Cybersecurity ยท Belgium
Cybersecurity law in Belgium: NIS2 compliance (2026)
Belgium shaded by its cybersecurity status
Cybersecurity in Belgium: comprehensive law.
FrameworkLaw of 26 April 2024 establishing a framework for the cybersecurity of networks and information systems of general interest for public security (Belgian NIS2 Law), transposing EU Directive 2022/2555; supervised by the Centre for Cybersecurity Belgium (CCB) as national competent authority and CSIRT.
Belgium has a comprehensive horizontal cybersecurity regime built on the NIS2 Law of 26 April 2024, which entered into force on 18 October 2024 and is enforced by the Centre for Cybersecurity Belgium (CCB). It is complemented by the sector-specific EU Digital Operational Resilience Act (DORA, applicable since 17 January 2025) supervised by the National Bank of Belgium and FSMA, and the recent Law of 19 December 2025 transposing the Critical Entities Resilience (CER) Directive. Belgium also operates its own CyberFundamentals (CyFun) framework providing a presumption of NIS2 conformity.
NIS2 & cybersecurity law in Belgium
In Belgium, baseline cybersecurity obligations come from the EU NIS2 Directive, transposed into national law, which sets risk-management and incident-reporting duties for essential and important entities.
- Framework
- the NIS2 Directive (EU) 2022/2555, transposed into national law
- Approach
- cybersecurity risk-management measures plus mandatory incident reporting for in-scope entities
- Applies to
- medium and large entities in critical sectors: energy, transport, banking, health, water, digital infrastructure, ICT and public administration
- Incident reporting
- an early warning within 24 hours and a full notification within 72 hours to the national CSIRT
- Maximum fine
- up to โฌ10 million or 2% of global annual turnover for essential entities
- Oversight
- the national competent authority and CSIRT designated under NIS2
NIS2 is a directive, so Belgium implements it through national law; exact scope and deadlines can vary slightly by transposition.
NIS2 in Belgium: FAQ
Yes. As an EU member, Belgium has transposed the NIS2 Directive (EU) 2022/2555 into national law, covering essential and important entities in critical sectors.
Medium and large organisations in sectors such as energy, transport, banking, health, water, digital infrastructure and public administration.
An early warning within 24 hours of becoming aware and a fuller incident notification within 72 hours to the national CSIRT.
Up to โฌ10 million or 2% of global annual turnover for essential entities, with lower ceilings for important entities.
Key points
The Law of 26 April 2024 (published in the Belgian Official Gazette on 17 May 2024, in force 18 October 2024) transposes NIS2. The Centre for Cybersecurity Belgium (CCB) is the horizontal national competent authority, single point of contact and national CSIRT; essential and important entities were required to register by 18 March 2025.
The law applies to 18 sectors of high criticality and other critical sectors (energy, transport, banking, financial market infrastructures, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal, waste management, chemicals, food, manufacturing, digital providers, research), distinguishing 'essential' and 'important' entities based on size and criticality.
Significant incidents must be notified to the CCB (via its portal) with an early warning without undue delay and at most 24 hours after awareness, a full incident notification within 72 hours (24 hours for trust service providers), an intermediate report upon request, and a final report within one month.
The CCB has issued the CyberFundamentals framework with four assurance levels (Small, Basic, Important, Essential) mapped to NIST CSF, ISO/IEC 27001/27002, CIS Controls and IEC 62443; CyFun verification/certification or ISO/IEC 27001 certification provides a presumption of conformity with NIS2 risk-management obligations.
The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554) applies to Belgian banks, insurers, investment firms and ICT third-party providers since 17 January 2025, supervised by the National Bank of Belgium (NBB) and FSMA; DORA acts as lex specialis over NIS2 for the financial sector.
Belgium transposed the CER Directive (2022/2557) through the Law of 19 December 2025 (published in the Belgisch Staatsblad on 19 January 2026), creating a national framework for identifying and supervising critical entities; those designated as critical are automatically deemed 'essential' under NIS2.
Timeline - major decisions & events
The Data Protection Authority (APD/GBA) moved from individual complaint-handling toward 'systemic impact enforcement' with proactive audits targeting healthcare, finance, public sector, ad-tech and education, sharpening scrutiny of security and breach obligations in high-risk sectors.
Belgian Data Protection Authority โBelgium's NIS2 regime became effective: in-scope essential and important entities must apply risk-management measures and report significant incidents to the CCB (24h early warning, 72h update, 30-day final report), with registration required by 18 March 2025.
Centre for Cybersecurity Belgium (CCB) โThe Royal Decree completed transposition of EU Directive 2022/2555, named the CCB the national cybersecurity authority and national CSIRT, set conformity-assessment procedures, and recognised the CyberFundamentals (CyFun) framework and ISO/IEC 27001 as compliance references.
Centre for Cybersecurity Belgium (CCB) โAttackers breached the systems of Antwerp's IT provider Digipolis, encrypting data and disrupting municipal services, libraries, museums and elderly-care medication systems, a landmark public-sector incident underscoring supply-chain cyber risk in Belgium.
VRT NWS โBelgium's renewed national strategy set six objectives to make the country one of the least cyber-vulnerable in Europe, prioritising critical-infrastructure protection, incident response and public-private-academic cooperation, with the CCB at the centre.
Centre for Cybersecurity Belgium (CCB) โA large distributed denial-of-service attack knocked out the Belnet network serving government bodies, affecting ~200 organisations and forcing the federal parliament to cancel committee sessions, Belgium's largest DDoS incident at the time.
The Record (Recorded Future News) โThe Law of 7 April 2019 (published 3 May 2019) created Belgium's first horizontal framework for the security of networks and information systems of general interest, imposing security and incident-reporting duties on operators of essential services and digital service providers.
Fieldfisher โThe Royal Decree of 14 October 2014 created the CCB as the national authority to monitor, coordinate and strengthen Belgian cybersecurity; it became operational in 2015 and is now the country's central cyber authority and CSIRT.
Centre for Cybersecurity Belgium (CCB) โBelgium - other topics
Cybersecurity in other countries
Last verified 8/8/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