Skip to content

NIS 2 IN BELGIUM

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information — the national act transposing Directive (EU) 2022/2555 in Belgium. Supervised by Centre for Cybersecurity Belgium (CCB).

TRANSPOSED — IN FORCE

Key facts

In force
18 October 2024
National law
Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information
Primary supervisor
Centre for Cybersecurity Belgium (CCB)
Max fine — essential entities
Up to EUR 10 million or 2% of global annual turnover, whichever is higher
Max fine — important entities
Up to EUR 7 million or 1.4% of global annual turnover, whichever is higher
Registration deadline
Essential entities had until 18 December 2024 (60 days from entry into force) to register on Safeonweb@work; important entities and providers followed on a rolling basis through Q1 2025.

Scope and national nuance

Belgium met the directive's 17 October 2024 transposition deadline with the law of 26 April 2024 entering into force on 18 October 2024. The CCB operates the central Safeonweb@work platform and is the single contact for registration and incident reporting.

Sector supervisors

SectorAuthorityAcronym
Energy and electronic communicationsInstitut belge des services postaux et des télécommunicationsBIPT
Financial servicesNational Bank of BelgiumNBB

What is specific to Belgium

DSI Advisory — NIS 2 Programme

Move from reading the law to evidencing compliance

Start with the free NIS 2 Scorecard to score your organisation across the twelve Article 21 security domains and receive a paragraph-cited PDF report. Then book a structured NIS 2 scope and gap assessment tailored to CCB’s supervisory expectations.

NIS 2 Scorecard →Scope & gap assessment →NIS 2 reference page →