NIS2 in Belgium
Belgium enacted its NIS2 law in April 2024, one of the first EU member states to fully transpose. CCB leads enforcement with fines up to €10 million.
Key Deadlines
Competent Authority
CCB is one of the most active NIS2 supervisors in the EU. It operates CERT.be as its incident response team and maintains a dedicated NIS2 platform (safeonweb@work). Proactive audits apply to Essential Entities.
Registration Process
Register at safeonweb.be/nis2. You'll need your CBE number (Crossroads Bank for Enterprises), sector classification, and contact details for your security officer.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Key Requirements
- 1Registration on the CCB NIS2 portal within 3 months
- 272-hour incident notification to CCB/CERT.be (24h early warning)
- 3Annual management review of cybersecurity posture
- 4CyberFundamentals framework compliance recommended (based on NIST/ISO 27001/CIS)
- 5Management liability for significant negligence
- 6Supplier security assessments mandatory
National Additions
FAQ: NIS2 in Belgium
What is the CyberFundamentals Framework?
Is Belgium's CCB strict on enforcement?
Ready to assess your NIS2 compliance?
Use our free tools to check your NIS2 scope and run a gap assessment.
Currency and sources
The legal details on this page were last checked on 25 July 2026. Some details rest on a single secondary source and are not verified against the national authority or official journal. Confirm with the competent authority before relying on them for a compliance decision.