Aller au contenu
Conformite

NIS2 en Belgique apres le 18 avril 2026 : la supervision n'est plus theorique

SV
Sophie Vandenberghe
Directrice conformite
9 août 2026
10 min de lecture
#NIS2#Belgique#CCB#CyFun#Supervision#Chaine d'approvisionnement#Conformite
Partager :
Conformite9 août 2026

NIS2 in Belgium After 18 April 2026

Belgium was among the first member states to transpose NIS2, through the law of 15 May 2025, published in the Belgian Official Gazette on 1 June 2025. Since then the Centre for Cybersecurity Belgium (CCB) has worked largely in an advisory posture.

That phase is over. With the 18 April 2026 deadline behind us, the CCB is supervising.

What the 18 April 2026 Deadline Required

By that date, essential entities had to be able to demonstrate that they were effectively implementing cybersecurity risk-management measures on a recognised pathway. In practice, for entities using the Belgian CyberFundamentals (CyFun®) framework, that meant one of:

  • A CyFun Basic or Important verification obtained, or
  • Being demonstrably in the process of obtaining one, or
  • A signed agreement with an accredited conformity assessment body

Entities on the ISO/IEC 27001 pathway demonstrate conformity through their certification instead. CyFun is the route the CCB designed for entities that do not already hold ISO 27001.

The full essential-entity certification level follows in 2027, and CyFun operates on a three-year audit cycle thereafter.

What Supervision Actually Looks Like

The shift matters because the CCB's toolkit is not limited to fines:

  • It can suspend or withdraw CyFun certifications
  • Loss of certification can disqualify an organisation from public procurement
  • It can publish the name of the entity and the nature of the breach

For a mid-sized Belgian supplier, the procurement consequence and the publication are frequently a sharper risk than the administrative penalty. A withdrawn certification is visible to every customer running third-party due diligence.

Underneath that sits the directive's own ceiling: up to €10 million or 2% of global annual turnover for essential entities, and personal accountability for the management body.

Three Situations

You hold a valid verification

Your exposure now is drift. Verification is a point-in-time statement, supervision is continuous, and the three-year cycle means the next assessment will look at what you sustained rather than what you built. The controls that decay fastest in practice are access review, supplier assessment, and exercise evidence.

Do this: schedule the evidence-generating activities as recurring obligations with named owners, not as project tasks that closed when the audit passed.

You are late

Being late is not the same as being unreachable. A signed agreement with an accredited assessment body was itself an acceptable demonstration of the pathway, and the practical question the CCB will ask is whether you are credibly progressing.

Do this, in order:

  1. Confirm your classification — essential or important — and your registration record
  2. Engage an accredited CAB and get the agreement signed
  3. Run a CyFun gap assessment and produce a dated remediation plan
  4. Close the incident-notification capability first: the 24-hour early warning and 72-hour report obligations apply regardless of your certification status

That last point is the one that most often goes unaddressed. Certification status does not suspend the notification duty.

You are unsure whether you are in scope

Scope turns on sector and size, and the supply-chain provisions pull in organisations that are not directly designated. If you supply an essential entity, your customer's supplier-security obligations become your commercial problem even where the law does not name you.

Do this: run the classification formally and document the conclusion, including a negative one. "We assessed ourselves as out of scope" is defensible. "We never looked" is not.

The Supply-Chain Squeeze

The most common way a Belgian SME discovers NIS2 is not through the CCB. It is through a customer questionnaire.

Essential and important entities must manage supply-chain security, which they discharge by pushing requirements down their vendor base. Expect contractual security clauses, evidence requests, and in some sectors a demand for CyFun verification as a condition of renewal.

Treating that as a sales problem rather than a compliance one is a mistake — but it is also the clearest business case for the work.

What To Have Ready

  • Classification decision, documented and dated
  • Registration record with the CCB
  • Risk-management measures mapped to the framework you chose
  • Incident notification runbook meeting the 24h/72h/1-month rhythm
  • Supplier security requirements and evidence of assessment
  • Management body training records — accountability is personal
  • Evidence that the above is maintained, not merely established

Sources

AVIS // DEMANDER UNE CONSULTATION EXPERT

Besoin d'assistance opérationnelle ?

Nos analystes sont disponibles pour vous aider à mettre en oeuvre les bonnes pratiques et sécuriser votre organisation contre les menaces émergentes.

COMMS // ABONNEMENT AU FLUX D'INTELLIGENCE

Briefing reçu. Abonnez-vous pour en recevoir plus.

Recevez des briefings classifiés et des analyses de menaces directement dans votre boite de reception sécurisée.

S'abonner à la Newsletter