Your First 30 Days: Registration, Scope and Risk Assessment
Most 30-day security plans open with multi-factor authentication. Belgian law does not. Before a single control gets implemented, a NIS2 entity has to be registered with the CCB, has to know which class of entity it is, and has to have run a risk analysis, because that analysis is what decides which CyberFundamentals level applies to you. This is the paperwork month. It is unglamorous, it has legal deadlines attached, and it blocks everything else.
This plan follows the order the Belgian NIS2 legislation itself uses, and ends at the CyberFundamentals framework. It implements no controls.
What You Will Have on Day 30
A completed CCB registration. A written answer to "are we essential or important", with the reasoning that got you there. A risk analysis that names your critical assets and your threats, approved by the people the law makes liable for it. A scored gap list against the CyberFundamentals level that analysis points at. And review meetings in the diary, with a named approver for each policy. What you will not have is a single implemented control. That is the next job and it is the longer one.
Week 1: Register with the CCB
The deadline has passed, which makes this urgent rather than optional
Article 13 of the Belgian NIS2 law of 26 April 2024 requires essential entities, important entities and domain name registration service providers to register with the national cybersecurity authority, the CCB. The clock ran five months from the law entering into force on 18 October 2024, so the deadline was 18 March 2025. Entities in the digital sector had two months under Article 14, so theirs was 18 December 2024. Both are long past, and neither comes with a grace period worth waiting for.
Find out whether you are already registered
More organisations than you would expect cannot answer this, because registration is a regulatory filing rather than an IT task and each side assumed the other did it.
- Ask whoever handles your regulatory filings, not your IT provider: the duty sits on the entity
- Look for a registration confirmation from the CCB in the mailbox of whoever signed it
- If nobody can produce a confirmation, work on the assumption that you are not registered
- Decide now who owns this filing from here on, by name
Gather what the registration asks for
Article 13 paragraph 1 lists the information you have to supply. Collecting it is most of the work.
- Entity name and company number (KBO/BCE)
- Address and current contact details, including an email address and a phone number
- Your IP ranges: this one catches people out and usually needs your IT provider
- Your sector and subsector under Annex I or Annex II of the law
- The list of Member States where you provide services that fall in scope
Register with the CCB
The law does not name a platform. It says registration follows the practical arrangements the CCB determines, and the CCB runs this through its Safeonweb@work portal.
- Follow the CCB's own current instructions rather than any third-party write-up, this page included
- Register the entity, not the group, unless the CCB's guidance tells you otherwise
- Use a shared mailbox as the contact address, not a personal one
- Keep the confirmation somewhere your successor will find it
Milestone: By end of Week 1: you either hold a registration confirmation, or you know by name who is producing one and by when.
Week 2: Work Out Which Entity You Are
Essential or important, and what each one actually obliges you to do
The two classes carry very different obligations, and this is the most misread thing in Belgian NIS2. Both must register. Both must take the security measures in Article 30. But only essential entities face a mandatory conformity assessment on a deadline. Under Article 41, an important entity may submit to one voluntarily.
Check yourself against Annexes I and II
Your class follows from your sector and subsector together with your size. Write the answer down with the reasoning, because you will be asked for both.
- Find the Annex I or Annex II row that matches what you actually do, not what your VAT code says
- Apply the size thresholds to that row
- Write one page: the row you matched, the headcount and turnover you applied, the conclusion
- Have it read by someone who was not involved in writing it
Know that the CCB can also decide for you
Size is not the only route into scope.
- Under Article 11 the CCB can identify an entity as in scope regardless of size, for example where it is the sole provider of a service, where failure would carry systemic risk, or where it is critical for a region
- Under Article 12 you must hand over the information the CCB needs for that identification, on request
- The CCB maintains and revises its list of entities at least every two years
- If the CCB has identified you, your registration clock runs from that identification rather than from the general deadline
Write down what your class obliges
The dates live in the Royal Decree of 9 June 2024, not in the law itself.
- Essential entity: Article 22 paragraph 1 required a first verification by a CCB-authorised conformity assessment body, at CyberFundamentals level basic or important depending on your risk analysis, by 18 April 2026
- Essential entity: Article 22 paragraph 2 requires certification at the essential level by 18 April 2027, or a CAB verification at a lower level where Article 7 applies (the risk analysis justifies it)
- Essential entity on the inspection route instead: Article 23 sets a self-assessment on the same 18 April 2026 date, and a progress status by 18 April 2027
- Important entity: Article 41 of the law makes the assessment voluntary, and no date attaches to it
- Both classes: Article 23 paragraph 3 requires continuous improvement, which has no end date at all
Milestone: By end of Week 2: a one-page written answer stating your class, the Annex row you matched, and the dated obligations that follow from it.
Week 2 decides which deadlines apply to you. If you already know you are in scope, read who must comply and the NIS2 deadlines alongside it: the dates differ by entity class.
Week 3: Run the Risk Analysis
The one that decides your CyberFundamentals level
Article 30 paragraph 5 requires every essential and important entity to carry out an all-hazards risk analysis, and to base its information security policy on the result. This is not a formality. For an essential entity, Article 22 paragraph 1 of the Royal Decree ties the level of its first CyFun verification (basic or important) to the outcome of this analysis. Article 7 lets it justify a level below essential with it, verified by a CAB. Under Article 9 an essential entity sends the analysis to the CCB alongside its conformity attestation.
List what you would be sorry to lose
Assets, systems, data, and the business processes that depend on them. This is the part people shortcut, and it is the part everything else is scored against.
- List the business processes that stop if a system is unavailable
- Map each process to the systems, data and suppliers it depends on
- Include software: CyberFundamentals Basic control ID.RA-01.1 asks for threats and vulnerabilities identified in all relevant assets, software included
- Note who owns each asset, because an asset with no owner gets no decision later
Score threat, vulnerability and impact
CyberFundamentals Basic control ID.RA-05.1 puts it plainly: risk is determined by threats, vulnerabilities and the impact on business processes and assets.
- Score all hazards, per Article 30 paragraph 5, not only the cyber ones: fire, flood, a key supplier failing and a key person leaving all count
- Use a scale you can defend out loud rather than a borrowed matrix nobody understands
- Record the reasoning next to the score, because the reasoning is what an assessor reads
- Let the result, not your preference, point at the CyberFundamentals level
Get it approved, not just written
An unapproved risk analysis is an unfinished one.
- Article 31 paragraph 1 puts approval of the risk-management measures on the management body, requires it to supervise implementation, and makes it liable for breaches of that obligation
- In a small company that is the director or the partners, not the IT provider
- Date the approval and record who gave it
- CyberFundamentals Basic control GV.RM-03.1 asks for an organisation-wide strategy to manage information and cybersecurity risk, updated when changes occur
Milestone: By end of Week 3: an approved, dated risk analysis that names your critical assets, your threats, and the CyberFundamentals level it points at.
Week 4: Gap Check, and Get the Reviews in the Diary
Turn the level into a list, and book the meetings that otherwise never happen
You now know which level you are aiming at. The last week turns that into a list of what is missing, and does the one piece of scheduling that decides whether the policy work ever happens at all. You are not writing policies this month. You are making sure the reviews have a date, a room and an owner.
Score yourself against the level
Walk the controls at your target level and mark each one done, partly done, or not started.
- Basic is 34 controls, Important 133, Essential 218, cumulative: each level contains the one below it
- Mark honestly: a control that works but is undocumented is partly done, not done
- For an essential entity on the inspection route this is a real deliverable, not an exercise: Article 23 paragraph 1 of the Royal Decree put a self-assessment at basic or important level on the 18 April 2026 date
- Keep the evidence you already have as you go, rather than hunting for it twice
Book the policy and procedure reviews
CyberFundamentals Basic control GV.PO-01.1 requires policies and procedures for managing information and cybersecurity to be established, documented, reviewed, approved, updated when changes occur, communicated and enforced.
- Put the review meetings in the diary now, with real dates, not "sometime this year"
- Have the person who will approve the outcome in the room, and name them in the invitation
- One meeting per policy area beats one meeting covering everything, because the second one overruns and gets cut short
- Record for each policy: the review date, the approver, and the outcome. That record is what you will be asked for
Write down what is still missing
The gap list is the deliverable of the whole month, and it is the thing that makes the next stretch estimable.
- One row per gap, with an owner by name and a realistic date
- Separate the gaps your IT provider closes from the ones only you can close
- Put a rough cost against each one, so the list can be decided on rather than admired
- Agree when you will look at it again
Milestone: By end of Week 4: a scored gap list against your target level, and dated review meetings with a named approver for each policy.
Which CyberFundamentals Basic Controls This Month Touches
This is assessment and governance work, so it touches the controls that ask for exactly that. All four are in the CCB's CyberFundamentals Basic set, which has 34 controls in total. These are four of them.
| ID | Control | Covered In |
|---|---|---|
| ID.RA-01.1 | Threats and vulnerabilities identified in all relevant assets | Week 3: asset and threat list |
| ID.RA-05.1 | Risk determined by threat, vulnerability and business impact | Week 3: risk scoring |
| GV.RM-03.1 | Organisation-wide strategy for managing information and cybersecurity risk | Week 3: approval by the management body |
| GV.PO-01.1 | Policies established, documented, reviewed, approved, communicated and enforced | Week 4: review meetings scheduled |
Your 30-Day Checklist
Track your progress with this summary checklist:
Week 1
- Confirmed whether you are registered
- Company number, contacts, IP ranges and sector gathered
- Registration submitted to the CCB
- Reminder set for the two-week change rule
Week 2
- Essential or important, written down with reasoning
- Annex I or II row identified
- Dated obligations for your class listed
- Checked whether the CCB has identified you
Week 3
- Critical assets and processes listed
- Threat, vulnerability and impact scored
- Risk analysis approved by the management body
- Target CyberFundamentals level chosen
Week 4
- Scored gap list against the target level
- Policy review meetings in the diary
- A named approver per policy
- Owner, cost and date for every gap
Not Sure Which Entity You Are?
Week 2 is where most organisations stall, because the answer decides every deadline that follows. Our free NIS2 scope check answers it in five on-screen clicks, with no email address. If you need the answer signed so you can forward it to a customer or an insurer, the written report is 395 EUR flat, ex VAT, delivered in 48 hours.
Frequently Asked Questions
Can I really not implement anything in 30 days?
You can, and you should if something obvious is broken: turning on multi-factor authentication does not need a risk analysis first. The point of this plan is different. The administrative steps are the ones with legal deadlines attached, they block everything downstream, and they are the ones that get postponed indefinitely because nobody enjoys them. Do them first and the implementation work finally has a scope, an owner and an estimate.
We missed the registration deadline. What happens now?
Register. The deadline under Article 13 of the Belgian NIS2 law was 18 March 2025 for essential and important entities, and 18 December 2024 under Article 14 for digital-sector entities. Neither comes with a grace period and neither gets easier by waiting. Being registered late is a materially better position than being unregistered when the CCB asks.
Does finishing these 30 days make us NIS2 compliant?
No, and nothing done in 30 days would. Article 30 requires a set of security measures to actually be in place and working. At day 30 you have registered, classified yourself, produced an approved risk analysis and scored your gaps. That is the starting position from which compliance work becomes possible. It is not compliance, and anyone selling you a 30-day compliance package is selling you the paperwork and calling it the result.
We are an important entity. Do we need a CyberFundamentals verification?
Not as an obligation. Article 41 of the Belgian NIS2 law says important entities may voluntarily submit to a regular conformity assessment. The dated obligations in the Royal Decree of 9 June 2024 apply to essential entities. You still have to take the Article 30 security measures and you still have to demonstrate continuous improvement. What is voluntary is the formal assessment, not the security.
Who has to approve the risk analysis?
Your management body. Article 31 paragraph 1 of the Belgian NIS2 law requires management bodies to approve the risk-management measures, to supervise their implementation, and holds them liable for breaches of that obligation. In a small company that is the director or the partners. It is not the IT provider, and it is not something that can be delegated away by contract.
How long until we actually reach CyberFundamentals Basic?
On our own client work, one to nine months from the end of this month, depending on where you start. Organisations already running managed IT with patching, backups and multi-factor authentication in place tend to reach Basic in one to three months. Starting from nothing, six to nine months is realistic. Anyone quoting you a fixed number without asking what you already have is guessing.
Related Articles
Sources
- CyberFundamentals Framework , Centre for Cybersecurity Belgium (CCB)
- Law of 26 April 2024 establishing a framework for the cybersecurity of network and information systems of general interest for public security , Belgian Official Gazette 17 May 2024, in force 18 October 2024. Registration: Art. 13-14. Security measures and risk analysis: Art. 30. Management body approval and liability: Art. 31. Responsibility: Art. 32. Voluntary assessment for important entities: Art. 41.
- Royal Decree of 9 June 2024 implementing the Law of 26 April 2024 , Belgian Official Gazette 24 June 2024. Conformity assessment deadlines for essential entities: Art. 22. Inspection route and continuous improvement: Art. 23.