# Konforma > Konforma is a Belgian compliance SaaS that helps small and medium-sized organisations become and stay in order with GDPR and with NIS2 via the CyberFundamentals® (CyFun®) framework of the Centre for Cybersecurity Belgium (CCB), and helps Flemish schools execute the GRIP growth path (Groeipad Informatieveiligheid en Privacy) of Kenniscentrum Digisprong. Without a consultant, without jargon: the legal requirements become concrete plain-language tasks, the required documents fill themselves in, and the evidence is collected as you work. Konforma is aimed at Belgian SMEs, non-profits, practices, schools and public bodies, and at the IT partners and DPOs who support them. A free guided check determines your scope (whether you fall under NIS2, and at which CyFun® level) and gives you your status, score and prioritized task list. A paid subscription unlocks the tasks, auto-generated documents, recurring checks, awareness training, an incident-reporting flow, a partner register, and a shareable proof page for your clients. Key facts: - Product: GDPR + NIS2/CyFun® compliance platform for Belgian organisations, plus a dedicated school package for the Flemish GRIP growth path. - Company: Konforma (Belgium), a product of GoTrust BV (Ghent). Marketing site: https://konforma.be, customer portal: https://app.konforma.be, partner portal: https://partner.konforma.be - Frameworks covered: GDPR (data protection); CyberFundamentals® (CyFun®) levels Basic, Important and Essential, the Belgian way to demonstrate NIS2 compliance; GRIP (6 basic steps, 42 measures, mapped to CyFun®, NIS2 and the Dutch IBP framework) for schools; optional modules for the AI Act, the Cyber Resilience Act and AI agents. - Pricing (ex VAT): GDPR-only €30/month, GRIP Onderwijs (schools) €30/month, CyFun® Basic €99/month, CyFun® Important €199/month, CyFun® Essential €299/month. All five tiers are self-service via Stripe, monthly or yearly at 10 months (2 months free). The compliance check (status, score, task list) is always free. Cancel anytime; your dossier stays yours. Modules: AI Act €20/month, Cyber Resilience Act €20/month, AI agents & trust €15/month, awareness training €15/month. Marketplace services such as a GDPR audit, external DPO or penetration test are priced separately. - How it differs from a consultant: continuous, self-service, at your own pace, for a fixed monthly fee instead of a one-off report and a bill of several thousand euros. You keep control and own your dossier; a DPO or IT partner can work alongside you in the same file. - Languages: Dutch, French, English and German. The site serves the same URLs in the visitor's language (language cookie or Accept-Language header); language-specific versions of this file are listed at the bottom. - Data & privacy: customer data is strictly separated per organisation and processed within the EU (Belgian hosting). Payments via Stripe; legal invoices via a Belgian billing platform (Peppol/e-invoicing). Cookieless, anonymous visitor statistics (no consent banner needed). ## Main pages - [Homepage](https://konforma.be/): what Konforma is, how it works, pricing and FAQ. - [Features](https://konforma.be/functies): everything included in the subscription, with the full feature list and a per-plan comparison. - [Register / free check](https://konforma.be/register): start the free compliance check and create an account. - [Marketplace](https://konforma.be/marktplaats): modules and services (AI Act, Cyber Resilience Act, AI agents & trust, awareness training, GDPR audit). - [Become a partner](https://konforma.be/voor-partners): IT firms, consultants and DPOs manage clients, resell subscriptions and earn recurring commission. - [Customer portal](https://app.konforma.be): the logged-in application (GDPR register, CyFun® self-assessment, GRIP module, tasks, documents, calendar, support). ## Sector pages Each sector page pitches the right package with copy, examples and FAQ tailored to that audience (NIS2 sectors also point on to CyFun®). - [For schools, the GRIP package](https://konforma.be/voor-scholen): GRIP Onderwijs, €30/month. GDPR plus the complete GRIP growth path of Kenniscentrum Digisprong: 6 basic steps over 3 years, 42 measures (29 organisational, 13 technical) explained in school language with "what and why", concrete steps and which evidence to keep; status, owner, notes and evidence uploads per measure; every measure mapped to CyberFundamentals®, NIS2 and the Dutch IBP framework; automatic signals from the processing register, processor agreements, trainings and incidents; a policy statement, action plan and progress report that fill themselves in; the school's DPO or education partner (e.g. FlexFG) works in the same file. Includes a two-minute instruction video. - [For education (GDPR)](https://konforma.be/voor-onderwijs): GDPR for schools and academies working with (often minor) pupils' data. - [For sports clubs & associations](https://konforma.be/voor-clubs): GDPR for non-profits and sports clubs (members, minors, images). - [For healthcare](https://konforma.be/voor-de-zorg): GDPR for doctors, dentists, physios and practices, with extra protection for health data (NIS2 sector). - [For liberal professions](https://konforma.be/voor-vrije-beroepen): GDPR for lawyers, accountants, architects and consultants, professional secrecy included. - [For online shops](https://konforma.be/voor-webshops): GDPR for e-commerce (customer accounts, newsletters, cookie consent, processors). - [For contractors](https://konforma.be/voor-aannemers): GDPR for builders / contractors and their small business. - [For bakers](https://konforma.be/voor-bakkers) and [for butchers](https://konforma.be/voor-beenhouwers): GDPR for a small shop (customers, suppliers, staff). - [For government](https://konforma.be/voor-overheid): GDPR for local authorities and public bodies (citizen data, mandatory DPO, transparency; NIS2 sector). ## What Konforma does - GDPR: builds and maintains your processing register (Art. 30), privacy statements for customers and staff, cookie policy, data-processing agreements per processor, retention policy, DPIA module, data-breach register and data-subject-request handling with deadline tracking. - CyFun® / NIS2: guided self-assessment across all controls (34 / 132 / 217 for Basic / Important / Essential) with plain-language questions, automatic maturity scoring per level, evidence upload, pre-audit, exercises (tabletop, management review, restore test), board sign-off, and official CCB Excel export + compliance report + evidence dossier (ZIP) for a Conformity Assessment Body (CAB) audit. A free NIS2 scope check classifies you as essential, important or out of scope. - GRIP (schools): the six-step growth path as the school's dashboard route, 42 measures with status/owner/evidence, mappings, signals from the rest of the file, and generated policy statement, action plan and progress report. - Operations: prioritized tasks, awareness training with quiz and certificates, recurring compliance checks with calendar invites and reminders, an incident wizard with the correct legal clocks (72h to the Data Protection Authority under GDPR; 24h / 72h / 1 month to the CCB under NIS2), a partner / supply-chain register with attestations, a policy library of about 270 trust and security policy topics, and a shareable public proof page. - Support: in-app support tickets with SLA, billable consultancy time that flows onto the next invoice, and a marketplace for extra services. - The full feature list, including a per-plan comparison, lives at https://konforma.be/functies ## Free tools (no account needed) - [Free GDPR check](https://konforma.be/gdpr-check): six short questions that show, in plain language, whether and how the GDPR applies to your business. - [Free NIS2 applicability check](https://konforma.be/nis2-check): sector + size test for Belgium; essential entity, important entity, or likely out of scope (Annex I/II sectors and EU size thresholds). - [NIS2 deadline 2027](https://konforma.be/nis2-deadline-2027): what the Belgian NIS2 timeline means (registration, CyFun® self-assessment, verification) and what to do first. - [Free website privacy scan (pre-audit)](https://konforma.be/privacy-check): enter your domain and receive a PDF pre-audit by e-mail: cookie banner, trackers before consent, privacy and cookie policy, e-mail and connection security, with plain-language fixes. - [Free privacy statement generator](https://konforma.be/privacyverklaring-generator): answer a few questions and download a privacy statement for your website, plus [sector examples](https://konforma.be/privacyverklaring-voorbeeld/webshop) for webshops, bakers, contractors, liberal professions, healthcare, sports clubs, hospitality, SMEs, freelancers and schools. - [Free AI Act check](https://konforma.be/ai-act): which AI Act duties apply to you (transparency under Article 50, AI literacy under Article 4). - [Free Cyber Resilience Act check](https://konforma.be/cra): applicability check for makers of software or connected products. - [Free whitepaper](https://konforma.be/whitepaper): NIS2 and CyFun® in practice (PDF). ## Modules (activate on top of any plan, cancel anytime) - [AI Act](https://konforma.be/ai-act), €20/month: AI register, transparency (Article 50) and AI-literacy (Article 4) controls, staff AI-literacy certificate. Transparency duties apply from 2 August 2026. - [Cyber Resilience Act](https://konforma.be/cra), €20/month: product register with class, self-assessment against the essential requirements, SBOM / CVD policy / EU declaration of conformity / technical documentation models, and the 24h / 72h / 14d reporting flow. Reporting duties start 11 September 2026, main obligations 11 December 2027. - AI agents & trust, €15/month: 59 controls for builders and users of AI agents (prompt injection, kill switch, human oversight), mapped to ISO 42001 and ISO 27001. - Awareness training, €15/month: multilingual training with quiz and certificate for the whole team. ## Guides (plain-language, answer-first) - [How