NIS2 Belgium (België): CCB, CyberFundamentals & Deadlines
Belgium's NIS2 law has applied since 18 October 2024. Registration with the CCB closed in 2025, and essential entities owed their first conformity evidence — CyberFundamentals or ISO/IEC 27001 — by 18 April 2026. This page covers who is in scope, what you owe, what it costs to get it wrong, and what is still due by 18 April 2027.
Introduction
Belgium transposed NIS2 through the Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security — the “NIS2 Law” — together with the Royal Decree of 9 June 2024 that executes it. Both have applied since 18 October 2024, replacing the NIS1 law of 7 April 2019.
What makes Belgium distinctive is not the duties, which follow the Directive closely, but the proof. Essential entities must periodically demonstrate compliance to the Centre for Cybersecurity Belgium (CCB) through a formal conformity assessment — CyberFundamentals, ISO/IEC 27001, or a CCB inspection. Few member states require standing evidence of this kind, and the first deadline has already passed.
What you must do in Belgium
All of these have applied since 18 October 2024. If you are only starting now, you are late on several of them — which affects your exposure, not whether the duties apply.
- Register with the CCB on Safeonweb@Work. The deadlines were 18 December 2024 for the digital sector and 18 March 2025 for everyone else. Both have passed; register now if you have not, and report any change to your details immediately. See Registration.
- Implement the 11 minimum risk-management measures, on an all-hazards basis and proportionate to your exposure, size and the likelihood and severity of incidents.
- Get your management body to approve and oversee them. Under the NIS2 Law the management body is personally liable if the entity breaches its risk-management obligations, and its members must follow cybersecurity training.
- Be able to report a significant incident within 24 hours. Then 72 hours, then a final report a month later. See Incident reporting.
- If you are an essential entity, produce conformity evidence. CyberFundamentals verification, an ISO/IEC 27001 package, or a CCB inspection — the first milestone was 18 April 2026 and the second is 18 April 2027. See Conformity assessment.
- Cooperate with the inspection service. On-site inspections, off-site supervision, ad hoc audits, security scans and requests for evidence are all available to it, and failing to comply exposes you to administrative fines in their own right.
NIS2 implementation in Belgium
The NIS2 Law and its Royal Decree took effect on 18 October 2024 with no transition period for the core duties: risk-management measures, incident notification, cooperation with the authorities and management-body accountability all applied from day one. Only registration and the conformity assessment were given their own clocks. Registration runs through Safeonweb@Work, the CCB's portal for Belgian organisations.
Status
In force since 18 October 2024. Registration deadlines passed in 2024 and 2025; the first conformity-evidence milestone passed on 18 April 2026. The next is 18 April 2027.
Core legislation
The Law of 26 April 2024 sets the duties; the Royal Decree of 9 June 2024 executes it, designating the CCB as national cybersecurity authority and setting the reference framework for periodic conformity assessment and the rules for approving assessment bodies.
Where everything happens
Safeonweb@Work — registration, the notification platform, the CyberFundamentals tooling and the label request all run through the same CCB portal.
| Obligation | Applied from |
|---|---|
| Risk-management measures, incident notification, cooperation with authorities, management-body approval, oversight, liability and training | 18 October 2024 — immediately, no transition |
| Registration — digital-sector entities | 18 December 2024 (2 months) |
| Registration — all other entities, and domain name registration services | 18 March 2025 (5 months) |
| First conformity evidence for essential entities | 18 April 2026 (18 months) |
| Final certification or progress report | 18 April 2027 (a further 12 months) |
Scope: are you in?
Three conditions, in principle, all of which must be met: you provide a service listed in Annex I or II of the NIS2 Law in the EU, you exceed the size of a medium-sized enterprise, and you are established in Belgium. Each has exceptions, and the exceptions are where most organisations get their answer wrong.
The size test
Measured under Recommendation 2003/361/EC. Headcount first:
- under 50 FTE — micro or small
- 50 to 249 FTE — medium
- 250 FTE or more — large
Then the financial figures: turnover over EUR 10m, or balance sheet total over EUR 10m, moves you up. Take the lower of the two — exceeding one ceiling alone does not change your status. And group figures are consolidated: partner and linked enterprises count.
In scope regardless of size
- Qualified trust service providers — essential.
- Non-qualified trust service providers — important, or essential if large.
- DNS service providers and TLD name registries — essential.
- Domain name registration services — the registration duty only.
- Providers of public electronic communications networks or publicly available services — important if micro or small, essential if medium or large.
- Entities identified as critical entities under the critical-entities resilience law — essential.
- Federal public administration entities — essential.
Two traps
Any service counts. The CCB is explicit that even the most ancillary service you provide can bring the whole organisation into scope. You have to review every service you offer to third parties, sector by sector.
The CCB can name you anyway. Under article 11 it may identify an entity of any size where it is the sole provider in Belgium of an essential service, where disruption could significantly affect public safety, security or health, where disruption could cause significant systemic risk, or where the entity matters critically at national or regional level.
Where you have to be established
As a rule the Belgian law applies to entities established in Belgium, where “establishment” means actually carrying on activity through a permanent installation — registered office, branch or subsidiary alike. Three exceptions matter:
- Providers of public electronic communications networks or services are caught if they provide services in Belgium, wherever they sit.
- DNS, TLD registries, domain registration, cloud, data centres, CDNs, managed services, managed security services, online marketplaces, search engines and social networks are caught if their main establishment or their EU legal representative is in Belgium. Main establishment means where cybersecurity risk-management decisions are predominantly taken; failing that, where cybersecurity operations are carried out; failing that, where the entity has most of its EU staff.
- Public administration entities are caught if Belgium established them.
Conformity assessment & CyberFundamentals
This is the part of the Belgian regime that has no close equivalent elsewhere. Essential entities do not merely have to comply — they have to prove it, periodically, to an accredited third party or to the CCB itself.
Essential entities
Supervised proactively and reactively, and subject to a mandatory regular conformity assessment. The inspection service may also inspect at any time.
Important entities
Supervised after the fact only — following an incident, or on evidence or indications of non-compliance. No regular conformity assessment. They may, however, volunteer for the essential regime and gain the same presumption of conformity.
Why bother
A conformity assessment statement carries a presumption of conformity: until proven otherwise, you are presumed to have met your obligations. That is a meaningful shift in who has to prove what.
Three routes, and what each one owed by when
Every clock below runs from 18 October 2024.
| Route | By 18 April 2026 | By 18 April 2027 |
|---|---|---|
| CyFun, assurance level Basic | Obtain a verification from an authorised conformity assessment body | — |
| CyFun, assurance level Important | Obtain a Basic or Important verification | If you took Basic first, obtain the Important verification |
| CyFun, assurance level Essential | Obtain a Basic or Important verification | Obtain the Essential certification |
| ISO/IEC 27001 | Send the CCB the scope of your future certification, your Statement of Applicability covering all measures implemented or in progress, and your most recent internal audit of their implementation | Obtain the certification from an authorised body |
| CCB inspection | Send the CCB a CyFun Basic or Important self-assessment, or your ISO 27001 information security policy, scope and Statement of Applicability | Report on progress towards compliance |
Bodies performing CyFun verification or certification must be authorised by the CCB after accreditation by BELAC. For the ISO route the body must be accredited by an organisation signed up to the European co-operation for Accreditation or International Accreditation Forum mutual recognition agreement, and separately authorised by the CCB. The CCB publishes the list of authorised bodies.
The CyberFundamentals levels
- Small — a starting point for micro-organisations or those with limited technical knowledge. It excludes the aspects relating to in-house application development.
- Basic — standard information security measures using technology and processes generally already available. Protects against known cybersecurity risks.
- Important — designed to minimise the risk of targeted attacks by actors with common skills and resources.
- Essential — designed to address advanced attacks by actors with extensive skills and resources.
CyFun draws on NIST CSF, ISO/IEC 27001 and 27002, IEC 62443 and the CIS Critical Security Controls. Getting the label takes four steps: risk-assess to choose your level using the CCB's selection tool, complete the self-assessment and fix what it finds, have an authorised body verify or certify it, then request the label on Safeonweb@Work.
Registration on Safeonweb@Work
Registration is a self-declaration. The CCB does not tell you that you are in scope — you assess yourself and file.
| Who | Window | Deadline |
|---|---|---|
| Digital-sector entities — DNS, TLD registries, domain registration, cloud, data centres, CDNs, managed services, managed security services, online marketplaces, search engines, social networks | 2 months | 18 December 2024 |
| All other essential and important entities | 5 months | 18 March 2025 |
What you have to provide
- Everyone: name and CBE number (Crossroads Bank for Enterprises, or an equivalent EU registration); current address and contact details including email address, IP address and telephone number; the relevant sector and subsector from Annex I or II; and the member states where you provide in-scope services.
- Digital-sector entities also provide the address of their principal place of business and other legal establishments in the Union — or their representative's, if not established in the Union — and their IP ranges.
Incident reporting
Significant incidents are notified to the CCB as national CSIRT, through its notification platform. The clock starts when you become aware.
| Stage | Deadline | What it is |
|---|---|---|
| Early warning | 24 hours | Without undue delay, and in any event within 24 hours of becoming aware. |
| Incident notification | 72 hours 24 hours for trust service providers |
The formal notification of the significant incident. |
| Interim report | On request | If the national CSIRT or the sectoral authority asks for it. |
| Final report | 1 month after the incident notification | If the incident is still ongoing, a progress report instead — then a final report within one month of the incident being handled. |
What counts as significant
An incident with a significant impact on the provision of an Annex I or II service which either has caused or is likely to cause serious disruption to that service or financial loss to you; or has caused or is likely to cause significant material, personal or non-material damage to other natural or legal persons. Any one limb is enough.
- Tell your customers too. Where appropriate you must inform the recipients of your services of significant incidents affecting them, and of significant cyber threats along with the measures they can take in response.
- Digital and trust entities follow the EU regulation instead. Implementing Regulation (EU) 2024/2690 sets the criteria for what counts as significant for DNS, TLD, cloud, data centre, CDN, managed service, managed security, marketplace, search engine, social network and trust service providers. Where it conflicts with the CCB notification guide, the regulation prevails for those entities.
National NIS2 timeline & key dates
Sectors in scope
- Annex I — highly critical sectors: energy (electricity, district heating and cooling, oil, gas, hydrogen); transport (air, rail, water, road); banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure; ICT service management between businesses; public administration; and space.
- Annex II — other critical sectors: postal and courier services; waste management; manufacture, production and distribution of chemicals; production, processing and distribution of food; manufacturing; manufacture of medical devices and in vitro diagnostic medical devices; manufacture of computer, electronic and optical products; manufacture of electrical equipment; manufacture of machinery and equipment not elsewhere classified; manufacture of motor vehicles, trailers and semi-trailers; manufacture of other transport equipment; digital providers; and research.
- The definitions are the hard part. Most services are defined by reference to other EU instruments rather than in plain language, so matching what you actually do to a listed service takes care. The CCB publishes a definition matrix compiling them into one document, and a scope test tool.
- You can be in several sectors at once. An organisation may provide services falling under multiple sectors, and the classification follows the service, not the company's self-image.
- Supply chain: suppliers outside scope can still be required by contract to meet a CyberFundamentals level. The CCB advises any potential supplier to a NIS2 entity to reach at least CyFun Basic.
How Belgium differs
Five things here will not carry across from a programme built for another member state.
- You have to prove compliance, on a schedule. This is the big one. Essential entities owe periodic third-party conformity evidence — CyFun verification or certification, or ISO/IEC 27001, or a CCB inspection. Most member states supervise reactively and ask for proof only when something goes wrong.
- There is a national framework built for the job. CyberFundamentals is Belgium's own, free to use, with four levels and a formal label. Implementing it gives a presumption of conformity — a genuine legal benefit, not just good practice.
- Fines start at EUR 500 and have unusual heads. There is a dedicated tier for penalising your own staff or subcontractors for complying with the law in good faith, and another for obstructing supervision. All amounts double for repeat behaviour within three years.
- Management liability is defined, not gestured at. The law's explanatory memorandum defines a “member of a management body” to include anyone with decisive influence over the appointment of a majority of directors, applies the Companies and Associations Code test for control, and applies recursively where that member is itself a legal person.
- Changes to your registration are due immediately — not within 14 days as in Sweden or Bulgaria.
Belgian terms you will meet
Belgian law is published in French and Dutch, and the CCB's tooling is available in both. These are the strings worth recognising.
| French | Dutch | English |
|---|---|---|
| loi NIS2 | NIS2-wet | the NIS2 Law of 26 April 2024 |
| arrêté royal | koninklijk besluit | Royal Decree — here, of 9 June 2024 |
| Centre pour la Cybersécurité Belgique (CCB) | Centrum voor Cybersecurity België (CCB) | the national cybersecurity authority and CSIRT |
| entité essentielle | essentiële entiteit | essential entity |
| entité importante | belangrijke entiteit | important entity |
| incident significatif | significant incident | significant incident — the 24-hour trigger |
| évaluation de conformité | conformiteitsbeoordeling | conformity assessment |
| organisme d'évaluation de la conformité | conformiteitsbeoordelingsinstantie | conformity assessment body (CAB) |
| BCE — Banque-Carrefour des Entreprises | KBO — Kruispuntbank van Ondernemingen | Crossroads Bank for Enterprises; your CBE number |
| amende administrative | administratieve geldboete | administrative fine |
| CyberFundamentals (CyFun®) · Safeonweb@Work · BELAC | the framework, the portal, and the national accreditation body — identical in both languages | |
Penalties for non-compliance
Belgium sets out five separate fine ranges, each with a EUR 500 floor, and doubles every one of them for repeat behaviour within three years.
| Breach | Fine |
|---|---|
| Failing the information obligations in article 12 (the identification process) | EUR 500 – 125,000 |
| Sanctioning your own employee or subcontractor for carrying out obligations under the law in good faith and within their duties | EUR 500 – 200,000 |
| Failing your supervision obligations | EUR 500 – 200,000 |
| Risk-management or reporting duties — important entities | EUR 500 – 7,000,000 or 1.4% of the total worldwide annual turnover of the undertaking you belong to, whichever is higher |
| Risk-management or reporting duties — essential entities | EUR 500 – 10,000,000 or 2%, whichever is higher |
The tier for penalising staff is worth pausing on. If an employee or a subcontractor reports an incident or insists on a control because the law requires it, and you retaliate, that is a distinct offence carrying up to EUR 200,000 — independent of whether your security measures were adequate.
Measures beyond fines
The CCB may issue warnings and binding instructions; order you to cease conduct or to bring your risk management or reporting into compliance; order you to inform the people you provide services to, or to make aspects of your non-compliance public; and order you to implement the recommendations it has given.
Three measures apply to essential entities only: the CCB may designate a monitoring officer to oversee you, temporarily suspend a certification or authorisation covering part or all of your services, and temporarily prohibit the exercise of managerial functions.
How to prepare for NIS2 in Belgium
- Review every service you provide, not just your main one, against Annex I and II using the CCB's definition matrix and scope test. Then apply the size test, consolidating partner and linked enterprises. Record the reasoning — it is the basis of your registration.
- Register on Safeonweb@Work if you have not. Both deadlines have passed, so late registration is better than none, and keep the details current: changes are reportable immediately.
- Choose your conformity route deliberately. CyFun verification, ISO/IEC 27001, or CCB inspection are not equivalent in cost or timing, and if you are an essential entity the 18 April 2027 milestone is what you are now working towards.
- Risk-assess to pick your CyFun assurance level, using the CCB selection tool. Running below your NIS2 classification is permitted with justification — and sanctionable without it.
- Put management training and sign-off on the record. The management body must approve the measures, oversee them and be trained, and it is liable for the entity's breaches.
- Rehearse the 24-hour early warning, and agree in advance who is authorised to decide an incident is significant.
- Set supplier requirements. CyFun Basic is the CCB's own recommended floor for anyone in a NIS2 entity's supply chain, which makes it a defensible contractual ask.
- Keep the evidence. Self-assessments, internal audits, Statements of Applicability and training records are exactly what the inspection service and your assessment body will want to see.
Operating in more than one EU country
NIS2 is one Directive and 27 national laws. Belgium sits at the demanding end, and its conformity assessment has no equivalent in most member states.
- Establishments in several member states mean several laws. The CCB is explicit: you are subject to the transposition law of each member state where you are established, with the national authorities cooperating on inspections and incident notifications.
- Digital providers answer to one country. Cloud, data centre, CDN, managed service, managed security, DNS, TLD, domain registration, marketplace, search and social network providers are governed where their main establishment or EU legal representative sits — so a single filing, not twenty-seven.
- Size tests are not portable. Belgium consolidates partner and linked enterprises, as Sweden does. Bulgaria switches that aggregation off entirely, and Germany relieves it only where the entity is IT-independent. The same group can be in scope in Brussels and out in Sofia.
- Proof obligations are the real divergence. An ISO/IEC 27001 certificate serves you across borders; a CyberFundamentals label is Belgian. If you operate in several member states, ISO may be the more efficient route even though CyFun is free.
- Reporting clocks travel well. The 24-hour, 72-hour and one-month chain matches most member states, including the 24-hour rule for trust service providers.
- Sector rules can displace the general regime — DORA for financial entities being the common case.
Official links & resources
FAQ: NIS2 in Belgium
When did the NIS2 law take effect in Belgium?
Where do I register, and what if I missed the deadline?
What was due on 18 April 2026?
Do important entities need a conformity assessment?
Is CyberFundamentals mandatory?
Who is the competent authority?
What are the fines?
We are not in scope. Does any of this reach us?
Is my management personally exposed?
Sources & verification
Every date, figure and obligation on this page was read from the CCB's own published guidance on 3 August 2026. Public NIS2 trackers contradict each other and are not used here.
- Safeonweb@Work — The NIS2 Law — scope and its exceptions, the size bands, both registration deadlines and data sets, the 11 measures, the reporting chain, supervision, the full sanction ranges, and the conformity assessment timeline.
- CCB — NIS2 — the law's full title and its relationship to the Royal Decree of 9 June 2024.
- CCB — CyberFundamentals Framework — the four levels, and CyFun 2023 and CyFun 2025 running in parallel until 18 April 2027.
- Implementing Regulation (EU) 2024/2690 — technical requirements and significance criteria for digital and trust service entities.
