Executive summary
- The first compliance milestone of 18 April 2026 has passed; the CCB is actively enforcing
- By 18 April 2027, essential entities must demonstrate the Essential level or submit a remediation plan
- That plan contains evidence at the Important level plus a plan to reach Essential by 18 April 2028
- The CCB explicitly cites new threats linked to advanced AI systems
- Important entities are exempt from mandatory assessment, but every other obligation has applied since October 2024
- CyFun® 2025 adds Govern as a function and puts more weight on supply chain and OT; 2023 and 2025 run alongside each other until 18 April 2027
- A CyFun® label is not the same thing as NIS2 compliance
- The Commission proposed targeted amendments to the directive on 20 January 2026; these are not in force
- Incident reporting and management accountability are governance questions, not IT questions
NIS2 in Belgium: the first deadline has passed, the hard one is still ahead
On 18 April 2026, essential entities had to show for the first time where they stood in their NIS2 journey. That milestone is behind us, the Centre for Cybersecurity Belgium is actively supervising, and last month its Inspection Service wrote to every essential entity about the next step: 18 April 2027.
The gap between those two dates is wider than a year. The first asked for an undertaking — a self-assessment, a scope, a signed agreement with an assessment body. The second asks for a result.
The first deadline asked for an intention. The second asks for a level.
Where Belgium stands today
Belgium was among the first member states to transpose NIS2, through the Act of 26 April 2024, in force since 18 October 2024, together with the Royal Decree of 9 June 2024. The framework has been filled in step by step ever since.
Registration through Safeonweb@Work is behind us. The first compliance milestone for essential entities, set at 18 April 2026, has passed: organisations that chose CyFun® had to produce at least a verification at Basic or Important level; those that chose ISO/IEC 27001 had to submit their certification scope, Statement of Applicability and most recent internal audit report; those that opted for direct supervision had to provide a self-assessment with supporting evidence.
Since 17 July 2026, operators of critical infrastructure are automatically classified as essential entities. The CCB is now in the enforcement phase.
What the CCB’s new communication actually asks for
The CCB Inspection Service has sent a general communication and a request for information to all Belgian essential NIS2 entities, covering the mandatory conformity assessment due by 18 April 2027.
The substance: essential entities that cannot demonstrate by that date that they have implemented cybersecurity measures equivalent to CyFun® assurance level Essential must submit a remediation plan. That plan has two parts:
- evidence of compliance with measures at least equivalent to the Important level
- a substantiated description of the measures planned to reach Essential by 18 April 2028 at the latest
No remediation plan is required from entities that can demonstrate, on 18 April 2027, that they meet the Essential level — or substantiated measures at a lower level, based on their own risk analysis.
This approach applies to all three assessment routes: CyFun® certification or verification by an accredited conformity assessment body, ISO/IEC 27001 certification by an accredited body, or a conformity assessment carried out by the Inspection Service itself. One detail matters: the communication changes nothing about the legal obligations or deadlines set out in the NIS2 Act and its Royal Decree. It makes explicit what the Inspection Service expects to see.
The reasoning behind it is worth noting. The CCB points to the new threats associated with the rise of advanced artificial intelligence systems, and to the questions these raise around governance, risk assessment, supply chain security, monitoring and incident response. In other words: the framework is moving, and it is moving for reasons that were not on the table a year ago.
Essential or important: the classification decides everything
For many organisations this is still the first real question.
Essential entities — large organisations in sectors such as energy, transport, healthcare and digital infrastructure — are subject to mandatory, regular ex-ante supervision. They have to demonstrate their compliance actively, on the schedule described above.
Important entities are subject to ex-post supervision. They are not obliged to undergo a conformity assessment, though they may do so voluntarily, which gives them a presumption of conformity. Mind the trap: every other obligation — the security measures, the reporting duty, management accountability — applies in full, and has applied since 18 October 2024.
Unsure about your classification? The CCB provides a scope test through Safeonweb@Work. Record the outcome together with the reasoning behind it. You will need that document later.
CyFun® or ISO 27001: which route, and which version?
Roughly three quarters of registered entities chose CyFun®, the framework the CCB developed for the Belgian context. ISO/IEC 27001 remains a fully valid alternative.
The difference lies in the starting point. CyFun® works through tiered assurance levels — Small, Basic, Important, Essential — and emphasises concrete, actionable measures with a measurable score per control. ISO/IEC 27001 starts from building a complete information security management system, which is usually a broader and longer undertaking.
The Essential level is fundamentally different in nature from Basic or Important: it is a management system certification, with a documentation audit, an on-site implementation audit, annual surveillance audits and recertification. An organisation sitting at Basic today and aiming for Essential by April 2027 does not have an administrative problem. It has a project plan.
Since October 2025 there is a second choice to make on top of that: which version of CyFun®.
A self-assessment shows what you intend to do. A certification shows what you have.
What changes in CyFun® 2025?
The CCB released a new version of the framework in October 2025. It is aligned with the NIST Cybersecurity Framework 2.0 and with European legislation, NIS2 first among them, and more than eighty experts and organisations reviewed the draft. The substantive shifts:
- Governance becomes a function in its own right. CyFun® 2023 followed the five NIST functions Identify, Protect, Detect, Respond and Recover. CyFun® 2025 adds Govern, and governance measures appear from the Important level upwards. That connects directly to the management accountability set out in the Belgian NIS2 Act.
- The supply chain is given explicit space in the controls: suppliers and partners.
- OT security is addressed explicitly, which matters for industrial and healthcare environments.
- The controls are more clearly worded, with fuller guidance on interpretation and implementation.
The timing is the part to remember. CyFun® 2023 and CyFun® 2025 run alongside each other until 18 April 2027; until that date you choose which version your verification or certification is based on. Statements and certificates based on CyFun® 2023 remain valid until 18 April 2028 at the latest. After that, only CyFun® 2025 is accepted.
That is the same date as the compliance milestone above. On 18 April 2027, two questions therefore meet: have you reached your target level, and which version of the framework are you being assessed against?
One nuance that regularly trips organisations up: holding a CyFun® label does not automatically mean you are NIS2 compliant. Obligations such as the 24-hour, 72-hour and one-month reporting deadlines still have to be covered in your own procedures.
Incident reporting is a governance question, not a technical one
The timeframes are well known: an early warning within 24 hours, a notification within 72 hours, a final report within one month.
What goes wrong in practice is rarely the technology. It is the question of who, within those first 24 hours, has the authority to determine that this is a reportable incident — and to make that call on a Saturday night, on incomplete information, while the response team is still working out what actually happened.
The same applies to management accountability. The management body has to approve the cybersecurity measures and follow the required training, and carries personal responsibility for doing so. That is not a formality you tick off in a meeting. It is why a NIS2 programme starts in the boardroom rather than the server room.
Why this is legal and technical work at the same time
The ten measures from the directive read like a technical list: risk analysis, incident handling, continuity and backups, supply chain, secure development, measuring effectiveness, cyber hygiene and training, cryptography, access control, multi-factor authentication.
But every one of them raises a legal question. Which level is appropriate to our risks, and how do we defend that choice? What do we impose contractually on suppliers, and what happens when they refuse? What does “secure development” mean for software we buy rather than build?
The reverse is equally true: legal analysis stalls without a technical picture. You cannot determine an appropriate level without knowing which systems are running and how they connect.
That is why this course puts two trainers in the room together: a lawyer specialising in cybersecurity law and a practitioner who carries out implementations. Legal question, technical answer, and the other way round.
And meanwhile the European framework is moving too
While Belgium enforces its law, the directive itself is being reopened.
On 20 January 2026 the European Commission published a proposal for targeted amendments to the NIS2 Directive, alongside a proposal to revise the Cybersecurity Act. That proposal — COM(2026) 13, procedure 2026/0012(COD) — sets out to clarify the scope, simplify jurisdictional rules, streamline the collection of data on ransomware and strengthen cross-border supervision, with a broader coordinating role for ENISA. The obligation to appoint an EU representative would also be extended to any essential or important entity not established in the Union but offering services within it. The Commission estimates it would ease compliance for some 28,700 companies.
Separately, the Digital Omnibus package touches incident reporting: a single EU reporting portal for notifications under Articles 23 and 30, with ENISA operating it as a technical service provider and forwarding notifications to the competent national addressees. The thresholds, deadlines and addressees themselves stay as they are.
Both texts are proposals. They are going through the ordinary legislative procedure and are not law yet. But anyone building an implementation plan today is better off doing so knowing that the scope and the reporting route may still shift.
At the same time ENISA continues to fill in the framework, and the NIS Cooperation Group publishes reference documents on the security measures for entities falling under NIS2. That is not legislation, but it is what supervisors look at when they judge whether your measures are appropriate.
Where to start
- Confirm your classification — essential, important or out of scope — and record the reasoning in writing.
- Check your registration through Safeonweb@Work. A late registration beats a recorded absence of one.
- Set your target level and compare it with where you are today. The gap is your project plan, not an action item.
- Choose your CyFun® version. Until 18 April 2027 you can still opt for 2023 or 2025; after that you cannot. Weigh up whether to finish an ongoing trajectory on 2023 or switch straight away.
- Assign the reporting mandate: who decides within 24 hours, and who stands in for that person.
- Put management accountability on the board’s agenda, including the training obligation.
- Document your evidence measure by measure. In an assessment, what counts is not what you do but what you can show.
From legal text to a working implementation plan in two days
NIS2 Lead Implementer Belgium: Legislation and Practice starts from the legal framework every time and then moves to practical application. Day one covers the legal framework: the basic concepts, an in-depth analysis of the NIS2 obligations, the Belgian transposition (registration, cybersecurity measures, training, incident reporting, conformity assessment, supervision) and what all of that means for your internal procedures and your supplier contracts. Day two is implementation: hands-on sessions with the CyFun® framework using realistic scenarios, and building strategies and action plans for your own organisation.
The course is taught by Chris De Vuyst and Bernd Fiten: a lawyer specialising in cybersecurity law and a hands-on cybersecurity practitioner, in the room together.
This version of the course has been updated with the most recent documentation from ENISA and the NIS Cooperation Group on implementing NIS2, with the European Commission’s proposal to adapt the scope of the directive, and with fuller guidance and exercises on CyFun® 2025, the new version of the framework the CCB recommends for implementing the Belgian NIS2 Act.
14–15 December 2026 — Park Inn by Radisson Diegem, in English.
Also available in Dutch (20–21 October 2026, Antwerp) and French (12–13 November 2026, Nivelles-Sud).
20 participants on average, 24 maximum.
€1,495 excl. VAT, €1,195 for public institutions, including lunch, a printed syllabus and digital learning material.
No prior knowledge required.
Worth 30 CPE credits, recognised by the Institute for Company Lawyers (IJE-IBJ) and the FSMA, and eligible for Flemish training leave and Brussels paid educational leave.
SME portfolio funding available under the cybersecurity theme.
The CyFun® framework is owned by the Centre for Cybersecurity Belgium and CyFun® is a registered trademark of the CCB. The framework and its conformity assessment scheme are available at cyfun.eu, their only authentic source. DPI’s services may contribute to third-party assessments but never replace an accredited third-party assessment.
Sources and further reading
- Centre for Cybersecurity Belgium — communication to essential NIS2 entities
- Safeonweb@Work — registration, scope test and FAQ
- CyberFundamentals Framework 2025 — CCB, including a comparison of the key measures in CyFun® 2023 and 2025
- Proposal COM(2026) 13 amending the NIS2 Directive — European Commission
- Directive (EU) 2022/2555 (NIS2) — EUR-Lex
- Act of 26 April 2024 (Belgian NIS2 Act) — Justel
Frequently asked questions
We are an important entity. Do we need a conformity assessment?
Not as an obligation. Important entities are supervised after the fact and may undergo an assessment voluntarily. Every other obligation does apply, and has done since October 2024.
What exactly is a remediation plan?
The plan essential entities submit if they cannot demonstrate the Essential level on 18 April 2027. It contains evidence of compliance at least equivalent to the Important level, plus a substantiated plan to reach Essential by 18 April 2028.
Does the CCB communication change the legal deadlines?
No. The Inspection Service sets out what it expects to see; the obligations and timeframes in the NIS2 Act and the Royal Decree are unchanged.
Do we have to move to CyFun® 2025?
Not immediately. CyFun® 2023 and CyFun® 2025 run alongside each other until 18 April 2027, and until then you choose which version your assessment is based on. Statements and certificates based on the 2023 version stay valid until 18 April 2028 at the latest; after that only the 2025 version is accepted.
Does a CyFun® label mean we are NIS2 compliant?
No. The label shows that you have implemented the measures of a given assurance level. Specific obligations, such as the reporting deadlines, still have to be covered in your own procedures.
Is the directive itself still going to change?
The European Commission published a proposal for targeted amendments on 20 January 2026, covering among other things the scope, the jurisdictional rules and the reporting route. It is a proposal, not law yet.
How does NIS2 relate to the Cyber Resilience Act?
NIS2 looks at the cybersecurity of your organisation. The CRA looks at the properties of your products. They overlap without replacing each other. If you place products with digital elements on the market yourself, you have both files open. See also CRA Lead Implementer.
Is prior knowledge required?
No. The course is built for a range of profiles, from organisations just starting out to teams already well advanced and looking to refine their approach.
Do I receive a certificate?
You receive a certificate of completion after the two days, together with a concrete action plan and the tools to carry on straight away.