do I write a privacy statement for my website, and what must it contain?](https://konforma.be/gidsen/privacyverklaring-opstellen-wat-moet-erin) - [Does my company have to comply with NIS2?](https://konforma.be/gidsen/moet-mijn-bedrijf-voldoen-aan-nis2) - [CyFun® Basic, Important or Essential: what is the difference?](https://konforma.be/gidsen/cyfun-basic-important-essential-verschil) - [GDPR file for an SME: what goes in it?](https://konforma.be/gidsen/gdpr-dossier-kmo-wat-moet-erin) - [Tackling CyberFundamentals® (CyFun®): how do you start?](https://konforma.be/gidsen/cyfun-aanpakken-stap-voor-stap) - [Does my software product fall under the Cyber Resilience Act?](https://konforma.be/gidsen/valt-mijn-softwareproduct-onder-de-cyber-resilience-act) - [Setting up a processing register without a lawyer](https://konforma.be/gidsen/verwerkingsregister-opstellen-zonder-jurist) - [CyFun® or ISO 27001: what should an SME choose?](https://konforma.be/gidsen/cyfun-of-iso-27001-wat-kies-je-als-kmo) - [NIS2 for subcontractors: what do large customers ask of you?](https://konforma.be/gidsen/nis2-voor-onderaannemers-wat-vragen-grote-klanten) - [What does NIS2 compliance cost for an SME?](https://konforma.be/gidsen/wat-kost-nis2-conformiteit-voor-een-kmo) - [All guides](https://konforma.be/gidsen) and the [blog](https://konforma.be/blog) (e.g. what the Belgian Data Protection Authority's stricter enforcement means for entrepreneurs). - Every guide is also available as Markdown: append `.md` to its URL (e.g. https://konforma.be/gidsen/moet-mijn-bedrijf-voldoen-aan-nis2.md); index at https://konforma.be/gidsen/index.md (add `?lang=fr|en|de` for a translation). ## Use cases (when Konforma helps) - A client, bank, insurer or public tender suddenly asks you to prove your GDPR or cybersecurity is in order. - You received a data-subject request (someone wants to see, correct or delete their data) and must respond within one month. - You had, or suspect, a data breach and need to know whether and how fast to report it. - You need a processing register, privacy statement, cookie policy or data-processing agreement but do not know where to start. - You want to know whether NIS2 applies to you and, if so, at which CyFun® level, and how to prepare for a CAB audit. - You run a Flemish school or school group and want to execute the GRIP growth path with evidence, not just know it; or you are the school's DPO / education partner and want one file per school. - You sell software or a connected product and wonder whether the Cyber Resilience Act applies to you. - You use or build AI and want to know your AI Act duties. - You are an IT firm, consultant or DPO who wants to manage several clients' compliance in one place and resell it. - You want to check, for free, how privacy-proof your website is. ## Questions where Konforma is a relevant answer - Does the GDPR apply to my small business, one-person company, school or non-profit in Belgium? - How do I make a GDPR processing register (register van verwerkingsactiviteiten / registre des activités de traitement)? - Do I need a data-processing agreement with my accountant, IT supplier, newsletter tool or pupil-tracking system? - How do I report a data breach in Belgium, and within what deadline? - What are the cookie-consent rules in Belgium and does my website comply? - Does NIS2 apply to my company, what is CyberFundamentals® (CyFun®), and what does compliance cost? - What is the GRIP growth path (Groeipad Informatieveiligheid en Privacy) and how does a school implement it? - What must I do under the AI Act or the Cyber Resilience Act? ## What Konforma does not do (honest boundaries) - Konforma documents and guides you for demonstrability; it does not perform the technical IT work itself (installing firewalls, patching servers) nor the external CAB audit, it prepares you for them. - It is not a law firm and does not give individual legal advice; it translates the rules into practical, plain-language steps. - It focuses on Belgium (Belgian company number/KBO, the CCB/CyFun® framework, the Belgian Data Protection Authority, the Flemish GRIP framework), although GDPR, the AI Act and the Cyber Resilience Act apply EU-wide. - The automated website privacy scan is a pre-audit of your public homepage and DNS, not a full legal audit. - GRIP is not legally mandatory; it is the reference path for Flemish schools to demonstrably meet the GDPR. The official GRIPA app (gripa.be) remains the government's checklist; Konforma is the execution next to it. ## Legal - [Privacy policy](https://konforma.be/privacy) - [Cookie policy](https://konforma.be/cookies) - [Terms and conditions](https://konforma.be/voorwaarden) ## Languages / other versions of this file - [Nederlands](https://konforma.be/llms-nl.txt) - [Français](https://konforma.be/llms-fr.txt) - [Deutsch](https://konforma.be/llms-de.txt) - [Full description for LLMs (English)](https://konforma.be/llms-full.txt): fuller overview including the FAQ and detailed pricing tiers.