NIS2 in Belgium and your SME

NIS2 is no longer a future mandate—it is active Belgian law. With key regulatory milestones already behind us and final certification deadlines approaching, mid-sized and small businesses must act now to secure their compliance and avoid severe operational bottlenecks.

Why preparation cannot wait? Thousands of Belgian organizations require formal auditing before the April 2027 cutoff. However only two accredited Conformity Assessment Bodies (CABs) are currently authorized to deliver CyFun certification in Belgium. Organisations that structure their compliance early will secure priority scheduling. Those that delay risk extended waiting lists, missed deadlines, and regulatory exposure.

Non-compliance risks:
Financial penalties: Fines reaching up to €10 million or 2% of total global annual turnover (NIS2 Article 83)
Leadership accountability: Direct personal liability for executive leadership and management boards for compliance failures.

Navigating NIS2 does not have to disrupt your core operations. We designed this resource hub specifically to help SMEs understand their obligations, streamline CyFun/ISO 27001 readiness, and guarantee timely audit placement.

Let's cover the basics

NIS2 and the four terms you need

NIS2 Legislation

The European Union’s upgraded cybersecurity framework obligates thousands of mid-sized and large enterprises—along with their extended supply chains—to validate baseline security posture. Belgium became the first EU member state to formally enact this into national legislation via the Law of 26 April 2024.

CyberFundamentals (CyFun) Framework

A free guidance standard published by the Centre for Cybersecurity Belgium (CCB) outlining concrete compliance benchmarks. The framework is structured across four tiers: Small (7 controls), Basic (34 controls), Important (132controls), and Essential (217 controls). Most SMEs land on Basic.

Conformity Assessment Body (CAB)

An accredited, third-party auditing agency officially authorized to evaluate an organization's CyFun posture and grant formal certification. While specialized security partners handle technical gap remediation and preparation, the CAB conducts the official audit.

Audit-Readiness

The operational state where every required security measure is properly implemented, fully documented, and backed by verifiable proof. Being audit-ready ensures your business meets all necessary criteria before the formal CAB evaluation takes place.

Why Brick9?

Word NIS2 audit-ready met Brick9

Before diving into NIS2, it is important to understand how the cyber threat landscape has shifted: no business is too small to be a target. In the AI era, attackers no longer need massive budgets to execute sophisticated cyberattacks. However, strengthening your digital environment shouldn't just be a matter of regulatory obligation. Compliance frameworks like NIS2 exist as a direct response to these growing threats and the clear necessity for active defense.

Most SMEs fall under the CyberFundamentals (CyFun) Basic level, which involves 34 controls organized across six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. These measures include everyday security essentials—such as maintaining an up-to-date hardware inventory, enforcing Multi-Factor Authentication (MFA) across all corporate accounts, restricting user permissions to strictly what is needed, and isolating administrative accounts for dedicated use.

If navigating these requirements sounds complex, you do not have to do it alone. Will Brick9 make you NIS2 compliant? We make your organization audit-ready. As your IT Managed Service Provider (MSP), we implement, document, and maintain the necessary technical controls to meet every requirement. Once your infrastructure is fully prepared, an accredited Conformity Assessment Body (CAB) auditor conducts the official assessment and awards your certification.

een donkere afbeelding met de tekst NIS2 en symbolen voor cyberbeveiliging als achtergrond
How it works?

How that process works in 5 steps?

1

Scoping call

An initial exploratory discussion to understand your business operations, supply chain connections, and digital ecosystem. This conversation allows us to evaluate your baseline needs with zero obligation to proceed.

2

Gap assessment

Using specialized evaluation tools, we determine your required target tier. While most SMEs qualify for the Basic level, organizations operating in critical sectors or take part of their supply chain may require Important or Essential status. We then evaluate and score your posture against every required control using the Brick9 tool.

3

Gap close plan and price

Following the assessment, we build a structured gap-closing plan that covers both technical implementation and necessary documentation. You will receive a clear proposal outlining the initial remediation costs alongside a flexible monthly or quarterly maintenance plan to ensure that the gap will stay closed! You will receive a quote with a clear pricing.

4

Gap-closing phase

This is the critical implementation stage where your customized remediation plan is actively executed. Technical improvements often include Microsoft 365 environment upgrades, organization-wide Multi-Factor Authentication (MFA) deployment, and the configuration and testing of secure cloud backups. We conclude this phase with a final security posture check and a comprehensive trial run against the official CAB checklist to guarantee audit readiness.

5

The recurring service

Once the initial security gaps are resolved, we transition to a scheduled monthly or quarterly review process. Your IT infrastructure is highly dynamic, meaning your security posture must continually adapt. As personnel change, new policies are drafted, and backup systems require routine testing, we provide ongoing management and oversight to ensure your organization remains permanently audit-ready.

two friendly people at office shaking hands in accord
FAQs

In this section we address some of the commom questions

question and answers image with 2 people pointing at a question mark
Read our insights

Latest blog posts

an white icon of an user on the black background.
Brick9 team
an white icon of an user on the black background.
5 min

NIS2 in Belgium: What It Means for Your Organisation

If you run a business In Belgium there's a good chance NIS2 now applies to you, whether directly or through a client or supplier who expects you to comply.

Read more
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
5

The Silenced Ring: Why Outdated Telephony is Ghosting Your Customers

If your business phone system relies on physical hardware tucked away in a server closet or a meter cupboard, you are fighting a modern war with obsolete tools.

Read more
an white icon of an user on the black background.
Brick9 Teams
an white icon of an user on the black background.
7min

Is your printing a burden on your modern workplace?

Your team works with the most advanced cloud tools, yet the printer is still the factor dragging down productivity.

Read more
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
5min

The hidden dangers of old corporate IT

The misunderstanding of the "Reset button" and why "deleting" is not enough

Read more
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
7 min

Is my SME a target to hackers

"We are too small to be interesting to hackers." But the reality of 2026 strongly contradicts that assertion.

Read more