NIS2 obligations for Belgian SMEs

Scoping, classification and a defensible route to conformity, for organisations that would rather understand the obligation than outsource the panic.

← Back to home

Where NIS2 stands in Belgium today

The Belgian transposition, the law of 26 April 2024, has been in force since 18 October 2024. Registration closed on 18 December 2024 for providers of digital services such as DNS, cloud, data centres, managed services and online marketplaces, and on 18 March 2025 for everyone else, though it remains a standing obligation for any organisation newly in scope. The date by which essential entities had to show the Centre for Cybersecurity Belgium that they were following a recognised conformity route passed on 18 April 2026. The orientation phase is over.

The CCB has moved from explaining the law to supervising it: inspections, audits and binding instructions. Essential entities are supervised proactively, whether or not anything has gone wrong. Important entities are supervised reactively, which is not the same thing as being left alone.

If you registered and started a track, your horizon is full conformity, with the certification-based routes running to April 2027. If you did not, the position is uncomfortable but recoverable, and it starts with an honest scoping exercise rather than a rushed set of policies.

The first question is whether you are in scope at all

More organisations assume they are out of scope than actually are. A smaller group assume they are in scope because a customer said so. Both mistakes are expensive, in opposite directions.

Many SMEs are not caught by the law itself but pulled in through their customers' supply chain obligations, arriving as questionnaires and contract clauses. That is a genuine requirement, but it is a commercial one, and it should not be answered with the same programme a regulated entity needs.

How I work through it

  1. Scope and classification Which legal entities fall in scope, on what grounds, and whether they are essential or important. This determines your supervisory regime and how much evidence you will have to produce, so it is written down and reasoned, not assumed.
  2. Obligation mapping Your obligations set against what you already have. Governance and management accountability, risk management measures, business continuity, supply chain, and incident reporting. Most organisations discover they already meet a substantial part of this without evidence to show for it.
  3. Choosing a conformity route CyberFundamentals verification, ISO 27001 certification, or a self-assessment followed by inspection. They differ in cost, in credibility toward customers, and in how much of the work you can reuse elsewhere. This is a decision to make deliberately and early, because reversing it is expensive.
  4. Closing gaps and building evidence Turning measures into practices that leave a trace. A control you perform but cannot evidence counts for nothing with a supervisor, and a control you evidence but do not perform is worse than nothing.
  5. Incident reporting you can actually execute The reporting clock is short: an early warning within 24 hours, a notification within 72 hours, and a final report within a month of that notification rather than of the incident. The national CSIRT can ask for an interim report at any point, and if the incident is still running after a month you send a progress report and the final report once it is closed. That only works if someone knows they own it before the incident, not after.

What you get

Who this is for

Belgian organisations that are in scope, think they might be, or are being pushed by a customer who is. It fits best where management wants to understand the obligation and decide on it, rather than buy a document set that makes the question go away.

A word on the market you are shopping in. NIS2 has produced a great deal of urgency-driven selling, and a policy pack bought under deadline pressure is the most reliable way to spend real money on nothing. If a supplier quotes you a price before establishing your scope and classification, they are quoting for paperwork, not for compliance.

Questions I get

We supply a NIS2 entity but are not in scope ourselves. What do we owe?

Contractually, possibly quite a lot. Your customer must manage supply chain risk, so their obligation reaches you as questionnaires and clauses. That is a commercial requirement rather than a legal one, and it is usually satisfied with far less than a full compliance programme. Knowing which of the two you are answering saves real money.

We missed the April 2026 deadline. How bad is that?

Not fatal, and not something to leave alone. Supervision is live, so the useful move is to register, determine your scope properly, and start a recognised route with dates you can genuinely meet. Documented, demonstrable progress is a materially better position in front of a supervisor than silence.

What are the penalties?

For essential entities, administrative fines reach 10 million euro or 2 percent of worldwide annual turnover, whichever is higher. For important entities, 7 million euro or 1.4 percent. Fines are the visible end of the scale. The measures that arrive first, binding instructions, mandatory audits and, for essential entities, a temporary ban on exercising management functions, tend to be the more disruptive part.

Is CyFun mandatory?

No. CyberFundamentals is the route the CCB built and the one most Belgian organisations take, but ISO 27001 certification is an accepted alternative and inspection on the basis of a self-assessment is a third. Which one is cheapest depends entirely on where you already stand and what your customers ask to see.

More on the CyFun route and assurance levels

Who inside the company is responsible?

The management body. NIS2 makes approving and overseeing the risk management measures a management responsibility and expects management to be trained well enough to do it. Delegating the work is entirely normal. Delegating the accountability is not possible.

Start with a focused conversation

Fifteen minutes is usually enough to work out whether this is the right engagement, what the scope should be, and what it would realistically take.

Request an intro call