Belgium NIS2 Transposition

Belgian law of 26 April 2024 implementing NIS2 under the Centre for Cybersecurity Belgium, with CyberFundamentals certification as a presumption of conformity.

JurisdictionBelgium
CategoryCybersecurity
StatusActive
Effective date
Latest development

Analysis

Belgium has fully transposed NIS2 via the Law of 26 April 2024 and a Royal Decree of 9 June 2024, with the Centre for Cybersecurity Belgium (CCB) as the central authority and CyberFundamentals (CyFun®) / ISO 27001 certification giving a presumption of conformity under certain conditions.Publication of the NIS2 law – CCB Belgian Official Journal – Law of 26 April 2024 (NUMAC 2024202344) Transposition in Belgium – NIS2 Directive Lex Mundi – Belgium NIS2 Implementation CCB NIS2 FAQ (PDF) CyFun® in Belgium


Key Requirements (Belgium NIS2 Transposition)

Scope and Covered Entities

Institutional Architecture and Competent Authority

Cybersecurity Risk‑Management Measures

Under the Belgian NIS2 law and Royal Decree, entities must implement comprehensive cybersecurity risk‑management measures aligned with Article 21 NIS2, operationalized via national references such as CyberFundamentals:

Incident Reporting Obligations

Conformity Assessment and Presumption of Conformity

Registration and Identification of Entities

Enforcement, Sanctions, and Governance


Compliance Challenges

1. Scope and Entity Identification

2. Aligning Existing ISMS with CyberFundamentals / ISO 27001 Scope

  • Challenge: Organizations with ISO/IEC 27001 must align their scope and Statement of Applicability with NIS2 requirements to benefit from presumption of conformity in Belgium.CCB NIS2 FAQ (PDF) CyFun® in Belgium
  • Example: The CyFun documentation specifies that certification scope must include networks and information systems of the organization as a whole, which can be difficult for large groups with complex boundaries.CCB NIS2 FAQ (PDF) CABs in Belgium – CyFun

3. Implementing Incident Reporting Timelines and Processes

4. Resource and Capability Constraints

5. Multi‑Regulatory Alignment (NIS2, GDPR, DORA, Sector Rules)


Implementation Best Practices

1. Use CyberFundamentals (CyFun®) as the Primary Implementation Framework

  • Action: Adopt CyberFundamentals as a structured framework to implement Belgian NIS2 requirements, targeting appropriate assurance levels (BASIC, IMPORTANT, ESSENTIAL).
  • CyFun maps controls to NIS2 obligations and supports verification/certification that grants presumption of conformity.CyFun® in Belgium CCB NIS2 FAQ (PDF)
  • Resources:
  • Official CyFun information for Belgium: CyFun® in Belgium
  • Accredited conformity assessment bodies (CABs): CABs in Belgium – CyFun
  • CCB guidance and FAQs: CCB NIS2 FAQ (PDF)

###

Recent developments

  • — A recent compliance overview for Belgium’s NIS2 regime reiterates key **deadlines for self-assessment and classification**, including the 2026-04-18 self‑assessment submission (CyFun or ISO 27001) and 2026-07-17 automatic classification of critical infrastructure operators as critical entities, underscoring tightening supervision on essential services. (source)
  • — Belgium has completed the **principal transposition of NIS2** via the Law of 26 April 2024 and a Royal Decree, and as of 2026-08-06 has moved beyond legislation into **operational supervision and conformity assessment**, signaling active enforcement and oversight of essential and important entities. (source)
  • — An update from an EU institutional tracker shows Belgium as **fully transposed and notified** under NIS2, with the Centre for Cybersecurity Belgium designated as the competent authority, confirming that Belgian entities in sectors such as energy, health, digital infrastructure, and public administration are now firmly under NIS2‑aligned cybersecurity supervision. (source)
  • — An EU‑level NIS2 transposition tracker confirms **Belgium’s transposition and upcoming enforcement timelines**, noting transposition dates and that national NIS2 frameworks, including Belgium’s, are scheduled to be fully in force around late 2026, reinforcing that Belgian entities must already treat NIS2 obligations as binding. (source)
  • — An EU‑wide NIS2 enforcement tracker reports that **Belgium is among the first Member States where NIS2 fines have been imposed**, including an example fine of €185,000, and notes that national CSIRTs have started systematic audits of essential entities, contributing to a marked increase in cybersecurity spending across the EU. (source)
  • — A detailed implementation guide explains that Belgium’s NIS2 Law of 26 April 2024, in force since 2024-10-18, was **substantially amended by the Law of 19 December 2025 on the resilience of critical entities (CER Law)**, aligning cybersecurity and critical-entity resilience obligations and clarifying supervisory powers and enforcement arrangements. (source)
  • — Belgium is highlighted as the **first EU country to enforce ex‑ante NIS2 supervision**, requiring by 2026-04-18 that essential entities submit verified cybersecurity documentation via CyberFundamentals (CyFun), ISO/IEC 27001 certification, or direct CCB inspection, with non-compliance subject to administrative measures and fines up to **10 million EUR or 2% of global turnover**. (source)
  • — A policy update from a European cybersecurity industry association reports that **23 of 27 EU Member States have transposed NIS2**, explicitly listing Belgium among the transposed countries and positioning it as a frontrunner, which industry commentators view as increasing Belgium’s regulatory certainty but also its compliance burden. (source)
  • — A Belgian cybersecurity consultancy describes 2026 as the year **cyber compliance becomes mandatory**, emphasizing that NIS2 obligations apply from 2024-10-18, that the first verification deadline of 2026-04-18 has passed, and that entities must plan for **full CyberFundamentals/ISO 27001 certification by 2027**, triggering significant investment and program upgrades in the private sector. (source)
  • — A Belgium‑focused compliance guide explains that NIS2 has shifted the country from a manual “identification” regime to a **self‑assessment and self‑registration model** via the Safeonweb@Work portal, with registration deadlines largely in 2024–2025 and differentiated oversight and fine caps for **Essential Entities (EE)** and **Important Entities (IE)**, prompting organizations to reassess their scope and governance. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates