NIS2, Are you on scope?
Belgium's new cybersecurity law enters into force. Check it out now.
The Centre for Cybersecurity Belgium (CCB)'s recommendation on how to comply with the Belgian NIS2 legislation in just 7 steps.
Use our scope test tool to determine whether or not your organisation falls within the scope of the Belgian NIS2 Law.
Since NIS2 entities have to manage the cybersecurity of their supply chain, they may require your organisation to take cybersecurity measures: The Centre for Cybersecurity Belgium recommends to identify those who are vital to your cybersecurity and to invite them to implement at least the CyberFundamentals assurance level Basic.
All NIS2 entities are required to register on Safeonweb@Work:
The current registration portal will soon be updated to include registration forms specific to NIS2.
Starting from the 18th October 2024, all NIS2 entities are required to notify the CCB about significant incidents, i.e. any incident that has a significant impact on the provision of their services and that:
Significant incidents can be notified to the CCB via its incident notification platform or by phone via +32 (0)2 501 05 60 (only for emergencies for NIS2 Entities)
Access the notification platform
Incident notification is just one element of an incident response plan. If your organisation does not yet have an incident response plan, it might be useful to start from our policy templates.
Our CyFun® Selection Tool allows you to determine the appropriate assurance level (basic, important or essential) for your organisation.
Boards and management need to be trained on cybersecurity to assume their responsibilities and liabilities as required by the NIS2 legislation. For making management decisions on cyber security strategies and measures at board level, basic knowledge of risk management and cyber security are indispensable. It would be reasonable to plan management training before April 2025.
In addition to management training, employee training is always part of your cybersecurity measures.
NIS2 entities can use the CyFun® framework in 3 steps to comply with NIS2:
Essential entities shall have their implementation regularly assessed and reviewed by a third party. This can be done through a CyFun® certification granted by an accredited and authorised conformity assessment body (CAB). Essential entities have to obtain the assurance level basic or important before 18/04/2026, the final level needs to certified before 18/04/2027.
Important entities may subject themselves to the same regular conformity assessment under CyFun®, which gives them a presumption of conformity.
Please be aware that having the appropriate CyFun® label or certificate might be very important for the Boards and management to be able to demonstrate compliance in case of an incident.
List of authorised and accredited conformity assessment bodies: (coming soon).
Watch our explanatory video or consult our detailed analysis of the NIS2 law