NIS2 · National implementation
NIS2 in Belgium
Belgium transposed NIS2 through the law of 26 April 2024, in force since 18 October 2024 — the directive's own deadline, making Belgium the reference implementation.
- National law
- Loi du 26 avril 2024 / Wet van 26 april 2024
- NIS2 transposition law
- Status
- In force
- In force
- 18 October 2024
- Authority
- Centre for Cybersecurity Belgium (CCB)
Supervision
The Centre for Cybersecurity Belgium (CCB) is the national authority and CSIRT. Registration runs through the CCB's Safeonweb@Work portal, and the initial Belgian registration deadlines have already passed, so unregistered in-scope entities are late, not early.
What is specific to Belgium
Belgium built a distinctive assurance model: the CyberFundamentals (CyFun) framework, with levels (Basic, Important, Essential) mapped to entity classes. Essential entities demonstrate conformity through certification verified by accredited bodies rather than waiting for authority audits. This makes Belgium the member state where third-party certification is most directly wired into NIS2 compliance.
Official sources
Primary references: the national statute book at www.ejustice.just.fgov.be and the national cybersecurity authority at ccb.belgium.be.
NIS2 in Belgium: frequently asked questions
Last reviewed:
Related reading
Definitions
