← All resources

NIS2 Belgium: are estate agents and syndics in scope?

Published October 5, 2026 · 9 min read · CyberNovaLabs.io

Short answer: no. Real estate appears in no annex of the Belgian NIS2 law. But your in-scope client will send you its security questionnaire, your professional rules already demand discretion, and your client-funds account is a target. This guide separates what does not apply from what does.

The short answer

No. A Belgian estate agency, letting agent or syndic is not, as such, an entity covered by the Belgian NIS2 law. The law of 26 April 2024 applies only to the sectors listed in its annexes: eleven « highly critical » sectors in Annex I and seven « other critical » sectors in Annex II[1]. Real estate occupies none of those lines. The French word for real estate does not appear once in the consolidated text of the law, annexes included[1]. No size threshold to compute, no registration with the CCB, no NIS2 fine.

Three things still apply to you directly: the security questionnaire your in-scope client will send, the duty of discretion written into your professional rules, and the client-funds account through which rental guarantees, rents and deposits pass. That is the useful part of this guide.

NIS2 Belgium and real estate: are you in scope?

The law reads in two steps: sector first, size second. If the first test fails, the second never arises.

What the Belgian law requires, and of whom

To measure precisely what you do not have to do, here is what weighs on those who are covered.

ObligationWhoReference
Register with the national cybersecurity authority within five months of the law entering into force or of identification, with company number, contact details, IP ranges and sub-sectorEssential entities, important entities and domain name registration service providersart. 13[1]
« All-hazards » risk management measures: risk analysis, incident handling, business continuity and backups, supply chain security, cyber hygiene and training, cryptography, human resources securityEssential and important entitiesart. 30(3)[1]
Notify significant incidentsEssential and important entitiesTitle 3[1]
Periodic conformity assessment by a conformity assessment body approved by the national authority, or inspection by that authorityMandatory for essential entities; voluntary for important onesart. 39 to 42[1]
Administrative fine of 500 to 7,000,000 euros or 1.4 % of total worldwide annual turnover, whichever is higherImportant entityart. 59(4)[1]
Administrative fine of 500 to 10,000,000 euros or 2 % of total worldwide annual turnover, whichever is higherEssential entityart. 59(5)[1]

The Belgian timetable adds its own dates. An essential entity that chooses the CyberFundamentals framework must have its Basic or Important level verified by an approved body by 18 April 2026 at the latest, and obtain certification of the Essential level by 18 April 2027 if its risk assessment places it there[3][4]. An important entity is supervised after the fact: following an incident or on indications of non-compliance[2][3].

None of this can be invoked against you. Remember only article 42: an entity that submits to the assessment is presumed, until proven otherwise, to comply with article 30[1]. It will want to extend that presumption to its suppliers. You are one. The same logic applies to Dutch law firms, also out of scope and questioned anyway.

What still applies to you

1. The security questionnaire from your in-scope client

Article 30(3)(4) requires the covered entity to address « supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers »[1]. In operational terms: the hospital, municipality, inter-municipal body, public welfare centre or carrier whose property you manage must show that it assessed you. It does so by questionnaire, by contract clause, sometimes by audit. You are not covered — you are assessed, and the difference is decided by how fast you answer. Our notes on Belgian healthcare and hospitals, which are fully in scope, show where the pressure comes from. The supplier security questionnaire template gives you the questions before they arrive.

2. Your professional rules already say « discretion »

Article 13, second paragraph, 2° of the law of 11 February 2013 imposes on IPI members « a duty of discretion, meaning that any information obtained in a professional capacity is used only in a professional context, taking account of the right to privacy of all parties concerned »[5]. A tenant file exfiltrated from a mailbox puts that duty in play before the IPI, long before any NIS2 discussion. The same law distinguishes the intermediary, the syndic and the letting manager in article 2, 5°, 6° and 7°, and splits the Institute's register into two columns in article 3[5]: obligations do not read the same way depending on which column you are registered in.

3. The GDPR, which has no size threshold

A prospective tenant file concentrates payslips, household composition, sometimes creditworthiness data. On 19 December 2024 the Belgian Data Protection Authority issued an opinion on the definition of « financial income and equivalents in kind » requested from applicants for Walloon public housing: opinion no. 116/2024 frames the processing of that income data[6]. The proportionality reasoning it applies to public housing is the one that will be put to you in the private market.

