Completing a CyFun self-assessment can look manageable on paper. Preparing for verification is different. At that point, your team must show scope, evidence, ownership and implementation in a way that a Conformity Assessment Body can actually assess.
That is why CyFun verification should not be treated as a final-week compliance exercise. The CCB’s CyberFundamentals process starts with risk assessment and assurance-level selection, then moves through self-assessment, corrective measures, CAB assessment and label request. In practice, verification readiness depends on whether your documentation, technical controls and operational reality tell the same story.
Why Security Teams Often Start Too Late
Many teams underestimate the gap between “we have filled in the self-assessment” and “we are ready for external verification.” The first is often a structured internal exercise. The second requires evidence that is complete, current, traceable and owned.
Late preparation usually creates the same problems: unclear scope, missing proof, control owners who are not ready to explain their measures, and evidence that exists somewhere but is not easy to retrieve. A practical preparation plan prevents that scramble.
Checklist Part 1: Scope, Registration and Assurance Level
Start with the foundation. If the scope is unclear, every later evidence discussion becomes messy.
- Confirm whether NIS2 applies to the organisation.
- Define the organisational scope: legal entity, business units, locations and services.
- Define the technical scope: systems, networks, cloud services, identity platforms and outsourced services.
- Identify critical suppliers and dependencies.
- Register the organisation where required in the Safeonweb@work context.
- Use the CyFun Selection Tool or equivalent risk assessment process to determine the appropriate assurance level.
- Document why the selected level is appropriate.
- Check whether you are preparing for Basic, Important or Essential.
- Remember the distinction: Basic and Important relate to verification, while Essential involves certification.
This step is not administrative housekeeping. It determines what the CAB will expect to see and which controls need evidence.
Checklist Part 2: Self-Assessment, Evidence and Ownership
Once the scope and level are clear, turn the self-assessment into a proof pack. Each measure should have three things: a status, an owner and evidence.
Build a control tracker with these fields:
- CyFun measure or control reference
- Current self-assessment score or status
- Control owner
- Evidence owner
- Evidence location
- Last review date
- Open gaps
- Corrective action
- Target completion date
- Management acceptance, where relevant
Evidence should be specific. A policy document alone rarely proves that a measure works. For example, access control evidence may include policy, role design, identity platform screenshots, access review records and joiner-mover-leaver samples. Incident management evidence may include the procedure, escalation contacts, recent test records and lessons learned.
For each control, ask: can we show both design and operation? If the answer is no, mark the gap early.
Checklist Part 3: Internal Review, Training and Interview Prep
Before involving a CAB, run an internal readiness review. This should be more than a document check.
- Review whether evidence matches the declared scope.
- Confirm that control owners understand their responsibilities.
- Check that management reporting reflects the same risk picture as the self-assessment.
- Prepare teams for interviews.
- Make sure technical staff can explain how key measures work in practice.
- Verify that training obligations and awareness activities are documented.
- Test whether evidence can be retrieved quickly during assessment.
This is where many hidden issues surface. A control may be implemented, but only one person knows how to explain it. A policy may be approved, but the operational record may be incomplete. A dashboard may exist, but not cover the scoped environment.
Verification readiness is partly about cybersecurity maturity and partly about organisational coherence.
Checklist Part 4: CAB Selection and Verification Planning
A Conformity Assessment Body is not just a calendar item. Select one early enough to understand timelines, required documents and assessment expectations.
- Confirm that the CAB is authorised for the relevant CyFun work.
- Agree the intended scope before the assessment starts.
- Ask what evidence format the CAB expects.
- Clarify whether on-site verification of key measures is expected.
- Align availability of security, IT, risk, legal, procurement and management stakeholders.
- Reserve time for remediation if gaps are found.
- Plan final evidence freeze dates.
- Keep a version-controlled evidence pack.
Do not plan verification as if every control will be accepted immediately. A realistic timeline includes review, clarification and possible corrective actions.
Common Gaps to Fix Before Verification
The most common weaknesses are rarely exotic. They are usually practical.
- Scope does not match the actual technology environment.
- Supplier dependencies are not included in the risk picture.
- Evidence is outdated or undated.
- Policies exist but implementation proof is thin.
- Access reviews are inconsistent.
- Incident response is documented but not tested.
- Training is planned but not evidenced.
- Control owners are named, but not briefed.
- Management approval is missing.
- The self-assessment score is more optimistic than the evidence supports.
Treat these gaps as preparation signals, not failures. Finding them internally is far better than discovering them during verification.
Build a Simple CyFun Proof Pack
A useful proof pack does not need to be beautiful. It needs to be complete and navigable. Structure it around scope, risk assessment, self-assessment, control evidence, corrective actions, training, incident readiness, supplier management and management review.
Each folder or register should answer the same questions: what is the measure, who owns it, what evidence proves it, when was it last reviewed and what remains open?
That structure helps both the security team and the assessor. More importantly, it turns CyFun preparation into a repeatable operating model instead of a one-time document chase.
Make Verification the Logical End Point
CyFun verification becomes much less stressful when teams prepare from the evidence backwards. Start with scope. Select the right assurance level. Turn the self-assessment into owned controls. Gather proof that shows implementation, not just intention. Review internally before the CAB sees the file.
If security teams do that early, verification becomes what it should be: a structured confirmation of cybersecurity work already embedded in the organisation.