NIS2 Deadlines Belgium: April 2026, April 2027 and April 2028
Belgium's NIS2 compliance is moving fast. By April 18, 2026, essential entities needed a CyFun Basic or Important verification by an authorised CAB, a self-assessment on the CCB-inspection route, or their ISO 27001 scope and Statement of Applicability. With about 1,500 essential and 2,500 important entities registered one year after the law took effect (CCB, November 2025), here's your complete timeline and action plan.
NIS2 Timeline: Where We Are Now
NIS2 directive officially adopted by the EU
NIS2 entered into force (20 days after publication)
Member states deadline to transpose into national law
EU proposed NIS2 amendments and Cybersecurity Act 2
Belgium: first step for essential entities (CAB verification, CCB-inspection self-assessment, or ISO 27001 scope and Statement of Applicability)
Deadline for Member States to identify critical entities (CER Directive, Art. 6); an entity identified as critical is essential under NIS2 (Art. 3(1)(f))
Cyber Resilience Act: reporting obligations start (Reg. (EU) 2024/2847)
On the CAB and ISO routes, essential entities need an Essential-equivalent conformity assessment; on the CCB-inspection route, a progress report (Royal Decree, Art. 22 and 23). The CCB Inspection Service asks those that cannot reach Essential for a remediation plan. An entity whose own risk assessment justifies a lower CyFun level may choose that level instead, and must show by 18 April 2027 that it meets that level
Cyber Resilience Act: main obligations apply to products with digital elements
End date of a remediation plan: Essential-equivalent measures in place (CCB Inspection Service expectation, not a change to the law)
What Does This Mean for Your Business?
NIS2 is now legally binding in Belgium. Here's what this means in practice: Not sure if you are in scope? Check here.
Registration well advanced
One year after the law took effect, about 1,500 essential and 2,500 important entities were registered, about 4,000 in total (CCB, November 2025). Three quarters have chosen a security framework, and the CCB says most of those picked CyberFundamentals over ISO 27001. If you haven't registered yet, do so immediately.
Incident reporting is mandatory
Significant cyber incidents must be reported within 24 hours. New ransomware-specific reporting requirements include attack vector and whether ransom was paid.
Five authorised bodies, none for Essential
On the CCB list dated 7 September 2026, five Conformity Assessment Bodies are authorised for verification at Basic and Important level, and none is authorised for Essential certification yet.
Good News: It's Not Too Late
If you haven't started your NIS2 compliance journey yet, don't despair. Here's why starting now still makes sense:
Gradual enforcement
Regulators understand the scale of the challenge. The CCB Inspection Service has said it will prioritise verifying Important-level equivalence by April 18, 2027, so demonstrable progress at that level counts.
CyberFundamentals provides a path
The Belgian CCB's framework gives you a clear, structured approach to compliance - start with the Basic level and build from there.
First step once the deadline has passed: confirm you are actually in scope. Our free 2-minute NIS2 scope check gives that determination directly on screen, no email required. Want to put a signed file (scope, CyFun level, prioritized control list) on the table for a regulator or customer? The written report is €395 flat (ex VAT), delivered in 48 hours.
April 18, 2026: First Conformity Step for Essential Entities
By April 18, 2026, essential entities had to complete one of three routes (Royal Decree, Art. 22 and 23). An entity identified later has 18 months from its identification date. Here is what each step meant:
Confirm your registration
Ensure you're registered with the CCB at ccb.belgium.be.
Pick your route
CyFun certification route: a Basic or Important verification by an authorised CAB. CCB-inspection route: a Basic or Important self-assessment. ISO 27001 route: scope and Statement of Applicability
Gather documentation
Prepare the evidence behind that route: the CAB verification, the CyFun self-assessment, or the ISO 27001 scope and Statement of Applicability
Send it to the CCB by April 18, 2026
The CCB FAQ names certification@ccb.belgium.be for the ISO 27001 scope and Statement of Applicability
NIS2 Penalties: What's at Risk?
Non-compliance can result in significant fines. The penalties are designed to be proportionate but meaningful: Read our full overview of NIS2 penalties.
| Entity Type | Maximum Fine | Additional Consequences |
|---|---|---|
| Essential entities | €10 million or 2% of global turnover | Personal liability for management |
| Important entities | €7 million or 1.4% of global turnover | Management can be suspended |
| Late incident reporting | Administrative fines | Public disclosure possible |
Your Action Plan: Start Today
Here's what to do right now, regardless of where you are in your compliance journey: Follow our detailed 5-step implementation plan and review the NIS2 requirements.
Assess your scope
Determine if your organization falls under NIS2 (essential or important sector, size thresholds)
Start with CyberFundamentals Basic
Begin implementing the 34 controls in the CCB's entry level - it provides a solid foundation
Document everything
Keep records of what you're implementing and when. This shows good faith effort.
Set up incident reporting
Ensure you have a process to detect and report incidents within 24 hours
Plan for higher levels
Essential entities default to Essential; important entities pick theirs with the CCB Selection Tool, a risk assessment. A voluntary CyFun assessment is at Important level at least (Royal Decree, Art. 11). Plan your path from Basic upward
How Easy Cyber Protection Helps
We make NIS2 compliance manageable for organizations catching up:
Rather look for yourself first? Open the live demo - a shared sandbox with real CyFun data, one click, no signup and no card. There is no free tier.
Frequently Asked Questions
Is it too late to start NIS2 compliance?
No, it's not too late. While the deadline has passed, enforcement is ramping up gradually. Organizations that demonstrate active efforts toward compliance are in a much better position than those doing nothing. Start with CyberFundamentals Basic level today.
What happens if I'm not compliant by the deadline?
Technically, organizations in scope should already be compliant. However, regulators understand the scale of the challenge. Focus on making demonstrable progress.
When will audits and enforcement actually start?
Enforcement capacity is still being built, and the CCB Inspection Service has said it will prioritise verifying Important-level equivalence by April 18, 2027. Spot checks and incident-triggered investigations can happen anytime, but widespread systematic audits are expected to increase gradually. This gives you a window to make progress.
Do I need to register with the CCB?
If your organization qualifies as an essential or important entity under NIS2, you may need to register with the Centre for Cybersecurity Belgium (CCB). Check ccb.belgium.be for current registration requirements and guidance.
What's the fastest way to get started with compliance?
Start with the CyberFundamentals Basic level - it has 34 controls and provides a solid baseline. You can begin implementing these today with Easy Cyber Protection. Then work your way up to the level your NIS2 class and your own risk assessment call for.
Related Articles
Sources
- NIS2 Directive (EU) 2022/2555 : Official Journal of the European Union
- NIS2 Article 41: Transposition : October 17, 2024 deadline
- Centre for Cybersecurity Belgium (CCB) : CyberFundamentals Framework & Registration
- NIS2 Article 34: Administrative Fines : Penalty amounts for essential and important entities
- NIS2 Directive Overview : European Commission
- CCB CyFun Selection Tool
- Royal Decree of 9 June 2024 (NIS2), Art. 22 and 23 (French text)
- CCB: One year of NIS2 in Belgium (28 November 2025)
- CCB Inspection Service letter, ref. NCCA/JK/INS/2026-002 (11 August 2026)
- CCB list of authorised CABs (version 7 September 2026)
- CyFun: CABs in Belgium
- CER Directive (EU) 2022/2557, Art. 6
- CCB: FAQ NIS2 and CyberFundamentals