Insights
Essential entities that cannot demonstrate CyberFundamentals Essential by 18 April 2027 may submit a remediation plan instead. That is a different route to the same obligation, not an extra year.
By 18 April 2027, essential entities under the Belgian NIS2 law are expected to demonstrate cybersecurity measures equivalent to the CyberFundamentals assurance level Essential. Organisations that cannot do so are asked to submit a remediation plan instead.
That plan has two parts. It has to contain evidence of measures equivalent to the Important level, and a description of how the organisation intends to reach the Essential level by 18 April 2028.
The same approach applies to all three conformity routes. CyFun certification through an authorised body, ISO 27001 certification through an authorised body, and assessment by the inspection service itself are treated identically. Choosing the ISO route does not buy you a different conversation.
Read quickly, this looks like an extra year. Read again, and it is something else. There is nothing to apply for and no term that shifts. 18 April 2027 remains the day on which you have to be able to show something. What changed is the level you have to show, not the date on which you have to show it.
This is not a free pass to leave things to sort themselves out. What the route does is build in additional realism for a great many organisations, and that realism makes it possible to become properly aligned with NIS2 without doing it in a rush.
The distinction matters, because the remediation route is not the easy route. It asks for evidence at the Important level, and for a plan that someone else will read and judge. An organisation that has simply been putting this off does not qualify for it either. Being demonstrably at a lower level is a position. Being busy with it is not.
CyFun 2025 is the only version that may still be used from 18 April 2027, and it has been available for a relatively short time. In a lot of places that meant substantial rework on material that was already finished.
The harder part sits where most people do not look for it. Bringing documentation into line with existing practice is least straightforward precisely for the organisations that have already implemented a great deal. They have the measures. What they often do not have is the paper trail showing that the measures work the way the organisation believes they do.
That is the pattern underneath this whole file. For a considerable number of essential entities, the gap is not a shortage of security. The gap is the distance between what happens every day and what can be demonstrated to someone who was not there.
There is a second exception, and it is easy to read past. No remediation plan is required from an entity that can justify, on the basis of its risk analysis, cybersecurity measures equivalent to a lower assurance level.
That is a different door, not a lighter version of the same one. It is also a door that should have been opened some time ago. As an essential entity, you were expected to know which assurance level applied to you well before this point, and re-evaluating now to arrive at a lower conclusion can reasonably be expected to draw follow-up.
When was that determination last examined, and would it stand up if someone asked you to explain how you reached it?
Without a realistic route you end up with a lot of paper tigers: organisations that look compliant but that had to skip too many steps to be ready on time.
A certificate obtained by cutting corners has a peculiar property. It removes the pressure to fix the thing that was cut. The organisation now holds documented evidence that it is fine, which is exactly the condition in which nobody goes looking any further.
The useful exercise is an honest one. Look at what is genuinely left, and test whether the strict timeline is achievable at the quality you would want to defend. If the answer is no, take the longer route on purpose rather than ending up in it. There is a real difference between an organisation that submits a remediation plan because it made a considered choice and one that submits it because the date arrived.
One practical consequence is worth keeping in view. Evidence that covers a period cannot be assembled afterwards. Records of reviews, of tests, of decisions taken and incidents handled only exist if they were being kept while the period was running. Choosing the longer route means starting to record now, not later.
And whichever route you take, the measures have to be properly and genuinely implemented. Otherwise you end up with another paper tiger, and that contributes nothing to real cybersecurity, which is what NIS2 set out to achieve in the first place. An organisation that can explain where it stands and what it is doing next is in a considerably better position than one holding a file that was finished on time.
This piece follows a general communication and information request that the Inspection Service of the Centre for Cybersecurity Belgium sent to Belgian essential entities in August 2026. A shorter version first appeared on LinkedIn; this page is the version that is kept up to date.