IT Partner? See how to deliver NIS2 audit-readiness

View partner offer →
By · Founder, Easy Cyber Protection · · How we write this

What is NIS2? Complete Guide for Belgian Businesses

NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity directive. It entered into force on 16 January 2023, and the Belgian law that transposes it applies since 18 October 2024. It sets security measures and incident-reporting duties for medium and large organisations in 18 sectors, and for some smaller ones regardless of size (Art. 2, 21 and 23). In Belgium, about 4,000 entities had registered by November 2025 (CCB).

Belgian business team discussing NIS2 cybersecurity compliance

Who Must Comply with NIS2?

NIS2 applies to organizations in sectors of high criticality (Annex I) and other critical sectors (Annex II). Whether an entity is essential or important depends on its sector and its size (Art. 3). The scope is much broader than the original NIS directive. Read our full scope guide.

Critical infrastructure sectors under NIS2: energy, transport, healthcare, digital

Sectors of high criticality (Annex I)

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking & financial infrastructure
  • Healthcare (hospitals, labs, pharma)
  • Drinking water & wastewater
  • Digital infrastructure (DNS, cloud, data centers)
  • ICT service management (business-to-business)
  • Public administration
  • Space

Other critical sectors (Annex II)

  • Postal & courier services
  • Waste management
  • Chemicals (manufacture, production, distribution)
  • Food production & distribution
  • Manufacturing (medical devices, electronics, machinery)
  • Digital providers (marketplaces, search engines)
  • Research organizations

Not sure whether your company falls under NIS2 and at what CyberFundamentals level? Our free scope check answers that question in five on-screen clicks, no email required. Need a signed answer you can forward to your customer or insurer? The written report is €395 flat (ex VAT), delivered in 48 hours.

What Does NIS2 Require?

NIS2 mandates "appropriate and proportionate" cybersecurity measures. The key requirements are: See all 10 requirements in detail.

Risk Management

Identify, analyze, and address cybersecurity risks systematically

Incident Handling

Detect, respond to, and report security incidents within 24 hours

Business Continuity

Backup, disaster recovery, and crisis management plans

Supply Chain Security

Assess and manage risks from suppliers and vendors

Basic Cyber Hygiene

Policies on passwords, updates, access control, encryption

Staff Training

Ensure employees understand their cybersecurity responsibilities

NIS2 in Belgium: CyberFundamentals

The Centre for Cybersecurity Belgium (CCB) created the CyberFundamentals framework to help organizations comply with NIS2. It's the official Belgian approach, recognized by the government and aligned with EU requirements. On 17 June 2026, the EU NIS Cooperation Group published a reference document tied to Implementing Regulation 2024/2690 that maps NIS2 security measures across frameworks, placing CyberFundamentals alongside ISO/IEC 27001, IEC 62443 and NIST CSF 2.0. Learn more about CyberFundamentals.

CyberFundamentals assurance levels. Our price is not on this table on purpose: one licence covers all three levels, and it is set by your employee count, not by the level you target. Per month: Nano 1 – 4: €49, Micro 5 – 12: €99, Core 13 – 29: €169, Growth 30 – 49: €229, Medium 50 – 249: €395, Large 250 – 999: €750, 1,000+ on request. Moving up a level costs nothing.
LevelControlsFor
Basic 34 Standard security needs
Important 133 Important entities that opt for a CyFun assessment (Important at least, Royal Decree, Art. 11)
Essential 218 Essential entities (default; lower only if their own risk assessment justifies it)

NIS2 Penalties: What's at Risk?

NIS2 introduces significant penalties for non-compliance: Read more about NIS2 penalties.

CategoryMaximum FineAdditional
Essential entities €10 million or 2% of global turnover Personal liability for management
Important entities €7 million or 1.4% of global turnover Management can be suspended
Late incident reporting Administrative fines Public disclosure possible

When Must You Comply?

The NIS2 Directive entered into force on 16 January 2023. Member states had until 17 October 2024 to transpose it into national law, and the Belgian law of 26 April 2024 applies since 18 October 2024. Organizations should already be working on compliance. View all NIS2 deadlines.

Now Assess whether your organization is in scope
Now Start implementing CyberFundamentals baseline
April 18, 2026 First step for essential entities: a CyFun Basic or Important verification by an authorised CAB, a self-assessment if they chose CCB inspection, or the ISO 27001 scope and Statement of Applicability (Royal Decree, Art. 22 and 23). Important entities had no administrative formality. About 4,000 entities were registered one year after the law took effect (CCB, November 2025).
Ongoing Document your cybersecurity posture
When incidents occur Report significant incidents within 24 hours

How to Get Started with NIS2 Compliance

Don't be overwhelmed. The goal isn't perfection. It's continuous improvement.

Business owner working on cybersecurity compliance with clear dashboard
1

Assess your scope

Are you in an essential or important sector? Do you meet the size threshold?

2

Start with basics

Begin with CyberFundamentals "Basic" level: 34 practical controls

3

Document everything

Keep records of what you implement and when

4

Build gradually

Move up when your NIS2 class or your own risk assessment calls for it: essential entities default to Essential

5

Get help

Work with your IT partner or use a compliance platform like Easy Cyber Protection

How Easy Cyber Protection Helps

One task at a time . No overwhelm: just clear next steps
Progress tracking . See exactly where you stand
Evidence collection . Document compliance as you go
IT partner collaboration . Share tasks with your technical team

Rather look for yourself first? Open the live demo - a shared sandbox with real CyFun data, one click, no signup and no card. There is no free tier.

Frequently Asked Questions

Does my company need to comply with NIS2?

If you operate in a sector listed in Annex I or II AND are medium-sized or larger (50+ staff, or both turnover and balance sheet above €10 million), you likely need to comply. Some critical services must comply regardless of size.

What is the difference between NIS2 and GDPR?

GDPR focuses on personal data protection, while NIS2 focuses on overall cybersecurity and network security. Many organizations need to comply with both. GDPR has higher fines (€20M/4% turnover) but NIS2 adds management liability.

What happens if I don't comply with NIS2?

Essential entities face fines up to €10 million or 2% of global turnover. Important entities face up to €7 million or 1.4%. Management can also be held personally liable and suspended.

What is CyberFundamentals?

CyberFundamentals is the Belgian framework created by the CCB (Centre for Cybersecurity Belgium) to help organizations meet NIS2 requirements. It defines three cumulative levels: Basic, Important, and Essential.

How long does NIS2 compliance take?

It depends on your starting point and target tier. CyFun Basic (34 controls) takes 1 to 9 months depending on your security baseline. Well-equipped organisations reach Basic in 1-3 months, greenfield clients need 6-9 months or more. CyFun Important and Essential are multi-year arcs because each tier carries more controls and more evidence to build. The Royal Decree allows an Important verification at the first step (Art. 22 §1), and essential entities need Essential by 18 April 2027, or Important plus a plan to reach it by 18 April 2028. There is no way to shortcut the evidence.

Related Articles

Sources

  1. NIS2 Directive (EU) 2022/2555 , Official Journal of the European Union
  2. NIS2 Directive Overview , European Commission
  3. Centre for Cybersecurity Belgium (CCB) , CyberFundamentals Framework
  4. NIS2 Article 34: Administrative Fines , Penalty amounts for essential and important entities
  5. CCB: FAQ NIS2 and CyberFundamentals
  6. Recommendation 2003/361/EC (SME definition)
  7. Royal Decree of 9 June 2024 (NIS2, French text)
  8. CCB: One year of NIS2 in Belgium (28 November 2025)
  9. CCB: The NIS2 Law (entry into force 18 October 2024)