NIS2 Country Guide

NIS2 Belgium (België): CCB, CyberFundamentals & Deadlines

Belgium's NIS2 law has applied since 18 October 2024. Registration with the CCB closed in 2025, and essential entities owed their first conformity evidence — CyberFundamentals or ISO/IEC 27001 — by 18 April 2026. This page covers who is in scope, what you owe, what it costs to get it wrong, and what is still due by 18 April 2027.

In force: 18 Oct 2024 Law: 26 April 2024 + RD 9 June 2024 Authority: CCB — Safeonweb@Work Conformity evidence: 18 Apr 2026 → 18 Apr 2027 Last updated: 3 Aug 2026

Introduction

Belgium transposed NIS2 through the Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security — the “NIS2 Law” — together with the Royal Decree of 9 June 2024 that executes it. Both have applied since 18 October 2024, replacing the NIS1 law of 7 April 2019.

What makes Belgium distinctive is not the duties, which follow the Directive closely, but the proof. Essential entities must periodically demonstrate compliance to the Centre for Cybersecurity Belgium (CCB) through a formal conformity assessment — CyberFundamentals, ISO/IEC 27001, or a CCB inspection. Few member states require standing evidence of this kind, and the first deadline has already passed.

Quick links: the CCB's NIS2 overview and the Safeonweb@Work portal: ccb.belgium.be/regulation/nis2 · atwork.safeonweb.be/nis2. New to the Directive? Start with “What is NIS2?” and “NIS vs NIS2”.

What you must do in Belgium

All of these have applied since 18 October 2024. If you are only starting now, you are late on several of them — which affects your exposure, not whether the duties apply.

  • Register with the CCB on Safeonweb@Work. The deadlines were 18 December 2024 for the digital sector and 18 March 2025 for everyone else. Both have passed; register now if you have not, and report any change to your details immediately. See Registration.
  • Implement the 11 minimum risk-management measures, on an all-hazards basis and proportionate to your exposure, size and the likelihood and severity of incidents.
  • Get your management body to approve and oversee them. Under the NIS2 Law the management body is personally liable if the entity breaches its risk-management obligations, and its members must follow cybersecurity training.
  • Be able to report a significant incident within 24 hours. Then 72 hours, then a final report a month later. See Incident reporting.
  • If you are an essential entity, produce conformity evidence. CyberFundamentals verification, an ISO/IEC 27001 package, or a CCB inspection — the first milestone was 18 April 2026 and the second is 18 April 2027. See Conformity assessment.
  • Cooperate with the inspection service. On-site inspections, off-site supervision, ad hoc audits, security scans and requests for evidence are all available to it, and failing to comply exposes you to administrative fines in their own right.
Not in scope? Two things still reach you. The CCB can identify any organisation as essential or important regardless of size in four defined circumstances. And if you supply a NIS2 entity, it may contractually require you to meet a CyberFundamentals level — the CCB advises every potential supplier to meet at least CyFun Basic.

NIS2 implementation in Belgium

The NIS2 Law and its Royal Decree took effect on 18 October 2024 with no transition period for the core duties: risk-management measures, incident notification, cooperation with the authorities and management-body accountability all applied from day one. Only registration and the conformity assessment were given their own clocks. Registration runs through Safeonweb@Work, the CCB's portal for Belgian organisations.

Status

In force since 18 October 2024. Registration deadlines passed in 2024 and 2025; the first conformity-evidence milestone passed on 18 April 2026. The next is 18 April 2027.

Core legislation

The Law of 26 April 2024 sets the duties; the Royal Decree of 9 June 2024 executes it, designating the CCB as national cybersecurity authority and setting the reference framework for periodic conformity assessment and the rules for approving assessment bodies.

Where everything happens

Safeonweb@Work — registration, the notification platform, the CyberFundamentals tooling and the label request all run through the same CCB portal.

ObligationApplied from
Risk-management measures, incident notification, cooperation with authorities, management-body approval, oversight, liability and training 18 October 2024 — immediately, no transition
Registration — digital-sector entities 18 December 2024 (2 months)
Registration — all other entities, and domain name registration services 18 March 2025 (5 months)
First conformity evidence for essential entities 18 April 2026 (18 months)
Final certification or progress report 18 April 2027 (a further 12 months)

Scope: are you in?

Three conditions, in principle, all of which must be met: you provide a service listed in Annex I or II of the NIS2 Law in the EU, you exceed the size of a medium-sized enterprise, and you are established in Belgium. Each has exceptions, and the exceptions are where most organisations get their answer wrong.

The size test

Measured under Recommendation 2003/361/EC. Headcount first:

  • under 50 FTE — micro or small
  • 50 to 249 FTE — medium
  • 250 FTE or more — large

Then the financial figures: turnover over EUR 10m, or balance sheet total over EUR 10m, moves you up. Take the lower of the two — exceeding one ceiling alone does not change your status. And group figures are consolidated: partner and linked enterprises count.

In scope regardless of size

  • Qualified trust service providers — essential.
  • Non-qualified trust service providers — important, or essential if large.
  • DNS service providers and TLD name registries — essential.
  • Domain name registration services — the registration duty only.
  • Providers of public electronic communications networks or publicly available services — important if micro or small, essential if medium or large.
  • Entities identified as critical entities under the critical-entities resilience law — essential.
  • Federal public administration entities — essential.

Two traps

Any service counts. The CCB is explicit that even the most ancillary service you provide can bring the whole organisation into scope. You have to review every service you offer to third parties, sector by sector.

The CCB can name you anyway. Under article 11 it may identify an entity of any size where it is the sole provider in Belgium of an essential service, where disruption could significantly affect public safety, security or health, where disruption could cause significant systemic risk, or where the entity matters critically at national or regional level.

Where you have to be established

As a rule the Belgian law applies to entities established in Belgium, where “establishment” means actually carrying on activity through a permanent installation — registered office, branch or subsidiary alike. Three exceptions matter:

  • Providers of public electronic communications networks or services are caught if they provide services in Belgium, wherever they sit.
  • DNS, TLD registries, domain registration, cloud, data centres, CDNs, managed services, managed security services, online marketplaces, search engines and social networks are caught if their main establishment or their EU legal representative is in Belgium. Main establishment means where cybersecurity risk-management decisions are predominantly taken; failing that, where cybersecurity operations are carried out; failing that, where the entity has most of its EU staff.
  • Public administration entities are caught if Belgium established them.
Establishments in several member states mean several laws. You will be subject to the transposition law of each member state concerned, with the national authorities cooperating on inspections and incident notifications. See Operating in more than one EU country.

Conformity assessment & CyberFundamentals

This is the part of the Belgian regime that has no close equivalent elsewhere. Essential entities do not merely have to comply — they have to prove it, periodically, to an accredited third party or to the CCB itself.

Essential entities

Supervised proactively and reactively, and subject to a mandatory regular conformity assessment. The inspection service may also inspect at any time.

Important entities

Supervised after the fact only — following an incident, or on evidence or indications of non-compliance. No regular conformity assessment. They may, however, volunteer for the essential regime and gain the same presumption of conformity.

Why bother

A conformity assessment statement carries a presumption of conformity: until proven otherwise, you are presumed to have met your obligations. That is a meaningful shift in who has to prove what.

Three routes, and what each one owed by when

Every clock below runs from 18 October 2024.

RouteBy 18 April 2026By 18 April 2027
CyFun, assurance level Basic Obtain a verification from an authorised conformity assessment body
CyFun, assurance level Important Obtain a Basic or Important verification If you took Basic first, obtain the Important verification
CyFun, assurance level Essential Obtain a Basic or Important verification Obtain the Essential certification
ISO/IEC 27001 Send the CCB the scope of your future certification, your Statement of Applicability covering all measures implemented or in progress, and your most recent internal audit of their implementation Obtain the certification from an authorised body
CCB inspection Send the CCB a CyFun Basic or Important self-assessment, or your ISO 27001 information security policy, scope and Statement of Applicability Report on progress towards compliance

Bodies performing CyFun verification or certification must be authorised by the CCB after accreditation by BELAC. For the ISO route the body must be accredited by an organisation signed up to the European co-operation for Accreditation or International Accreditation Forum mutual recognition agreement, and separately authorised by the CCB. The CCB publishes the list of authorised bodies.

The CyberFundamentals levels

  • Small — a starting point for micro-organisations or those with limited technical knowledge. It excludes the aspects relating to in-house application development.
  • Basic — standard information security measures using technology and processes generally already available. Protects against known cybersecurity risks.
  • Important — designed to minimise the risk of targeted attacks by actors with common skills and resources.
  • Essential — designed to address advanced attacks by actors with extensive skills and resources.

CyFun draws on NIST CSF, ISO/IEC 27001 and 27002, IEC 62443 and the CIS Critical Security Controls. Getting the label takes four steps: risk-assess to choose your level using the CCB's selection tool, complete the self-assessment and fix what it finds, have an authorised body verify or certify it, then request the label on Safeonweb@Work.

Two live subtleties. First, two versions of CyFun run in parallel: a new 2025 version launched in October 2025, and CyFun 2023 and CyFun 2025 coexist until 18 April 2027, with entities free to choose which to apply. The Small level was not revised and is identical in both. Second, you may deliberately run at a CyFun level below your NIS2 classification if a thorough risk analysis justifies it — an essential entity could operate at CyFun Important. That does not change your classification, and the inspection service can sanction an entity for wrongly conforming to a lower level.

Competent authorities & CSIRT

Belgium concentrates NIS2 in one body to an unusual degree. The Centre for Cybersecurity Belgium (CCB) is the national cybersecurity authority, the national CSIRT and the inspection service, and it runs the portal you register and report through.

RoleAuthorityNotes
National cybersecurity authority Centre for Cybersecurity Belgium (CCB) Designated by the Royal Decree of 9 June 2024. Publishes the guidance, identifies entities under article 11, authorises conformity assessment bodies and maintains the CyberFundamentals framework.
National CSIRT CCB All significant incident notifications go here, through the CCB notification platform.
Registration authority CCB, via Safeonweb@Work The single portal for registration, notification, CyberFundamentals tooling and label requests.
Inspection service CCB inspection service, and sectoral inspection services where they exist On-site inspections, off-site supervision, ad hoc audits, security scans and requests for information and evidence. May act jointly.
Conformity assessment bodies Private bodies authorised by the CCB CyFun bodies must first be accredited by BELAC. ISO/IEC 27001 bodies must be accredited under an EA or IAF mutual recognition agreement and separately authorised by the CCB.
Sectoral authorities Designated by the Royal Decree The law provides for sectoral authorities and sectoral inspection services alongside the CCB, and they may request interim incident reports. See Sources for why we do not name individual designations here.

Registration on Safeonweb@Work

Registration is a self-declaration. The CCB does not tell you that you are in scope — you assess yourself and file.

WhoWindowDeadline
Digital-sector entities — DNS, TLD registries, domain registration, cloud, data centres, CDNs, managed services, managed security services, online marketplaces, search engines, social networks 2 months 18 December 2024
All other essential and important entities 5 months 18 March 2025

What you have to provide

  • Everyone: name and CBE number (Crossroads Bank for Enterprises, or an equivalent EU registration); current address and contact details including email address, IP address and telephone number; the relevant sector and subsector from Annex I or II; and the member states where you provide in-scope services.
  • Digital-sector entities also provide the address of their principal place of business and other legal establishments in the Union — or their representative's, if not established in the Union — and their IP ranges.
Changes must be reported immediately. Not within two weeks as in Bulgaria or Sweden — the Belgian law says immediately. Some of your data is pulled automatically from the Crossroads Bank for Enterprises during registration, but keeping the rest current is on you. If you already gave this information to a sectoral authority, you only need to update it where necessary.

Incident reporting

Significant incidents are notified to the CCB as national CSIRT, through its notification platform. The clock starts when you become aware.

StageDeadlineWhat it is
Early warning 24 hours Without undue delay, and in any event within 24 hours of becoming aware.
Incident notification 72 hours
24 hours for trust service providers
The formal notification of the significant incident.
Interim report On request If the national CSIRT or the sectoral authority asks for it.
Final report 1 month after the incident notification If the incident is still ongoing, a progress report instead — then a final report within one month of the incident being handled.

What counts as significant

An incident with a significant impact on the provision of an Annex I or II service which either has caused or is likely to cause serious disruption to that service or financial loss to you; or has caused or is likely to cause significant material, personal or non-material damage to other natural or legal persons. Any one limb is enough.

  • Tell your customers too. Where appropriate you must inform the recipients of your services of significant incidents affecting them, and of significant cyber threats along with the measures they can take in response.
  • Digital and trust entities follow the EU regulation instead. Implementing Regulation (EU) 2024/2690 sets the criteria for what counts as significant for DNS, TLD, cloud, data centre, CDN, managed service, managed security, marketplace, search engine, social network and trust service providers. Where it conflicts with the CCB notification guide, the regulation prevails for those entities.

National NIS2 timeline & key dates

27 Dec 2022 — Directive (EU) 2022/2555 (NIS2) is published in the EU Official Journal.
26 Apr 2024 — the Belgian NIS2 Law is adopted, superseding the NIS1 law of 7 April 2019.
9 Jun 2024 — the Royal Decree executing the law is adopted, designating the CCB as national cybersecurity authority.
18 Oct 2024the law applies. Risk-management measures, incident notification, cooperation and management-body duties all begin. Belgium meets the EU transposition deadline of 17 October 2024 by a day.
18 Dec 2024 — registration deadline for digital-sector entities (2 months).
18 Mar 2025 — registration deadline for all other entities (5 months).
Oct 2025 — CyberFundamentals 2025 launches. It runs alongside CyFun 2023 until 18 April 2027.
18 Apr 2026first conformity evidence due from essential entities: a CyFun verification, an ISO 27001 package, or a self-assessment to the CCB. 18 months from entry into force.
18 Apr 2027final milestone. CyFun Essential certification, ISO 27001 certification, or a progress report — depending on your route. CyFun 2023 also retires on this date.

Sectors in scope

  • Annex I — highly critical sectors: energy (electricity, district heating and cooling, oil, gas, hydrogen); transport (air, rail, water, road); banking; financial market infrastructure; health; drinking water; waste water; digital infrastructure; ICT service management between businesses; public administration; and space.
  • Annex II — other critical sectors: postal and courier services; waste management; manufacture, production and distribution of chemicals; production, processing and distribution of food; manufacturing; manufacture of medical devices and in vitro diagnostic medical devices; manufacture of computer, electronic and optical products; manufacture of electrical equipment; manufacture of machinery and equipment not elsewhere classified; manufacture of motor vehicles, trailers and semi-trailers; manufacture of other transport equipment; digital providers; and research.
  • The definitions are the hard part. Most services are defined by reference to other EU instruments rather than in plain language, so matching what you actually do to a listed service takes care. The CCB publishes a definition matrix compiling them into one document, and a scope test tool.
  • You can be in several sectors at once. An organisation may provide services falling under multiple sectors, and the classification follows the service, not the company's self-image.
  • Supply chain: suppliers outside scope can still be required by contract to meet a CyberFundamentals level. The CCB advises any potential supplier to a NIS2 entity to reach at least CyFun Basic.

How Belgium differs

Five things here will not carry across from a programme built for another member state.

  • You have to prove compliance, on a schedule. This is the big one. Essential entities owe periodic third-party conformity evidence — CyFun verification or certification, or ISO/IEC 27001, or a CCB inspection. Most member states supervise reactively and ask for proof only when something goes wrong.
  • There is a national framework built for the job. CyberFundamentals is Belgium's own, free to use, with four levels and a formal label. Implementing it gives a presumption of conformity — a genuine legal benefit, not just good practice.
  • Fines start at EUR 500 and have unusual heads. There is a dedicated tier for penalising your own staff or subcontractors for complying with the law in good faith, and another for obstructing supervision. All amounts double for repeat behaviour within three years.
  • Management liability is defined, not gestured at. The law's explanatory memorandum defines a “member of a management body” to include anyone with decisive influence over the appointment of a majority of directors, applies the Companies and Associations Code test for control, and applies recursively where that member is itself a legal person.
  • Changes to your registration are due immediately — not within 14 days as in Sweden or Bulgaria.

Belgian terms you will meet

Belgian law is published in French and Dutch, and the CCB's tooling is available in both. These are the strings worth recognising.

FrenchDutchEnglish
loi NIS2NIS2-wetthe NIS2 Law of 26 April 2024
arrêté royalkoninklijk besluitRoyal Decree — here, of 9 June 2024
Centre pour la Cybersécurité Belgique (CCB)Centrum voor Cybersecurity België (CCB)the national cybersecurity authority and CSIRT
entité essentielleessentiële entiteitessential entity
entité importantebelangrijke entiteitimportant entity
incident significatifsignificant incidentsignificant incident — the 24-hour trigger
évaluation de conformitéconformiteitsbeoordelingconformity assessment
organisme d'évaluation de la conformitéconformiteitsbeoordelingsinstantieconformity assessment body (CAB)
BCE — Banque-Carrefour des EntreprisesKBO — Kruispuntbank van OndernemingenCrossroads Bank for Enterprises; your CBE number
amende administrativeadministratieve geldboeteadministrative fine
CyberFundamentals (CyFun®) · Safeonweb@Work · BELACthe framework, the portal, and the national accreditation body — identical in both languages

Penalties for non-compliance

Belgium sets out five separate fine ranges, each with a EUR 500 floor, and doubles every one of them for repeat behaviour within three years.

BreachFine
Failing the information obligations in article 12 (the identification process) EUR 500 – 125,000
Sanctioning your own employee or subcontractor for carrying out obligations under the law in good faith and within their duties EUR 500 – 200,000
Failing your supervision obligations EUR 500 – 200,000
Risk-management or reporting duties — important entities EUR 500 – 7,000,000 or 1.4% of the total worldwide annual turnover of the undertaking you belong to, whichever is higher
Risk-management or reporting duties — essential entities EUR 500 – 10,000,000 or 2%, whichever is higher

The tier for penalising staff is worth pausing on. If an employee or a subcontractor reports an incident or insists on a control because the law requires it, and you retaliate, that is a distinct offence carrying up to EUR 200,000 — independent of whether your security measures were adequate.

Measures beyond fines

The CCB may issue warnings and binding instructions; order you to cease conduct or to bring your risk management or reporting into compliance; order you to inform the people you provide services to, or to make aspects of your non-compliance public; and order you to implement the recommendations it has given.

Three measures apply to essential entities only: the CCB may designate a monitoring officer to oversee you, temporarily suspend a certification or authorisation covering part or all of your services, and temporarily prohibit the exercise of managerial functions.

Fines and measures are set proportionately, taking the situation and any repeat offending into account. But note the exposure is not limited to your security posture: failing to answer the inspection service, or retaliating against someone who complied with the law, each carries its own range.

How to prepare for NIS2 in Belgium

  1. Review every service you provide, not just your main one, against Annex I and II using the CCB's definition matrix and scope test. Then apply the size test, consolidating partner and linked enterprises. Record the reasoning — it is the basis of your registration.
  2. Register on Safeonweb@Work if you have not. Both deadlines have passed, so late registration is better than none, and keep the details current: changes are reportable immediately.
  3. Choose your conformity route deliberately. CyFun verification, ISO/IEC 27001, or CCB inspection are not equivalent in cost or timing, and if you are an essential entity the 18 April 2027 milestone is what you are now working towards.
  4. Risk-assess to pick your CyFun assurance level, using the CCB selection tool. Running below your NIS2 classification is permitted with justification — and sanctionable without it.
  5. Put management training and sign-off on the record. The management body must approve the measures, oversee them and be trained, and it is liable for the entity's breaches.
  6. Rehearse the 24-hour early warning, and agree in advance who is authorised to decide an incident is significant.
  7. Set supplier requirements. CyFun Basic is the CCB's own recommended floor for anyone in a NIS2 entity's supply chain, which makes it a defensible contractual ask.
  8. Keep the evidence. Self-assessments, internal audits, Statements of Applicability and training records are exactly what the inspection service and your assessment body will want to see.

Operating in more than one EU country

NIS2 is one Directive and 27 national laws. Belgium sits at the demanding end, and its conformity assessment has no equivalent in most member states.

  • Establishments in several member states mean several laws. The CCB is explicit: you are subject to the transposition law of each member state where you are established, with the national authorities cooperating on inspections and incident notifications.
  • Digital providers answer to one country. Cloud, data centre, CDN, managed service, managed security, DNS, TLD, domain registration, marketplace, search and social network providers are governed where their main establishment or EU legal representative sits — so a single filing, not twenty-seven.
  • Size tests are not portable. Belgium consolidates partner and linked enterprises, as Sweden does. Bulgaria switches that aggregation off entirely, and Germany relieves it only where the entity is IT-independent. The same group can be in scope in Brussels and out in Sofia.
  • Proof obligations are the real divergence. An ISO/IEC 27001 certificate serves you across borders; a CyberFundamentals label is Belgian. If you operate in several member states, ISO may be the more efficient route even though CyFun is free.
  • Reporting clocks travel well. The 24-hour, 72-hour and one-month chain matches most member states, including the 24-hour rule for trust service providers.
  • Sector rules can displace the general regime — DORA for financial entities being the common case.

Official links & resources

Safeonweb@Work — The NIS2 Law — the CCB's full guidance on scope, obligations, supervision, sanctions and the timeline. The authoritative starting point.
CCB — NIS2 — the regulator's overview, brochure and FAQ.
CyberFundamentals Framework — the four levels, the selection and self-assessment tools, and the list of authorised assessment bodies.
NIS2 Quickstart Guide — the CCB's seven-step route to compliance.

FAQ: NIS2 in Belgium

When did the NIS2 law take effect in Belgium?
18 October 2024 — the Law of 26 April 2024 together with the Royal Decree of 9 June 2024. There was no transition period for the core duties, which applied immediately. Only registration and the conformity assessment had their own deadlines.
Where do I register, and what if I missed the deadline?
On Safeonweb@Work. The deadlines were 18 December 2024 for digital-sector entities and 18 March 2025 for everyone else. Both have passed. Registering late is better than not registering: failing the identification and information obligations carries a fine of EUR 500 to 125,000 in its own right.
What was due on 18 April 2026?
The first conformity evidence from essential entities, 18 months after entry into force. Depending on the route you chose, that was a CyberFundamentals verification from an authorised body, or an ISO/IEC 27001 package sent to the CCB (scope, Statement of Applicability and most recent internal audit), or a CyFun self-assessment if you opted for direct CCB inspection. The next milestone is 18 April 2027. See Conformity assessment.
Do important entities need a conformity assessment?
No. Important entities are supervised ex post only — after an incident, or where there is evidence or indication of non-compliance — and are not subject to the regular conformity assessment. They may volunteer for the same regime as essential entities, which earns them the same presumption of conformity.
Is CyberFundamentals mandatory?
No. It is one of three routes, alongside ISO/IEC 27001 certification and direct CCB inspection. But implementing CyFun gives a presumption of conformity, it is free to use, and the CCB built it for exactly this purpose. Note that two versions run in parallel — CyFun 2023 and CyFun 2025 — until 18 April 2027, and you may choose which to apply.
Who is the competent authority?
The Centre for Cybersecurity Belgium (CCB), designated by the Royal Decree of 9 June 2024. It is unusually consolidated: national cybersecurity authority, national CSIRT for incident notifications, the inspection service, the body that authorises conformity assessment bodies, and the operator of the Safeonweb@Work portal. The law also provides for sectoral authorities and sectoral inspection services alongside it.
What are the fines?
Up to EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important entities, whichever is higher — with a EUR 500 floor on every range, and separate ranges up to EUR 200,000 for obstructing supervision or for penalising staff who complied with the law in good faith. All amounts double for repeat behaviour within three years. See Penalties.
We are not in scope. Does any of this reach us?
Possibly, in two ways. The CCB can identify an organisation of any size as essential or important where it is the sole provider in Belgium of an essential service, where disruption could significantly affect public safety, security or health, where it could cause significant systemic risk, or where the entity is critical at national or regional level. And if you supply a NIS2 entity, it may require a CyberFundamentals level of you by contract — the CCB recommends every potential supplier reach at least CyFun Basic.
Is my management personally exposed?
Yes. The management body must approve the risk-management measures and oversee their implementation, and it is liable if the entity breaches those obligations. Members must follow training. The law's explanatory memorandum defines a “member of a management body” broadly — including anyone with decisive influence over the appointment of a majority of directors — and applies the test recursively where the member is itself a legal person. For essential entities, the CCB can also temporarily prohibit an individual from exercising managerial functions.

Sources & verification

Every date, figure and obligation on this page was read from the CCB's own published guidance on 3 August 2026. Public NIS2 trackers contradict each other and are not used here.

  • Safeonweb@Work — The NIS2 Law — scope and its exceptions, the size bands, both registration deadlines and data sets, the 11 measures, the reporting chain, supervision, the full sanction ranges, and the conformity assessment timeline.
  • CCB — NIS2 — the law's full title and its relationship to the Royal Decree of 9 June 2024.
  • CCB — CyberFundamentals Framework — the four levels, and CyFun 2023 and CyFun 2025 running in parallel until 18 April 2027.
  • Implementing Regulation (EU) 2024/2690 — technical requirements and significance criteria for digital and trust service entities.
What we deliberately do not state. We no longer name individual sectoral authorities. An earlier version of this page stated that BIPT was competent for electronic communications and that the NBB and FSMA supervised the financial sector. The CCB's own NIS2 guidance names no sectoral authority at all, referring only to “the sectoral authority (if it exists)”, and we could not confirm the designations in the Royal Decree. The CCB states that only the texts published in the Belgian official journal are authoritative, so that is where a definitive list should be sought. We give no CyFun control counts: figures circulate for each level, but the CCB's framework page publishes none. We do not date the critical-entities resilience law, because the CCB's own page cites two different years for it in adjacent paragraphs. And we give no count of entities in scope, because registration is self-declared and no total is published.
Information provided for general guidance. Only the texts published in the Belgian official journal — the Law of 26 April 2024 and the Royal Decree of 9 June 2024 — are authoritative; consult them and Belgian legal counsel for final NIS2 compliance requirements.