IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

Missed the Belgian NIS2 Deadline of April 18, 2026? What Now

April 18, 2026 was the first NIS2 conformity date in Belgium, and it applied to essential entities only. If your organisation is an essential entity and missed it, here is what the step required, what the official sources say about catching up, and what they leave open.

What April 18, 2026 Actually Required

The Royal Decree of 9 June 2024, which implements the Belgian NIS2 law, sets the steps. They differ by entity class:

  • 1
    Essential entities, April 18, 2026 or 18 months after identification: on the CyFun certification route, a Basic or Important verification by a CCB-authorised conformity assessment body, at the level their risk analysis supports (Art. 22 §1). If they chose supervision by the CCB inspection service, a Basic or Important self-assessment (Art. 23 §1). On the ISO 27001 route, the scope and Statement of Applicability of the future certification.
  • 2
    Important entities, April 18, 2026: no administrative formality with the CCB (CCB FAQ). They must still implement all NIS2 measures, and the CCB can ask for evidence, for example after an incident. A voluntary CyFun assessment is a self-assessment verified by a CAB at Important level or higher (Art. 11).

If you are not sure whether your organization is classified as important or essential, start with who must comply with NIS2.

What Comes Next for an Essential Entity

Missing the April 2026 step does not move the next dates. Three facts from the sources:

1. April 18, 2027 stands

By then an essential entity on the CyFun route needs a CyFun Essential certificate (Art. 6 and 22 §2). On the ISO route it needs an ISO 27001 certification with measures equivalent to CyFun Essential. The third route is an inspection by the CCB.

2. A lower level only when your risk assessment justifies it

An essential entity may choose a lower CyFun level where its own risk assessment justifies it (Art. 7), without prior CCB approval but at its own responsibility. It must show by April 18, 2027 that it meets that level; on the CyFun route that is a CAB verification. The inspection service can check both the choice and the conformity.

3. A remediation plan if you will not reach Essential in time

The CCB Inspection Service letter sets it out per route. On the CyFun route, an entity without an Essential certificate by April 18, 2027 "is requested to submit a remediation plan", which "should preferably consist of" a CyFun Important certificate and the measures to reach Essential by April 18, 2028. On the ISO route the plan is due by April 18, 2027 and should preferably consist of an ISO 27001 certification with measures equivalent to CyFun Important. On the inspection route, the entity "will be asked to provide a remediation plan": evidence of Important-equivalent measures plus the measures planned for Essential. The letter says it does not change the legal obligations.

Your Route, and the 2027 Remediation Plan

The first three blocks are the routes the Royal Decree sets. Stay on the route you chose for your regular conformity assessment. The fourth block is the remediation plan for the 2027 date.

A

CyFun with a conformity assessment body

For: essential entities on the CyFun certification route

A CCB-authorised conformity assessment body verifies your CyFun controls at Basic or Important. The Essential certificate is due by April 18, 2027 (Art. 22 §2), but the CCB list of 7 September 2026 names no body authorised for CyFun Essential yet. Check the current list before you book.

What you need: a filled CyberFundamentals workbook with evidence per control, at the level your risk analysis supports.

B

Self-assessment under CCB inspection

For: essential entities that chose supervision by the CCB inspection service

The Royal Decree asked these entities for a Basic or Important self-assessment by the April 2026 date (Art. 23 §1), and for a progress report within 30 months (Art. 23 §2). The inspection service then assesses conformity itself, at most once a year (Art. 10).

What you need: the CyFun self-assessment at Basic or Important, with evidence behind each score.

C

ISO 27001 with a Statement of Applicability

For: essential entities on the ISO 27001 route

The Royal Decree accepts ISO/IEC 27001 as a reference framework (Art. 5). By the April 2026 date an essential entity on this route sent the scope and Statement of Applicability of its future certification. The CCB FAQ asks for the scope, the Statement of Applicability and the most recent internal audit, sent to certification@ccb.belgium.be.

What you need: an ISO 27001 certification whose scope covers all your networks and information systems, a Statement of Applicability that shows measures equivalent to the CyFun level concerned, and your most recent internal audit report.

D

Remediation plan for April 2027

For: essential entities that will not reach Essential by April 18, 2027

Named in the CCB Inspection Service letter of 11 August 2026 (ref. NCCA/JK/INS/2026-002). It is a request for information under Article 48 of the NIS2 law and does not change the legal obligations.

What you owe: on the CyFun route, preferably a CyFun Important certificate; on the ISO route, preferably an ISO 27001 certification with measures equivalent to CyFun Important, submitted by April 18, 2027; on the inspection route, evidence of Important-equivalent measures. Each time plus the measures planned to reach Essential by April 18, 2028. When you do not need it: if you have fully implemented Essential-level measures by April 18, 2027, or if your risk analysis justifies a lower level and you show by that date that you meet it.

How to Prepare Your Catch-Up

Whatever your route, the same groundwork applies:

  1. 1

    Confirm your entity class

    Essential or important depends on sector and size (NIS2 Directive, Art. 3). The April 2026 step applied to essential entities only.

  2. 2

    Confirm your route

    CyFun with a conformity assessment body, CyFun under CCB inspection, or ISO 27001. The route decides what you owe.

  3. 3

    Run the risk analysis

    The Royal Decree ties the level of your first verification to it (Art. 22 §1), and it is what can justify a level below Essential (Art. 7). Essential entities send it to the CCB with their conformity attestation (Art. 9).

  4. 4

    Fill the CyberFundamentals workbook with evidence

    Score each control honestly and keep an evidence reference per control. A CAB or the inspection service will read it, and a wall of top scores without evidence helps nobody.

  5. 5

    Contact the CCB inspection service

    The sources describe no late procedure for the April 2026 step. Ask the inspection service (inspection@ccb.belgium.be) how to regularise your position, and keep a written record of the answer.

No time to start from a blank workbook? Our instant on-screen scope check gives a rough estimate of scope, entity class and CyFun level in two minutes, no email required. Want a prioritized BASIC control list (30/90/180-day buckets) as the starting point for your catch-up? The written report is €395 flat, delivered in 48 hours.

What the CCB Has Said

Two points from the CCB sources we read:

  • Priority until April 2027. The inspection service will prioritise checking that essential entities have measures equivalent to CyFun Important by April 18, 2027. Its letter of 11 August 2026 gives new threats from advanced AI as the reason.
  • Evidence on request. For important entities, the CCB can ask for evidence that the measures are implemented, for example after an incident (CCB FAQ).

Our reading: neither point is a grace period, and a documented catch-up is the position you can show when someone asks.

How Easy Cyber Protection Shortens the Catch-Up Loop

We built a compliance engine around the CCB CyberFundamentals workbook because that file is what a CAB, the inspection service and an ISO 27001 reviewer read. The April 2026 release shipped CCB Excel export and auditor reimport, so the workbook you prepare in ECP can go to a CAB without rework.

  • Every BASIC, IMPORTANT, and ESSENTIAL control mapped, with the evidence for each one kept in a real document store.
  • CCB-compatible Excel export: the same workbook format the CCB publishes.
  • Auditor reimport: the CAB sends back a marked-up workbook, ECP merges the findings into the live state without manual reconciliation.
  • Multi-tier progression: start at BASIC or IMPORTANT, promote to ESSENTIAL for the 2027 date.

Frequently Asked Questions

What did the April 18, 2026 NIS2 step require in Belgium?

It applied to essential entities, in three routes (Royal Decree of 9 June 2024, Art. 22 and 23). On the CyFun route, a Basic or Important verification by an authorised conformity assessment body. Under CCB inspection, a Basic or Important self-assessment. On the ISO 27001 route, the scope and Statement of Applicability. For an entity identified later, the date is 18 months after identification. Important entities had no administrative formality, but must implement all NIS2 measures.

I missed it. Will I be fined immediately?

The sources we read (the CCB FAQ, the inspection service letter of 11 August 2026 and the Royal Decree) do not tie a fine to the April 2026 step. The NIS2 law sets maximum fines for infringements in general. Ask the CCB inspection service about your situation, and keep working towards the April 18, 2027 date.

Can I still do the April 2026 step late?

The sources describe no late procedure for it. The step itself is still what the Royal Decree describes: a CAB verification on the CyFun route, a self-assessment under CCB inspection, or the ISO scope and Statement of Applicability. Contact the CCB inspection service before you assume a late submission is accepted.

What is the remediation plan for 2027?

The CCB inspection service asks essential entities that will not reach Essential by April 18, 2027 for a remediation plan. It should preferably consist of a certificate at CyFun Important level, or the ISO or inspection equivalent, plus the measures planned to reach Essential by April 18, 2028 (letter NCCA/JK/INS/2026-002 of 11 August 2026). No plan is needed if you reach Essential in time, or if your risk analysis justifies a lower level and you show by then that you meet it.

Will my supply chain partners ask for proof?

Many will. Article 21(2)(d) of NIS2 makes supply chain security a required control area, and Article 21(3) makes in-scope entities weigh their suppliers' cybersecurity practices. The CCB advises organisations that may be in a NIS2 entity's supply chain to at least comply with CyFun Basic, and notes that an entity could impose a CyFun level on its direct suppliers.

How does a managed compliance platform help with a catch-up?

A platform that maps every CyFun control to evidence collection and produces a CCB-compatible Excel export shortens the catch-up loop from "draft from blank" to "fill the gaps the platform already identified".

Related Articles

Sources

  1. Directive (EU) 2022/2555 (NIS2): Articles 3, 21, 34
  2. Belgian NIS2 Law of 26 April 2024
  3. CCB CyberFundamentals Framework + Workbook
  4. Centre for Cybersecurity Belgium (CCB)
  5. CCB Inspection Service communication on NIS2 essential entities: ref NCCA/JK/INS/2026-002, letter of 11 August 2026. Source for the remediation plan and the April 18, 2028 endpoint.
  6. CCB: NIS2 page (supply-chain advice)
  7. BELAC: Belgian Accreditation Body
  8. CCB: FAQ NIS2 and CyberFundamentals
  9. CCB Inspection Service letter NCCA/JK/INS/2026-002 (11 August 2026)
  10. CCB: authorised conformity assessment bodies (list version 7 September 2026)
  11. Royal Decree of 9 June 2024 (NIS2), Art. 5-11, 22 and 23 (French text)