Skip to main content
🇳🇱 Netherlands (CCV)

CYRA — the Cyber Resilience Assessment for SMEs

A Dutch national maturity method (CCV) that helps growing organisations measure and improve their cyber resilience — a pragmatic step before ISO 27001 or NIS2.

What is CYRA?

CYRA (Cyber Resilience Assessment) is a Dutch maturity and certification method managed by the CCV (Centrum voor Criminaliteitspreventie en Veiligheid). It is designed for SMEs and growing organisations that need a structured, achievable path to cyber resilience.

It assesses maturity across IT security, privacy and supply-chain responsibility, with an optional OT module, building on the NIST CSF functions. It is an ideal on-ramp toward NIS2 and ISO 27001.

The CYRA domains

Govern, Identify, Protect

Governance and organisation, asset and risk identification, protective measures.

Detect, Respond, Recover

Monitoring, incident response and continuity/recovery — the NIST CSF core.

Privacy & Supply chain

Personal-data protection and third-party responsibility modules.

OT (optional)

Operational-technology measures aligned to IEC 62443.

CYRA with ResiPlan

ResiPlan includes the CYRA measure catalogue and runs a 0–4 maturity GAP analysis with evidence and an exportable report.

Cross-mapping links CYRA to ISO 27001 and NIS2 — rate ISO 27001 once and the equivalent CYRA measures fill in automatically, so your CYRA assessment is a head start, not extra work.

Frequently asked questions

What is CYRA?

CYRA (Cyber Resilience Assessment) is a Dutch cyber-resilience maturity and certification method for SMEs, managed by the CCV since January 2025.

Is CYRA the same as the Cyber Resilience Act (CRA)?

No. CYRA is a Dutch maturity assessment method; the CRA is a separate EU regulation on the security of products with digital elements.

Does CYRA help with NIS2?

Yes — CYRA is built on the NIST CSF functions and maps to NIS2 and ISO 27001, making it a practical first step toward those obligations.

Can I assess CYRA and ISO 27001 together?

Yes. In ResiPlan you cover both in one assessment: rating ISO 27001 controls auto-fills the equivalent CYRA measures through cross-mapping.

Other frameworks

ResiPlan covers 10 frameworks with cross-mapping: assess once, prove everywhere.

Assess your CYRA compliance

Run a maturity gap analysis, attach your evidence and generate a report — with cross-mapping to the other frameworks.

CYRA — Cyber Resilience Assessment maturity model | ResiPlan