What is NIS2? Complete Guide for Belgian Businesses
NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity directive. It entered into force on 16 January 2023, and the Belgian law that transposes it applies since 18 October 2024. It sets security measures and incident-reporting duties for medium and large organisations in 18 sectors, and for some smaller ones regardless of size (Art. 2, 21 and 23). In Belgium, about 4,000 entities had registered by November 2025 (CCB).
Who Must Comply with NIS2?
NIS2 applies to organizations in sectors of high criticality (Annex I) and other critical sectors (Annex II). Whether an entity is essential or important depends on its sector and its size (Art. 3). The scope is much broader than the original NIS directive. Read our full scope guide.
Sectors of high criticality (Annex I)
- Energy (electricity, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking & financial infrastructure
- Healthcare (hospitals, labs, pharma)
- Drinking water & wastewater
- Digital infrastructure (DNS, cloud, data centers)
- ICT service management (business-to-business)
- Public administration
- Space
Other critical sectors (Annex II)
- Postal & courier services
- Waste management
- Chemicals (manufacture, production, distribution)
- Food production & distribution
- Manufacturing (medical devices, electronics, machinery)
- Digital providers (marketplaces, search engines)
- Research organizations
Not sure whether your company falls under NIS2 and at what CyberFundamentals level? Our free scope check answers that question in five on-screen clicks, no email required. Need a signed answer you can forward to your customer or insurer? The written report is €395 flat (ex VAT), delivered in 48 hours.
What Does NIS2 Require?
NIS2 mandates "appropriate and proportionate" cybersecurity measures. The key requirements are: See all 10 requirements in detail.
Risk Management
Identify, analyze, and address cybersecurity risks systematically
Incident Handling
Detect, respond to, and report security incidents within 24 hours
Business Continuity
Backup, disaster recovery, and crisis management plans
Supply Chain Security
Assess and manage risks from suppliers and vendors
Basic Cyber Hygiene
Policies on passwords, updates, access control, encryption
Staff Training
Ensure employees understand their cybersecurity responsibilities
NIS2 in Belgium: CyberFundamentals
The Centre for Cybersecurity Belgium (CCB) created the CyberFundamentals framework to help organizations comply with NIS2. It's the official Belgian approach, recognized by the government and aligned with EU requirements. On 17 June 2026, the EU NIS Cooperation Group published a reference document tied to Implementing Regulation 2024/2690 that maps NIS2 security measures across frameworks, placing CyberFundamentals alongside ISO/IEC 27001, IEC 62443 and NIST CSF 2.0. Learn more about CyberFundamentals.
| Level | Controls | For |
|---|---|---|
| Basic | 34 | Standard security needs |
| Important | 133 | Important entities that opt for a CyFun assessment (Important at least, Royal Decree, Art. 11) |
| Essential | 218 | Essential entities (default; lower only if their own risk assessment justifies it) |
NIS2 Penalties: What's at Risk?
NIS2 introduces significant penalties for non-compliance: Read more about NIS2 penalties.
| Category | Maximum Fine | Additional |
|---|---|---|
| Essential entities | €10 million or 2% of global turnover | Personal liability for management |
| Important entities | €7 million or 1.4% of global turnover | Management can be suspended |
| Late incident reporting | Administrative fines | Public disclosure possible |
When Must You Comply?
The NIS2 Directive entered into force on 16 January 2023. Member states had until 17 October 2024 to transpose it into national law, and the Belgian law of 26 April 2024 applies since 18 October 2024. Organizations should already be working on compliance. View all NIS2 deadlines.
How to Get Started with NIS2 Compliance
Don't be overwhelmed. The goal isn't perfection. It's continuous improvement.
Assess your scope
Are you in an essential or important sector? Do you meet the size threshold?
Start with basics
Begin with CyberFundamentals "Basic" level: 34 practical controls
Document everything
Keep records of what you implement and when
Build gradually
Move up when your NIS2 class or your own risk assessment calls for it: essential entities default to Essential
Get help
Work with your IT partner or use a compliance platform like Easy Cyber Protection
How Easy Cyber Protection Helps
Rather look for yourself first? Open the live demo - a shared sandbox with real CyFun data, one click, no signup and no card. There is no free tier.
Frequently Asked Questions
Does my company need to comply with NIS2?
If you operate in a sector listed in Annex I or II AND are medium-sized or larger (50+ staff, or both turnover and balance sheet above €10 million), you likely need to comply. Some critical services must comply regardless of size.
What is the difference between NIS2 and GDPR?
GDPR focuses on personal data protection, while NIS2 focuses on overall cybersecurity and network security. Many organizations need to comply with both. GDPR has higher fines (€20M/4% turnover) but NIS2 adds management liability.
What happens if I don't comply with NIS2?
Essential entities face fines up to €10 million or 2% of global turnover. Important entities face up to €7 million or 1.4%. Management can also be held personally liable and suspended.
What is CyberFundamentals?
CyberFundamentals is the Belgian framework created by the CCB (Centre for Cybersecurity Belgium) to help organizations meet NIS2 requirements. It defines three cumulative levels: Basic, Important, and Essential.
How long does NIS2 compliance take?
It depends on your starting point and target tier. CyFun Basic (34 controls) takes 1 to 9 months depending on your security baseline. Well-equipped organisations reach Basic in 1-3 months, greenfield clients need 6-9 months or more. CyFun Important and Essential are multi-year arcs because each tier carries more controls and more evidence to build. The Royal Decree allows an Important verification at the first step (Art. 22 §1), and essential entities need Essential by 18 April 2027, or Important plus a plan to reach it by 18 April 2028. There is no way to shortcut the evidence.
Related Articles
Sources
- NIS2 Directive (EU) 2022/2555 , Official Journal of the European Union
- NIS2 Directive Overview , European Commission
- Centre for Cybersecurity Belgium (CCB) , CyberFundamentals Framework
- NIS2 Article 34: Administrative Fines , Penalty amounts for essential and important entities
- CCB: FAQ NIS2 and CyberFundamentals
- Recommendation 2003/361/EC (SME definition)
- Royal Decree of 9 June 2024 (NIS2, French text)
- CCB: One year of NIS2 in Belgium (28 November 2025)
- CCB: The NIS2 Law (entry into force 18 October 2024)