Home / Cybersecurity / NIS2 in Belgium
NIS2 in Belgium: what applies and what to do now
NIS2 Law of 26 April 2024 — applies since 18 October 2024. Authority: the Centre for Cybersecurity Belgium (CCB), plus a sector authority for some sectors. Belgium was one of the first EU countries to transpose NIS2 and its authority, the CCB, already inspects essential entities.
→ Talk to a cybersecurity advisor
The essentials
- The law of 26 April 2024 has applied since 18 October 2024.
- Registration on Safeonweb@Work was due by 18 March 2025 (18 December 2024 for some digital providers). Not registered yet? Do it now.
- Essential entities had to complete a first conformity assessment by 18 April 2026 and must hold CyberFundamentals (CyFun®) or ISO/IEC 27001 certification by 18 April 2027.
- The CCB framework has three assurance levels — Basic, Important, Essential. Basic is recommended for suppliers of NIS2 entities that are not in scope themselves.
- Important entities are supervised after the fact (for example after an incident); a voluntary CyFun® or ISO 27001 assessment gives them a presumption of conformity.
Registration. Register on Safeonweb@Work (CCB). The general deadline was 18 March 2025 — late registrants should register now.
Obligations once in scope
- 01 Risk analysis and information-security policies
- 02 Incident handling
- 03 Business continuity, backups and crisis management
- 04 Supply-chain security (your suppliers and service providers)
- 05 Security in buying, developing and maintaining systems, including vulnerability handling
- 06 Policies to assess whether the measures work
- 07 Basic cyber hygiene and staff training
- 08 Cryptography and encryption
- 09 HR security, access control and asset management
- 10 Multi-factor authentication and secured communications
Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month.
Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).
NIS2 by sector in Belgium
Not in scope yourself?
If you supply companies that are, you will receive their requirements. See the 30 questions of a supplier security questionnaire →
Other countries
Frequently asked questions
Does NIS2 apply to my company in Belgium?
It applies to medium and large companies in the sectors listed by the directive, and to some providers whatever their size. Use our free NIS2 check to get an answer for Belgium in two minutes.
Who is the authority in Belgium?
The Centre for Cybersecurity Belgium (CCB), plus a sector authority for some sectors.
What if we missed the registration deadline?
Register now and document the reason. Authorities look at good faith and at what you do next; staying unregistered is the worst option.
Sources
- CCB Safeonweb@Work — The NIS2 Law
- CCB — 18 April 2026 deadline for essential entities
- CCB — NIS2 Quickstart Guide
Last checked: 28 September 2026. This page is general information, not legal advice.
NIS2 in Belgium: where do you stand?
Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg