Belgium NIS2 compliance guide — CCB CyberFundamentals framework tiers and enforcement

Belgium’s 3-Tier CyberFundamentals Scheme: How the CCB Maps Your NIS2 Obligations — and What Each Tier Requires

Belgium moved faster than any other EU member state on NIS2. When Directive 2022/2555 was published in December 2022, most national governments were still consulting. Belgium had national legislation — the Law of 26 April 2024 — signed and in force by 18 October 2024. By the one-year mark, 4,000 entities were registered and 75% had already selected a compliance framework, with the majority choosing the CCB’s own CyberFundamentals (CyFun) scheme.

That speed matters. It means Belgium’s enforcement infrastructure is operational, not hypothetical, and the Centre for Cybersecurity Belgium is not waiting for further EU pressure to act. The 18 April 2026 deadline for essential entities to demonstrate active compliance is less than a year away, and the CCB has already stated this is “a binding regulatory obligation, not a procedural formality.”

This guide covers the parts most Belgium-focused NIS2 articles miss: how the CCB’s four operational units interact with regulated entities, how the CyberFundamentals tiers map to your specific obligations, and how the three conformity assessment pathways compare in practice.

Does NIS2 Apply to Your Belgian Organisation?

Belgium’s NIS2 law uses a three-part test. Your organisation falls in scope if it: provides a service listed in Annex I or Annex II of the law, employs 50 or more full-time staff or generates over €10 million in annual turnover, and operates under Belgian jurisdiction.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Five categories fall in scope regardless of size: qualified trust service providers, DNS service providers, top-level domain (TLD) registries, providers of public electronic communications networks, and domain name registrators. If your organisation is in one of these categories, size thresholds do not apply.

Annex Sectors Entity Classification
I — Highly Critical Energy, transport, health, drinking water, wastewater, digital infrastructure, ICT managed services, public administration, space Essential
I — Highly Critical Banking, financial markets Essential — but subject to DORA rather than NIS2 for most obligations
II — Other Critical Postal services, waste management, chemicals, food production, manufacturing, digital providers, research Important

The Essential vs Important classification determines your supervision intensity, not just your fine ceiling. Essential entities face proactive, ex ante supervision: the CCB can initiate unannounced on-site inspections at any time. Important entities face reactive, ex post supervision and are inspected based on evidence of non-compliance or following a reported incident. Misclassifying yourself as Important when you are actually Essential means operating without the required audit readiness infrastructure.

Public administrations at federal level are in scope but exempt from administrative fines — they face binding corrective orders instead. The CCB also has the power to designate any entity as Essential or Important outside standard thresholds if it is the sole provider of a critical service, poses systemic risk, or has significant cross-border implications. Use the Essential vs Important classification guide if your sector sits near a boundary, and run the NIS2 scope assessment to confirm applicability.

The CCB’s Four Operational Units — and What Each Means for Your Organisation

Most Belgium NIS2 guides describe the Centre for Cybersecurity Belgium as “the national authority” and stop there. Understanding how the CCB’s four units interact with regulated entities is operationally relevant: different units handle different touchpoints, and knowing which one you are dealing with changes what you need to prepare.

CERT.be — National CSIRT and Technical Incident Response

CERT.be is Belgium’s national Computer Security Incident Response Team. When your Article 23 early warning lands at notif.safeonweb.be within 24 hours of discovering a significant incident, it is processed by the CERT.be function within the CCB. CERT.be also provides containment and remediation guidance, assists government departments with technical incident response, and coordinates with other EU national CSIRTs during cross-border events. Your Article 23 notification procedures are not just documentation artefacts — they directly determine how quickly CERT.be can act when you report.

CyTRIS — Cyber Threat Research and Intelligence Sharing

CyTRIS operates as the first point of contact for incident intake and conducts ongoing threat intelligence operations. Practically, CyTRIS may contact your organisation before you detect a problem. If it identifies your infrastructure in compromised credential dumps, active exploit campaigns, or intelligence shared through the Early Warning System (EWS), it issues what it calls spear warnings — individual, organisation-specific messages about specific vulnerabilities on your infrastructure. CyTRIS also hosts quarterly “Connect and Share” webinars for essential service providers and manages MISP Threat Sharing platforms for cross-CSIRT intelligence exchange.

NCCA — National Cybersecurity Certification Authority

The NCCA implements the EU Cybersecurity Act and manages European cybersecurity certification schemes for ICT products, services, and processes. For NIS2-regulated entities, the NCCA is most relevant when procuring certified ICT components — the EU Cybersecurity Act’s certification framework applies to supply chain elements that feed into Article 21(2)(d) and (e) obligations. Organisations targeting supply chain security compliance through certified vendor components will interact with schemes administered under NCCA oversight.

NCC-BE — National Cybersecurity Coordination Centre

The NCC-BE coordinates Belgium’s participation in the EU Cybersecurity Competence Network, managing access to EU research and innovation funding and connecting industry, academia, and public bodies. For regulated entities, NCC-BE is most relevant if your organisation is investing in building internal security capabilities through EU-funded programmes — a medium-term capability resource rather than a day-one compliance priority.

What Belgium’s Law of 26 April 2024 Changed from NIS1

Belgium’s NIS1 law (2019) covered a narrower set of operators of essential services with lighter obligations and no management liability provisions. The Law of 26 April 2024 expanded scope, mandated specific measures, and introduced personal accountability for board members. The three structural changes most relevant for compliance planning:

Wider and more precise scope. NIS2 covers roughly twice as many sectors as NIS1. Manufacturing, food production, waste management, and postal services are new additions. The size thresholds (50 employees, €10M turnover) create a significantly larger regulated population than NIS1’s narrower operator-of-essential-services designations.

Mandatory minimum measures. NIS1 required “appropriate measures” without specifying them. Article 21(2) of Directive 2022/2555 mandates a minimum set of ten measure categories: risk analysis and information system security, incident handling, business continuity and crisis management, supply chain security, secure systems acquisition and development, policies assessing measure effectiveness, cyber hygiene and training, cryptography and encryption, HR security and access control, and multi-factor authentication. These are not a recommended baseline — they are the legal minimum.

Management accountability. Under NIS2, management bodies must formally approve cybersecurity risk-management measures, complete cybersecurity training, and personally accept liability for organisational non-compliance. Board members may face temporary prohibition from management functions if an organisation repeatedly fails to remediate after CCB orders. NIS1 contained no equivalent provision. For what this means in practice for your board, the board obligations guide covers documentation and training requirements.

Your Core Obligations Under Belgian NIS2

Belgian NIS2 entities must satisfy five categories of ongoing obligation. Registration via Safeonweb@Work was required by March 2025 — if your organisation has not yet registered, do so immediately. Failure to comply with a registration order carries an administrative fine of up to €200,000, and the CCB uses its registration database as the starting point for all supervisory and enforcement activity.

Cybersecurity risk-management measures (Article 21). You must implement proportionate technical, operational, and organisational measures covering all ten Article 21(2)(a)–(j) categories. Proportionality is assessed against your sector exposure, entity size, and the likelihood and severity of incidents. The CCB’s recommended implementation path is the CyberFundamentals framework at the appropriate assurance level, described in detail in the next section. A risk assessment against the ten measure categories is the required starting point.

Significant incident notification. Incidents significantly affecting service availability or confidentiality must be reported through notif.safeonweb.be on a three-step schedule: an early warning within 24 hours of discovery, a full notification within 72 hours, and a final report within one month. Trust service providers face a tighter 24-hour window for full notification. The incident reporting guide covers how “significant” is defined and what each notification must contain.

Management training and approval. Your management body must formally approve the cybersecurity measures you implement. Board and executive training in cybersecurity risk is mandatory — not discretionary. Documentation of that training and approval is what an auditor will request during a conformity assessment.

Authority cooperation. Essential and important entities must cooperate with CCB supervision, providing information on request, facilitating inspections, and complying with binding instructions. Refusing a supervisory request carries fines starting at €500 and scaling to €200,000 depending on the nature of the refusal.

The CyberFundamentals Framework — Belgium’s Unique Compliance Pathway

No other EU member state has developed a national cybersecurity framework as tightly integrated with NIS2 enforcement as Belgium’s CyberFundamentals (CyFun) scheme. A formal CyFun label creates a legal presumption of conformity with NIS2 obligations — the same legal effect as ISO/IEC 27001 certification. Belgium co-owns the scheme with Ireland and Romania, and Portugal and Croatia are in the process of adopting it.

Four Assurance Levels

Level Target Organisation Controls Min. Score Verification Standard
Small Micro-organisations with limited IT Baseline guidance Self-assessment
Basic Entry-level hygiene for all enterprises 34 essential controls 2.5 / 5 ISO 17029 verification by accredited CAB
Important Higher-risk orgs, targeted attack scenarios 34 + 99 additional 3.0 / 5 ISO 17029 verification by accredited CAB
Essential Critical infrastructure, advanced threats 34 + 99 + 85 advanced 3.5 / 5 ISO 17021-1 certification by accredited CAB

The verification versus certification distinction matters for cost and timeline. Basic and Important levels require third-party verification under ISO 17029 — a process designed to be proportionate and faster, with accredited Conformity Assessment Bodies (CABs) approved by the CCB. The Essential level requires full management system certification under ISO 17021-1, the same standard used for ISO 27001 certification, which is more resource-intensive and typically takes six to twelve months from preparation to label issuance.

CyFun 2025 — What Changed and Why It Matters Now

The CCB released an updated version of the framework in 2025 that most compliance guides have not yet incorporated. If your organisation completed a CyFun self-assessment against the prior version, your coverage may be incomplete under the current framework.

Governance as a sixth function. CyFun 2025 aligned with NIST Cybersecurity Framework 2.0, adding Governance alongside the existing five functions (Identify, Protect, Detect, Respond, Recover). The structure is now 6 functions, 22 categories, and 106 subcategories. The Governance function directly addresses the management accountability obligation in Article 20 of the Directive — meaning board-level cybersecurity oversight is now a measurable CyFun control, not just a legal statement.

Extended OT and supply chain controls. CyFun 2025 added specific controls for operational technology (OT) environments and interconnected supply chains, addressing a gap that particularly affected manufacturing, energy, and water entities in the prior version.

Clarified maturity scoring. The update introduced explicit documentation-versus-implementation maturity scoring, reducing the risk that “policy on paper” scores mask absent implementation. This is relevant for conformity assessment: a CAB verifying at Basic level will now assess whether controls are operationally implemented, not just documented.

For a structured comparison of how CyFun controls map against ISO 27001 requirements, the NIS2 vs ISO 27001 guide covers the control overlap and the gaps you need to close regardless of which path you choose.

Three Conformity Assessment Pathways — Choosing the Right One

By 18 April 2026, essential entities must demonstrate they are actively pursuing one of three conformity pathways. The choice carries materially different risk profiles.

Pathway 1: CyFun verification or certification. Engage an accredited CAB, complete your self-assessment targeting Basic or Important for April 2026 (Essential for April 2027), and obtain a formal CyFun label. This is the CCB’s preferred route and produces the clearest presumption of NIS2 conformity. A list of accredited CABs is published at cyfun.eu.

Pathway 2: ISO/IEC 27001 certification. By 18 April 2026, submit your certification scope, Statement of Applicability, and most recent internal audit report to the CCB. Full ISO 27001 certification must be completed by 18 April 2027. This pathway suits organisations that already have an active ISO 27001 programme or a certified management system infrastructure that can absorb NIS2 scope. A gap analysis against the ten Article 21 measure categories is the required first step.

Pathway 3: Direct CCB inspection. Submit a self-assessment and formally request an audit by the CCB’s inspection service. The CCB explicitly warns that this pathway “may lead directly to supervisory measures” — meaning the inspection itself can trigger enforcement action if significant gaps are found, rather than providing a remediation window. This is best understood as a last resort for organisations that cannot engage a CAB before the April 2026 deadline, not a lower-effort alternative.

One important caveat applies to all three pathways: a CyFun label or ISO 27001 certificate addresses risk-management measures — it does not automatically satisfy Article 23 incident notification requirements. Those procedures require separate documented processes and tested response capabilities. Conformity assessment and incident response readiness are distinct obligations under Belgian law.

Enforcement — How the CCB Investigates and What Fines Look Like

Belgium operates a dual supervisory model. The CCB is the primary enforcement authority, but sectoral regulators handle day-to-day compliance oversight in their domains: FSMA and the National Bank of Belgium for financial services, BIPT for telecommunications, FANC and CREG for energy and nuclear. When a significant incident crosses sector boundaries, involves national interest, or reveals systemic non-compliance, the CCB’s override authority activates immediately. Escalation to the CCB is mandatory when a significant incident occurs or major non-compliance is confirmed.

The supervision tier determines how proactively the CCB monitors your organisation:

  • Essential entities (ex ante): The CCB can initiate proactive audits, require regular conformity assessments, and conduct on-site inspections at any time. No triggering incident is required.
  • Important entities (ex post): The CCB investigates based on evidence of non-compliance or following an incident report. Important entities may voluntarily opt into the essential entity oversight regime.

