NIS2 applies to your organisation if you operate in one of 18 listed sectors and employ at least 50 FTEs or exceed €10 million in annual turnover or balance-sheet total — and in Belgium the law has been fully in force since 18 October 2024. Some entities fall under it regardless of size, and small subsidiaries of large groups are often in scope without realising it. This self-assessment settles the question in about ten minutes: out of scope, important entity, or essential entity.
Key takeaways
- The Belgian NIS2 law of 26 April 2024 took effect on 18 October 2024; registration deadlines (18 December 2024 and 18 March 2025) have already passed, and the CCB actively cross-checks non-registered organisations against KBO data.
- Scope is decided by two tests combined: your sector (Annex I high-criticality or Annex II other critical) and your size (50+ FTEs or over €10 million turnover/balance total).
- DNS providers, TLD registries, qualified trust services, public telecom providers and public administrations are in scope at any size — no threshold applies.
- Group structures count: a 20-person Belgian subsidiary of a 500-person group is in scope unless its IT and services are demonstrably independent from the group.
- Essential entities face proactive audits and fines up to €10 million or 2% of worldwide turnover, and must file a verified CyberFundamentals assessment by 18 April 2026; important entities face reactive supervision and fines up to €7 million or 1.4%.
The two tests that decide everything
Belgian NIS2 scope rests on the size-cap rule from EU Recommendation 2003/361/EC combined with the sector annexes. Size first: you count as at least medium-sized once you employ 50 FTEs or exceed €10 million in annual turnover or balance-sheet total — one criterion suffices. Then sector: Annex I lists the high-criticality sectors, Annex II the other critical ones.
| Annex | Sectors | Medium-sized (50–249 FTE) | Large (250+ FTE or >€50M turnover) |
|---|---|---|---|
| Annex I — high criticality | Energy, transport, banking, financial market infrastructure, healthcare (incl. pharma and medical-device R&D), drinking water, waste water, digital infrastructure, B2B ICT management (MSPs/MSSPs), public administration, space | Important entity | Essential entity |
| Annex II — other critical | Postal and courier services, waste management, chemicals, food production and distribution, manufacturing (medical devices, electronics, machinery, vehicles), digital providers (marketplaces, search engines, social platforms), research organisations | Important entity | Important entity |
Note how wide “manufacturing” and “food” reach: a machine builder with 60 employees or a food wholesaler with €12 million turnover is an important entity, whether or not anyone has told them.
Who is in scope at any size?
Article 3 §3 of the Belgian law pulls specific categories in regardless of headcount or revenue: providers of public electronic communications networks or services, DNS service providers, TLD name registries, qualified trust service providers, entities designated as sole providers of a critical service, entities whose disruption could significantly affect public safety or health, and central and regional public administrations. A five-person DNS provider is in scope; a five-person bakery is not.
The ten-minute decision tree
- Special category? DNS, TLD registry, qualified trust services, public telecom, or a central/regional government body → in scope regardless of size; go to step 5. Otherwise continue.
- Sector check. Active in an Annex I or Annex II sector? No → directly out of scope (but check step 6). Yes → continue.
- Standalone size check. At least 50 FTEs, or more than €10 million turnover or balance total? Yes → in scope; go to step 5. No → continue.
- Group check. Part of a group (over 50% linked, with partner holdings from 25% counting proportionally) that aggregates above the threshold? If yes: is your network and IT infrastructure fully operationally and technically independent from the group? Independent → out of scope on a standalone basis (Article 3 §2, read with Recital 16 — the CCB accepts this if the autonomy is demonstrable). Not independent → in scope via consolidation.
- Category. Large enterprise (250+ FTEs or over €50 million turnover / €43 million balance) in an Annex I sector → essential entity. Every other in-scope case → important entity.
- Supply-chain check. Out of scope but selling software, ICT services or critical components to NIS2 entities? Article 21(2)(d) makes their obligations contractually yours — customers will demand demonstrable security, typically a CyFun Basic label, as covered in the NIS2 supply-chain guide.
The CCB offers an official interactive version of this test on Safeonweb@work (atwork.safeonweb.be/nis2), using NACE codes, headcount and turnover.
What does your category mean in practice?
| Parameter | Essential entity | Important entity |
|---|---|---|
| Supervision | Ex-ante: proactive, scheduled CCB audits and inspections | Ex-post: reactive, after an incident or complaint |
| Maximum fine | €10,000,000 or 2% of worldwide turnover | €7,000,000 or 1.4% of worldwide turnover |
| Board duties (Art. 20) | Mandatory cybersecurity training, formal approval of risk measures, active oversight; personal liability, with temporary management bans possible for essential entities | |
| Expected CyFun level | CyFun Essential (217 controls) or ISO/IEC 27001, certified by an accredited CAB | CyFun Important (132 controls) or Basic (34 controls), demonstrable on inspection |
| Hard deadline | Verified assessment (min. Basic/Important) filed by 18 April 2026; full Essential certification by 18 April 2027 | No fixed audit date, but must be compliant when checked |
The reporting duty applies to both categories since 18 October 2024: early warning to the CCB within 24 hours of a significant incident, detailed notification within 72 hours. The fine mechanics are unpacked in NIS2 fines in Belgium, and the level-by-level control work in CyFun Basic to Important.
Where does the timeline stand as of August 2026?
- 18 October 2024 — law in force; 24h/72h incident reporting active.
- 18 December 2024 — registration deadline for digital infrastructure, telecom, MSPs (passed).
- 18 March 2025 — general registration deadline on Safeonweb@work (passed). The CCB runs automated KBO cross-checks and approaches non-registered organisations, which risk administrative sanctions.
- 18 April 2026 — essential entities must have filed their first CAB-verified CyFun assessment (passed; the CCB has been running active audits since early 2026).
- 18 April 2027 — full CyFun Essential or ISO 27001 certification for essential entities.
- 1 January 2030 — non-designated local governments must reach CyFun Basic.
Neighbouring countries lag Belgium: the Dutch Cyberbeveiligingswet was approved by the Tweede Kamer on 15 April 2026 with intended entry into force on 1 July 2026, and France enforces its transposition through ANSSI with registration via MonEspaceNIS2. A Belgian entity with Dutch or French branches should track three regimes, not one.
Four misconceptions that keep costing companies
- “Under 50 employees means exempt.” Not for DNS/telecom/trust-service providers or public bodies, not for consolidated group subsidiaries, and not commercially: the Article 21(2)(d) chain effect reaches small suppliers through contracts.
- “NIS2 is IT-sector legislation.” It spans 18 sectors; food, chemicals, waste and machine building are as much in scope as software.
- “We registered, so we’re compliant.” Registration is step one. Compliance means risk measures, the 24h/72h reporting process, trained directors and a demonstrable CyFun level.
- “Important entities can wait for an inspection.” The obligations have applied since day one; an incident triggers scrutiny at exactly the moment you cannot fix the past.
From scope answer to first measures
Whatever your category, the technical core is the same: access control with MFA, network segmentation, incident detection and logging. That is why the scope answer leads directly to an architecture question — these are precisely the measures a single SASE platform delivers together, as mapped control-by-control in NIS2 security measures translated to SASE controls. For an EU mid-market team, an EU-sovereign platform like Jimber covers the access, segmentation and logging measures from one console — with the audit trail your CyFun assessor will ask for, and without adding a US jurisdiction question to your compliance file. Know your category, then close the gap: book a demo to see how much of your NIS2 control set one platform covers, or start from the NIS2 compliance checklist.
Frequently asked questions
Our Belgian company has 20 employees but our international group has 500. Are we in scope?
In principle yes, because figures of linked enterprises (over 50% ownership) are aggregated. You only escape on a standalone basis if you can demonstrate to the CCB that your network, IT systems and service delivery are fully operationally and technically independent from the group.
Does NIS2 apply to SaaS companies?
SaaS providers qualify as digital providers under Annex II once they cross 50 FTEs or €10 million. Below that, B2B customers that are themselves in scope will still demand NIS2-grade security contractually via Article 21(2)(d).
Is registering on Safeonweb@work enough to be compliant?
No. Registration is an administrative first step. The law also requires implemented risk-management measures, a working 24-hour/72-hour incident-reporting process, trained board members and a demonstrable CyberFundamentals level.
What personal risks do directors run under Article 20?
Board members must follow cybersecurity training, formally approve risk measures and supervise their execution. In cases of serious negligence at essential entities, the CCB can impose a temporary ban on exercising management functions, on top of the organisation’s fines.
Who performs the audit that essential entities needed by 18 April 2026?
A Conformity Assessment Body (CAB) accredited by BELAC, or an accredited ISO 27001 certification body. The verified assessment had to cover at least the CyFun Basic or Important level, with full Essential certification due by 18 April 2027.
How does NIS2 incident reporting differ from GDPR?
NIS2 requires an early warning to the CCB within 24 hours and a detailed notification within 72 hours for significant incidents, regardless of whether personal data is involved. GDPR separately requires notifying the data protection authority within 72 hours only when personal data is breached. One incident can trigger both.
Is a CyFun Basic label enough to satisfy the whole law?
No. Basic covers the 34 technical baseline controls, but the law also demands governance: incident-reporting readiness, supply-chain clauses, board training and, depending on your category, a higher assurance level with external verification.