NIS2 Belgium Digital Infrastructure: Why BNIX, DNS Belgium, and Belnet Answer to BIPT, Not Just the CCB
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Belgium’s Centre for Cybersecurity (CCB) gets credited as the country’s sole NIS2 authority in almost every compliance overview. For digital infrastructure, that’s incomplete. BNIX, the internet exchange point routing traffic for Proximus, Telenet, Orange, and international content networks through Brussels, is operated by Belnet, Belgium’s national research and education network [13][14]. DNS Belgium runs the .be registry behind roughly 1.7 million domain names [7]. Neither is supervised day to day by the CCB. That job belongs to BIPT, the Belgian Institute for Postal Services and Telecommunications — Belgium’s regulator map for this sector has three bodies in it, not one [8]. The classification matters more now than a year ago: the CCB’s 18 April 2026 deadline for essential-entity compliance evidence has already passed, and incident reports are up nearly 70% year over year [9][10].
Does NIS2’s Digital Infrastructure Sector Cover You?
Digital infrastructure is one of NIS2 Annex I’s sectors of high criticality, and Belgium’s transposing law carries it forward without modification. Eight entity types sit inside it — and only three of them become essential entities automatically, regardless of headcount or turnover.
| Entity type | In the digital infrastructure sector? | Essential regardless of size? |
|---|---|---|
| Internet exchange point (IXP) operators | Yes | No — standard size thresholds apply |
| DNS service providers (excl. root name servers) | Yes | Yes |
| Top-level domain (TLD) name registries | Yes | Yes |
| Qualified trust service providers | Yes | Yes |
| Cloud computing service providers | Yes | No |
| Data centre service providers | Yes | No |
| Content delivery network (CDN) providers | Yes | No |
| Public electronic communications network/service providers | Yes | No |
The legal basis for the “regardless of size” column is narrow: Article 3(1)(b) names only “qualified trust service providers and top-level domain name registries as well as DNS service providers” as essential entities with no size test attached [1]. Everyone else on the list — IXPs included — reaches essential status only by clearing the ordinary large-enterprise thresholds, or lands as important below that line. That single distinction is why Belnet’s BNIX and DNS Belgium, two organisations in the same Annex I sector, can end up on different sides of the classification test. Our guide to Belgium’s CyberFundamentals tiers covers the essential-versus-important headcount and turnover mechanics in full.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
One Sector, Three Regulators: CCB, BIPT, and FPS Economie
Most Belgium NIS2 overviews describe a single regulator. For digital infrastructure, that flattens a genuinely three-way split that a compliance team needs to get right before it, not after an inspection.
| Body | Role | Covers |
|---|---|---|
| CCB (Centre for Cybersecurity Belgium) | National NIS2 authority, CSIRT, single registration point | All sectors — registration, incident intake, malicious/illegal-attack follow-up |
| BIPT (Belgian Institute for Postal Services and Telecommunications) | Sectoral authority and sectoral inspectorate | Digital infrastructure (excluding trust services) and postal/courier — internet providers, DNS, TLD registries, cloud, data centres, CDNs, electronic communications networks/services [8] |
| FPS Economie (Federal Public Service Economy) | Article 17 eIDAS supervisory body | Qualified trust service providers [11] |
CCB and BIPT operate under a cooperation protocol, not a clean hand-off. Entities that demonstrate compliance via certification (CyberFundamentals or ISO 27001) get monitored by CCB alone. For inspection-based supervision, the split runs by entity type: BIPT alone inspects operators it has designated as critical infrastructure, while CCB and BIPT jointly build the annual inspection plan for everyone else [8]. Incident handling divides similarly — CCB takes reports pointing to a malicious or illegal computer attack; BIPT handles the rest [8]. Registering with CCB’s Safeonweb@Work portal is the correct first step for every entity, but for digital infrastructure operators it’s the start of the relationship, not the end — BIPT is who shows up for the inspection. Our guide to Belgium’s CCB structure covers CERT.be, CyTRIS, NCCA, and NCC-BE in detail; BIPT sits entirely outside that internal CCB structure, as a separate federal regulator.
Belnet’s Split Identity: NREN by Mandate, IXP Operator by Function
Belnet is Belgium’s National Research and Education Network, holding the legal status of a public service with its own management structure inside the Federal Public Service for Science Policy Programming (Belspo) [13]. In that capacity, it connects universities, federal administrations, and international research networks such as GEANT — a role that looks more like public-sector IT than digital infrastructure in the NIS2 sense. But Belnet also operates BNIX, Belgium’s national internet exchange point, founded in 1995 and a charter member of Euro-IX [14]. That second function is what pulls Belnet into Annex I’s digital infrastructure sector as an IXP operator, regardless of how its NREN work is classified.
NIS2 classifies entities by activity, not ownership — a public-service operator performing a digital-infrastructure function gets no carve-out for being publicly funded. What isn’t automatic is whether that specific function clears the bar for essential status. IXPs are absent from Article 3(1)(b)’s size-independent list [1], so BNIX’s classification runs on the ordinary large-enterprise threshold, or on the Article 2 catch-all for entities that are the sole provider of a service critical to societal or economic activity in a Member State. Belnet has not published a formal NIS2 classification for BNIX, and no primary Belgian source does either — treat this as reasoned inference, not verified fact: BNIX is, practically speaking, Belgium’s only nationally significant IXP, which makes the sole-provider argument plausible even before a pure headcount-and-turnover test is run. Any organisation running a comparable dual-purpose network should expect the same two-step test: classify the organisation, then classify each function it performs separately.
DNS Belgium: Essential by Default, No Size Test Needed
DNS Belgium doesn’t face Belnet’s ambiguity. As the entity delegated the .be top-level domain, it is a TLD name registry under Article 6(21) and therefore essential under Article 3(1)(b) the moment it provides the service — no size threshold, no catch-all argument required [1][2]. DNS Belgium’s own compliance guidance confirms the consequence: every registrar, reseller, and registry operating in Belgium had to register with the CCB by 18 December 2024, two months after the law’s 18 October 2024 entry into force — five months ahead of the general registration deadline the rest of the economy faced [7].
The obligation splits further by what a registrar actually runs. One offering recursive or authoritative nameserver services is a DNS service provider in its own right and owes the full NIS2 risk-management and incident-reporting regime [7]. One that only sells domain registrations without running nameservers faces lighter Article 28 obligations instead — maintaining and verifying registrant contact data, publishing it, and providing access to law enforcement on legitimate request [7]. Article 27’s EU-wide entity registry adds a separate filing on top of CCB registration: DNS providers, TLD registries, and domain registration services must submit organisation details, sector classification, and IP address ranges, updating within three months of any change [4]. Our Article 27 registration guide walks through the exact fields and portal mechanics.
The CIR 2024/2690 Gap: Why an IXP Builds Its Own Rulebook
All eight entity types in the table above answer to Article 21(2)’s ten baseline security measures — risk analysis, incident handling, business continuity, supply chain security, secure acquisition and maintenance, effectiveness assessment, cyber hygiene, cryptography, access control, and multi-factor authentication [3]. Commission Implementing Regulation (EU) 2024/2690 adds a second, far more prescriptive layer on top — but its own Article 1 names only eleven entity types, and internet exchange points are not among them [6]. DNS Belgium, as a DNS provider and TLD registry, is squarely inside that list and works through 150-plus documented controls across 13 Annex sections. BNIX is not — it builds its Article 21(2) evidence against its own risk assessment rather than a pre-set Annex.
| Entity type | CIR 2024/2690 in scope? | What that means in practice |
|---|---|---|
| DNS Belgium (TLD registry / DNS provider) | Yes | 150+ documented controls across 13 Annex sections |
| BNIX (IXP, operated by Belnet) | No | Article 21(2)(a)–(j) baseline only, on the entity’s own technical judgement |
| GlobalSign (qualified trust service provider) | Yes | Same 13-section Annex, plus existing eIDAS obligations to FPS Economie |
For the 13-section Annex, our complete guide to CIR 2024/2690 breaks down every section, and the digital infrastructure compliance checklist turns them into an audit-evidence list. For DNS-specific technical controls — DNSSEC, zone-transfer authentication, resolver hardening — see our DNS and TLD security guide. For the EU-wide baseline this article builds on, see our digital infrastructure compliance guide; the Netherlands runs a comparable two-rulebook split, covered in our Netherlands digital infrastructure guide.
