NIS2 Belgium: healthcare, hospitals and labs, who is in scope?
Belgium puts healthcare among the highly critical NIS2 sectors. Here is who is genuinely in scope, what the CCB expects, and why two deadlines have already gone by.
The short answer
Under NIS2, Belgium places healthcare among the « highly critical » sectors of Annex I of the law of 26 April 2024, in force since 18 October 2024[2]. So if you run a hospital, a clinic or a clinical laboratory, the answer is probably yes. But not every care provider sits in the same place: scope depends on your size and on whether you deliver the care service yourself. A two-doctor practice is out. A general hospital employing twelve hundred people is in, and in principle it is an essential entity, the strictest regime[1][3].
The second point is less comfortable. For Belgian healthcare, two deadlines are already behind us. Registration with the Centre for Cybersecurity Belgium (CCB) was due on 18 March 2025, and the first CyberFundamentals certification or verification on 18 April 2026[1][3]. It is now late September 2026: if either one is missing, this is no longer preparation, it is catching up. The next step is 18 April 2027.
Are you in scope? NIS2 Belgium healthcare in four questions
The CCB reasons per legal entity, not per hospital site and not per group. Work through these questions in order, and write the answers down: that note is what will serve as your evidence.
- Do you deliver the care service yourself? Most organisations skip this one. The CCB NIS2 FAQ is explicit: an organisation that merely calls on third-party care providers does not automatically fall in scope as a healthcare provider[4]. A medical centre hosting self-employed practitioners is therefore not in the same position as a hospital that employs its clinical staff.
- What size are you, in the European sense? In a highly critical sector such as healthcare, a large enterprise is in principle an essential entity; a medium-sized one is an important entity[3]. The entry threshold sits at medium-enterprise size: at least 50 staff, or financial figures above the small-enterprise thresholds, with the reference figure published by the CCB being 10 million euros[1][3].
- Are you a partner of, or linked to, other companies? The European SME definition is technical: where relevant it aggregates headcount and financial data of partner and linked enterprises[3]. A 30-person laboratory owned by a 900-person group does not count as a small enterprise.
- Have you been designated by the CCB? The CCB may designate an entity regardless of size, in particular where it is critical or is the sole provider of an essential service[3][4]. A reference laboratory that is alone in offering a given technique can therefore be in scope with 20 staff.
The specifically Belgian trap. Providers of regional health data exchange networks, the Réseau Santé Wallon for instance, do not as such fall under the healthcare sector definition used by NIS2, according to the CCB FAQ[4]. That releases them from no other legal or contractual duty, and it changes nothing about yours: if your hospital is an essential entity, securing your end of the chain is your job, including what you push into those networks and the access you open to them.
The Belgian timeline, and where we actually stand
Unlike some member states, Belgium published firm dates and a framework. Here is the timeline, with its real status as at 30 September 2026.
| Deadline | Who | What must be done | Status |
|---|---|---|---|
| 18 October 2024 | All | Law of 26 April 2024 enters into force[2] | Passed |
| 18 March 2025 | Entities already covered | Registration with the CCB via Safeonweb@work[1] | Passed |
| 5 months after identification | Entities identified later | Same registration, rolling deadline[1] | Ongoing |
| 18 April 2026 | Essential entities | CyberFundamentals certification or verification at Basic or Important level[3] | Passed |
| 18 April 2027 | Essential entities | Certification of the final chosen level[3] | About 7 months |
CyberFundamentals or ISO 27001?
The CCB offers its own CyberFundamentals (CyFun) framework as a way to structure and demonstrate your risk-management measures; ISO/IEC 27001 is also usable[1]. For a hospital the difference that matters is not the content but the control: for essential entities, regular conformity assessment is mandatory; for important entities it is voluntary, under the arrangements set out by the CCB[1]. A general hospital classed as essential therefore has no choice about producing evidence, only about the route.
Reporting an incident: two authorities, two clocks
This is where Belgian hospitals get caught, because ransomware on a patient record triggers two separate duties, to two different authorities, and neither one substitutes for the other.
- To the CCB, under NIS2: for a significant incident, an early warning within 24 hours of becoming aware, an incident notification within 72 hours, then a final report no later than one month after that notification. If the incident is still ongoing you file a progress report, then the final report within a month of its resolution; intermediate reports may be requested[1][5].
- To the Data Protection Authority, under the GDPR: Article 33 requires notification without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals; any delay must be justified[7].
A report to the CCB is not a notification to the DPA, and the reverse holds too[4][7]. For a hospital the GDPR risk assessment starts higher up: health data is a special category under Article 9. If you want to see how an authority then reasons about the amount, we set out the five-step method the EDPB applies to calculate a GDPR fine.
Where the 24 hours disappear. The clock does not start when the executive committee meets, nor when the IT supplier calls back: it runs from becoming aware of the incident. In a hospital that awareness is often born at night, in the on-call IT team or with a nurse who can no longer open a record. If your procedure does not say who has authority to declare a significant incident at three in the morning, your 24 hours are already spent by breakfast.
Fines, directors and personal accountability
The Belgian caps follow the directive: 10 million euros or 2 % of worldwide annual turnover for an essential entity, 7 million euros or 1.4 % for an important entity, whichever is higher[2][9]. For a hospital the percentage is rarely the number that bites; the real exposure is elsewhere.
The law puts the duty on the management body: its members must follow training sufficient to understand cyber risks and assess risk-management practices, must approve the measures and supervise their implementation, and the law holds the body accountable for the entity's failures to meet these obligations[4]. In a hospital association that means the board by name, not the IT manager.
A word on the figures, to avoid both panic and complacency. The CCB reports 105 incidents notified in Belgium in 2025 against 109 in 2024: that is a national counter covering all sectors, not a healthcare scoreboard[8]. The Belgian estate, meanwhile, counted 103 general hospitals across 189 sites as at 1 January 2025[6]. That concentration is the blind spot: when a hundred institutions share a handful of electronic patient record vendors and infrastructure suppliers, one compromised provider hits several essential entities on the same morning. We described the same logic for another subcontracting-heavy sector in our NIS2 guide for transport and logistics in the Netherlands.
The five first actions
- Settle your status in writing. A two-page note: legal entity, activities, headcount and consolidated financial data, service delivered in-house, conclusion (out of scope, important, essential). Signed by management, dated. Without that document you can prove nothing.
- Check your Safeonweb@work registration. Not « ask the supplier »: open the account and read the date. If it is missing, register now and keep the acknowledgement.
- Run the CyFun self-assessment at Important level and produce the gap list, sorted by cost and lead time. That is the document that turns NIS2 into a budget a board can defend.
- Write the dual notification procedure, 24h/72h to the CCB and 72h to the DPA, with a single on-call number, a named decision-maker and a pre-drafted message template. Then rehearse it, on a Sunday.
- Enrol the management body in training and keep the evidence: attendance list, date, content. It is the item nobody prepares and everybody will ask for.
At CyberNovaLabs.io
We do not sell certification and we do not sign statutory audits: on NIS2 that work belongs to a conformity assessment body. What we do is the link before and the link after. Upstream, we help settle your status and build the gap list so a board can decide on numbers. Downstream, we train teams and directors, including on the AI uses that touch patient data, which is where risk is created day to day. Our Belgian work runs out of Brussels, in French and in Dutch. Engagements are quoted case by case.
If you want a read on your own position, write to us in two lines: your presumed status and the date of your registration. We will tell you where you actually stand.
Sources
- CCB — NIS2 : Obligations
- CCB — La directive NIS2 : que cela signifie-t-il pour mon organisation ?
- CCB — NIS2 : échéance du 18 avril 2026, ce que les entités essentielles doivent avoir mis en place
- CCB — FAQ NIS2 en Belgique
- CCB — La notification des incidents NIS2
- SPF Santé publique — Les soins de santé en chiffres (2025)
- Autorité de protection des données — Notifier et gérer une violation de données
- CCB — Cyber Threat Landscape and actions taken in Belgium
- CCB — Mesures administratives et amendes sous NIS2
Qualified meetings, no lock-in.
Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.
Read next
Data breach at FWB: three weeks before it was confirmed (05/10)
Flagged from outside in mid-September, confirmed on 5 October 2026: the EAD-online.be data breach shows where the GDPR's 72 hours are really lost, and why the weak link is so often a supplier.
Read the article →October 7, 2026 · 7 min readNIS2 France: are hotels and tourism in scope?
Tourist accommodation is absent from the NIS2 annexes, and France's transposition was still in parliament on 7 October 2026. Yet in May 2026 three French tourism operators lost their reservation databases within 72 hours. Here is what actually applies to you.
Read the article →October 6, 2026 · 7 min readDGFiP breach: stolen logins, no MFA, no detection (29/09/2026)
On 29 September 2026 France's cyber agency ANSSI published its incident report on the cyberattacks against the tax administration. No rare technique: passwords stolen from personal computers, a second factor sent by email, sensitive applications reachable without segmentation, and a portal nobody was watching. All four links exist in most SMEs.
Read the article →