Directive NIS2 European Union
BE · Member state

NIS2 in Belgium


What binds you in Belgium is the national law transposing NIS2 — not the directive itself. Here is who supervises you, where you register, and where you report.

Transposition
Transposed
Competent authority
Centre for Cybersecurity Belgium
National CSIRT
VAT on your purchase
21%

Reviewed . Verify against the national official journal before relying on this for a filing.

The text that actually binds you

National transposition


Article 30

Law of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security

Adopted
In force
Risk-management measures
11

Completed by a Royal Decree published in June 2024, which carries much of the operational detail.

This is not the article you read in the directive

Article 30 restates the ten measures of article 21(2) of the directive and adds an eleventh, standalone obligation at Article 30 §3: a coordinated vulnerability disclosure policy. An entity that worked only from the directive text would be short one measure in Belgium.

Registration

Safeonweb@Work portal (atwork.safeonweb.be)

Registration with the CCB is mandatory and was due within five months of entry into force. Entities that come into scope later register on coming into scope, not on the original national deadline.

Open the portal →

Supervision

CCB inspections

The CCB has been running NIS2 inspections since April 2026.

National assessment framework

CyberFundamentals Framework — CyFun® 2025

version 2, published by Centre for Cybersecurity Belgium (CCB). Built on NIST Cybersecurity Framework 2.0.

  • essential entities only — Show at least a CyFun Basic or Important verification, or submit an ISO/IEC 27001 Statement of Applicability to the CCB instead. Two tracks, either is accepted.
  • essential entities only — The target CyberFundamentals level must be CERTIFIED by a conformity assessment body accredited by BELAC and authorised by the CCB. An external assessment, not a self-assessment.

A label is not compliance

Holding a CyberFundamentals label does not by itself prove NIS2 compliance. Ireland's NCSC puts it plainly: the framework "does not prove that an entity is compliant with their NIS2 obligations but can provide a structured assessment framework to demonstrate cybersecurity maturity." Compliance is owed under the national transposition law; CyFun is the instrument most commonly used to demonstrate it, not a substitute for it.

CyFun in full — levels, controls and what it does not cover →

Who supervises you

Centre for Cybersecurity Belgium is the competent authority designated by Belgium. It holds the article 32 and 33 supervisory powers: inspections and audits, requests for information and evidence, binding instructions, orders to remedy deficiencies, and administrative fines. For essential entities those powers are exercised ex ante — without needing any indication of non-compliance.

Incident notifications under article 23 normally go to CCB / CSIRT.be, though some member states route them through the competent authority instead. Confirm the channel before you need it: the 24-hour clock is not the moment to discover which portal applies.

What differs from the directive

Because NIS2 is a directive, Belgium legislated its own version of it. The security baseline in article 21 is common across the Union and will not differ. What does differ:

  • Registration. The portal, the information required and the deadline are national.
  • Scope. Several member states extended coverage below the directive's size thresholds, or added sectors of national importance.
  • Penalty calibration. The article 34 ceilings are common; how the authority calibrates within them is not.
  • Reporting format. Deadlines are fixed by the directive; the form and the language are national.

If you operate in several member states

You have one security programme and several compliance relationships. Registration, supervision and reporting are per-jurisdiction, and a cross-border incident can require filings in each affected member state. Article 26 sets jurisdiction rules — generally the member state of establishment, with specific rules for digital providers.

Cart 0