NIS2 is here. Are you ready?
In Belgium, NIS2 has triggered an essential wave of self-assessment and external audits. But once those reports are completed and the gaps identified, the real question begins: how do we sustain security in practice?
Europe's cybercrime is targeting NIS2 essential entities.
53.7%
of cyber incidents in Europe affected essential entities under NIS2 (source: ENISA)
60%
of intrusions start with phishing; AI-supported identity compromise dominates
81.1%
ransomware still dominates
cybercrime activity against EU organisations
The 7 steps to NIS2 compliance in Belgium.
Each step reinforces the “assume breach” mindset: understanding that cybersecurity resilience under NIS2 is not a one-time exercise but a continuous, auditable commitment to preparedness.
Consult the official CCB NIS2 portal to verify your classification and understand which authority supervises your sector. If you are part of another organisation’s supply chain, the CCB recommends aligning at least with the Basic level of the CyberFundamentals (CyFun®) framework.
This ensures your organisation is officially recognised and can receive updates, guidance, and instructions from the authorities. It is also the starting point for meeting your reporting obligations in case of a cyber incident. You can complete this process via the official CCB platform.
From 18 October 2024 onward, all in-scope organisations must notify the CCB within 24–72 hours of any significant cybersecurity incident. This requires not only knowing how to report via the Safeonweb notification platform, but also having a tested incident response plan.
Organisations using the Belgian CyFun® framework should define which assurance level applies to them: Basic, Important, or Essential. This level determines the depth of controls and the form of evidence required for compliance or certification.
NIS2 explicitly requires that management be capable of making informed cybersecurity decisions. Board and leadership teams should have completed cybersecurity and risk management training by April 2025 at the latest. In parallel, employee awareness remains a core control under NIS2’s risk management measures.
Once the scope and level are defined, organisations must conduct a gap analysis against CyFun® (or ISO/IEC 27001) and implement the required controls. This process should be structured, gradual, and evidence-based, ensuring documentation and review at each stage of implementation.
Essential entities are required to undergo regular third-party assessments, ideally through CyFun® certification by an accredited body. The initial assurance level must be achieved by April 2026, with full certification required by April 2027.
Important entities are encouraged to follow the same path, as certification provides clear proof of compliance and strengthens trust with clients and regulators.
- Stay compliant with the NIST framework
- Stay one step ahead of threat actors
- Get a free consultation
- Stay compliant with the NIST framework
- Stay one step ahead of threat actors
- Get a free consultation
Here is what experts across industries say about NIS2.
Partner Digital Regulations
Chief Global Strategy Officer, ISACA
Managing Director, Applied Risk
Expert NIS2 Directive
Enterprise-grade, made for the mid-market.
This is tailored cybersecurity that meets the scale and complexity of mid-market organisations without the overhead of enterprise-only tools. Simple and to the point. AI-driven detection and expert-led response prevent downtime, protect revenue, and safeguard operations while helping you prepare for the unexpected.
Protect business continuity
- Best-of-breed EDR and ITDR
- 24/7 in-house SOC
- 24/7 incident response
Build future readiness
- Annual cyber reviews
- Attack surface deep dives
- Proactive vulnerability and threat hunting
Simplify cybersecurity
- All-in-one, all-you-need package
- Onboarding within hours
- Built for your scale and risk profile
Accelerate compliance
- Streamlined audits and regulatory alignment
- Competitive cyber insurance premiums
- Frictionless insurance qualification and renewals
Discover why companies choose Eye Security.
Protect yourself against digital threats with Europe's leading Open XDR solution. Try a demo to see how Eye Security compares to your existing solution.
- Protect your business 24/7
- Prevent ransomware & data breaches
- Respond to attacks within minutes
- Mitigate financial losses with cyber insurance, advised by brokers
Trusted by European companies: