Home / Cybersecurity / NIS2 in Belgium / Manufacturing

Belgium · Manufacturing · Annex II

NIS2 for manufacturers in Belgium

Manufacturing is listed in Annex II of the NIS2 directive. Medium and large companies are important entities (lighter supervision, after the fact). In Belgium, the rules come from the NIS2 Law of 26 April 2024, applicable since 18 October 2024; the authority is the Centre for Cybersecurity Belgium (CCB), plus a sector authority for some sectors.

→ Talk to a cybersecurity advisor

Who is covered in this sector

Other manufacturing activities (for example furniture or textiles) are not listed, unless another sector applies.

The threats we see most in manufacturing

Five priority measures

  1. 01 Asset inventory including machines and OT networks
  2. 02 Remote access for machine builders only through a controlled gateway with MFA
  3. 03 Offline backups of ERP/MES and machine programs
  4. 04 Patch and vulnerability routine for OT
  5. 05 Security requirements in purchase contracts — and check the Cyber Resilience Act for your own connected products

What Belgium requires

Registration. Register on Safeonweb@Work (CCB). The general deadline was 18 March 2025 — late registrants should register now.

Significant incidents: early warning within 24 hours, notification within 72 hours, final report within one month. Fines set by the directive: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities (whichever is higher).

Tools and guides

Manufacturing in other countries

Other sectors in Belgium

Frequently asked questions

Is my manufacturer company in scope of NIS2 in Belgium?

Manufacturing is an Annex II sector. Medium and large companies are important entities (lighter supervision, after the fact). Small companies are generally out of scope unless designated. Our NIS2 check gives you the answer in two minutes.

What should we do first?

Register if you are in scope, name an owner, run a short risk assessment, and fix the basics: MFA, tested backups, patching, incident routine.

We are a supplier to this sector. Does it affect us?

Yes, indirectly: your customers must secure their supply chain and will ask you for evidence. See our supplier questionnaire guide.

Sources

Last checked: 28 September 2026. This page is general information, not legal advice.

Free first call · English

Manufacturing in Belgium: a first view, free

Tell us where you stand. An English-speaking advisor replies within one business day with a first view and, if useful, a written quote. No commitment.

  • Reply within one business day
  • Written scope and price before any work
  • Netherlands · Belgium · Luxembourg

Prefer email? Write to contact@cybernovalabs.io

→ Free cybersecurity call