Belgium NIS2 Transposition
Belgian law of 26 April 2024 implementing NIS2 under the Centre for Cybersecurity Belgium, with CyberFundamentals certification as a presumption of conformity.
| Jurisdiction | Belgium |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
Belgium has fully transposed NIS2 via the Law of 26 April 2024 and a Royal Decree of 9 June 2024, with the Centre for Cybersecurity Belgium (CCB) as the central authority and CyberFundamentals (CyFun®) / ISO 27001 certification giving a presumption of conformity under certain conditions.Publication of the NIS2 law – CCB Belgian Official Journal – Law of 26 April 2024 (NUMAC 2024202344) Transposition in Belgium – NIS2 Directive Lex Mundi – Belgium NIS2 Implementation CCB NIS2 FAQ (PDF) CyFun® in Belgium
Key Requirements (Belgium NIS2 Transposition)
Scope and Covered Entities
- Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security implements Directive (EU) 2022/2555 (NIS2) in Belgium and repeals the 2019 NIS1 law.Publication of the NIS2 law – CCB Belgian Official Journal – Law of 26 April 2024
- The law applies to “essential” and “important” entities in sectors of high criticality (e.g. energy, transport, health, banking, digital infrastructure) and other sectors listed in Annexes aligned with NIS2.Transposition in Belgium – NIS2 Directive Digital Strategy – NIS2 implementation in Belgium (European Commission)
- The law and Royal Decree became applicable on 18 October 2024, from which date the substantive risk‑management and incident‑reporting obligations apply to essential and important entities.Transposition in Belgium – NIS2 Directive Loyens & Loeff – Belgium moves forward with transposition
Institutional Architecture and Competent Authority
- Centre for Cybersecurity Belgium (CCB) is designated as national cybersecurity authority, single point of contact (SPOC) and national CSIRT for NIS2 in Belgium.Transposition in Belgium – NIS2 Directive Lex Mundi – Belgium NIS2 Implementation OpenKritis – EU NIS2 in Belgium
- The National Crisis Centre (NCCN) co-leads crisis governance under the Belgian NIS2 framework, with sectoral regulators retaining specific supervisory roles.NIS2 Belgium Implementation Guide (CloudSoul)
- The CCB coordinates NIS2 law implementation together with the Prime Minister’s Cabinet, as stated in official CCB communications.Publication of the NIS2 law – CCB OpenKritis – EU NIS2 in Belgium
Cybersecurity Risk‑Management Measures
Under the Belgian NIS2 law and Royal Decree, entities must implement comprehensive cybersecurity risk‑management measures aligned with Article 21 NIS2, operationalized via national references such as CyberFundamentals:
- Entities must adopt technical, operational and organizational measures covering risk analysis, information system security policy, incident management, business continuity, supply‑chain security, access control, and use of cryptography.Belgian Official Journal – Law of 26 April 2024 NIS2 Directive – EUR‑Lex
- Belgian Royal Decree references CyberFundamentals (CyFun®) and ISO/IEC 27001 as frameworks for conformity assessment; validated or certified implementation gives presumption of conformity (until proven otherwise).CCB NIS2 FAQ (PDF) Lex Mundi – Belgium NIS2 Implementation
- The scope of certification must match the NIS2 law scope for the organization as a whole; otherwise the certification does not confer presumption of conformity.CCB NIS2 FAQ (PDF) CyFun® in Belgium
Incident Reporting Obligations
- Entities have strict incident‑reporting timelines, following NIS2: initial notification within 24 hours, further reporting at 72 hours, and a final report within one month for significant incidents.NIS2 Directive – EUR‑Lex CyFun 2025 – Belgium’s Updated Framework (NIS Institute)
- CyberFundamentals certification does not automatically cover incident‑reporting obligations, so entities must ensure internal procedures for these timelines.CyFun 2025 – Belgium’s Updated Framework (NIS Institute) CCB NIS2 FAQ (PDF)
Conformity Assessment and Presumption of Conformity
- Essential entities are subject to mandatory regular conformity assessments under CCB supervision; important entities have lighter or risk‑based oversight but still must comply substantively.Lex Mundi – Belgium NIS2 Implementation Loyens & Loeff – Belgium NIS2
- Presumption of conformity to NIS2 in Belgium can be obtained via:
- CyberFundamentals verification (assurance levels BASIC and IMPORTANT)
- CyberFundamentals certification (assurance level ESSENTIAL)
- ISO/IEC 27001 certification with acceptable scope and Statement of Applicability validated by CCB.CCB NIS2 FAQ (PDF) CyFun® in Belgium CABs in Belgium – CyFun
- The presumption is rebuttable: CCB can still take supervisory measures if non‑compliance is detected despite certification.CCB NIS2 FAQ (PDF) ERA – NIS2 Transposition for Railway Sector (PDF)
Registration and Identification of Entities
- By 17 April 2025, EU Member States must establish lists of covered NIS2 entities, with possible self‑registration obligations.Loyens & Loeff – Belgium NIS2 NIS2 Directive – EUR‑Lex
- In Belgium, essential and important entities must register with the CCB, and around 1,500 essential and 500 important entities had registered by late 2025 according to CyFun‑related industry reporting.Belgium’s first year of NIS2 – CyFun 2025 (Cranium) Digital Strategy – NIS2 Belgium
Enforcement, Sanctions, and Governance
- The Belgian NIS2 law provides administrative sanctions and fines for non‑compliance, mirroring NIS2’s regime (including potential significant financial penalties for essential entities).Belgian Official Journal – Law of 26 April 2024 NIS2 Directive – EUR‑Lex
- The law also includes governance obligations, e.g. management‑level responsibility for approval of cybersecurity measures and potential personal liability under certain circumstances.NIS2 Directive – EUR‑Lex NIS2 Belgium Implementation Guide
Compliance Challenges
1. Scope and Entity Identification
- Challenge: Determining whether an organization qualifies as an essential or important entity under Belgian NIS2, especially for cross‑sector or multi‑country groups.Publication of the NIS2 law – CCB Transposition in Belgium – NIS2 Directive
- Example: Legal analyses note uncertainty for certain service providers (e.g. cloud, MSPs, some digital platforms) on their classification and registration duties.Lex Mundi – Belgium NIS2 Implementation Loyens & Loeff – Belgium NIS2
2. Aligning Existing ISMS with CyberFundamentals / ISO 27001 Scope
- Challenge: Organizations with ISO/IEC 27001 must align their scope and Statement of Applicability with NIS2 requirements to benefit from presumption of conformity in Belgium.CCB NIS2 FAQ (PDF) CyFun® in Belgium
- Example: The CyFun documentation specifies that certification scope must include networks and information systems of the organization as a whole, which can be difficult for large groups with complex boundaries.CCB NIS2 FAQ (PDF) CABs in Belgium – CyFun
3. Implementing Incident Reporting Timelines and Processes
- Challenge: Integrating 24h/72h/1‑month incident reporting into existing incident‑response processes, especially where SOC and crisis management are not yet mature.NIS2 Directive – EUR‑Lex CyFun 2025 – NIS Institute
- Example: CyFun 2025 guidance emphasizes that possessing a CyFun label alone is insufficient; entities must document specific reporting workflows to meet NIS2 timelines.CyFun 2025 – NIS Institute CCB NIS2 FAQ (PDF)
4. Resource and Capability Constraints
- Challenge: Smaller essential/important entities face limited cybersecurity resources, making compliance with full NIS2 risk‑management and governance obligations difficult.Belgium’s first year of NIS2 – CyFun 2025 (Cranium) NIS2 Directive – Impact Assessment – EC
- Example: Industry analyses of Belgium’s first year of NIS2 note significant effort required for entities to implement CyFun and register with CCB, particularly in sectors like local utilities and healthcare providers.Belgium’s first year of NIS2 – Cranium NIS2 Belgium Implementation Guide
5. Multi‑Regulatory Alignment (NIS2, GDPR, DORA, Sector Rules)
- Challenge: Harmonizing NIS2 with GDPR, DORA, sector‑specific security rules and existing national requirements to avoid conflicting obligations.NIS2 Directive – EUR‑Lex Lex Mundi – Belgium NIS2 Implementation
- Example: Financial sector entities must align NIS2 measures with DORA ICT risk management and supervisory expectations from the National Bank of Belgium and FSMA, creating complex mapping exercises.DORA Regulation – EUR‑Lex NIS2 Belgium Implementation Guide
Implementation Best Practices
1. Use CyberFundamentals (CyFun®) as the Primary Implementation Framework
- Action: Adopt CyberFundamentals as a structured framework to implement Belgian NIS2 requirements, targeting appropriate assurance levels (BASIC, IMPORTANT, ESSENTIAL).
