processes. |
| ESSENTIAL | PR.AC-1.4 → PR.AA-01.4 | For transactions within the organisation's critical systems, the organisation shall For transactions within the organisation's critical systems, the organisation shall implement Multi Factor Authentication (MFA), cryptographic certificates, identity tokens, cryptographic keys and other credentials as appropriate and where feasible. |
| ESSENTIAL | PR.AC-2.3 → PR.AA-06.3 | Critical zones shall have additional physical access controls beyond those applied to general facilities. |
| ESSENTIAL | PR.AC-2.4 → PR.AA-06.4 | Assets Assets located within critical zones shall be physically protected against unauthorised access, damage, or interference. |
| ESSENTIAL | R.AC-3.5 → PR.AA-03.5 | The security The security for connections with external systems shall be verified and framed by documented agreements. |
| ESSENTIAL | PR.AC-4.8 → PR.AA-05.8 | Account usage restrictions for specific time periods and locations shall be Account usage restrictions for specific time periods and locations shall be taken into account in the organisation's security access policy and applied accordingly. |
| ESSENTIAL | PR.AC-4.9 → PR.AA-05.9 | Privileged users shall be managed, monitored and audited. |
| ESSENTIAL | PR.AC-5.5 → PR.IR-01.5 | The organisation shall implement, where feasible, authenticated proxy servers for defined communications traffic between The organisation shall implement, where feasible, authenticated proxy servers or firewalls with URL filtering and threat intelligence capabilities for defined communications traffic between its critical systems and external networks. |
| ESSENTIAL | PR.AC-5.6 → PR.IR-01.6 | The The organisation shall ensure that its critical systems are designed to fail securely and remain protected in the event of an operational failure of a border protection device. |
| ESSENTIAL | PR.AC-6.2 → PR.AA-02.2 | The organisation shall ensure The organisation shall ensure that unique credentials are used for each authenticated user, device, and process interacting with the organisation's critical systems. These credentials shall be verified, and the unique identifiers shall be captured during system interactions. Exceptions may be made for emergency access ("break-glass" procedures), provided such access is strictly controlled, logged, and reviewed. |
| ESSENTIAL | PR.AT-1.3 → PR.AT-01.4 | The organisation shall The organisation shall evaluate whether its cybersecurity awareness training is effective in improving knowledge, behaviour, and readiness across the organisation. |
| ESSENTIAL | PR.AT-3.4 → GV.SC-07.3 | The organisation shall audit business-critical The organisation shall audit business-critical third-party service providers for security compliance. |
| ESSENTIAL | PR.DS-1.1 → PR.DS-01.6 | The organisation shall protect its critical The organisation shall protect the confidentiality of its critical assets while at rest. |
| ESSENTIAL | PR.DS-2.1 → PR.DS-02.2 | The organisation shall protect its critical The organisation shall protect its critical and sensitive information while in transit. |
| ESSENTIAL | PR.DS-4.3 → PR.DS-10.1 | The organisation’s critical systems shall be protected against denial-of-service attacks or the effect of such attacks The organisation’s critical systems shall be protected against denial-of-service attacks or at least the effect of such attacks shall be limited. |
| ESSENTIAL | PR.DS-6.2 → PR.DS-01.2 | The organisation shall implement automated tools where feasible to provide notification upon discovering discrepancies during integrity verification. |
| ESSENTIAL | PR.DS-6.3 → PR.DS-01.3 | The organisation shall implement The organisation shall define and implement automated responses to detected integrity violations, using predefined safeguards that are proportionate to the severity and impact of the violation. |
| ESSENTIAL | PR.DS-7.1 → PR.IR-01.7 | The development and test The organisation shall ensure that development and test environments are strictly separated from the production environment, particularly in ICS/OT systems where any crossover could compromise safety, endanger health, or disrupt essential operations. |
| ESSENTIAL | PR.DS-8.1 → DE.CM-09.2 | The organisation shall implement hardware integrity checks to detect unauthorised tampering The organisation shall implement hardware integrity checks to detect unauthorised tampering of critical system hardware. Controls shall be proportionate to the organisation’s risk profile and operational capacity. |
| ESSENTIAL | PR.DS-8.2 → DE.CM-09.3 | The The organisation's incident response plan shall include measures to detect unauthorised tampering with the hardware of critical systems. |
| ESSENTIAL | PR.IP-1.2 → PR.PS-01.2 | The organisation shall configure its business-critical systems to The organisation shall configure its business-critical systems to operate with only the essential functions needed for the intended purpose. This includes reviewing and updating baseline configurations to disable any non-essential capabilities. |
| ESSENTIAL | PR.IP-2.2 → PR.PS-06.3 | Secure software development practices shall be integrated into all phases of the software development lifecycle, and their effectiveness shall be regularly monitored and improved. |
| ESSENTIAL | PR.IP-3.2 → PR.PS-06.4 | For planned changes to the organisation's critical systems, a security impact analysis shall be performed in a separate test environment before implementation in an operational environment. |
| ESSENTIAL | PR.IP-4.4 → PR.DS-11.4 | Backup The organisation shall regularly verify the integrity and recoverability of backups through coordinated testing with all relevant continuity and incident response functions. Backup testing shall be integrated into broader resilience planning, including business continuity, disaster recovery, and cyber incident response. |
| ESSENTIAL | PR.IP-4.5 → PR.DS-11.5 | Backups of critical systems (such as operating systems, configurations, and applications) shall be kept separate from backups of critical information (such as business data, documents, and databases) to support faster and more reliable recovery. |
| ESSENTIAL | PR.IP-7.2 → ID.IM-03.7 | The organisation shall implement independent teams to assess The organisation shall implement independent teams to assess its processes, best practices, and technology solutions to safeguard critical systems and assets. |
| ESSENTIAL | PR.IP-9.2 → ID.IM-04.2 | The organisation shall coordinate the development and The organisation shall coordinate the development and testing of Incident Response Plans and other cybersecurity plans that affect operations with stakeholders to ensure that these plans align with overall organisational goals and enhance resilience. |
| ESSENTIAL | PR.MA-1.5 → ID.AM-08.7 | The organisation shall prevent The organisation shall prevent unauthorised removal of maintenance equipment which contains critical system information of the organisation. |
| ESSENTIAL | PR.MA-1.6 → ID.AM-08.9 | Maintenance tools and portable storage devices shall be inspected Maintenance tools and portable storage devices shall be inspected as they enter the facility and shall be protected by anti-malware solutions that scan them for malicious code before they are used on the organisation's systems. |
| ESSENTIAL | PR.MA-1.7 → ID.AM-08.10 | The organisation shall verify security controls following The organisation shall verify security controls following maintenance or repairs/patching, and take action as appropriate. |
| ESSENTIAL | PR.MA-2.3 → ID.AM-08.13 | The organisation shall require The organisation shall require remote maintenance diagnostic services to be performed from a system that implements security features similar to the security features implemented on the equivalent organisation's critical system. |
| ESSENTIAL | PR.PT-1.4 → PR.PS-04.5 | The organisation shall The organisation shall ensure that authorised personnel can extend or enhance audit logging and monitoring capabilities when needed to support investigations or incident response. |
| ESSENTIAL | PR.PT-3.2 → PR.PS-01.3 | The organisation shall disable The organisation shall identify and disable specific functions, ports, protocols, and services within its critical systems that are not required for business operations. |
| ESSENTIAL | PR.PT-3.3 → PR.PS-01.4 | The organisation shall implement technical safeguards to enforce a policy of ‘deny-all’ and ‘permit-by-exception’ so that only authorised software programmes are executed. |
| ESSENTIAL | PR.PT-4.2 → PR.IR-01.8 | The organisation shall control the information The organisation shall define, monitor, and control the flow of information and data within and between its critical systems to ensure that only authorised and secure exchanges occur, regardless of network boundaries or system architecture. |
| ESSENTIAL | PR.PT-4.3 → PR.IR-01.9 | The organisation shall manage The organisation shall manage interfaces with external telecommunications services as part of its broader network security policy, by defining how traffic is controlled, ensuring the confidentiality and integrity of transmitted information, and reviewing and documenting any exceptions to established rules. |
| ESSENTIAL | DE.AE-2.2 → DE.AE-02.2 | The organisation shall implement automated mechanisms where feasible to review and analyse detected events. |
| ESSENTIAL | DE.AE-3.3 → DE.AE-03.3 | The organisation shall The organisation shall combine event analysis with information from vulnerability scans, system performance data, monitoring of critical systems, and facility monitoring, where feasible. |
| ESSENTIAL | DE.AE-4.1 → DE.AE-04.1 | The organisation shall assess the negative impacts of detected events on its operations, assets, and individuals, and shall link these impacts to the results of its risk assessments. |
| ESSENTIAL | DE.CM-1.3 → DE.CM-01.4 | The organisation shall The organisation shall continuously monitor its network to spot signs of cyber threats or unusual activity, using clearly defined rules for what counts as a potential security incident. |
| ESSENTIAL | DE.CM-2.2 → DE.CM-02.2 | Physical access to the organisation's critical systems and devices, in addition to physical access monitoring to the facility, shall be supplemented by physical intrusion alarms, surveillance equipment, and independent monitoring teams. |
| ESSENTIAL | DE.CM-4.2 → DE.CM-09.4 | The organisation shall The organisation shall establish a system to accurately distinguish between legitimate alerts and false positives, ensuring effective detection and removal of malicious code. |
| ESSENTIAL | DE.CM-7.2 → PR.PS-01.5 | Unauthorised configuration changes to Unauthorised configuration changes to organisation's systems shall be monitored and addressed with the appropriate mitigation actions. |
| ESSENTIAL | DE.DP-5.2 → ID.IM-03.9 | The organisation shall conduct specialised assessments including in-depth monitoring, vulnerability scanning, malicious user testing, insider threat assessment, performance/load testing, and verification and validation testing The organisation shall conduct specialised assessments including in-depth monitoring, vulnerability scanning, malicious user testing, insider threat assessment, performance/load testing, and verification and validation testing on the organisation's critical systems. |
| ESSENTIAL | RS.AN-1.2 → RS.MA-02.2 | Automated tools shall be used to support the investigation and impact assessment of validated cybersecurity incidents. |
| ESSENTIAL | RS.AN-3.1 → RS.AN-06.1 | Actions performed during an investigation shall be recorded, and the records' integrity and provenance shall be preserved. |
| ESSENTIAL | RS.AN-3.2 → RS.AN-03.1 | Each incident shall be analysed to determine what occurred and to identify its root cause. |
| ESSENTIAL | RS.AN-5.2 → ID.RA-08.2 | The organisation shall implement automated mechanisms The organisation shall implement automated mechanisms for disseminating and tracking remedial measures related to vulnerability information that automatically handles vulnerability data collection, disseminates information, tracks remedial measures, includes reporting and accountability, and enables continuous monitoring. |
| ESSENTIAL | RC.CO-1.2 → RC.CO-04.2 | The organisation shall assign a Public Relations Officer (PRO) to manage public communications during information/cybersecurity incident recovery, ensuring that public updates are shared while maintaining the confidentiality, integrity, and accuracy of the information. |
| ESSENTIAL | RC.CO-2.1 → RC.CO-04.3 | The organisation shall implement a crisis The organisation shall implement a crisis communication strategy to mitigate negative impacts during a crisis and help restore its reputation afterward. |
| ESSENTIAL | RC.RP-1.2 → RC.RP-02.1 | The The organisation's essential functions and services shall be continued with little or no loss of operational continuity, and continuity shall be maintained until full system recovery. |
Most 2023 descriptions were redrafted for 2025, so in that table a change of obligation verb is reported only when the diff literally replaces one verb by another — a "shall" that merely appears in a rewritten sentence is not an obligation change. Between the two 2025 templates the edits are small, so any change of obligation verb is reported.
The texts are read straight from the CCB workbooks — the CyFun 2023 self-assessment tool (v2025-10-21) and the three CyFun 2025 templates — and compared word by word. A difference that is only spacing or an invisible character is not reported. The page is regenerated whenever the templates change, so it cannot drift away from them.
Every measure of the framework, with the 2023 measure it comes from and what changed, is listed on the measures page.