The Trust-Service Layer: FPS Economie and GlobalSign
Trust services are the one part of Belgium’s digital-infrastructure sector BIPT explicitly does not touch [8]. Qualified trust service providers already answer to FPS Economie under Article 17 of the eIDAS Regulation, a supervisory relationship that predates NIS2 and continues alongside it [11]. GlobalSign, whose EMEA headquarters sits in Leuven, was among the first certificate authorities to secure Qualified Trust Service Provider status through a Belgian supervisory body [12] — a sign Belgium’s trust-service sector isn’t a footnote. A compliance officer at a Belgium-based trust service provider is effectively managing two regulators for one set of infrastructure: FPS Economie for the qualification itself, and NIS2 (registration through CCB, technical controls under the CIR) for everything else.
What’s Already Overdue
Belgium moved first and fast: the NIS2 law took effect 18 October 2024, digital-infrastructure and other named providers registered by 18 December 2024, and the general registration deadline followed on 18 March 2025 [7][9]. The next milestone has already passed as of this article’s publication — essential entities were required to submit CyberFundamentals or ISO 27001 compliance evidence to the CCB by 18 April 2026, with full Essential-level CyFun certification due 18 April 2027 [9]. Independent reporting suggests the CCB extended flexibility to entities that had requested a conformity assessment before the deadline but were waiting on assessment-body capacity — flexibility that covers documented delay, not entities that never started [10]. The same reporting notes incident reports rose almost 70% year over year, which the CCB attributes partly to NIS2’s stricter notification rules — a sign that incident-triggered scrutiny, not proactive audits, is the likelier near-term enforcement path for any operator still building its evidence file [10]. For the fine ceilings once an infringement is confirmed, see our dedicated guide to Belgium’s NIS2 penalties.
Frequently Asked Questions
Does the CCB supervise BNIX and DNS Belgium directly?
Registration runs through the CCB for every entity. Day-to-day supervision, inspections, and enforcement for digital infrastructure (outside trust services) belong to BIPT under its cooperation protocol with the CCB [8].
Is Belnet an essential entity under NIS2?
Not automatically. Its NREN function and its BNIX role are assessed separately; as an IXP operator, BNIX doesn’t get the size-independent status reserved for DNS providers, TLD registries, and trust service providers under Article 3(1)(b) [1]. No primary source has published Belnet’s specific classification — treat this as reasoned inference.
Does CIR 2024/2690 apply to a Belgian internet exchange point?
No. Article 1 names DNS providers, TLD registries, cloud, data centre, CDN, MSP/MSSP, marketplace/search/social platforms, and trust service providers — IXPs aren’t on that list and stay on the Article 21(2) baseline [6].
Why does DNS Belgium face NIS2 obligations regardless of size?
As a TLD name registry, DNS Belgium falls under Article 3(1)(b), making TLD registries and DNS providers essential the moment they provide the service, with no headcount or turnover test [1].
The Bottom Line
Belgium’s digital-infrastructure sector is one Annex I category with three regulators and two technical rulebooks layered underneath it. DNS Belgium is essential by default and works through CIR 2024/2690’s full Annex. BNIX, operated by Belnet, reaches essential status — if it reaches it — on scale or criticality rather than automatically, and builds its own risk-based control set instead. Trust service providers like GlobalSign answer to FPS Economie on top of everything else. All three register through the CCB; none are supervised day to day by the CCB alone. Get that distinction right before the next inspection cycle, and Belgium’s digital-infrastructure compliance becomes a documentation exercise against a known regulator, not a guessing game about who shows up.
Sources
- [1] NIS2 Directive, Article 3 — Essential and Important Entities
- [2] NIS2 Directive, Article 6 — Definitions
- [3] NIS2 Directive, Article 21 — Cybersecurity Risk-Management Measures
- [4] NIS2 Directive, Article 27 — Registry of Entities
- [5] NIS2 Directive, Article 34 — Penalties
- [6] “Commission Implementing Regulation (EU) 2024/2690” (EUR-Lex)
- [7] DNS Belgium — Getting Started with NIS2 as a Registrar and Reseller
- [8] BIPT — Security of Networks and Information Systems
- [9] “NIS2: 18 April 2026 Deadline — What Essential Entities Must Have in Place” (CCB Belgium)
- [10] Jimber — NIS2 Fines in Belgium: What Enforcement Actually Looks Like (2026)
- [11] “Trusted List” (SPF Economie / FPS Economy, Belgium)
- [12] GlobalSign — Qualified Trust Services for eIDAS
- [13] “Belgian National Research and Education Network Belnet Celebrates 30th Anniversary” (Belnet corporate)
- [14] BNIX — Internet Exchange (IX)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