- CyFun maps controls to NIS2 obligations and supports verification/certification that grants presumption of conformity.CyFun® in Belgium CCB NIS2 FAQ (PDF)
- Resources:
- Official CyFun information for Belgium: CyFun® in Belgium
- Accredited conformity assessment bodies (CABs): CABs in Belgium – CyFun
- CCB guidance and FAQs: CCB NIS2 FAQ (PDF)
###
Recent developments
- — A recent compliance overview for Belgium’s NIS2 regime reiterates key **deadlines for self-assessment and classification**, including the 2026-04-18 self‑assessment submission (CyFun or ISO 27001) and 2026-07-17 automatic classification of critical infrastructure operators as critical entities, underscoring tightening supervision on essential services. (source)
- — Belgium has completed the **principal transposition of NIS2** via the Law of 26 April 2024 and a Royal Decree, and as of 2026-08-06 has moved beyond legislation into **operational supervision and conformity assessment**, signaling active enforcement and oversight of essential and important entities. (source)
- — An update from an EU institutional tracker shows Belgium as **fully transposed and notified** under NIS2, with the Centre for Cybersecurity Belgium designated as the competent authority, confirming that Belgian entities in sectors such as energy, health, digital infrastructure, and public administration are now firmly under NIS2‑aligned cybersecurity supervision. (source)
- — An EU‑level NIS2 transposition tracker confirms **Belgium’s transposition and upcoming enforcement timelines**, noting transposition dates and that national NIS2 frameworks, including Belgium’s, are scheduled to be fully in force around late 2026, reinforcing that Belgian entities must already treat NIS2 obligations as binding. (source)
- — An EU‑wide NIS2 enforcement tracker reports that **Belgium is among the first Member States where NIS2 fines have been imposed**, including an example fine of €185,000, and notes that national CSIRTs have started systematic audits of essential entities, contributing to a marked increase in cybersecurity spending across the EU. (source)
- — A detailed implementation guide explains that Belgium’s NIS2 Law of 26 April 2024, in force since 2024-10-18, was **substantially amended by the Law of 19 December 2025 on the resilience of critical entities (CER Law)**, aligning cybersecurity and critical-entity resilience obligations and clarifying supervisory powers and enforcement arrangements. (source)
- — Belgium is highlighted as the **first EU country to enforce ex‑ante NIS2 supervision**, requiring by 2026-04-18 that essential entities submit verified cybersecurity documentation via CyberFundamentals (CyFun), ISO/IEC 27001 certification, or direct CCB inspection, with non-compliance subject to administrative measures and fines up to **10 million EUR or 2% of global turnover**. (source)
- — A policy update from a European cybersecurity industry association reports that **23 of 27 EU Member States have transposed NIS2**, explicitly listing Belgium among the transposed countries and positioning it as a frontrunner, which industry commentators view as increasing Belgium’s regulatory certainty but also its compliance burden. (source)
- — A Belgian cybersecurity consultancy describes 2026 as the year **cyber compliance becomes mandatory**, emphasizing that NIS2 obligations apply from 2024-10-18, that the first verification deadline of 2026-04-18 has passed, and that entities must plan for **full CyberFundamentals/ISO 27001 certification by 2027**, triggering significant investment and program upgrades in the private sector. (source)
- — A Belgium‑focused compliance guide explains that NIS2 has shifted the country from a manual “identification” regime to a **self‑assessment and self‑registration model** via the Safeonweb@Work portal, with registration deadlines largely in 2024–2025 and differentiated oversight and fine caps for **Essential Entities (EE)** and **Important Entities (IE)**, prompting organizations to reassess their scope and governance. (source)
Related regulations
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
- Netherlands NIS2 Transposition (Cyberbeveiligingswet) — Netherlands, Active, effective 2026-08-15
- Italy NIS2 Transposition (Legislative Decree 138/2024) — Italy, Active, effective 2024-10-16
Put it into practice
- Generate the policy: NIS2 policy generator (generatepolicy.com)
- Buy the policy pack: NIS2 Compliance Policy (cyberpolicy.shop)
- Build it yourself: DORA + NIS2 EU Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates