NIS2 in Belgium — the CCB, CyFun, and a deadline that has already passed.
Belgium transposed early and transposed fully. The Law of 26 April 2024 and its Royal Decree of 9 June 2024 entered into force on 18 October 2024 — the directive's own deadline — with the Centre for Cybersecurity Belgium (CCB) as national competent authority and national CSIRT in one body, supported by sectoral authorities named in the Royal Decree.
What makes Belgium distinctive is not the timetable but the assurance model. Essential entities do not simply declare compliance; they demonstrate it, through CyberFundamentals (CyFun) verification, a certificate against ISO 27001, or CCB inspection. The first evidence deadline for essential entities was 18 April 2026. It has passed. Anyone in scope who has not yet engaged with it is now late, not early.
Who it applies to
Essential and important entities across the directive's 18 sectors, established in Belgium or offering services there, with digital-sector providers brought in on an accelerated schedule. Every in-scope entity had to register with the CCB through Safeonweb@Work by 18 March 2025; entities that cross the thresholds later must register without undue delay and with no transitional period. Registration is not a formality: it is what puts you on the CCB's supervision list and starts your evidence clock.
The clock
Competent authority: Centre for Cybersecurity Belgium (CCB). Transposition: Law of 26 April 2024.
| When | What happens |
|---|---|
| 26 April 2024 | NIS2 law adopted; Royal Decree follows on 9 June 2024 |
| 18 October 2024 | Law and Royal Decree enter into force |
| 18 March 2025 | Registration deadline with the CCB via Safeonweb@Work |
| 18 April 2026 | Essential entities: evidence of conformity due (CyFun, ISO 27001 or CCB inspection) |
CyFun, ISO 27001, or an inspector
The CCB's CyberFundamentals framework is tiered — Small, Basic, Important, Essential — and the upper tiers are built to line up with what the law asks of each entity class. An essential entity can demonstrate conformity with a CyFun verification at the matching level, with an ISO 27001 certificate, or by submitting to CCB inspection. The three routes ask for the same underlying thing: controls that demonstrably operate, with evidence someone outside the organization can examine. TruSecure maps CyFun's tiers and ISO 27001's Annex A onto one control library, so the choice of route changes the export, not the work — and a verification body, a certification auditor, or a CCB inspector reads the same evidence in their own shape.
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the Belgium transposition reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed when the authority asks for it.
| What the law asks | Where it is answered |
|---|---|
| Register with the CCB, and keep the registration current | Entity profile · classification and registration facts held as records |
| Demonstrate conformity — CyFun, ISO 27001 or inspection | Control library · CyFun tiers and Annex A mapped onto one control set |
| Report significant incidents: 24 hours, 72 hours, one month | Incident workflow · clocked from awareness, each stage pre-built from the last |
| Show management body oversight and training | Governance workspace · approvals, training records, named owners |
| Give the verifier, auditor or inspector what they sample | Per-route exports · same evidence, CyFun, ISO or CCB shape |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Classification
- essential · registered 12 Mar 2025
- Assurance route
- CyFun Essential · verification scheduled
- Controls evidenced
- 58/61 · 3 open, each with an owner and a date
- Incident drills
- 2 this year · 24h / 72h clocks met
- Export
- sealed · sha256:7d3a...e2c9
Where teams usually start
With a demo walked through by TruSecure — your entity classification against the Belgian law, the CyFun tier that matches it, the controls you already operate mapped onto both CyFun and Annex A, and a sample incident drill against the 24-hour clock. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 (Directive (EU) 2022/2555) is enforced in Belgium by Centre for Cybersecurity Belgium (CCB). TruSecure determines applicability against Belgium's national transposition specifically, rather than the EU baseline alone, and maps its requirements to a single control model shared across every framework it supports. TruSecure is operated by European entities — TRUSECURE S.R.L. in Romania and Trusecure Ltd in the United Kingdom — and stores all Customer Content with a single EU sub-processor in French and German datacentres. No Customer Content is transferred to the United States or to Asia, so the EU–US Data Privacy Framework is not a dependency.