Frameworks
Prove your security story with Cyra
Without Cyra certification, Dutch customers and government partners question your security maturity.
Tidal makes certification achievable. Progress through maturity levels systematically, implement controls across all domains, and achieve the certification that opens doors to bigger opportunities.

CYRA in depth
CYRA stands for Cyber Rating, the certification scheme administered by het CCV, the Dutch Centre for Crime Prevention and Safety. It rates how far an organisation has taken its digital resilience, and it draws its control measures from ISO/IEC 27001 and ISO/IEC 27701 for IT, the NEN 7510 series for health care, and parts 2-1 and 3-3 of IEC 62443 for operational technology.
In practice, cyber maturity gets claimed rather than rated. A supplier states that it takes security seriously, the customer has no yardstick to hold that against, and both fall back on a questionnaire.
By working towards a CYRA certificate, the comparison becomes concrete. Levels and control measures are fixed in the scheme and assessed by a certification body licensed by the CCV, so a customer can ask for a level instead of a promise.
How Tidal helps you get certified
Hit the ground running
Start with our pre-built controls, policies, and risk assessment templates.
Our platform guides you through establishing your ISMS scope, identifying assets, and implementing right-sized controls that match your business needs.


Why Tidal Control
We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.
Made in Europe
Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.
Continuous automation
Automated evidence collection from cloud providers and development tools working 24/7 for you.
Real security
Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.
Go beyond Cyra
Explore complementary frameworks that strengthen your cybersecurity maturity.
ISO 27001
Building international security foundations? ISO 27001 provides the security framework that underpins Cyra maturity, enabling both local and global recognition.
NIST SP 800-53
Aligning with global security standards? NIST SP 800-53 provides complementary controls that enhance Cyra's security approach with international best practices.
ABDO
Protecting defence contracting work? ABDO security requirements complement Cyra for defence organisations and contractors.
BIO
Meeting government security requirements? BIO aligns with Cyra's maturity approach for Dutch government organisations and their suppliers.
Integrate with your existing tools

Testimonials
What our customers say
With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.
Frequently asked questions
CYRA (Cyber Rating) is a Dutch cybersecurity maturity certification scheme administered by het CCV, the Centre for Crime Prevention and Safety. It helps organisations demonstrate their security capabilities, and it's increasingly required by Dutch government and private sector organisations when selecting suppliers and partners, particularly for critical services.
CYRA runs over four levels: Entry, Basic, Intermediate, and Advanced. Which one to target depends on your sector, customer requirements, and risk profile, and most organisations aim for Entry or Basic first and grow from there. Our platform helps you assess where you stand and plan the step to your target level.
CYRA draws its control measures from ISO/IEC 27001 and ISO/IEC 27701 for IT, the NEN 7510 series for health care, and parts 2-1 and 3-3 of IEC 62443 for operational technology. If you've implemented any of these, you'll have a strong foundation for CYRA. Our platform helps you map existing controls to CYRA requirements.
Timeline depends on the level you target and your current security posture. Reaching Entry or Basic typically takes 3-6 months, and the step up to Intermediate usually takes another 6-9 months. Our platform helps you implement efficiently with clear requirements and automated evidence collection.
The scheme is split into subdomains: CYRA-IT, CYRA-OT, CYRA-Health Care, and CYRA-NDO for resilience against digital criminal infiltration. We provide pre-built controls, guide you through implementation, and help maintain evidence across the subdomains in your scope.
Our platform continuously monitors your security controls, tracks evidence of maturity maintenance, and schedules required assessments. You'll receive alerts for upcoming reviews and any gaps, helping you maintain certification and progress to higher maturity levels over time.


























