NIS 2 — Belgium
NIS 2 IN BELGIUM
Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information — the national act transposing Directive (EU) 2022/2555 in Belgium. Supervised by Centre for Cybersecurity Belgium (CCB).
TRANSPOSED — IN FORCE
Key facts
In force
18 October 2024
National law
Primary supervisor
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Essential entities had until 18 December 2024 (60 days from entry into force) to register on Safeonweb@work; important entities and providers followed on a rolling basis through Q1 2025.
Scope and national nuance
Belgium met the directive's 17 October 2024 transposition deadline with the law of 26 April 2024 entering into force on 18 October 2024. The CCB operates the central Safeonweb@work platform and is the single contact for registration and incident reporting.
Sector supervisors
| Sector | Authority | Acronym |
|---|---|---|
| Energy and electronic communications | Institut belge des services postaux et des télécommunications | BIPT |
| Financial services | National Bank of Belgium | NBB |
What is specific to Belgium
- Belgium was the first EU member state to fully transpose the directive on time — covered entities have been operating under the national law since October 2024.
- CCB is both the national CSIRT and the central NIS 2 supervisor, simplifying the regulatory interface for covered entities.
- Belgium adopted the CyberFundamentals Framework (CyFun) as a recommended baseline for the security measures required by the directive — entities aligned to CyFun Essential or Important can use it as evidence of compliance.
- Incident reporting and entity registration both run through the Safeonweb@work portal — a single interface that other member states are referencing as a benchmark.
DSI Advisory — NIS 2 Programme
Move from reading the law to evidencing compliance
Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to CCB’s supervisory expectations.