Belgium’s NIS2 Act Adds Registration and Assurance to Cybersecurity
Belgium’s NIS2 regime combines risk-management and incident-reporting duties with something many national implementations leave less explicit: registration followed by a structured route to independent assurance.
The Act of 26 April 2024 establishing a cybersecurity framework for networks and information systems of general interest for public security transposed NIS2. Most obligations applied from 18 October 2024, with the Centre for Cybersecurity Belgium, or CCB, at the centre of registration, incident handling and supervision.
For essential and important entities, the implementation story has three connected parts: know that you are in scope, operate the required controls and be able to demonstrate their effectiveness.
Self-identification creates an early governance test
The Belgian framework required covered entities to register through Safeonweb@Work. Entities in specified digital sectors had a two-month period after 18 October 2024; most other entities had five months. Those initial deadlines have passed, but the underlying duty to maintain accurate registration remains relevant.
Scope cannot be decided from a trading name. Organisations need to map legal entities, services, size and sector. A corporate group may have one security operation while several subsidiaries have different classifications and reporting duties.
The registration evidence should include the legal analysis, service description, size data, submitted information and later CCB communications. Changes in service, ownership or contact details need a monitored update process.
Management must approve and understand the measures
From 18 October 2024, management bodies of covered entities were required to approve cybersecurity risk-management measures, oversee implementation, follow training and face responsibility for violations by the entity within the statutory framework.
Approval should be based on the regulated services and their risk, not a generic security-policy bundle. Management needs a view of material gaps, incidents, supplier concentration, continuity and funded remediation. Minutes should record decisions and follow-up.
The measure set includes incident handling, business continuity, crisis management, supply-chain security, vulnerability management, access control, asset management, cryptography and authentication. These controls need to be connected. For example, an unmaintained asset inventory undermines patching, incident scope and recovery at once.
CyberFundamentals provides a national assurance route
Belgium permits essential entities to use the CCB’s CyberFundamentals framework, ISO/IEC 27001 or direct CCB inspection within the prescribed assurance model. CyberFundamentals uses Basic, Important and Essential assurance levels selected from the entity’s risk assessment.
The transition schedule required initial verification or evidence milestones by 18 April 2026 and, for higher routes, further certification or progress by 18 April 2027. By the current verification date for this article, the first milestone is no longer a future planning point. Entities should preserve what they submitted or obtained and track the next applicable step.
A certification decision should not be made solely by procurement or marketing. The scope must cover the networks and information systems supporting the regulated services. A narrow corporate-office certificate can leave the operational service outside the evidence boundary.
Incident reporting needs one decision path
Significant incidents follow the NIS2 staged model: an early warning within 24 hours, an incident notification within 72 hours and later reporting. The initial message is designed for speed and coordination, not forensic perfection.
Entities should define who determines significance, who can notify the CCB and which suppliers must provide immediate facts. A processor or managed-service provider may see the event first, but the regulated entity remains responsible for its external duty.
Tabletop exercises should include incomplete and changing information. The team should practise correcting a preliminary assessment without treating the first notification as an irreversible public conclusion.
The evidence spine
A mature Belgian NIS2 file should connect:
- scope analysis and registration;
- regulated services and supporting systems;
- risk assessment and selected assurance level;
- management approval and remediation oversight;
- certification, verification or direct-supervision evidence;
- supplier responsibilities and escalation; and
- incident decisions and notifications.
Belgium’s approach makes cybersecurity assurance visible. The goal is not to collect a certificate and stop. It is to maintain a defensible chain from the service’s risk to the controls, their independent verification and the management decisions that keep them effective.
Official sources
- Centre for Cybersecurity Belgium: NIS2 notification guide
- Centre for Cybersecurity Belgium: NIS2 FAQ and implementation timeline
Continue the series
- Also in Belgium: Belgium’s Whistleblower Law Makes Confidential Case Handling a System Requirement
- European National Cyber & Digital Law Series index
This article provides general information and is not legal advice.


