Skip to main content
NIS2 · BELGIUM

NIS2 in Belgium — the CCB, CyFun, and a deadline that has already passed.

Belgium transposed early and transposed fully. The Law of 26 April 2024 and its Royal Decree of 9 June 2024 entered into force on 18 October 2024 — the directive's own deadline — with the Centre for Cybersecurity Belgium (CCB) as national competent authority and national CSIRT in one body, supported by sectoral authorities named in the Royal Decree.

What makes Belgium distinctive is not the timetable but the assurance model. Essential entities do not simply declare compliance; they demonstrate it, through CyberFundamentals (CyFun) verification, a certificate against ISO 27001, or CCB inspection. The first evidence deadline for essential entities was 18 April 2026. It has passed. Anyone in scope who has not yet engaged with it is now late, not early.

Who it applies to

Essential and important entities across the directive's 18 sectors, established in Belgium or offering services there, with digital-sector providers brought in on an accelerated schedule. Every in-scope entity had to register with the CCB through Safeonweb@Work by 18 March 2025; entities that cross the thresholds later must register without undue delay and with no transitional period. Registration is not a formality: it is what puts you on the CCB's supervision list and starts your evidence clock.

The clock

Competent authority: Centre for Cybersecurity Belgium (CCB). Transposition: Law of 26 April 2024.

NIS2 in Belgium · timeline
WhenWhat happens
26 April 2024NIS2 law adopted; Royal Decree follows on 9 June 2024
18 October 2024Law and Royal Decree enter into force
18 March 2025Registration deadline with the CCB via Safeonweb@Work
18 April 2026Essential entities: evidence of conformity due (CyFun, ISO 27001 or CCB inspection)

CyFun, ISO 27001, or an inspector

The CCB's CyberFundamentals framework is tiered — Small, Basic, Important, Essential — and the upper tiers are built to line up with what the law asks of each entity class. An essential entity can demonstrate conformity with a CyFun verification at the matching level, with an ISO 27001 certificate, or by submitting to CCB inspection. The three routes ask for the same underlying thing: controls that demonstrably operate, with evidence someone outside the organization can examine. TruSecure maps CyFun's tiers and ISO 27001's Annex A onto one control library, so the choice of route changes the export, not the work — and a verification body, a certification auditor, or a CCB inspector reads the same evidence in their own shape.

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the Belgium transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.

Belgium requirements · how TruSecure answers them
What the law asksWhere it is answered
Register with the CCB, and keep the registration currentEntity profile · classification and registration facts held as records
Demonstrate conformity — CyFun, ISO 27001 or inspectionControl library · CyFun tiers and Annex A mapped onto one control set
Report significant incidents: 24 hours, 72 hours, one monthIncident workflow · clocked from awareness, each stage pre-built from the last
Show management body oversight and trainingGovernance workspace · approvals, training records, named owners
Give the verifier, auditor or inspector what they samplePer-route exports · same evidence, CyFun, ISO or CCB shape

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

Belgium NIS2 readiness file · excerptSample data
Classification
essential · registered 12 Mar 2025
Assurance route
CyFun Essential · verification scheduled
Controls evidenced
58/61 · 3 open, each with an owner and a date
Incident drills
2 this year · 24h / 72h clocks met
Export
sealed · sha256:7d3a...e2c9

Where teams usually start

With a demo walked through by TruSecure — your entity classification against the Belgian law, the CyFun tier that matches it, the controls you already operate mapped onto both CyFun and Annex A, and a sample incident drill against the 24-hour clock. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 (Directive (EU) 2022/2555) is enforced in Belgium by Centre for Cybersecurity Belgium (CCB). TruSecure determines applicability against Belgium's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.

Frequently Asked Questions

What is the CyFun framework and does it satisfy NIS2?
CyFun is Belgium's own tiered cybersecurity framework, built to demonstrate NIS2-aligned practice — TruSecure maps CyFun's tiers directly onto the same control model used for the EU baseline, so one assessment produces both.