The risk specific to this trade: the client-funds account

Here is the element no generic NIS2 guide will reach. Article 21/2 of the law of 11 February 2013 requires the intermediary estate agent and the letting manager to separate their own funds from third-party funds, and to « always ask clients and third parties to pay those funds exclusively into that account »[5]. The same article requires transfer to an earmarked account where the funds cannot be passed to the beneficiary within four months on substantiated grounds, except where the total received for one person, one transaction or one file does not exceed 2,500 euros[5]. The syndic, for its part, keeps separate accounts for each co-ownership association.

The scenario, in six lines. An attacker gets into a property manager's mailbox through a reused password with no second factor. Nothing is stolen: it is read. The attacker waits for the sentence « here is the account number for the rental guarantee », installs a quiet forwarding rule, then resends the same email with a modified IBAN. The tenant pays where told. Your legal duty is precisely to name a single account: that duty is what makes the fraud credible. The CCB received 9,929,354 suspicious emails at suspicious@safeonweb.be in 2025, up 9.31 % year on year, and 635 notifications from Belgian organisations, 556 of them linked to cyber incidents[7].

Three controls cut this scenario short, and none needs a licence: a second factor on every mailbox, an alert on the creation of a forwarding rule, and confirmation of every IBAN through a channel other than email.

The first 5 actions

  1. Write your « out of scope » answer once. One page: the law of 26 April 2024, Annexes I and II, your activity absent from both, your company number, the name of your security contact. It will serve every client questionnaire. The free NIS2 check produces that conclusion in a few minutes.
  2. A second factor on every mailbox, starting with the managers who handle the client-funds account. It is the one measure whose cost-to-risk ratio is beyond argument in this trade.
  3. Check SPF, DKIM and DMARC on your domain. Until DMARC is set to « reject », anyone can write to your tenants and co-owners in your agency's name. The free email security check returns all three verdicts.
  4. Impose a two-channel rule for every IBAN — written down, displayed, and applied both ways: the one you send and the one you receive.
  5. Use CyberFundamentals at BASIC level as your roadmap. The CCB framework has four levels — SMALL, BASIC, IMPORTANT, ESSENTIAL — it is free, and it is organised around five functions: identify, protect, detect, respond, recover[8]. In Wallonia, the cybersecurity voucher covers 75 % of an approved provider's fees excluding VAT, within a cap of 50,000 euros excluding VAT per beneficiary over three years[9]. The grants available by region are listed separately.

At CyberNovaLabs.io

CyberNovaLabs.io works in the Netherlands, Belgium, France and Luxembourg. For a Belgian agency, letting manager or syndic we do three things: establish in writing that you fall outside the scope of the Belgian NIS2 law, harden the mailbox and the client-funds payment chain, then prepare the file your in-scope clients will ask for. The NIS2 Belgium page sets out the national framework, and our AI and automation offer covers industrialising questionnaire responses. For winning mandates from institutional owners, see our notes on B2B appointment setting in commercial real estate and in Brussels.

Ask for a 30-minute review of your exposure: mailbox, client-funds account, client questionnaires. Priced on request, with no minimum term.

Sources

  1. Loi du 26 avril 2024 etablissant un cadre pour la cybersecurite des reseaux et des systemes d'information d'interet general pour la securite publique (version consolidee, Justel)
  2. Centre pour la Cybersecurite Belgique (CCB) - NIS2 : obligations
  3. Centre pour la Cybersecurite Belgique (CCB) - NIS2 : supervision
  4. Centre pour la Cybersecurite Belgique (CCB) - FAQ NIS2, version 2.0.1 (fevrier 2025)
  5. Loi du 11 fevrier 2013 organisant la profession d'agent immobilier (version IPI 02/2024)
  6. Autorite de protection des donnees (APD) - Avis n° 116/2024 du 19 decembre 2024
  7. Centre pour la Cybersecurite Belgique (CCB) - Cyber threat landscape and actions taken
  8. Centre pour la Cybersecurite Belgique (CCB) - CyberFundamentals Framework
  9. Region wallonne - Cheque « cybersecurite »
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked