Frameworks

Prove your security story with Cyra

Without Cyra certification, Dutch customers and government partners question your security maturity.

Tidal makes certification achievable. Progress through maturity levels systematically, implement controls across all domains, and achieve the certification that opens doors to bigger opportunities.

Product screenshot

CYRA in depth

CYRA stands for Cyber Rating, the certification scheme administered by het CCV, the Dutch Centre for Crime Prevention and Safety. It rates how far an organisation has taken its digital resilience, and it draws its control measures from ISO/IEC 27001 and ISO/IEC 27701 for IT, the NEN 7510 series for health care, and parts 2-1 and 3-3 of IEC 62443 for operational technology.

In practice, cyber maturity gets claimed rather than rated. A supplier states that it takes security seriously, the customer has no yardstick to hold that against, and both fall back on a questionnaire.

By working towards a CYRA certificate, the comparison becomes concrete. Levels and control measures are fixed in the scheme and assessed by a certification body licensed by the CCV, so a customer can ask for a level instead of a promise.

How Tidal helps you get certified

Why Tidal Control

We understand your challenges because we've been there. Our team of GRC experts and security professionals built Tidal to solve the real problems compliance teams face every day.

Made in Europe

Built and hosted in Europe. Your compliance data stays in the EU for full control and peace of mind.

Continuous automation

Automated evidence collection from cloud providers and development tools working 24/7 for you.

Real security

Build secure systems that protect your business and satisfy auditors, not just check compliance boxes.

Integrate with your existing tools

Testimonials

What our customers say

With a single click, one Tidal test checks dozens of disks for encryption. Doing that manually would take a lot of time.

Profile picture of Chiel Bos
Chiel Bos
COO·CBYTE
CBYTE logo

Frequently asked questions

CYRA (Cyber Rating) is a Dutch cybersecurity maturity certification scheme administered by het CCV, the Centre for Crime Prevention and Safety. It helps organisations demonstrate their security capabilities, and it's increasingly required by Dutch government and private sector organisations when selecting suppliers and partners, particularly for critical services.

CYRA runs over four levels: Entry, Basic, Intermediate, and Advanced. Which one to target depends on your sector, customer requirements, and risk profile, and most organisations aim for Entry or Basic first and grow from there. Our platform helps you assess where you stand and plan the step to your target level.

CYRA draws its control measures from ISO/IEC 27001 and ISO/IEC 27701 for IT, the NEN 7510 series for health care, and parts 2-1 and 3-3 of IEC 62443 for operational technology. If you've implemented any of these, you'll have a strong foundation for CYRA. Our platform helps you map existing controls to CYRA requirements.

Timeline depends on the level you target and your current security posture. Reaching Entry or Basic typically takes 3-6 months, and the step up to Intermediate usually takes another 6-9 months. Our platform helps you implement efficiently with clear requirements and automated evidence collection.

The scheme is split into subdomains: CYRA-IT, CYRA-OT, CYRA-Health Care, and CYRA-NDO for resilience against digital criminal infiltration. We provide pre-built controls, guide you through implementation, and help maintain evidence across the subdomains in your scope.

Our platform continuously monitors your security controls, tracks evidence of maturity maintenance, and schedules required assessments. You'll receive alerts for upcoming reviews and any gaps, helping you maintain certification and progress to higher maturity levels over time.