The fine structure under Belgian NIS2 is tiered by violation type and entity classification:

Violation Category Maximum Fine
Information obligation violations €125,000
Refusal to cooperate with supervision €200,000
Important entity: security / notification non-compliance €7,000,000 or 1.4% of global annual turnover (whichever is higher)
Essential entity: security / notification non-compliance €10,000,000 or 2% of global annual turnover (whichever is higher)
Repeat violations within 3 years All fines doubled

Financial penalties are one enforcement tool among several. The CCB can also issue public warnings, appoint supervisory officers, suspend certifications, and — for persistent non-compliance after repeated CCB orders — recommend temporary prohibition from holding management functions. The supervisory measures guide covers what triggers escalation from warning to sanction, and the penalties reference maps each fine category to its statutory basis.

Belgium’s NIS2 Compliance Timeline

Date Obligation Applies To
18 October 2024 Belgian NIS2 law entry into force; all obligations active from this date All entities
18 December 2024 Registration deadline: DNS, TLD, cloud, data centres, managed service providers Digital sector entities
18 March 2025 Registration deadline: all other essential and important entities All other entities
18 April 2026 Demonstrate active conformity pathway: CyFun Basic/Important verification, ISO 27001 scope + SoA submission, or CCB inspection request Essential entities
18 April 2027 Full CyFun Essential certification or full ISO 27001 certification Essential entities

Important entities are not bound by the April 2026 conformity assessment deadlines — but they remain fully subject to all security measure, incident notification, management training, and cooperation obligations from October 2024 onward. The certification deadlines apply to essential entities only; the operational obligations apply to everyone.

Key Takeaways

Belgium’s NIS2 implementation is among the most operationally advanced in the EU, which means the compliance margin for essential entities is narrowing rather than widening. Three practical priorities for any Belgian essential entity right now:

Choose your conformity pathway before mid-2025 if you have not already. CyFun Basic verification, ISO 27001, and the direct CCB inspection path each carry different timelines and risks. The direct inspection pathway can trigger enforcement action rather than resolve it — it is not a lower-effort alternative to CAB engagement.

Use the CyFun 2025 version, not the prior iteration. The addition of Governance as a sixth function and the updated OT controls means earlier self-assessments may be incomplete. Organisations targeting Basic level that completed their assessment against the previous version should validate their coverage against the current 106-subcategory structure.

Treat incident notification as a separate workstream. Framework certification and tested incident notification procedures are distinct obligations. CERT.be processes notifications; CyTRIS may contact you proactively. Both interactions require preparation that no certification label replaces.

Frequently Asked Questions

Does NIS2 apply to my Belgian SME?

If your SME employs fewer than 50 people and generates under €10 million in revenue, the general threshold rule exempts it — unless you operate in a size-exempt category (trust services, DNS, TLD, public communications, domain registration). Some SMEs are designated in scope by the CCB if they are the sole provider of a critical service. Run the Safeonweb@Work scope assessment to confirm.

Can I use ISO 27001 instead of CyberFundamentals?

Yes. The CCB accepts both pathways with equal legal standing. ISO 27001 certification or an active ISO 27001 programme with submitted scope and Statement of Applicability satisfies the April 2026 requirement for essential entities. For organisations without an existing ISO 27001 programme, CyFun is typically faster to implement because the control set is pre-defined for NIS2.

What happens if I missed the March 2025 registration deadline?

Register via Safeonweb@Work immediately. Failure to comply with a registration order carries a fine of up to €200,000. Late registration does not retroactively exempt your organisation from obligations that applied from 18 October 2024 — incident notification, security measures, and management training were all active from the law’s entry into force.

How long does CyberFundamentals verification take?

A well-prepared organisation targeting Basic verification (34 controls, 2.5/5 minimum score) can typically complete the process in three to six months. Important-level verification adds 99 controls and requires more preparation. Essential-level ISO 17021-1 certification typically takes six to twelve months from preparation start to label issuance. Begin with a self-assessment using the CyFun selection tool at cyfun.eu.

Is healthcare under the CCB or a sectoral authority?

Healthcare is an Annex I highly critical sector, and healthcare entities register with and report incidents to the CCB as the primary authority. Unlike finance (FSMA/NBB) or telecommunications (BIPT), there is no dedicated sectoral co-regulator for healthcare with day-to-day oversight powers. The CCB supervises healthcare entities directly under the ex ante essential entity regime.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: