
{"id":20492,"date":"2026-09-17T11:35:34","date_gmt":"2026-09-17T09:35:34","guid":{"rendered":"https:\/\/www.dp-institute.eu\/?p=20492"},"modified":"2026-09-17T11:35:34","modified_gmt":"2026-09-17T09:35:34","slug":"nis2-belgium-the-road-to-april-18-2027","status":"publish","type":"post","link":"https:\/\/www.dp-institute.eu\/en\/nis2-belgium-the-road-to-april-18-2027\/","title":{"rendered":"NIS2 Belgium: the road to April 18 2027"},"content":{"rendered":"<div style=\"max-width:1000px;margin:0 auto;font-family:Arial, sans-serif;color:#1f2937;line-height:1.7;\">\n<!-- Executive summary --><\/p>\n<div id=\"executive-summary\" style=\"background:#f8fafc;border:1px solid #e5e7eb;border-left:5px solid #1d4ed8;border-radius:12px;padding:25px;margin-bottom:30px;\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Executive summary<\/h2>\n<ul style=\"padding-left:20px;margin:0;\">\n<li style=\"margin-bottom:6px;\">The first compliance milestone of 18 April 2026 has passed; the CCB is actively enforcing<\/li>\n<li style=\"margin-bottom:6px;\">By 18 April 2027, essential entities must demonstrate the Essential level or submit a remediation plan<\/li>\n<li style=\"margin-bottom:6px;\">That plan contains evidence at the Important level plus a plan to reach Essential by 18 April 2028<\/li>\n<li style=\"margin-bottom:6px;\">The CCB explicitly cites new threats linked to advanced AI systems<\/li>\n<li style=\"margin-bottom:6px;\">Important entities are exempt from mandatory assessment, but every other obligation has applied since October 2024<\/li>\n<li style=\"margin-bottom:6px;\">CyFun\u00ae 2025 adds Govern as a function and puts more weight on supply chain and OT; 2023 and 2025 run alongside each other until 18 April 2027<\/li>\n<li style=\"margin-bottom:6px;\">A CyFun\u00ae label is not the same thing as NIS2 compliance<\/li>\n<li style=\"margin-bottom:6px;\">The Commission proposed targeted amendments to the directive on 20 January 2026; these are not in force<\/li>\n<li>Incident reporting and management accountability are governance questions, not IT questions<\/li>\n<\/ul>\n<\/div>\n<p><!-- NIS2 in Belgium: the first deadline has passed, the hard one is still ahead --><\/p>\n<div id=\"nis2-in-belgium-the-first-deadline-has-passed-the-hard-one\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">NIS2 in Belgium: the first deadline has passed, the hard one is still ahead<\/h2>\n<p style=\"margin:0 0 12px;\">On 18 April 2026, essential entities had to show for the first time where they stood in their NIS2 journey. That milestone is behind us, the Centre for Cybersecurity Belgium is actively supervising, and last month its Inspection Service wrote to every essential entity about the next step: <strong>18 April 2027<\/strong>.<\/p>\n<p style=\"margin:0 0 12px;\">The gap between those two dates is wider than a year. The first asked for an undertaking \u2014 a self-assessment, a scope, a signed agreement with an assessment body. The second asks for a result.<\/p>\n<p style=\"margin:0;\"><strong>The first deadline asked for an intention. The second asks for a level.<\/strong><\/p>\n<\/div>\n<p><!-- Where Belgium stands today --><\/p>\n<div id=\"where-belgium-stands-today\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Where Belgium stands today<\/h2>\n<p style=\"margin:0 0 12px;\">Belgium was among the first member states to transpose NIS2, through the Act of 26 April 2024, in force since 18 October 2024, together with the Royal Decree of 9 June 2024. The framework has been filled in step by step ever since.<\/p>\n<p style=\"margin:0 0 12px;\">Registration through Safeonweb@Work is behind us. The first compliance milestone for essential entities, set at 18 April 2026, has passed: organisations that chose CyFun\u00ae had to produce at least a verification at Basic or Important level; those that chose ISO\/IEC 27001 had to submit their certification scope, Statement of Applicability and most recent internal audit report; those that opted for direct supervision had to provide a self-assessment with supporting evidence.<\/p>\n<p style=\"margin:0;\">Since 17 July 2026, operators of critical infrastructure are automatically classified as essential entities. The CCB is now in the enforcement phase.<\/p>\n<\/div>\n<p><!-- What the CCB's new communication actually asks for --><\/p>\n<div id=\"what-the-ccb-s-new-communication-actually-asks-for\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">What the CCB&#8217;s new communication actually asks for<\/h2>\n<p style=\"margin:0 0 12px;\">The CCB Inspection Service has sent a general communication and a request for information to all Belgian essential NIS2 entities, covering the mandatory conformity assessment due by 18 April 2027.<\/p>\n<p style=\"margin:0 0 12px;\">The substance: essential entities that cannot demonstrate by that date that they have implemented cybersecurity measures equivalent to CyFun\u00ae assurance level <strong>Essential<\/strong> must submit a <strong>remediation plan<\/strong>. That plan has two parts:<\/p>\n<ul style=\"padding-left:20px;margin:0 0 12px;\">\n<li style=\"margin-bottom:6px;\">evidence of compliance with measures at least equivalent to the <strong>Important<\/strong> level<\/li>\n<li>a substantiated description of the measures planned to reach Essential by <strong>18 April 2028<\/strong> at the latest<\/li>\n<\/ul>\n<p style=\"margin:0 0 12px;\">No remediation plan is required from entities that can demonstrate, on 18 April 2027, that they meet the Essential level \u2014 or substantiated measures at a lower level, based on their own risk analysis.<\/p>\n<p style=\"margin:0 0 12px;\">This approach applies to all three assessment routes: CyFun\u00ae certification or verification by an accredited conformity assessment body, ISO\/IEC 27001 certification by an accredited body, or a conformity assessment carried out by the Inspection Service itself. One detail matters: the communication changes nothing about the legal obligations or deadlines set out in the NIS2 Act and its Royal Decree. It makes explicit what the Inspection Service expects to see.<\/p>\n<p style=\"margin:0;\">The reasoning behind it is worth noting. The CCB points to the new threats associated with the rise of advanced artificial intelligence systems, and to the questions these raise around governance, risk assessment, supply chain security, monitoring and incident response. In other words: the framework is moving, and it is moving for reasons that were not on the table a year ago.<\/p>\n<\/div>\n<p><!-- Essential or important: the classification decides everything --><\/p>\n<div id=\"essential-or-important-the-classification-decides-everything\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Essential or important: the classification decides everything<\/h2>\n<p style=\"margin:0 0 12px;\">For many organisations this is still the first real question.<\/p>\n<p style=\"margin:0 0 12px;\">Essential entities \u2014 large organisations in sectors such as energy, transport, healthcare and digital infrastructure \u2014 are subject to mandatory, regular ex-ante supervision. They have to demonstrate their compliance actively, on the schedule described above.<\/p>\n<p style=\"margin:0 0 12px;\">Important entities are subject to ex-post supervision. They are not obliged to undergo a conformity assessment, though they may do so voluntarily, which gives them a presumption of conformity. Mind the trap: every other obligation \u2014 the security measures, the reporting duty, management accountability \u2014 applies in full, and has applied since 18 October 2024.<\/p>\n<p style=\"margin:0;\">Unsure about your classification? The CCB provides a scope test through Safeonweb@Work. Record the outcome together with the reasoning behind it. You will need that document later.<\/p>\n<\/div>\n<p><!-- CyFun\u00ae or ISO 27001: which route, and which version? --><\/p>\n<div id=\"cyfun-or-iso-27001-which-route-and-which-version\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">CyFun\u00ae or ISO 27001: which route, and which version?<\/h2>\n<p style=\"margin:0 0 12px;\">Roughly three quarters of registered entities chose CyFun\u00ae, the framework the CCB developed for the Belgian context. ISO\/IEC 27001 remains a fully valid alternative.<\/p>\n<p style=\"margin:0 0 12px;\">The difference lies in the starting point. CyFun\u00ae works through tiered assurance levels \u2014 Small, Basic, Important, Essential \u2014 and emphasises concrete, actionable measures with a measurable score per control. ISO\/IEC 27001 starts from building a complete information security management system, which is usually a broader and longer undertaking.<\/p>\n<p style=\"margin:0 0 12px;\">The Essential level is fundamentally different in nature from Basic or Important: it is a management system certification, with a documentation audit, an on-site implementation audit, annual surveillance audits and recertification. An organisation sitting at Basic today and aiming for Essential by April 2027 does not have an administrative problem. It has a project plan.<\/p>\n<p style=\"margin:0 0 12px;\">Since October 2025 there is a second choice to make on top of that: which <strong>version<\/strong> of CyFun\u00ae.<\/p>\n<p style=\"margin:0;\"><strong>A self-assessment shows what you intend to do. A certification shows what you have.<\/strong><\/p>\n<\/div>\n<p><!-- What changes in CyFun\u00ae 2025? --><\/p>\n<div id=\"what-changes-in-cyfun-2025\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">What changes in CyFun\u00ae 2025?<\/h2>\n<p style=\"margin:0 0 12px;\">The CCB released a new version of the framework in October 2025. It is aligned with the NIST Cybersecurity Framework 2.0 and with European legislation, NIS2 first among them, and more than eighty experts and organisations reviewed the draft. The substantive shifts:<\/p>\n<ul style=\"padding-left:20px;margin:0 0 12px;\">\n<li style=\"margin-bottom:6px;\"><strong>Governance becomes a function in its own right.<\/strong> CyFun\u00ae 2023 followed the five NIST functions Identify, Protect, Detect, Respond and Recover. CyFun\u00ae 2025 adds Govern, and governance measures appear from the Important level upwards. That connects directly to the management accountability set out in the Belgian NIS2 Act.<\/li>\n<li style=\"margin-bottom:6px;\"><strong>The supply chain is given explicit space<\/strong> in the controls: suppliers and partners.<\/li>\n<li style=\"margin-bottom:6px;\"><strong>OT security is addressed explicitly<\/strong>, which matters for industrial and healthcare environments.<\/li>\n<li><strong>The controls are more clearly worded<\/strong>, with fuller guidance on interpretation and implementation.<\/li>\n<\/ul>\n<p style=\"margin:0 0 12px;\">The timing is the part to remember. CyFun\u00ae 2023 and CyFun\u00ae 2025 run alongside each other until <strong>18 April 2027<\/strong>; until that date you choose which version your verification or certification is based on. Statements and certificates based on CyFun\u00ae 2023 remain valid until 18 April 2028 at the latest. After that, only CyFun\u00ae 2025 is accepted.<\/p>\n<p style=\"margin:0 0 12px;\">That is the same date as the compliance milestone above. On 18 April 2027, two questions therefore meet: have you reached your target level, and which version of the framework are you being assessed against?<\/p>\n<p style=\"margin:0;\">One nuance that regularly trips organisations up: holding a CyFun\u00ae label does not automatically mean you are NIS2 compliant. Obligations such as the 24-hour, 72-hour and one-month reporting deadlines still have to be covered in your own procedures.<\/p>\n<\/div>\n<p><!-- Incident reporting is a governance question, not a technical one --><\/p>\n<div id=\"incident-reporting-is-a-governance-question-not-a-technical\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Incident reporting is a governance question, not a technical one<\/h2>\n<p style=\"margin:0 0 12px;\">The timeframes are well known: an early warning within 24 hours, a notification within 72 hours, a final report within one month.<\/p>\n<p style=\"margin:0 0 12px;\">What goes wrong in practice is rarely the technology. It is the question of who, within those first 24 hours, has the authority to determine that this is a reportable incident \u2014 and to make that call on a Saturday night, on incomplete information, while the response team is still working out what actually happened.<\/p>\n<p style=\"margin:0;\">The same applies to management accountability. The management body has to approve the cybersecurity measures and follow the required training, and carries personal responsibility for doing so. That is not a formality you tick off in a meeting. It is why a NIS2 programme starts in the boardroom rather than the server room.<\/p>\n<\/div>\n<p><!-- Why this is legal and technical work at the same time --><\/p>\n<div id=\"why-this-is-legal-and-technical-work-at-the-same-time\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Why this is legal and technical work at the same time<\/h2>\n<p style=\"margin:0 0 12px;\">The ten measures from the directive read like a technical list: risk analysis, incident handling, continuity and backups, supply chain, secure development, measuring effectiveness, cyber hygiene and training, cryptography, access control, multi-factor authentication.<\/p>\n<p style=\"margin:0 0 12px;\">But every one of them raises a legal question. Which level is appropriate to our risks, and how do we defend that choice? What do we impose contractually on suppliers, and what happens when they refuse? What does &#8220;secure development&#8221; mean for software we buy rather than build?<\/p>\n<p style=\"margin:0 0 12px;\">The reverse is equally true: legal analysis stalls without a technical picture. You cannot determine an appropriate level without knowing which systems are running and how they connect.<\/p>\n<p style=\"margin:0;\">That is why this course puts two trainers in the room together: a lawyer specialising in cybersecurity law and a practitioner who carries out implementations. Legal question, technical answer, and the other way round.<\/p>\n<\/div>\n<p><!-- And meanwhile the European framework is moving too --><\/p>\n<div id=\"and-meanwhile-the-european-framework-is-moving-too\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">And meanwhile the European framework is moving too<\/h2>\n<p style=\"margin:0 0 12px;\">While Belgium enforces its law, the directive itself is being reopened.<\/p>\n<p style=\"margin:0 0 12px;\">On <strong>20 January 2026<\/strong> the European Commission published a proposal for targeted amendments to the NIS2 Directive, alongside a proposal to revise the Cybersecurity Act. That proposal \u2014 COM(2026) 13, procedure 2026\/0012(COD) \u2014 sets out to clarify the scope, simplify jurisdictional rules, streamline the collection of data on ransomware and strengthen cross-border supervision, with a broader coordinating role for ENISA. The obligation to appoint an EU representative would also be extended to any essential or important entity not established in the Union but offering services within it. The Commission estimates it would ease compliance for some 28,700 companies.<\/p>\n<p style=\"margin:0 0 12px;\">Separately, the Digital Omnibus package touches incident reporting: a single EU reporting portal for notifications under Articles 23 and 30, with ENISA operating it as a technical service provider and forwarding notifications to the competent national addressees. The thresholds, deadlines and addressees themselves stay as they are.<\/p>\n<p style=\"margin:0 0 12px;\">Both texts are proposals. They are going through the ordinary legislative procedure and are not law yet. But anyone building an implementation plan today is better off doing so knowing that the scope and the reporting route may still shift.<\/p>\n<p style=\"margin:0;\">At the same time ENISA continues to fill in the framework, and the NIS Cooperation Group publishes reference documents on the security measures for entities falling under NIS2. That is not legislation, but it is what supervisors look at when they judge whether your measures are appropriate.<\/p>\n<\/div>\n<p><!-- Where to start --><\/p>\n<div id=\"where-to-start\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Where to start<\/h2>\n<ol style=\"padding-left:20px;margin:0;\">\n<li style=\"margin-bottom:10px;\"><strong>Confirm your classification<\/strong> \u2014 essential, important or out of scope \u2014 and record the reasoning in writing.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Check your registration<\/strong> through Safeonweb@Work. A late registration beats a recorded absence of one.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Set your target level<\/strong> and compare it with where you are today. The gap is your project plan, not an action item.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Choose your CyFun\u00ae version.<\/strong> Until 18 April 2027 you can still opt for 2023 or 2025; after that you cannot. Weigh up whether to finish an ongoing trajectory on 2023 or switch straight away.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Assign the reporting mandate<\/strong>: who decides within 24 hours, and who stands in for that person.<\/li>\n<li style=\"margin-bottom:10px;\"><strong>Put management accountability on the board&#8217;s agenda<\/strong>, including the training obligation.<\/li>\n<li><strong>Document your evidence measure by measure.<\/strong> In an assessment, what counts is not what you do but what you can show.<\/li>\n<\/ol>\n<\/div>\n<p><!-- From legal text to a working implementation plan in two days --><\/p>\n<div id=\"from-legal-text-to-a-working-implementation-plan-in-two-days\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">From legal text to a working implementation plan in two days<\/h2>\n<p style=\"margin:0 0 12px;\"><strong><a href=\"https:\/\/www.dp-institute.eu\/en\/courses\/nis2-lead-implementer-belgium-legislation-and-practice\/\" style=\"color:#1d4ed8;\">NIS2 Lead Implementer Belgium: Legislation and Practice<\/a><\/strong> starts from the legal framework every time and then moves to practical application. Day one covers the legal framework: the basic concepts, an in-depth analysis of the NIS2 obligations, the Belgian transposition (registration, cybersecurity measures, training, incident reporting, conformity assessment, supervision) and what all of that means for your internal procedures and your supplier contracts. Day two is implementation: hands-on sessions with the CyFun\u00ae framework using realistic scenarios, and building strategies and action plans for your own organisation.<\/p>\n<p style=\"margin:0 0 12px;\">The course is taught by <strong>Chris De Vuyst<\/strong> and <strong>Bernd Fiten<\/strong>: a lawyer specialising in cybersecurity law and a hands-on cybersecurity practitioner, in the room together.<\/p>\n<p style=\"margin:0;\">This version of the course has been updated with the most recent documentation from ENISA and the NIS Cooperation Group on implementing NIS2, with the European Commission&#8217;s proposal to adapt the scope of the directive, and with fuller guidance and exercises on <strong>CyFun\u00ae 2025<\/strong>, the new version of the framework the CCB recommends for implementing the Belgian NIS2 Act.<\/p>\n<\/div>\n<p><!-- CTA --><\/p>\n<div style=\"background:#fff7ed;border:1px solid #fdba74;border-left:5px solid #ea580c;border-radius:12px;padding:20px 22px;margin-bottom:25px;\">\n<p style=\"margin:0 0 12px;\"><strong>14\u201315 December 2026 \u2014 Park Inn by Radisson Diegem, in English.<\/strong><br \/>Also available in Dutch (20\u201321 October 2026, Antwerp) and French (12\u201313 November 2026, Nivelles-Sud).<br \/>20 participants on average, 24 maximum.<br \/>\u20ac1,495 excl. VAT, \u20ac1,195 for public institutions, including lunch, a printed syllabus and digital learning material.<br \/>No prior knowledge required.<\/p>\n<p style=\"margin:0 0 18px;\">Worth 30 CPE credits, recognised by the Institute for Company Lawyers (IJE-IBJ) and the FSMA, and eligible for Flemish training leave and Brussels paid educational leave.<br \/>SME portfolio funding available under the cybersecurity theme.<\/p>\n<p><a href=\"https:\/\/www.dp-institute.eu\/en\/courses\/nis2-lead-implementer-belgium-legislation-and-practice\/\" style=\"display:inline-block;background:#1d4ed8;color:#ffffff;text-decoration:none;font-weight:600;line-height:1.4;padding:12px 22px;border-radius:8px;\">View the full programme and register today<\/a>\n<\/div>\n<p style=\"margin:0 0 25px;font-size:14px;line-height:1.6;color:#475569;\"><em>The CyFun\u00ae framework is owned by the Centre for Cybersecurity Belgium and CyFun\u00ae is a registered trademark of the CCB. The framework and its conformity assessment scheme are available at cyfun.eu, their only authentic source. DPI&#8217;s services may contribute to third-party assessments but never replace an accredited third-party assessment.<\/em><\/p>\n<p><!-- Sources and further reading --><\/p>\n<div id=\"sources-and-further-reading\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Sources and further reading<\/h2>\n<ul style=\"padding-left:20px;margin:0;\">\n<li style=\"margin-bottom:6px;\"><a href=\"https:\/\/ccb.belgium.be\/nl\/news\/nieuwe-mededeling-voor-essentiele-nis2-entiteiten\" target=\"_blank\" rel=\"noopener nofollow\" style=\"color:#1d4ed8;\">Centre for Cybersecurity Belgium \u2014 communication to essential NIS2 entities<\/a><\/li>\n<li style=\"margin-bottom:6px;\"><a href=\"https:\/\/atwork.safeonweb.be\" target=\"_blank\" rel=\"noopener nofollow\" style=\"color:#1d4ed8;\">Safeonweb@Work<\/a> \u2014 registration, scope test and FAQ<\/li>\n<li style=\"margin-bottom:6px;\"><a href=\"https:\/\/cyfun.eu\/en\/cyberfundamentals-framework-2025\" target=\"_blank\" rel=\"noopener nofollow\" style=\"color:#1d4ed8;\">CyberFundamentals Framework 2025<\/a> \u2014 CCB, including a comparison of the key measures in CyFun\u00ae 2023 and 2025<\/li>\n<li style=\"margin-bottom:6px;\"><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/proposal-directive-regards-simplification-measures-and-alignment-cybersecurity-act\" target=\"_blank\" rel=\"noopener nofollow\" style=\"color:#1d4ed8;\">Proposal COM(2026) 13 amending the NIS2 Directive<\/a> \u2014 European Commission<\/li>\n<li style=\"margin-bottom:6px;\"><a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/oj\" target=\"_blank\" rel=\"noopener nofollow\" style=\"color:#1d4ed8;\">Directive (EU) 2022\/2555 (NIS2)<\/a> \u2014 EUR-Lex<\/li>\n<li>Act of 26 April 2024 (Belgian NIS2 Act) \u2014 Justel<\/li>\n<\/ul>\n<\/div>\n<p><!-- Frequently asked questions (schema.org FAQPage) --><\/p>\n<div id=\"frequently-asked-questions\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\" style=\"background:white;border:1px solid #e5e7eb;border-radius:12px;padding:25px;margin-bottom:25px;box-shadow:0 3px 10px rgba(0,0,0,0.05);\">\n<h2 style=\"color:#0f172a;margin:0 0 10px;\">Frequently asked questions<\/h2>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:8px 0 18px;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">We are an important entity. Do we need a conformity assessment?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">Not as an obligation. Important entities are supervised after the fact and may undergo an assessment voluntarily. Every other obligation does apply, and has done since October 2024.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">What exactly is a remediation plan?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">The plan essential entities submit if they cannot demonstrate the Essential level on 18 April 2027. It contains evidence of compliance at least equivalent to the Important level, plus a substantiated plan to reach Essential by 18 April 2028.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Does the CCB communication change the legal deadlines?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">No. The Inspection Service sets out what it expects to see; the obligations and timeframes in the NIS2 Act and the Royal Decree are unchanged.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Do we have to move to CyFun\u00ae 2025?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">Not immediately. CyFun\u00ae 2023 and CyFun\u00ae 2025 run alongside each other until 18 April 2027, and until then you choose which version your assessment is based on. Statements and certificates based on the 2023 version stay valid until 18 April 2028 at the latest; after that only the 2025 version is accepted.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Does a CyFun\u00ae label mean we are NIS2 compliant?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">No. The label shows that you have implemented the measures of a given assurance level. Specific obligations, such as the reporting deadlines, still have to be covered in your own procedures.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Is the directive itself still going to change?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">The European Commission published a proposal for targeted amendments on 20 January 2026, covering among other things the scope, the jurisdictional rules and the reporting route. It is a proposal, not law yet.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">How does NIS2 relate to the Cyber Resilience Act?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">NIS2 looks at the cybersecurity of your organisation. The CRA looks at the properties of your products. They overlap without replacing each other. If you place products with digital elements on the market yourself, you have both files open. See also <a href=\"https:\/\/www.dp-institute.eu\/en\/courses\/cra-lead-implementer\/\" style=\"color:#1d4ed8;\">CRA Lead Implementer<\/a>.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Is prior knowledge required?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">No. The course is built for a range of profiles, from organisations just starting out to teams already well advanced and looking to refine their approach.<\/p>\n<\/div>\n<\/div>\n<div itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\" style=\"padding:18px 0 0;border-top:1px solid #e5e7eb;\">\n<h3 itemprop=\"name\" style=\"color:#0f172a;margin:0 0 10px;\">Do I receive a certificate?<\/h3>\n<div itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<p itemprop=\"text\" style=\"margin:0;\">You receive a certificate of completion after the two days, together with a concrete action plan and the tools to carry on straight away.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Executive summary The first compliance milestone of 18 April 2026 has passed; the CCB is actively enforcing By 18 April 2027, essential entities must demonstrate the Essential level or submit a remediation plan That plan contains evidence at the Important level plus a plan to reach Essential by 18 April 2028 The CCB explicitly cites [&hellip;]<\/p>\n","protected":false},"author":45,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[619,37],"tags":[],"class_list":["post-20492","post","type-post","status-publish","format-standard","hentry","category-ciso","category-uncategorized"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/20492","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/users\/45"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/comments?post=20492"}],"version-history":[{"count":1,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/20492\/revisions"}],"predecessor-version":[{"id":20493,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/posts\/20492\/revisions\/20493"}],"wp:attachment":[{"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/media?parent=20492"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/categories?post=20492"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dp-institute.eu\/en\/wp-json\/wp\/v2\/tags?post=20492"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}