Service
Scoping, classification and a defensible route to conformity, for organisations that would rather understand the obligation than outsource the panic.
The Belgian transposition, the law of 26 April 2024, has been in force since 18 October 2024. Registration closed on 18 December 2024 for providers of digital services such as DNS, cloud, data centres, managed services and online marketplaces, and on 18 March 2025 for everyone else, though it remains a standing obligation for any organisation newly in scope. The date by which essential entities had to show the Centre for Cybersecurity Belgium that they were following a recognised conformity route passed on 18 April 2026. The orientation phase is over.
The CCB has moved from explaining the law to supervising it: inspections, audits and binding instructions. Essential entities are supervised proactively, whether or not anything has gone wrong. Important entities are supervised reactively, which is not the same thing as being left alone.
If you registered and started a track, your horizon is full conformity, with the certification-based routes running to April 2027. If you did not, the position is uncomfortable but recoverable, and it starts with an honest scoping exercise rather than a rushed set of policies.
More organisations assume they are out of scope than actually are. A smaller group assume they are in scope because a customer said so. Both mistakes are expensive, in opposite directions.
Many SMEs are not caught by the law itself but pulled in through their customers' supply chain obligations, arriving as questionnaires and contract clauses. That is a genuine requirement, but it is a commercial one, and it should not be answered with the same programme a regulated entity needs.
Belgian organisations that are in scope, think they might be, or are being pushed by a customer who is. It fits best where management wants to understand the obligation and decide on it, rather than buy a document set that makes the question go away.
A word on the market you are shopping in. NIS2 has produced a great deal of urgency-driven selling, and a policy pack bought under deadline pressure is the most reliable way to spend real money on nothing. If a supplier quotes you a price before establishing your scope and classification, they are quoting for paperwork, not for compliance.
Contractually, possibly quite a lot. Your customer must manage supply chain risk, so their obligation reaches you as questionnaires and clauses. That is a commercial requirement rather than a legal one, and it is usually satisfied with far less than a full compliance programme. Knowing which of the two you are answering saves real money.
Not fatal, and not something to leave alone. Supervision is live, so the useful move is to register, determine your scope properly, and start a recognised route with dates you can genuinely meet. Documented, demonstrable progress is a materially better position in front of a supervisor than silence.
For essential entities, administrative fines reach 10 million euro or 2 percent of worldwide annual turnover, whichever is higher. For important entities, 7 million euro or 1.4 percent. Fines are the visible end of the scale. The measures that arrive first, binding instructions, mandatory audits and, for essential entities, a temporary ban on exercising management functions, tend to be the more disruptive part.
No. CyberFundamentals is the route the CCB built and the one most Belgian organisations take, but ISO 27001 certification is an accepted alternative and inspection on the basis of a self-assessment is a third. Which one is cheapest depends entirely on where you already stand and what your customers ask to see.
More on the CyFun route and assurance levels
The management body. NIS2 makes approving and overseeing the risk management measures a management responsibility and expects management to be trained well enough to do it. Delegating the work is entirely normal. Delegating the accountability is not possible.
Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.
Request an intro call