Belgium’s NIS2 Healthcare Bottleneck: Only 2 BELAC-Accredited Auditors for Every Essential Hospital
On 13 January 2026, AZ Monica hospital in Antwerp shut down servers at both its Antwerp and Deurne campuses after detecting what it described as a serious disruption to its computer systems. More than 70 surgeries were cancelled. Seven patients, including critical cases, were transferred to other facilities. The emergency department dropped to reduced capacity, and the dispatch systems that route the region’s Mobile Urgency Groups went dark [8]. The cause was never disclosed publicly — and under Belgium’s NIS2 law, that kind of silence is no longer optional for long.
Belgium was the first EU member state to have NIS2 legislation in force, and healthcare sits in Annex I’s highest-criticality tier [1][2]. But most Belgium-focused NIS2 guidance treats healthcare as a footnote to the general compliance framework. It isn’t one. Belgian hospitals answer to a specific authority — the Centre for Cybersecurity Belgium (CCB), not a health ministry — follow a specific compliance pathway, and now face a bottleneck almost nobody is writing about: as of this research, only two accredited bodies in the entire country can issue the verification statement essential entities need before 18 April 2026 [5][6].
This guide covers exactly who is in scope, which authority to register with, why the auditor shortage matters for your timeline, and what each role in your organisation should do next.
Does NIS2 Apply to Your Belgian Healthcare Organisation?
In short: if you’re a hospital, clinic group, pharmaceutical manufacturer, or medical device maker of meaningful size, yes. Annex I, Sector 5 of Directive (EU) 2022/2555 places five categories of health-related entity in the highest-criticality tier: healthcare providers as defined under Directive 2011/24/EU; EU reference laboratories designated under Regulation (EU) 2022/2371; entities carrying out research and development on medicinal products; entities manufacturing basic pharmaceutical products and preparations; and manufacturers of medical devices formally listed as critical during a declared public health emergency under Regulation (EU) 2022/123 [1][7][10].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
That last category is narrower than most compliance checklists imply. A medical device manufacturer only falls into this Annex I bucket if its product sits on the EU’s activated critical-devices list during a recognised emergency. Every other MDR- or IVDR-regulated device maker sits under Annex II (Manufacturing) instead — important entity, not essential, with the ordinary supply-chain and access-control obligations rather than the health sector’s proactive supervision.
| Entity type | Annex | Default classification | Threshold |
|---|---|---|---|
| Hospitals, clinics, healthcare providers (larger) | I, Sector 5 | Essential | ≥250 staff, or ≥€50M turnover and ≥€43M balance sheet |
| Hospitals, clinics, healthcare providers (smaller) | I, Sector 5 | Important | ≥50 staff, or ≥€10M turnover |
| EU reference laboratories | I, Sector 5 | Essential (standard test) | Standard threshold test |
| Pharmaceutical R&D and manufacturing entities | I, Sector 5 | Essential or Important | Standard threshold test |
| Medical device manufacturer (public-health-emergency critical list) | I, Sector 5 | Essential or Important | Scope tied to the EU critical-devices list, not size alone |
| Medical device manufacturer (ordinary MDR/IVDR, not on the list) | II | Important | ≥50 staff, or ≥€10M turnover |
Belgium applies the Directive’s standard size test to determine essential versus important status, with no health-specific carve-out [10]. In practice, that resolves quickly for Belgium’s largest hospitals. UZ Leuven runs 1,995 beds and employs more than 9,000 people [11]. UZ Gent operates over 1,000 beds with roughly 6,000 staff [12]. UZ Brussel, smaller at 721 beds, still employs an estimated 3,800 to 5,000 people [13]. All three clear the 250-employee essential threshold several times over — for Belgium’s university hospital network, the size test isn’t a close call, and it isn’t for most general and regional hospitals above roughly 250 staff either.
Where the test does matter is at the margins. A standalone clinic under 50 staff and €10 million turnover generally sits outside NIS2 scope entirely — unless the CCB designates it in scope anyway as the sole provider of a critical regional service, a discretionary power the CCB holds over any entity regardless of size [2].
The CCB Is Your Authority — But Registration Isn’t the Whole Story
In short: register with the CCB via Safeonweb@Work, not a health ministry — but if you manufacture medical devices or pharmaceuticals, expect a second regulator too. The CCB is Belgium’s single national competent authority under Article 8 of the NIS2 Directive, and unlike energy (FANC/CREG) or telecoms (BIPT), healthcare has no dedicated day-to-day sectoral co-regulator for hospitals and clinics — the CCB supervises health-sector essential and important entities directly [2].
Registration runs through the Safeonweb@Work portal. Digital-infrastructure entities had until 18 December 2024; every other NIS2 entity, including hospitals, had until 18 March 2025 [3]. Missing that deadline doesn’t pause your obligations — incident notification, Article 21 security measures, and management training were all live from 18 October 2024, and failure to comply with a registration order carries a fine of up to €200,000 on its own [3].
Medical device and pharmaceutical manufacturers get a second point of contact. The Federal Agency for Medicines and Health Products (FAMHP, also known as AFMPS or FAGG) — Belgium’s competent authority for medicines and health products since 2007 — acts as a sectoral authority for the manufacturing and R&D entities inside Annex I, Sector 5, alongside the CCB’s overarching NIS2 supervision [9]. Hospitals and clinics don’t get this second layer; FAMHP’s role is specific to the device and pharmaceutical manufacturing side of the sector, not patient-care delivery.
The BELAC Bottleneck — Why “Get Certified” Is Harder Than It Sounds Right Now
In short: as of this research, Belgium has exactly two BELAC-accredited bodies that can issue a CyFun verification statement — and every essential hospital chasing the 18 April 2026 deadline is booking against that same shortage. The CCB, acting as Belgium’s National Cybersecurity Certification Authority, authorises conformity assessment bodies (CABs) to verify or certify CyFun compliance, but authorisation depends on BELAC accreditation — Belgium’s national accreditation body — under the EU’s standard accreditation framework [4].
Brand Compliance België became the first CAB to receive BELAC accreditation for CyFun verification on 4 September 2025, covering Basic and Important assurance levels under ISO/IEC 17029 [5]. What a Work SRL, operating as Trust CHECK, followed as the second — and the first based in Wallonia, accredited under BELAC registration No. 770-VV, with audits available in French, Dutch, and English [6]. As of this research, those two bodies are it. The CCB has indicated it expects further accreditations “around April 2026” [5] — not a comfortable margin if your hospital is targeting the Basic or Important verification statement by the same date.
A CyFun Basic or Important verification isn’t a document review. It requires a minimum of 1.5 person-days of assessment, including an on-site visit, before a CAB issues the verification statement your hospital then submits to the CCB via Safeonweb@Work [5]. With two CABs serving every essential and important entity in the country, waiting until early 2026 to book an assessment slot is a scheduling risk, not a hypothetical one. Organisations already running ISO/IEC 27001 have an alternative: submitting their certification scope and Statement of Applicability directly satisfies the same April 2026 checkpoint without touching the CyFun queue at all.
| Date | Obligation | Applies to |
|---|---|---|
| 18 October 2024 | Belgian NIS2 law in force; security measures, incident notification, and management training obligations begin | All in-scope entities |
| 18 December 2024 | Safeonweb@Work registration deadline | Digital-infrastructure entities |
| 18 March 2025 | Safeonweb@Work registration deadline | All other entities, incl. hospitals |
| 18 April 2026 | CyFun Basic/Important verification statement, or ISO 27001 scope + SoA, submitted to CCB | Essential entities |
| 18 April 2027 | Full CyFun Essential certification or ISO 27001 certification | Essential entities |
What Each Role in Your Organisation Needs to Do
| Role | Action |
|---|---|
| CISO / IT Security Lead | Confirm registration status at Safeonweb@Work, then map current controls to Article 21(2)(a)–(j) before booking a CAB slot |
| Compliance Officer | Decide CyFun vs. ISO 27001 now, and book a BELAC-accredited CAB early — only two bodies serve the whole country [5][6] |
| Board / Hospital Direction | Approve the Article 21 risk-management programme directly and document that approval — Belgium’s NIS2 law makes board members personally liable for oversight failures [2] |
| Device or pharma manufacturer within the group | Confirm whether your product sits on the EU’s public-health-emergency critical-devices list (Essential, Annex I) or falls under ordinary MDR/IVDR (Important, Annex II), and note FAMHP as a second regulatory contact [9] |
Penalty exposure follows the same essential/important split as the rest of Belgium’s NIS2 law: up to €10 million or 2% of worldwide turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher [2]. Belgium’s public-administration fine exemption applies to entities classified under the public-administration sector — a separate Annex I category from health. Hospitals sit in the health sector regardless of how they’re owned or governed, so that exemption doesn’t extend to them. For the full penalty structure and enforcement mechanics, see our Belgium NIS2 penalties guide, and for how the CCB’s four operational units (CERT.be, CyTRIS, NCCA, NCC-BE) handle incident response and certification, see our Belgium competent authority breakdown.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Frequently Asked Questions
Does NIS2 apply to a small private clinic in Belgium?
Only above the important-entity threshold — 50 or more staff, or €10 million or more in turnover — unless the CCB designates it in scope anyway as the sole provider of a critical regional health service, a discretionary power that applies regardless of size.
If my hospital is part of a larger group, do thresholds apply per site or across the group?
Under NIS2’s standard approach, size thresholds are calculated at the level of the registered legal entity. Where several smaller sites operate under one hospital group’s legal entity, that group’s combined staff and turnover count toward the threshold, even if no single site alone would clear it.
What happens if I can’t get a CyFun verification booked before 18 April 2026?
The ISO 27001 pathway is the practical fallback — submitting your certification scope and Statement of Applicability satisfies the same checkpoint without needing a CyFun-specific CAB slot. The CCB’s direct-inspection pathway also exists but is explicitly framed as a last resort that can trigger enforcement action rather than resolve it, not a lower-effort alternative to booking a CAB early.
Do I report incidents to the CCB or to FAMHP?
To the CCB, via Safeonweb@Work, in every case. FAMHP’s NIS2 role is sectoral oversight of medical device and pharmaceutical manufacturing entities, not incident notification — that routes through the CCB’s channels for every NIS2 entity regardless of sub-sector.
Are Belgian university hospitals essential or important entities?
Essential. UZ Leuven, UZ Gent, and UZ Brussel all employ well over the 250-staff threshold that defines essential status in Annex I’s health sector, which means they face the CCB’s proactive, ex-ante supervision model rather than the reactive model applied to important entities.
Sources
- Directive (EU) 2022/2555 (NIS2) — EUR-Lex
- NIS2 Regulation — Centre for Cybersecurity Belgium
- The NIS2 Law — CCB Safeonweb@Work
- Conformity Assessment Bodies (CAB) — CCB Safeonweb@Work
- NIS2 Conformity Assessment: Deadline April 18, 2026 Approaches — Cyberplan
- Second in Belgium, First in Wallonia: What a Work SRL Obtains BELAC Accreditation — Agoria
- Regulation (EU) 2022/123 (consolidated) — EUR-Lex
- 2026 Belgian Hospital Cyberattack — Wikipedia
- Federal Agency for Medicines and Health Products — Wikipedia
- NIS 2 Directive, Article 3: Essential and Important Entities
- UZ Leuven — Wikipedia
- Ghent University Hospital — Wikipedia
- UZ Brussel — Vrije Universiteit Brussel
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
