NIS2 Country Guide

NIS2 Belgium: Compliance, Authorities & Key Requirements

Learn how Belgium implements the NIS2 Directive: which sectors and entities are covered, how registration works via Safeonweb@Work, and what steps organisations must take to prepare for compliance.

Belgium In force: 18 Oct 2024 Registration by: 18 Mar 2025*

Introduction

Belgium has implemented NIS2 by adopting a new cybersecurity law and a royal decree. Entities operating essential or important services must comply with enhanced cybersecurity, risk management, and reporting requirements, and must register with the national authority within the prescribed deadlines.

Quick link: See the CCB’s NIS2 overview and registration portal on Safeonweb@Work: ccb.belgium.be/regulation/nis2 · atwork.safeonweb.be/nis2

NIS2 implementation in Belgium

Belgium transposed NIS2 via the Act of 26 April 2024 and the Royal Decree of 9 June 2024. The law entered into force on 18 October 2024. Registration is handled through Safeonweb@Work, with most entities registering by 18 March 2025 and digital-sector entities by 18 December 2024.

Status

In force since 18 Oct 2024.

Registration

Register via Safeonweb@Work. Deadlines: 18 Dec 2024 (digital sector) and 18 Mar 2025 (others).

SectorBelgium note
Electronic communications & digital infrastructures BIPT designated as competent authority for this sector (registration still via Safeonweb@Work).
Finance NBB and FSMA are the primary supervisors (notably for DORA) and cooperate with the CCB on NIS2 where relevant.
All other sectors The Centre for Cybersecurity Belgium (CCB) acts as national competent authority/CSIRT/SPOC, coordinating with sectoral bodies as needed.

What you need to know about compliance & certification

Belgium follows the NIS2 two-tier model (Essential / Important) and Article 21 risk-management measures.

Scope criteria

  • Provide a service in Annex I or II and meet size thresholds (≥50 employees or ≥€10m).
  • Established in Belgium or provide relevant services on Belgian territory.

Obligations

  • Risk management & security policy
  • Incident handling & reporting (CCB channels)
  • Business continuity & crisis management
  • Supply-chain security & vendor risk
  • Access control, segmentation, encryption
  • Executive/board accountability & training

Standards & alignment

Map controls to ISO/IEC 27001:2023, NIST CSF 2.0, and ENISA guidance as appropriate.

Incident reporting: Use the CCB notification guide for thresholds, timelines, and channels.

Competent authorities & CSIRT

The Centre for Cybersecurity Belgium (CCB) leads, with sectoral regulators collaborating where relevant.

RoleAuthorityNotes
National competent authority / CSIRT / Single Point of ContactCentre for Cybersecurity Belgium (CCB)Guidance, registration, supervision & incident handling coordination (Safeonweb@Work).
Electronic communications & digital infrastructuresBelgian Institute for Postal Services and Telecommunications (BIPT)Designated competent authority for this sector.
Financial sector (DORA primary)National Bank of Belgium (NBB) & FSMAFinancial supervision; cooperate with CCB for cyber incident oversight.

National NIS2 timeline & key dates

17 May 2024 — Publication of the NIS2 Act in the Belgian Official Journal.
9 Jun 2024 — Royal Decree published (implementation measures).
18 Oct 2024 — Law enters into force.
18 Dec 2024 — Registration deadline for digital-sector entities.
18 Mar 2025 — Registration deadline for other entities.

Sector-specific requirements (Belgium)

  • Electronic communications: BIPT supervises under the NIS2 law for this sector (registration via Safeonweb@Work still required).
  • Finance: DORA obligations overseen by NBB/FSMA; align with NIS2 risk-management and incident duties.
  • All others: CCB acts as competent authority and CSIRT; use CCB guides and portals.

Penalties for non-compliance

Belgian law provides supervisory powers and sanctions aligned with NIS2’s turnover-based caps. The CCB coordinates supervision; sectoral regulators may support enforcement in their domains.

How to prepare for NIS2 in Belgium

  1. Determine scope: confirm Annex I/II services and size thresholds; classify EE/IE.
  2. Register: submit details on Safeonweb@Work by your deadline.
  3. Governance: board accountability for cybersecurity.
  4. Risk management: align with ISO 27001 / NIST CSF; map to ENISA guidance.
  5. Supply chain: assess providers; set contractual security requirements.
  6. Incident readiness: follow the CCB notification guide; test 24/7 escalation.
  7. Continuity & crisis: document BCP/DR; exercise regularly.
  8. Train & prove: management training, staff awareness, evidence.

Official links & resources

FAQ: NIS2 in Belgium

When did NIS2 enter into force in Belgium?
On 18 October 2024.
Where do I register and by when?
Register on Safeonweb@Work. Digital sector by 18 Dec 2024, others by 18 Mar 2025.
Who is the competent authority?
The Centre for Cybersecurity Belgium (CCB) acts as national authority, CSIRT and SPOC; BIPT is competent for electronic communications & digital infrastructures; financial regulators NBB/FSMA oversee DORA and cooperate on NIS2 where relevant.
Information provided for general guidance; consult official national sources for updates.