NIS2 in Belgium and your SME

NIS2 has been Belgian law since April 2024. The deadline for essential-entity selfassessment passed on 18 April 2026. CyFun certification or ISO 27001 must follow by April2027. This is not a future thing. It is happening now. We prepared this webpage espcially for you and your SME to address your common questions and concerns. Fines for non-compliance reach €10 million  (NIS2 Article 83)and executives can be held personally liable.

Thousands of entities need audits by April 2027. And at the moment two CAB auditors are accredited in Belgium to certify CyFun. The queue is already forming. Organisations that prepare early get scheduled first. Those who wait get pushed back and risk missing the deadline entirely.

Let's cover the basics

NIS2 and the four terms you need

NIS2

NIS2 is the EU's new cybersecurity law. It forces thousands of organisations, andcritically their whole supply chain, to prove they have basic security in place. Belgium was the first EU country to transpose it into national law (Law of 26 April 2024).

CyFun (CyberFundamentals Framework)

It is the free framework published by Belgium's Centre for Cybersecurity (the CCB) that shows organisations exactly how to meet therequirement. It has four levels: Small (7 controls), Basic (34 controls), Important (132controls), and Essential (217 controls). Most SMEs land on Basic.

CAB(Conformity Assessment Body)

It is the accredited auditor who officially checks against CyFun and issues a certificate. We get you audit-ready. The CAB does the audit.

Audit-ready

Audit-ready means every control is documented, evidenced, and above the passing threshold. It does not mean certified. Brick9 makes you audit-ready. A CAB auditor certifies the outcome.

Why Brick9?

Be NiS2 audit-ready with Brick9  

Before talking about NIS2, let's talk about what changed. No business is anymore too small to be a target. There are no more big budgets needed in the AI are for the attackers. Read more in our blog. Stay tuned!
But let's make it clear. You do not secure your digital inveronment because of the regulation only. The regulation exists as an aswer of the spreading threats and the necessity of taking measures.  

"It all sounds too complex?" This is why Brick9 is here for you.
Most of the SME land on Basic level (34 controls) that are organized across six functions: Govern, Identify, Protect, Detect, Respond, and Recover. An example of a Control would be: a maintained list of all hardware, MFA enforced on all accounts wirth access to business systems, users only having the permissons they need and admin acccounts ebing separate and used only for admin tasks, etc. You do not have to do all this alone. Brick9 will get you covered.

Will Brick9 make me NIS2 compliant?
We will make you audit-ready. Your IT MSP (Managed Service Provider) will make you audit-ready. The CAB auditor is the one who certifies compliance.

How it works?

How that process works in 5 steps?

1

Scoping call

This is the introductory first conversation, with which we will conduct a kind of first "interview" to learn more about your business, your customers and suppliers, and your digital resources. You do not have any commitment to go further.

2

Gap assessment (half day, on-site)

Using a specilizied tools we pick your level. Most of the SMEs fall under Basic level, but we for example, supply energy infrastructure, you may need Important or Essetial level. Using the Brick9 tool we score all the controls (34 if the level is Basic).    

3

Gap close plan and price

This step is exactly as it says. After the initial assessment, we develop a gap-closing plan inclusing both implementation and documentation (documentation must exist in your structure as evidence) and you receive a written proposal including a gap-closing price and a monthly or a quaterly plan - for that gap to stay closed!

4

Gap-closing phase

The essential phase where the plan is implemented. This may include but not only: M365 upgrade, MFA rollout, cloud backup configured and tested. Final score check and trial run against the CAB checklist.

5

The recurring service

After the gap-close we schedule a monthly or a quaterly review. Why is this necessary? Your business system is alive. It evolve and develops. You have ex employees, new hires, a policy that needs review, a backup that must be regularly testes, etc. Staying audit-ready is continuous.

FAQs

In this section we address some of the commom questions

Brick9 Solutions

Core Solutions for Your Business Success

Check Point MDR

Protect your organization 24/7 against the most advanced cyberattacks with Check Point MDR (Horizon). While your team focuses on core operations, top analysts and security experts monitor your entire IT infrastructure. With a unique "prevention-first" approach, AI-driven analytics, and immediate ...

Check Point Harmony Email & Collaboration

Protect your SME against the most advanced cyber threats with Check Point Harmony Email & Collaboration. This innovative, API-based solution integrates seamlessly with Microsoft 365 and Google Workspace to stop phishing, malware, and ransomware before they even reach your employees' inboxes.

NIS2 & The Brick9 Tool

Protect your SME against the most advanced cyber threats with Check Point Harmony Email & Collaboration. This innovative, API-based solution integrates seamlessly with Microsoft 365 and Google Workspace to stop phishing, malware, and ransomware before they even reach your employees' inboxes.

Modern Workplace

Optimize productivity, flexibility, and cybersecurity within your SME with a fully integrated Modern Workplace powered by Microsoft 365 Business Premium. Thanks to the powerful combination of trusted Office apps, cloud collaboration, and advanced identity management, ...

Managed Microsoft 365

Get the most out of your cloud environment and proactively protect your business data with Managed Microsoft 365 from Brick9. Many SMEs use Microsoft 365 for email and documents but lack the time or expertise to properly manage the complex security, licensing, and configurations.

IT & Cybersecurity Audit

Map your SME's digital vulnerabilities and strengthen your cyber resilience with an independent IT & Cybersecurity Audit from Brick9. Many organizations rely blindly on their current IT setup until a ransomware attack or data breach painfully exposes where the weak spots lie.

SaaS Backup

Protect your enterprise's most critical data with our SaaS Backup solution. Many companies mistakenly assume that Microsoft and Google are fully responsible for restoring their data. In reality, they offer only limited retention. Brick9 provides an independent, off-site copy of all your emails, files, and Teams data, ...

Cloud PBX & 3CX VoIP

Take your SME's communication to the next level with a Cloud PBX based on 3CX. With our VoIP solutions, you are no longer tied to a fixed telephone line at the office. Your team is reachable anywhere on their business number via their smartphone, laptop, or desktop, with the full functionality of a modern PBX.

Read our insights

Latest blog posts

an white icon of an user on the black background.
an white icon of an user on the black background.
5 min

NIS2 in Belgium: What It Means for Your Organisation

If you run a business In Belgium there's a good chance NIS2 now applies to you, whether directly or through a client or supplier who expects you to comply.

Read More
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
5

The Silenced Ring: Why Outdated Telephony is Ghosting Your Customers

If your business phone system relies on physical hardware tucked away in a server closet or a meter cupboard, you are fighting a modern war with obsolete tools.

Read More
an white icon of an user on the black background.
Brick9 Teams
an white icon of an user on the black background.
7min

Is your printing a burden on your modern workplace?

Your team works with the most advanced cloud tools, yet the printer is still the factor dragging down productivity.

Read More
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
5min

The hidden dangers of old corporate IT

The misunderstanding of the "Reset button" and why "deleting" is not enough

Read More
an white icon of an user on the black background.
Brick9 Team
an white icon of an user on the black background.
7 min

Is my SME a target to hackers

"We are too small to be interesting to hackers." But the reality of 2026 strongly contradicts that assertion.

Read More