Skip to content
World Watch/Belgium/Cybersecurity

Cybersecurity ยท Belgium

Cybersecurity law in Belgium: NIS2 compliance (2026)

Comprehensive lawCountry index 93 ยท A+

Belgium shaded by its cybersecurity status

Cybersecurity in Belgium: comprehensive law.

FrameworkLaw of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security (Belgian NIS2 Law), transposing EU Directive 2022/2555; supervised by the Centre for Cybersecurity Belgium (CCB) as national competent authority and CSIRT.

Belgium has a comprehensive horizontal cybersecurity regime built on the NIS2 Law of 26 April 2024, which entered into force on 18 October 2024 and is enforced by the Centre for Cybersecurity Belgium (CCB). It is complemented by the sector-specific EU Digital Operational Resilience Act (DORA, applicable since 17 January 2025) supervised by the National Bank of Belgium and FSMA, and the recent Law of 19 December 2025 transposing the Critical Entities Resilience (CER) Directive. Belgium also operates its own CyberFundamentals (CyFun) framework providing a presumption of NIS2 conformity.

NIS2 & cybersecurity law in Belgium

In Belgium, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.

Framework
the NIS2 Directive (EU) 2022/2555, transposed into national law
Approach
cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
Applies to
medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
Incident reporting
an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
Maximum fine
up to โ‚ฌ10 million or 2% of global annual turnover for essential entities
Oversight
the national competent authority and CSIRT designated under NIS2

NIS2 is a directive, so Belgium implements it through national law; exact scope and deadlines can vary slightly by transposition.

NIS2 in Belgium: FAQ

Does NIS2 apply in Belgium?

Yes. As an EU member, Belgium has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.

Who must comply with NIS2 in Belgium?

Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.

What are the NIS2 incident-reporting deadlines in Belgium?

An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.

What are the penalties under NIS2 in Belgium?

Up to โ‚ฌ10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.

Key points

NIS2 transposition and competent authority

The Law of 26 April 2024 (published in the Belgian Official Gazette on 17 May 2024, in force 18 October 2024) transposes NIS2. The Centre for Cybersecurity Belgium (CCB) is the horizontal national competent authority, single point of contact and national CSIRT; essential and important entities were required to register by 18 March 2025.

Scope: essential vs. important entities

The law applies to 18 sectors of high criticality and other critical sectors (energy, transport, banking, financial market infrastructures, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal, waste management, chemicals, food, manufacturing, digital providers, research), distinguishing 'essential' and 'important' entities based on size and criticality.

Incident notification duties (24h / 72h / 1 month)

Significant incidents must be notified to the CCB (via its portal) with an early warning without undue delay and at most 24 hours after awareness, a full incident notification within 72 hours (24 hours for trust service providers), an intermediate report upon request, and a final report within one month.

CyberFundamentals (CyFun) framework

The CCB has issued the CyberFundamentals framework with four assurance levels (Small, Basic, Important, Essential) mapped to NIST CSF, ISO/IEC 27001/27002, CIS Controls and IEC 62443; CyFun verification/certification or ISO/IEC 27001 certification provides a presumption of conformity with NIS2 risk-management obligations.

Sectoral overlay: DORA for financial entities

The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies to Belgian banks, insurers, investment firms and ICT third-party providers since 17 January 2025, supervised by the National Bank of Belgium (NBB) and FSMA; DORA acts as lex specialis over NIS2 for the financial sector.

Critical Entities Resilience (CER) Directive transposition

Belgium transposed the CER Directive (2022/2557) through the Law of 19 December 2025 (published in the Belgisch Staatsblad on 19 January 2026), creating a national framework for identifying and supervising critical entities; those designated as critical are automatically deemed 'essential' under NIS2.

Timeline - major decisions & events

Jan 1, 2026guidanceofficial
Belgian DPA adopts 2026-2028 Strategic Plan shifting to systemic enforcement

The Data Protection Authority (APD/GBA) moved from individual complaint-handling toward 'systemic impact enforcement' with proactive audits targeting healthcare, finance, public sector, ad-tech and education, sharpening scrutiny of security and breach obligations in high-risk sectors.

Belgian Data Protection Authority โ†—
Oct 18, 2024lawofficial
NIS2 Law and implementing Royal Decree enter into force

Belgium's NIS2 regime became effective: in-scope essential and important entities must apply risk-management measures and report significant incidents to the CCB (24h early warning, 72h update, 30-day final report), with registration required by 18 March 2025.

Centre for Cybersecurity Belgium (CCB) โ†—
Jun 9, 2024lawofficial
Royal Decree implementing NIS2 designates CCB as national authority and CSIRT

The Royal Decree completed transposition of EU Directive 2022/2555, named the CCB the national cybersecurity authority and national CSIRT, set conformity-assessment procedures, and recognised the CyberFundamentals (CyFun) framework and ISO/IEC 27001 as compliance references.

Centre for Cybersecurity Belgium (CCB) โ†—
Dec 5, 2022incident
Play ransomware attack cripples the City of Antwerp

Attackers breached the systems of Antwerp's IT provider Digipolis, encrypting data and disrupting municipal services, libraries, museums and elderly-care medication systems, a landmark public-sector incident underscoring supply-chain cyber risk in Belgium.

VRT NWS โ†—
May 20, 2021guidanceofficial
National Security Council approves Cybersecurity Strategy 2.0 (2021-2025)

Belgium's renewed national strategy set six objectives to make the country one of the least cyber-vulnerable in Europe, prioritising critical-infrastructure protection, incident response and public-private-academic cooperation, with the CCB at the centre.

Centre for Cybersecurity Belgium (CCB) โ†—
May 4, 2021incident
Massive DDoS attack on Belnet disrupts government and parliament

A large distributed denial-of-service attack knocked out the Belnet network serving government bodies, affecting ~200 organisations and forcing the federal parliament to cancel committee sessions, Belgium's largest DDoS incident at the time.

The Record (Recorded Future News) โ†—
Apr 7, 2019law
NIS Law transposes the first EU NIS Directive

The Law of 7 April 2019 (published 3 May 2019) created Belgium's first horizontal framework for the security of networks and information systems of general interest, imposing security and incident-reporting duties on operators of essential services and digital service providers.

Fieldfisher โ†—
Oct 14, 2014lawofficial
Centre for Cybersecurity Belgium (CCB) established by Royal Decree

The Royal Decree of 14 October 2014 created the CCB as the national authority to monitor, coordinate and strengthen Belgian cybersecurity; it became operational in 2015 and is now the country's central cyber authority and CSIRT.

Centre for Cybersecurity Belgium (CCB) โ†—

Belgium - other topics

Cybersecurity in other countries

Last verified 8/8/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’