Abstract network security visualization representing oversight of Belgium's financial sector cybersecurity

NIS2 in Belgium’s Financial Sector: Why NBB and FSMA — Not the CCB — Are Your Regulators Under DORA

If you run compliance at a Belgian bank, insurer, or investment firm, you have probably been told that NIS2 doesn’t apply to you — DORA does. That’s mostly true. But “mostly” is the part that gets Belgian financial entities into trouble, because the handoff from the Centre for Cybersecurity Belgium (CCB) to the National Bank of Belgium (NBB) and the Financial Services and Markets Authority (FSMA) is narrower and more specific than most compliance teams assume.

Belgium’s NIS2 Law of 26 April 2024 designates a sectoral authority for finance by name, in a specific article, with a specific carve-out for trading venues. The legal mechanism that lets DORA take over from NIS2 only displaces the obligations DORA’s technical standards actually cover — not everything NIS2 Article 21 asks for. This guide walks through who regulates what, why, and which NIS2 obligations survive the handoff — see our broader Belgium NIS2 competent authority overview for how the CCB structures supervision across every other sector.

Does NIS2 or DORA Apply to Your Belgian Financial Entity?

In one sentence: if you’re a credit institution, insurer, payment institution, investment firm, or fund manager above DORA’s size thresholds, DORA applies and NBB or FSMA supervises you directly — not the CCB. If you fall into one of six categories DORA explicitly excludes, you’re back under full Belgian NIS2 obligations if you meet the size thresholds.

The table below maps entity type to supervisor and to whether Belgian NIS2’s cybersecurity-specific provisions (Titles 3 to 5 of the Law of 26 April 2024 — risk-management measures, supervision, and sanctions) still apply.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Entity type Belgian supervisor NIS2 Titles 3–5 apply?
Credit institutions (banks) NBB No — DORA replaces them
Insurance / reinsurance undertakings (above Solvency II thresholds) NBB No
Payment and e-money institutions NBB No
Investment firms FSMA No
Fund managers (AIFMs above threshold) FSMA No
(Re)insurance intermediaries, crowdfunding providers FSMA No
Trading-venue operators FSMA (cooperating), NBB (lead) No
Sub-threshold AIFMs, small insurers, micro pension schemes (≤15 members), MiFID-exempt persons, micro/SME insurance intermediaries, post office giro institutions CCB Yes, in full, if Belgian NIS2 size thresholds are met [12]
NBB itself — central-securities-depository (CSD) function only CCB (narrowly) Yes, for the CSD activity [7]

That last row surprises most people: the NBB regulates the sector, but a specific piece of its own operations — its central-securities-depository business — is itself a NIS2 entity, because DORA’s carve-out only follows the activity, not the institution’s name [7]. The same logic runs the other way. If you’re a small insurance intermediary structured as an SME, DORA doesn’t cover you at all, and dropping NIS2 tracking because finance is DORA’s problem leaves you with zero cybersecurity compliance framework — a gap that shows up fastest during a CCB spot-check, not during a self-assessment.

The Legal Mechanism: How Article 80 Hands Finance to NBB and FSMA

In plain language: EU law lets sector-specific rules replace NIS2’s obligations where they cover the same ground equally well. DORA claims that status for finance. Belgium’s implementing law then names NBB and FSMA as the authorities who take over.

The mechanism runs through two linked provisions. NIS2 Article 4 says that where a sector-specific EU legal act imposes cybersecurity risk-management and incident-notification requirements “at least equivalent in effect” to NIS2’s own — matching Article 21(1)-(2) on risk management and Article 23(1)-(6) on notification — NIS2 does not apply to the entities that act covers [1]. DORA’s Article 1(2) is the provision that claims this status: it states that for financial entities identified as essential or important under national NIS2 rules, DORA “shall be considered a sector-specific Union legal act for the purposes of Article 4” of NIS2 [2]. For the general, sector-agnostic comparison between the two regimes, see our NIS2 vs DORA overview. DORA’s Recital 16 restates the intent in less technical language — that DORA is lex specialis to NIS2 for the financial sector — but a recital only explains the rationale; Article 1(2) is the binding text that actually does the work [3].

Belgium then had to decide, at national level, who exercises supervision over the DORA-scoped entities its own NIS2 law would otherwise cover. Article 80 of the Law of 26 April 2024 designates the NBB as sectoral authority for finance, with the FSMA taking the cooperating role specifically for trading-venue operators [7]. Practically, that means titles 3 to 5 of the Belgian NIS2 Law — the risk-management measures, supervisory powers, and administrative sanctions — simply do not apply to DORA-scoped financial entities; NBB and FSMA exercise the equivalent DORA powers instead [7][8].

DORA replaces NIS2’s Article 21 risk-management and incident-reporting rules for entities the NBB and FSMA already supervise — but Article 4 only displaces what DORA’s own technical standards actually cover. Everything DORA’s regulatory technical standards stay quiet on — physical security specifics, HR security, and non-ICT supplier contracts — reverts to NIS2 Article 21 in full, and Belgian compliance teams who stopped tracking NIS2 the day DORA applied are the ones an audit catches first.

NBB: Prudential Supervisor and DORA Authority for Belgium’s Systemic Banks

The NBB’s role here isn’t new territory for the institution — it’s an extension of the prudential supervision it already runs under the twin-peaks model that splits Belgian financial oversight between stability (NBB) and conduct (FSMA) [9]. Under DORA, the NBB is the competent authority for credit institutions, insurance and reinsurance undertakings, and payment and e-money institutions [9].

The scale of what that covers became more concrete on 1 December 2025, when the NBB’s annual assessment redesignated eight banks as Other Systemically Important Institutions (O-SIIs) — the domestic equivalent of globally systemic banks: BNP Paribas Fortis, KBC Group, Euroclear Holding, ING Belgium, and Belfius Bank, each carrying a 1.5% capital buffer requirement, plus the Bank of New York Mellon, Argenta, and Crelan at 0.75% [4]. These are the institutions where a DORA-covered ICT incident has the most immediate systemic consequence, and they’re the ones whose incident-reporting obligations to the NBB carry the closest scrutiny.

NBB Circular NBB_2026_04, published 1 April 2026, governs how major ICT-related incidents get reported under DORA Article 19(1), plus the voluntary notification of significant cyber threats under Article 19(2) [5]. It revises the prior year’s circular and extends its scope to Belgian branches of third-country credit institutions, stockbroking firms, and insurers — a detail worth flagging if your compliance mapping still treats NBB-supervised as synonymous with Belgian-incorporated [5].

FSMA: Conduct Supervisor for Investment Firms and Fund Managers

Where the NBB owns prudential stability, the FSMA owns conduct — and under DORA that split carries over cleanly. A Belgian bill adopted 30 January 2025 confirmed the FSMA as DORA supervisor for investment firms, fund managers (AIFMs above threshold), (re)insurance intermediaries, and crowdfunding service providers [9].

The FSMA’s most visible DORA deliverable is the Register of Information (RoI) — the inventory of ICT third-party providers every in-scope entity must file. 2025 was a full submission cycle for every entity in scope; 2026 is a reduced exercise, where entities with no material change since 2025 can simply confirm the prior filing still holds rather than resubmit from scratch [6]. If your ICT vendor list changed — a new cloud provider, a new managed security service — you’re still on the hook for a fresh submission even in a limited-scope cycle year.

What NIS2 Still Requires — Even Under DORA

The most consequential mistake we see in Belgian financial-sector compliance mapping is treating DORA applies as a complete substitute for NIS2 thinking. It isn’t, for two distinct reasons.

First, DORA’s Article 4 equivalence only covers what DORA’s own risk-management and incident-notification rules address. NIS2’s broader hygiene requirements — physical and environmental security, HR security screening, and the non-ICT elements of supplier management under Article 21(2)(d) — aren’t restated inside DORA’s regulatory technical standards, so nothing displaces the NIS2 obligation on those points for entities where any residual NIS2 scope remains, and certainly not for entities DORA never touches [1][8].

Second, DORA Article 2(3) names six categories of financial entity it does not cover at all: sub-threshold alternative investment fund managers, small insurance and reinsurance undertakings below Solvency II’s activity thresholds, occupational pension schemes with 15 members or fewer, persons exempted under MiFID II, insurance and reinsurance intermediaries that qualify as micro or small/medium enterprises, and post office giro institutions [12]. None of these get a NIS2 exemption to match — if they meet Belgium’s NIS2 size-threshold scope rules for their actual sector classification, full Belgian NIS2 obligations apply, supervised by the CCB, with no DORA safety net. That includes registering with the CCB via Safeonweb@work like any other in-scope entity.

The CCB also keeps a residual coordinating role even for fully DORA-scoped entities: cross-sector incidents, the Safeonweb@work reporting channel other NIS2 entities use, and national-level cooperation sit outside what NBB and FSMA supervise directly [8]. In practice, a Belgian bank’s compliance function needs three reference points, not one: DORA for ICT risk and incident reporting, NIS2 Article 21’s broader hygiene items for anything DORA’s RTS don’t specify, and an awareness of where CCB-level coordination could still touch a cross-sector incident.

Penalties: DORA Sanctions vs Belgian NIS2 Fines

The two regimes carry genuinely different penalty structures, and citing the wrong one to a board is an easy, avoidable error.

Regime Entity penalty Individual penalty Enforcing authority
DORA (Belgium’s Law of 25 March 2025) Up to €5,000,000 or 10% of net annual turnover, whichever is higher Up to €5,000,000 NBB or FSMA, by entity type [10]
Belgian NIS2 Law (essential entities) Up to €10,000,000 or 2% of worldwide turnover, whichever is higher Personal liability for management bodies CCB [11]
Belgian NIS2 Law (important entities) Up to €7,000,000 or 1.4% of worldwide turnover, whichever is higher Personal liability for management bodies CCB [11]

Note the different ceilings: DORA’s 10%-of-turnover cap is proportionally steeper than NIS2’s 2%, though NIS2’s absolute euro ceiling runs higher for essential entities. Whichever framework applies to your entity, both use a whichever-amount-is-higher logic between the fixed sum and the percentage — the fixed figure is a floor for smaller entities, not the real exposure for a large bank.

Compliance Checklist by Role

  • CISO / IT Security Lead: Confirm which authority — NBB or FSMA — actually supervises your entity type, then map your ICT risk-management framework against DORA’s requirements first. Separately audit physical security, HR security, and non-ICT supplier contracts against NIS2 Article 21(2), since DORA’s technical standards don’t fully restate them.
  • Compliance Officer / Legal: Verify your entity doesn’t fall into one of DORA Article 2(3)’s six excluded categories. If it does, check Belgian NIS2 size thresholds directly — you may owe full NIS2 compliance to the CCB with no DORA coverage at all.
  • Board / C-Suite: Understand that DORA’s penalty ceiling (10% of turnover) and NIS2’s (2% for essential entities) are structurally different — get the right figure in front of the board, tied to the regime that actually applies to your entity.
  • ICT Vendor Management: If your entity is FSMA- or NBB-supervised, confirm whether your Register of Information needs a fresh 2026 submission or a status-unchanged confirmation, based on whether your ICT vendor list changed since 2025.

Frequently Asked Questions

Does the CCB have any authority over Belgian banks at all?
Only residually — for cross-sector incident coordination and the shared Safeonweb@work channel other NIS2 entities use. Day-to-day supervision of DORA-scoped financial entities sits with the NBB or FSMA, not the CCB [8].

My fintech is a small MiFID-exempt firm — do I need to worry about NIS2 or DORA?
If you’re exempted under MiFID II Articles 2-3, DORA’s Article 2(3) excludes you from its scope entirely [12]. That doesn’t exempt you from NIS2 — check Belgium’s NIS2 size thresholds for your actual sector classification, because you may owe full compliance to the CCB.

Is Euroclear regulated the same way as a retail bank?
Euroclear Holding is one of Belgium’s eight O-SIIs and sits under NBB supervision like the retail-facing banks on that list, though its role as a systemic settlement infrastructure brings additional oversight layers beyond the scope of this guide [4].

Key Takeaways

The handoff from NIS2 to DORA in Belgium’s financial sector is real, but it’s an Article 80 designation with named limits — not a blanket exemption. NBB and FSMA supervise the entities DORA actually covers; the CCB keeps a coordinating role and full jurisdiction over the entities DORA leaves out. Map your entity against both regimes, not just the one your peers talk about most.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Directive (EU) 2022/2555, Article 4 — Sector-specific Union legal acts
  2. DORA, Regulation (EU) 2022/2554, Article 1 — Subject matter
  3. DORA, Regulation (EU) 2022/2554, Recital 16 (EUR-Lex, CELEX 32022R2554)
  4. National Bank of Belgium — Eight Belgian banks redesignated as systemically important institutions (1 December 2025)
  5. National Bank of Belgium — Circular NBB_2026_04, Reporting of major ICT-related incidents under DORA (1 April 2026)
  6. FSMA — DORA Register of Information on third-party ICT service providers: limited update in 2026
  7. CloudSoul — NIS2 Belgium: Law of 26 April 2024 Implementation Guide
  8. isms.online — Who Really Enforces NIS 2 in Belgium? Navigating CCB & Sector Regulator Power
  9. financialregulations.eu — FSMA & NBB Belgium: Financial Licensing & Regulation 2026
  10. DLA Piper — Divergence in Administrative Penalties under DORA (October 2025)
  11. Jimber — NIS2 fines in Belgium: what enforcement looks like (2026)
  12. DORA, Regulation (EU) 2022/2554, Article 2 — Scope
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: