NIS2 in Belgium: CCB, CyberFundamentals & Deadlines
Belgium was one of the first EU countries to transpose NIS2 into national law. The Belgian law of April 26, 2024 gives the Centre for Cybersecurity Belgium (CCB) full authority over NIS2 compliance. Belgium chose a unique path: the CyberFundamentals framework. Here is everything you need to know.
The Belgian NIS2 Law (April 26, 2024)
Belgium transposed the EU NIS2 directive into national law on April 26, 2024. This makes Belgium one of the fastest EU member states to act. The law establishes the Centre for Cybersecurity Belgium (CCB) as the single national authority for NIS2 compliance.
Early adopter
Belgium published its NIS2 law before the EU deadline of October 17, 2024. Most member states missed that deadline.
Single authority
The CCB handles registration, compliance monitoring, incident reporting and enforcement. One point of contact for everything.
Broader scope
Belgium added sectors beyond the EU minimum. More organizations fall under the Belgian law than the directive requires.
Management liability
Senior management is personally responsible for cybersecurity. They can face fines or suspension for non-compliance.
Role of the CCB (Centre for Cybersecurity Belgium)
The CCB is Belgium's national cybersecurity authority. Under NIS2, it takes on several critical roles:
Registration portal
All in-scope entities must register via Safeonweb@Work. The CCB maintains the official register of essential and important entities.
Framework provider
The CCB developed CyberFundamentals, a tiered compliance framework tailored to Belgian organizations.
Incident response
Significant incidents must be reported to the CCB within 24 hours. The CCB coordinates response and shares threat intelligence.
Enforcement
The CCB can impose fines, order corrective measures, and in severe cases suspend management of non-compliant organizations.
CyberFundamentals: Belgium's Unique Framework
CyberFundamentals (CyFun) is what makes Belgium different. Instead of relying solely on ISO 27001, the CCB created a practical, tiered framework. It maps to international standards (NIST CSF, ISO 27001, CIS Controls) but is simpler to adopt. Read our full CyberFundamentals guide .
The 3 CyFun Tiers
| Tier | Controls | Cost | What it is |
|---|---|---|---|
| Basic | 34 controls | Framework free, CAB verification paid | Entry level: the core controls every higher level builds on |
| Important | 133 controls | Framework free, CAB verification paid | Adds 99 controls; the minimum for an important entity's voluntary assessment (Royal Decree, Art. 11) |
| Essential | 218 controls | Framework free, CAB certification paid | All controls; the default for essential entities, lower only where their risk assessment justifies it (Art. 7) |
Which level applies to your company follows from your NIS2 class and your own risk assessment: essential entities default to Essential. Our free NIS2 scope determination gives you a rough estimate on screen in five questions, no email required. Want the determination in writing for your file or to forward to a customer? The written report is €395 flat (ex VAT), delivered in 48 hours.
Belgian Registration: The Numbers
Belgium's registration process is well underway. Here are the latest figures:
About 1,500 essential entities
Plus about 2,500 important entities, registered one year after the law took effect (CCB, November 2025).
About 4,000 registrations in total
Across all sectors, about 4,000 entities had registered by November 2025: roughly 1,500 essential and 2,500 important (CCB).
Most chose CyFun
Three quarters of registered entities have chosen a security framework, and the CCB says most of those picked CyberFundamentals as their compliance framework. The rest chose ISO 27001.
Registration is mandatory
If you fall under NIS2 scope and have not registered yet, do so immediately at Safeonweb@Work.
Belgian NIS2 Deadlines
Belgium has set clear milestones. Missing them puts your organization at risk of enforcement action. See all NIS2 deadlines in detail .
Belgian NIS2 law adopted (Loi NIS2)
First step for essential entities (CAB verification, CCB-inspection self-assessment, or ISO 27001 scope and Statement of Applicability)
Deadline for Member States to identify critical entities (CER Directive, Art. 6); an entity identified as critical is essential under NIS2 (Art. 3(1)(f))
On the CAB and ISO routes, essential entities need an Essential-equivalent conformity assessment; on the CCB-inspection route, a progress report (Royal Decree, Art. 22 and 23). The CCB Inspection Service asks those that cannot reach Essential for a remediation plan. An entity whose own risk assessment justifies a lower CyFun level may choose that level instead, and must show by 18 April 2027 that it meets that level
End date of a remediation plan: Essential-equivalent measures in place (CCB Inspection Service expectation, not a change to the law)
How Belgium Differs from Other EU Countries
Belgium stands out in the EU NIS2 landscape. Here is how:
CyFun is unique
No other EU country has a tiered, practical framework like CyberFundamentals. Most rely on ISO 27001 alone, which is expensive and complex for SMEs.
Ahead of schedule
Belgium transposed NIS2 months before the EU deadline. Many member states still have not finished their transposition in 2026.
Single authority model
Belgium uses one authority (CCB) for everything. Some countries split responsibilities across multiple agencies, creating confusion.
Broader sector coverage
Belgium extended NIS2 scope beyond the EU minimum. More sectors and smaller entities are included.
Belgian Enforcement: CAB Audits
Enforcement is becoming real. The CCB has been working with Conformity Assessment Bodies (CABs) to prepare for audits.
No CAB authorised for CyFun Essential yet
On the CCB list of 7 September 2026, five bodies verify at Basic and Important, and none certifies Essential. Check cyfun.eu/en/cabs/cabs-belgium before you book.
Audits already started
Early adopters have already undergone CyFun audits. The audit process follows a structured approach based on the chosen CyFun tier.
The April 2026 step came first
Before the 2027 conformity assessment, essential entities needed a CAB verification at Basic or Important, a self-assessment on the CCB-inspection route, or their ISO 27001 scope and Statement of Applicability.
Proportional enforcement
The CCB considers your organization size, sector, and demonstrated effort. Good-faith progress matters.
How Easy Cyber Protection Helps
We help Belgian organizations get audit-ready for CyberFundamentals:
Frequently Asked Questions
Is NIS2 already law in Belgium?
Yes. Belgium transposed NIS2 into national law on April 26, 2024. The law gives the Centre for Cybersecurity Belgium (CCB) authority over registration, compliance and enforcement. Belgium was one of the first EU countries to complete transposition.
What is CyberFundamentals and why does Belgium use it?
CyberFundamentals (CyFun) is a tiered cybersecurity framework developed by the CCB. It has 3 cumulative levels: Basic (34 controls), Important (133 controls), and Essential (218 controls). Belgium created it as a practical alternative to ISO 27001. Three quarters of registered entities have chosen a framework, and the CCB says most picked CyFun.
What did the April 2026 NIS2 step require in Belgium?
The deadline was April 18, 2026, and it has passed. By that date, essential entities on the CyFun route needed a Basic or Important verification from a CCB-authorised conformity assessment body. Those that chose supervision by the CCB inspection service sent a Basic or Important self-assessment instead. Those on the ISO 27001 route sent their scope and Statement of Applicability (Royal Decree of 9 June 2024, Art. 22 and 23). An Essential-equivalent conformity assessment is due by April 18, 2027, and that deadline is unchanged. These dates count from the law's entry into force; for an entity identified later, they count from its identification date (Royal Decree, Art. 22 and 23). Entities that cannot reach that level in time are asked to file a remediation plan with the CCB Inspection Service. That plan should preferably consist of proof of compliance at CyFun Important level plus the measures planned to reach Essential by April 18, 2028 (CCB Inspection Service letter ref. NCCA/JK/INS/2026-002, 11 August 2026). An entity whose own risk assessment justifies a lower CyFun level may choose it instead, without prior CCB approval but at its own responsibility. It must then show by 18 April 2027 that it meets that level (on the CyFun route, through a CAB verification). Member States had to identify critical entities under the CER Directive by July 17, 2026; an entity identified as critical is an essential entity under NIS2 (Art. 3(1)(f)).
How many Belgian companies must comply with NIS2?
One year after the law took effect, about 1,500 essential and 2,500 important entities had registered, so about 4,000 in total (CCB, November 2025). Belgium extended the scope beyond the EU minimum, so more organizations are included than in most other member states.
How do I get audit-ready for CyberFundamentals in Belgium?
Start by registering at Safeonweb@Work if you have not already. Your CyFun level follows from your NIS2 class and your own risk assessment: essential entities default to Essential. Many start with CyFun Basic (34 controls) and work upward. Document your controls and gather evidence. Easy Cyber Protection helps you track progress and build your audit trail.
Related Articles
Sources
- Belgian NIS2 Law (April 26, 2024) , Belgisch Staatsblad / Moniteur belge
- Centre for Cybersecurity Belgium (CCB) , National cybersecurity authority
- CyberFundamentals Framework , CCB
- NIS2 Directive (EU) 2022/2555 , Official Journal of the European Union
- Safeonweb@Work , Registration portal
- Royal Decree of 9 June 2024 (NIS2), Art. 22 and 23 (French text)
- CCB: One year of NIS2 in Belgium (28 November 2025)
- CCB Inspection Service letter, ref. NCCA/JK/INS/2026-002 (11 August 2026)
- CCB list of authorised CABs (version 7 September 2026)
- CyFun: CABs in Belgium
- CER Directive (EU) 2022/2557, Art. 6
- CCB: FAQ NIS2 and CyberFundamentals