NIS2 in Belgium: What It Means for Your Organisation
Cybersecurity regulation in Belgium just got a lot more serious — and a lot more widespread. If you run a business here, there's a good chance NIS2 now applies to you, whether directly or through a client or supplier who expects you to comply.
Here's what you need to know.
What is NIS2, and why does it matter now?
NIS2 is the EU's cybersecurity directive (Directive (EU) 2022/2555), transposed into Belgian law through the Act of 26 April 2024 and in force since 18 October 2024. It's overseen by the Centre for Cybersecurity Belgium (CCB), which acts as the national cybersecurity authority, the national CSIRT, and the supervisory body, complete with its own inspection service.
The scale-up is dramatic. Its predecessor, NIS1, covered only a few hundred organisations. NIS2 pulls in more than 4,000 Belgian entities directly — and through supply-chain requirements, many more companies feel the ripple effects even if they're not technically "in scope."
Are you in scope?
Two criteria apply together:
- Your sector — 18 sectors are covered, including energy, transport, health, digital infrastructure, ICT service management, food, chemicals, waste, manufacturing, and public administration.
- Your size — generally, organisations with 50+ employees or €10 million+ in turnover.
There's no formal designation process anymore. You're expected to assess your own status.
Depending on your profile, you'll fall into one of two categories:
- Essential entity (large, most critical sectors): Proactive, regular supervision. Mandatory conformity assessment by an external body.
- Important entity (often mid-sized players): Ex-post supervision. No audit up front, but you must be demonstrably compliant when the CCB calls.
Not in scope? You may still be affected. NIS2 entities are required to assess their supply chains and pass compliance requirements down to suppliers and IT partners contractually. The CCB recommends every organisation in that chain reach CyFun Basic as a minimum — and it can designate an organisation as critical after the fact, regardless of size.
The core obligations
If NIS2 applies to you, here's what's expected:
- Registration with the CCB via the Safeonweb@work portal.
- Risk-management measures (per Article 21): risk analysis and security policy, incident handling, backup and continuity planning, supply-chain security, patch and vulnerability management, cryptography, access and asset management, multi-factor authentication (MFA), cyber hygiene and training, and periodic effectiveness reviews.
- Incident reporting, on a strict timeline: a 24-hour early warning, a 72-hour incident notification, and a final report within one month. Ransomware incidents trigger additional reporting questions.
- Management accountability: your management body must approve security measures, oversee implementation, and undergo training itself. Personal liability for directors is a real possibility.
CyberFundamentals (CyFun®): turning legal text into action
Rather than leaving organisations to interpret the law in a vacuum, the CCB built CyFun, a practical framework that translates NIS2's requirements into concrete, verifiable measures. It draws on NIST CSF 2.0, ISO 27001, the CIS Controls, and IEC 62443.
A CyFun or ISO/IEC 27001 verification gives you a presumption of conformity — and it's popular for good reason: roughly three in four entities choose CyFun because it's more accessible for SMEs than pursuing full ISO certification from scratch.
CyFun comes in four levels, each building on the last:
- Small — 7 measures (free), intended for micro-organisations and entry level use.
- Basic — ~34 measures, covering ~82% of common attack techniques, intended for SMEs and suppliers in the chain.
- Important — ~132 measures, covering ~94% of common attack techniques, intended for important entities.
- Essential — ~217 measures, covering ~100% of common attack techniques, intended for essential entities and critical infrastructure.
Attack coverage refers to the CCB's estimate of protection against the most common attack techniques.
The path to compliance generally looks like this: (1) carry out a risk assessment and choose your level, (2) complete a self-assessment with supporting evidence, and (3) get verification or certification from a BELAC-accredited Conformity Assessment Body (CAB).
One important caveat: a CyFun label isn't the same as full NIS2 compliance. Things like your incident-reporting deadlines still need to be documented separately in your own procedures.
Key dates to know
- 18 Oct 2024 — Belgian NIS2 Act enters into force.
- 18 Mar 2025 — Deadline for registration with the CCB.
- 18 Apr 2026 — Essential entities submit their first conformity assessment: a CAB verification at Basic or Important level, or their ISO 27001 scope and Statement of Applicability. Entities under the inspection route submit a self-assessment.
- 18 Apr 2027 — Target level reached: full Essential or ISO 27001 certification, or a progress report under inspection supervision. Entities designated later follow the same 18- and 30-month timeline, counted from their notification date.
What happens if you don't comply?
The penalties are steep. Essential entities face administrative fines of up to €10 million or 2% of worldwide annual turnover; important entities face up to €7 million or 1.4%. Beyond fines, the CCB can issue binding instructions, publicly disclose a breach, temporarily suspend a service, and hold directors personally liable.
That said, the CCB has said it's taking a coaching approach rather than a purely punitive one. Still, organisations that can't show any genuine effort toward compliance are in a weak position if — or when — the CCB comes calling.
Where to start
Getting NIS2-ready generally breaks down into three stages:
- Scope & baseline — Work out whether and how you're in scope, choose the right CyFun level, and run a gap analysis of your current environment against that level, with a prioritised action list and budget.
- Technical remediation — Address identity and MFA/conditional access, endpoint protection and 24/7 detection, next-gen firewalls and network segmentation, backup and recoverability, patch management, and logging/monitoring.
- Evidence & upkeep — Put policies and procedures in place, build an incident response plan around the 24/72-hour reporting flow, document evidence for each measure, deliver awareness training, and prepare for CAB verification.
Brick9 supports you through each of these three stages with the Brick9 NIS2 Readiness Tool: from initial scoping and gap analysis, through tracking technical remediation progress, to gathering and documenting evidence for CAB verification. That gives you full oversight of the entire journey in one central tool.
Curious where your organisation stands? Book a no-obligation conversation and we'll walk through your NIS2 journey together.
This article is informative and general in nature. Your actual obligations depend on your specific sector, size, and risk assessment, and this should not be taken as legal advice. For a tailored assessment of your NIS2 status, consider a no-obligation scan with a specialist partner such as Brick9 (brick9.com).
Sources: ccb.belgium.be, atwork.safeonweb.be, the Belgian Act of 26 April 2024 (NIS2) and its implementing Royal Decree.
