NIS2 in Belgium After 18 April 2026
Belgium was among the first member states to transpose NIS2, through the law of 15 May 2025, published in the Belgian Official Gazette on 1 June 2025. Since then the Centre for Cybersecurity Belgium (CCB) has worked largely in an advisory posture.
That phase is over. With the 18 April 2026 deadline behind us, the CCB is supervising.
What the 18 April 2026 Deadline Required
By that date, essential entities had to be able to demonstrate that they were effectively implementing cybersecurity risk-management measures on a recognised pathway. In practice, for entities using the Belgian CyberFundamentals (CyFun®) framework, that meant one of:
- A CyFun Basic or Important verification obtained, or
- Being demonstrably in the process of obtaining one, or
- A signed agreement with an accredited conformity assessment body
Entities on the ISO/IEC 27001 pathway demonstrate conformity through their certification instead. CyFun is the route the CCB designed for entities that do not already hold ISO 27001.
The full essential-entity certification level follows in 2027, and CyFun operates on a three-year audit cycle thereafter.
What Supervision Actually Looks Like
The shift matters because the CCB's toolkit is not limited to fines:
- It can suspend or withdraw CyFun certifications
- Loss of certification can disqualify an organisation from public procurement
- It can publish the name of the entity and the nature of the breach
For a mid-sized Belgian supplier, the procurement consequence and the publication are frequently a sharper risk than the administrative penalty. A withdrawn certification is visible to every customer running third-party due diligence.
Underneath that sits the directive's own ceiling: up to €10 million or 2% of global annual turnover for essential entities, and personal accountability for the management body.
Three Situations
You hold a valid verification
Your exposure now is drift. Verification is a point-in-time statement, supervision is continuous, and the three-year cycle means the next assessment will look at what you sustained rather than what you built. The controls that decay fastest in practice are access review, supplier assessment, and exercise evidence.
Do this: schedule the evidence-generating activities as recurring obligations with named owners, not as project tasks that closed when the audit passed.
You are late
Being late is not the same as being unreachable. A signed agreement with an accredited assessment body was itself an acceptable demonstration of the pathway, and the practical question the CCB will ask is whether you are credibly progressing.
Do this, in order:
- Confirm your classification — essential or important — and your registration record
- Engage an accredited CAB and get the agreement signed
- Run a CyFun gap assessment and produce a dated remediation plan
- Close the incident-notification capability first: the 24-hour early warning and 72-hour report obligations apply regardless of your certification status
That last point is the one that most often goes unaddressed. Certification status does not suspend the notification duty.
You are unsure whether you are in scope
Scope turns on sector and size, and the supply-chain provisions pull in organisations that are not directly designated. If you supply an essential entity, your customer's supplier-security obligations become your commercial problem even where the law does not name you.
Do this: run the classification formally and document the conclusion, including a negative one. "We assessed ourselves as out of scope" is defensible. "We never looked" is not.
The Supply-Chain Squeeze
The most common way a Belgian SME discovers NIS2 is not through the CCB. It is through a customer questionnaire.
Essential and important entities must manage supply-chain security, which they discharge by pushing requirements down their vendor base. Expect contractual security clauses, evidence requests, and in some sectors a demand for CyFun verification as a condition of renewal.
Treating that as a sales problem rather than a compliance one is a mistake — but it is also the clearest business case for the work.
What To Have Ready
- Classification decision, documented and dated
- Registration record with the CCB
- Risk-management measures mapped to the framework you chose
- Incident notification runbook meeting the 24h/72h/1-month rhythm
- Supplier security requirements and evidence of assessment
- Management body training records — accountability is personal
- Evidence that the above is maintained, not merely established