Home / Cybersecurity / NIS2 in Belgium / Managed IT services (MSP / MSSP)
NIS2 for managed service providers in Belgium
Managed IT services (MSP / MSSP) is listed in Annex I of the NIS2 directive. Large companies are essential entities; medium companies are important entities. In Belgium, the rules come from the NIS2 Law of 26 April 2024, applicable since 18 October 2024; the authority is the Centre for Cybersecurity Belgium (CCB), plus a sector authority for some sectors.
→ Talk to a cybersecurity advisor
Who is covered in this sector
- Managed service providers (MSP) delivering IT services to businesses
- Managed security service providers (MSSP)
Freelancers and micro-companies are below the size threshold, but their customers will still ask them for proof of security.
The threats we see most in managed it services (msp / mssp)
- Compromise of the remote-management tool, giving access to every client at once
- Stolen technician credentials
- Supply-chain attacks through software updates
- Ransomware spreading from one client to others
Five priority measures
- 01 Hardened RMM platform with MFA, IP restrictions and full logging
- 02 Separate admin accounts per client, no shared credentials
- 03 Written incident-notification commitments towards clients
- 04 Evidence pack for client questionnaires (policies, certificates, test reports)
- 05 Register in the country of your head office (NIS2 rule for MSPs)
What Belgium requires
- The law of 26 April 2024 has applied since 18 October 2024.
- Registration on Safeonweb@Work was due by 18 March 2025 (18 December 2024 for some digital providers). Not registered yet? Do it now.
- Essential entities had to complete a first conformity assessment by 18 April 2026 and must hold CyberFundamentals (CyFun®) or ISO/IEC 27001 certification by 18 April 2027.
- The CCB framework has three assurance levels — Basic, Important, Essential. Basic is recommended for suppliers of NIS2 entities that are not in scope themselves.
- Important entities are supervised after the fact (for example after an incident); a voluntary CyFun® or ISO 27001 assessment gives them a presumption of conformity.
Registration. Register on Safeonweb@Work (CCB). The general deadline was 18 March 2025 — late registrants should register now.
Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).
Tools and guides
Managed IT services (MSP / MSSP) in other countries
Other sectors in Belgium
Frequently asked questions
Is my managed service provider company in scope of NIS2 in Belgium?
Managed IT services (MSP / MSSP) is an Annex I sector. Large companies are essential entities; medium companies are important entities. Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.
What should we do first?
Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.
We are a supplier to this sector. Does it affect us?
Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.
Sources
- CCB Safeonweb@Work — The NIS2 Law
- CCB — 18 April 2026 deadline for essential entities
- CCB — NIS2 Quickstart Guide
Last checked: 28 September 2026. This page is general information, not legal advice.
Managed IT services (MSP / MSSP) in Belgium: a first view, free
Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.
- Reply within one business day
- Written scope and price before any work
- Netherlands · Belgium · Luxembourg