IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

NIS2 Deadlines Belgium: April 2026, April 2027 and April 2028

Belgium's NIS2 compliance is moving fast. By April 18, 2026, essential entities needed a CyFun Basic or Important verification by an authorised CAB, a self-assessment on the CCB-inspection route, or their ISO 27001 scope and Statement of Applicability. With about 1,500 essential and 2,500 important entities registered one year after the law took effect (CCB, November 2025), here's your complete timeline and action plan.

Business professional reviewing NIS2 compliance deadline
The NIS2 deadline has passed, but it's not too late to start

NIS2 Timeline: Where We Are Now

December 2022

NIS2 directive officially adopted by the EU

January 2023

NIS2 entered into force (20 days after publication)

October 17, 2024

Member states deadline to transpose into national law

January 20, 2026

EU proposed NIS2 amendments and Cybersecurity Act 2

April 18, 2026

Belgium: first step for essential entities (CAB verification, CCB-inspection self-assessment, or ISO 27001 scope and Statement of Applicability)

July 17, 2026

Deadline for Member States to identify critical entities (CER Directive, Art. 6); an entity identified as critical is essential under NIS2 (Art. 3(1)(f))

September 11, 2026

Cyber Resilience Act: reporting obligations start (Reg. (EU) 2024/2847)

April 18, 2027

On the CAB and ISO routes, essential entities need an Essential-equivalent conformity assessment; on the CCB-inspection route, a progress report (Royal Decree, Art. 22 and 23). The CCB Inspection Service asks those that cannot reach Essential for a remediation plan. An entity whose own risk assessment justifies a lower CyFun level may choose that level instead, and must show by 18 April 2027 that it meets that level

December 11, 2027

Cyber Resilience Act: main obligations apply to products with digital elements

April 18, 2028

End date of a remediation plan: Essential-equivalent measures in place (CCB Inspection Service expectation, not a change to the law)

What Does This Mean for Your Business?

NIS2 is now legally binding in Belgium. Here's what this means in practice: Not sure if you are in scope? Check here.

Registration well advanced

One year after the law took effect, about 1,500 essential and 2,500 important entities were registered, about 4,000 in total (CCB, November 2025). Three quarters have chosen a security framework, and the CCB says most of those picked CyberFundamentals over ISO 27001. If you haven't registered yet, do so immediately.

Incident reporting is mandatory

Significant cyber incidents must be reported within 24 hours. New ransomware-specific reporting requirements include attack vector and whether ransom was paid.

Five authorised bodies, none for Essential

On the CCB list dated 7 September 2026, five Conformity Assessment Bodies are authorised for verification at Basic and Important level, and none is authorised for Essential certification yet.

Good News: It's Not Too Late

If you haven't started your NIS2 compliance journey yet, don't despair. Here's why starting now still makes sense:

Gradual enforcement

Regulators understand the scale of the challenge. The CCB Inspection Service has said it will prioritise verifying Important-level equivalence by April 18, 2027, so demonstrable progress at that level counts.

CyberFundamentals provides a path

The Belgian CCB's framework gives you a clear, structured approach to compliance - start with the Basic level and build from there.

First step once the deadline has passed: confirm you are actually in scope. Our free 2-minute NIS2 scope check gives that determination directly on screen, no email required. Want to put a signed file (scope, CyFun level, prioritized control list) on the table for a regulator or customer? The written report is €395 flat (ex VAT), delivered in 48 hours.

April 18, 2026: First Conformity Step for Essential Entities

By April 18, 2026, essential entities had to complete one of three routes (Royal Decree, Art. 22 and 23). An entity identified later has 18 months from its identification date. Here is what each step meant:

1

Confirm your registration

Ensure you're registered with the CCB at ccb.belgium.be.

2

Pick your route

CyFun certification route: a Basic or Important verification by an authorised CAB. CCB-inspection route: a Basic or Important self-assessment. ISO 27001 route: scope and Statement of Applicability

3

Gather documentation

Prepare the evidence behind that route: the CAB verification, the CyFun self-assessment, or the ISO 27001 scope and Statement of Applicability

4

Send it to the CCB by April 18, 2026

The CCB FAQ names certification@ccb.belgium.be for the ISO 27001 scope and Statement of Applicability

NIS2 Penalties: What's at Risk?

Non-compliance can result in significant fines. The penalties are designed to be proportionate but meaningful: Read our full overview of NIS2 penalties.

Entity TypeMaximum FineAdditional Consequences
Essential entities €10 million or 2% of global turnover Personal liability for management
Important entities €7 million or 1.4% of global turnover Management can be suspended
Late incident reporting Administrative fines Public disclosure possible
NIS2 compliance roadmap illustration
Your path to NIS2 compliance: step by step

Your Action Plan: Start Today

Here's what to do right now, regardless of where you are in your compliance journey: Follow our detailed 5-step implementation plan and review the NIS2 requirements.

1

Assess your scope

Determine if your organization falls under NIS2 (essential or important sector, size thresholds)

2

Start with CyberFundamentals Basic

Begin implementing the 34 controls in the CCB's entry level - it provides a solid foundation

3

Document everything

Keep records of what you're implementing and when. This shows good faith effort.

4

Set up incident reporting

Ensure you have a process to detect and report incidents within 24 hours

5

Plan for higher levels

Essential entities default to Essential; important entities pick theirs with the CCB Selection Tool, a risk assessment. A voluntary CyFun assessment is at Important level at least (Royal Decree, Art. 11). Plan your path from Basic upward

How Easy Cyber Protection Helps

We make NIS2 compliance manageable for organizations catching up:

CyFun Basic as a baseline : Start with CyberFundamentals Basic (34 controls) and scale up. Your IT partner can scope which tier you need
One task at a time : No overwhelm - clear, prioritized next steps
Track your progress : Document compliance and see exactly where you stand
Evidence collection : Build your audit trail as you implement controls
IT partner collaboration : Share tasks with your technical team or MSP

Rather look for yourself first? Open the live demo - a shared sandbox with real CyFun data, one click, no signup and no card. There is no free tier.

Frequently Asked Questions

Is it too late to start NIS2 compliance?

No, it's not too late. While the deadline has passed, enforcement is ramping up gradually. Organizations that demonstrate active efforts toward compliance are in a much better position than those doing nothing. Start with CyberFundamentals Basic level today.

What happens if I'm not compliant by the deadline?

Technically, organizations in scope should already be compliant. However, regulators understand the scale of the challenge. Focus on making demonstrable progress.

When will audits and enforcement actually start?

Enforcement capacity is still being built, and the CCB Inspection Service has said it will prioritise verifying Important-level equivalence by April 18, 2027. Spot checks and incident-triggered investigations can happen anytime, but widespread systematic audits are expected to increase gradually. This gives you a window to make progress.

Do I need to register with the CCB?

If your organization qualifies as an essential or important entity under NIS2, you may need to register with the Centre for Cybersecurity Belgium (CCB). Check ccb.belgium.be for current registration requirements and guidance.

What's the fastest way to get started with compliance?

Start with the CyberFundamentals Basic level - it has 34 controls and provides a solid baseline. You can begin implementing these today with Easy Cyber Protection. Then work your way up to the level your NIS2 class and your own risk assessment call for.

Related Articles

Sources

  1. NIS2 Directive (EU) 2022/2555 : Official Journal of the European Union
  2. NIS2 Article 41: Transposition : October 17, 2024 deadline
  3. Centre for Cybersecurity Belgium (CCB) : CyberFundamentals Framework & Registration
  4. NIS2 Article 34: Administrative Fines : Penalty amounts for essential and important entities
  5. NIS2 Directive Overview : European Commission
  6. CCB CyFun Selection Tool
  7. Royal Decree of 9 June 2024 (NIS2), Art. 22 and 23 (French text)
  8. CCB: One year of NIS2 in Belgium (28 November 2025)
  9. CCB Inspection Service letter, ref. NCCA/JK/INS/2026-002 (11 August 2026)
  10. CCB list of authorised CABs (version 7 September 2026)
  11. CyFun: CABs in Belgium
  12. CER Directive (EU) 2022/2557, Art. 6
  13. CCB: FAQ NIS2 and CyberFundamentals