NIS2 and CyFun
NIS2 and CyFun for SMEs in Belgium
The NIS2 law has applied in Belgium since 18 October 2024. Many business leaders still wonder whether it applies to them and what they must do by when. Companies outside the law feel the effects too: customers that do fall under NIS2 must secure their supply chain and set stricter requirements for their suppliers.
Schedule an introductory meetingHere you can read whether NIS2 applies to you, which obligations and deadlines apply, how CyberFundamentals (CyFun®) works and how JViT guides you. This information is not legal advice; only the Belgian Official Gazette is legally binding.
Does your company fall under NIS2?
The Centre for Cybersecurity Belgium (CCB) offers a scope test on Safeonweb@Work. For a first assessment, answer these questions in order.
- Do you operate in a sector from Annex I or II of the law? Annex I (high criticality): energy, transport, banking, financial market infrastructure, health care, drinking water, waste water, digital infrastructure, business-to-business ICT service management (such as managed service providers), public administration (public administration entities that depend on the Federal State, identified public administration entities of the federated entities, the emergency zones and the Brussels-Capital Fire and Emergency Medical Service) and space. Annex II (other critical sectors): postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles and other transport equipment), digital providers and research. Neither? Go to question 5.
- Are you at least a medium-sized enterprise? You are from 50 employees, or if both annual turnover and balance sheet total exceed 10 million euros. You are large from 250 employees, or with more than 50 million euros in turnover and 43 million euros in balance sheet total. Partner and linked enterprises count as well, but the CCB may take into account the degree of independence of the entity from those enterprises (art. 3, § 2).
- Do you fall under it regardless of your size? This applies to, among others, providers of public electronic communications, trust service providers, DNS service providers, top-level domain name registries, entities providing domain name registration services, certain public services, entities identified as critical entities within the meaning of the law of 19 December 2025 on the resilience of critical entities, and organisations designated by the CCB itself.
- Are you an essential or an important entity? Large enterprises from Annex I are essential entities. Medium-sized enterprises from Annex I and medium-sized and large enterprises from Annex II are important entities. In addition, under art. 9 the following are always essential entities: qualified trust service providers, top-level domain name registries and DNS service providers, regardless of their size; providers of public electronic communications networks or services that are at least medium-sized; public administration entities that depend on the Federal State; critical entities; and entities that the CCB identifies as essential. Essential entities are subject to mandatory ex-ante supervision, important entities to ex-post supervision.
- You do not fall under it, but your customers do? Then you have no legal NIS2 obligations of your own, but you do face contractual requirements, questionnaires and audits from your customers. The CCB advises organisations that may be part of the supply chain of an NIS2 entity to comply at least with the measures of the CyberFundamentals (CyFun®) Framework level Basic.
What does NIS2 require in practice?
Registration. Essential and important entities register with the CCB via Safeonweb@Work, within five months of the entry into force of the law or of identification (art. 13, § 1). After the entry into force, that deadline expired on 18 March 2025, and for digital service providers already on 18 December 2024. You report changes within two weeks.
Risk management measures. You take appropriate and proportionate technical, operational and organisational measures. At a minimum, the law lists risk analysis and security policies, incident handling, backup and business continuity, supply chain security, cyber hygiene and training, encryption, access management and multi-factor authentication, among others.
Incident reporting. You report a significant incident to the CCB via notif.safeonweb.be:
- early warning within 24 hours of becoming aware of the incident;
- incident notification within 72 hours (24 hours for trust service providers);
- final report no later than one month after the incident notification, or a progress report if the incident is still ongoing by then.
The CCB may also request an intermediate report. You will only meet those deadlines with a reporting procedure rehearsed in advance.
Responsibility of the board. The management body approves the measures and oversees their implementation. The members of the management bodies of essential and important entities follow training (art. 31, § 2), so that they can assess the risks. Directors can be held liable, and in case of persistent shortcomings a temporary ban on managerial functions is possible.
Sanctions.
| Category | Maximum administrative fine |
|---|---|
| Essential entity | 10 million euros or 2% of worldwide annual turnover (whichever is higher) |
| Important entity | 7 million euros or 1.4% of worldwide annual turnover (whichever is higher) |
In case of repetition within three years, the fine can double.
CyFun: Basic, Important and Essential
CyberFundamentals (CyFun®) is the CCB framework for putting the NIS2 measures into practice, aligned with, among others, the NIST Cybersecurity Framework 2.0. Confirmed CyFun conformity at the right level gives a presumption of conformity with the NIS2 measures. Besides the entry level Small, intended for a first self-assessment, CyFun has three levels:
| Level | Protects against | Typical for | Assessment |
|---|---|---|---|
| Basic | Common risks, with standard measures for every business | Suppliers of NIS2 customers, important entities with limited risk | Verification |
| Important | Targeted attacks by actors with common skills and resources | Important and many essential entities | Verification |
| Essential | Advanced attacks by actors with extensive skills and resources | Essential entities with a high risk profile | Certification |
Which level suits you? That is determined by the CCB risk assessment tool (CyFun Selection Tool). For essential entities, the final level is Important or Essential.
CyFun 2023 or 2025? The CCB published a new version in 2025, with more attention to the supply chain, operational technology (OT) and auditability. CyFun® 2023 and CyFun® 2025 are both available during a transition period; after that, only CyFun® 2025 is accepted. If you start now, it is best to choose CyFun 2025 straight away.
ISO/IEC 27001 and the assessment. Essential entities may also use ISO/IEC 27001 if the scope covers the NIS2-relevant systems. The assessment is carried out by a conformity assessment body (CAB), accredited by BELAC and recognised by the CCB. It is mandatory for essential entities (or they choose a CCB inspection) and voluntary for important entities. JViT is not a CAB: we prepare and guide you.
Timeline
| Date | What |
|---|---|
| 17 May 2024 | NIS2 law of 26 April 2024 published in the Belgian Official Gazette |
| 9 June 2024 | Royal decree implementing the NIS2 law |
| 18 October 2024 | Entry into force; incident reporting obligation starts |
| 18 December 2024 | Registration of digital service providers |
| 18 March 2025 | Registration of other entities |
| 20 January 2026 | European Commission proposes targeted NIS2 amendments: proposal, not yet adopted (as of September 2026) |
| 18 April 2026 | Essential entities: first conformity step (CyFun verification Basic or Important, ISO 27001 scope and statement of applicability, or request for inspection) |
| 18 April 2027 | Essential entities: final level (CyFun Important or Essential, or ISO 27001 certificate) |
Today essential entities are working towards 18 April 2027. For now, the European proposal changes nothing in the Belgian law.
How JViT guides you
JViT is a security-first partner for managed IT and cybersecurity from Zonhoven, guided by our CISO. We do not only write policy, we also implement the measures, with one team and one point of contact.
- Baseline and gap analysis. With a NIS2 audit we determine whether and how the law applies to you and which CyFun level fits. You receive a prioritised roadmap with the effort per step.
- CyFun or ISO 27001 project. We develop policies, procedures and evidence and carry out the self-assessment together with you.
- CISO as a Service. With CISO as a Service you get an experienced CISO without a full-time hire, for risk and compliance management, security policy, incident response and awareness, with reporting that allows your board to approve and follow up measures.
- Technical measures. Ethical hacking with retest, vulnerability detection, zero-trust access, detection and response via SOC and SIEM, recovery procedures and exercises, the JViT Managed Phishing Awareness Platform and practical training for your employees.
- Preparation for the conformity assessment. We compile your audit file, check the evidence in advance, guide you during the assessment and follow up on the findings.
SME portfolio. Since 1 February 2026, advice on cybersecurity qualifies for the SME portfolio (kmo-portefeuille) (45% small, 35% medium-sized enterprises). See SME portfolio.
Frequently asked questions
Our company has fewer than 50 employees. Does NIS2 apply to us?
Usually not directly, unless you belong to a category that counts regardless of size, such as trust service providers or DNS service providers. Still, many small companies feel the effects. Customers that do fall under NIS2 must secure their supply chain and ask suppliers for demonstrable measures. The CCB advises organisations that may be part of the supply chain of an NIS2 entity to comply at least with the measures of the CyberFundamentals (CyFun®) Framework level Basic.
Is CyFun mandatory?
No. NIS2 requires appropriate measures, not a specific framework. CyFun is, however, the CCB reference framework, and confirmed CyFun conformity gives a presumption of conformity. Essential entities have their measures assessed via CyFun, ISO/IEC 27001 or a CCB inspection. For important entities and suppliers, CyFun is a practical way to show that the basics are in order.
Can we use ISO 27001 instead of CyFun?
Yes. Essential entities can use an ISO/IEC 27001 certificate, provided that its scope covers the network and information systems relevant to NIS2. The CCB reviews that scope and the statement of applicability. If you already have an ISO certificate, your assessment body can verify the scope so that you also obtain a CyFun label.
How quickly do we have to report an incident?
You report a significant incident to the CCB via notif.safeonweb.be. Within 24 hours of becoming aware of it, you send an early warning. The incident notification follows within 72 hours, within 24 hours for trust service providers. You submit the final report no later than one month after the incident notification. So define roles and contact details in advance.
Can JViT certify us?
No. A CyFun verification or certification and an ISO 27001 certificate are issued by an independent conformity assessment body accredited by BELAC and recognised by the CCB. JViT prepares you for it with a baseline assessment, a roadmap, policies and procedures, technical measures and a complete audit file, and guides you during and after the assessment.
Are directors personally responsible?
The management body must approve the cybersecurity measures, oversee their implementation and follow training to be able to assess the risks. Directors can be held liable if the organisation does not meet its obligations. In case of persistent shortcomings, a temporary ban on managerial functions is possible. Cybersecurity therefore belongs on the board’s agenda.
The 18 April 2026 milestone has passed. Are we too late?
For essential entities, 18 April 2026 was the first milestone; the next is 18 April 2027. If you missed that first step, start a project right away with a concrete plan and document your progress. Important entities have no fixed audit date, but must be able to show during an inspection that their measures work.
Sources
- Centre for Cybersecurity Belgium, The NIS2 law on Safeonweb@Work
- Centre for Cybersecurity Belgium, NIS2 quick start guide
- Centre for Cybersecurity Belgium, CyberFundamentals Framework
- Centre for Cybersecurity Belgium, Conformity assessment bodies (CAB)
- Centre for Cybersecurity Belgium, NIS2: 18 April 2026 deadline, what essential entities must have in place
- Centre for Cybersecurity Belgium, CyFun® 2025 is here!
- Centre for Cybersecurity Belgium, NIS2 Notification Guide, version 1.3 (August 2025)
- Belgian Official Gazette, Law of 26 April 2024 (NIS2 law) and Royal decree of 9 June 2024
- European Commission, Cybersecurity Package: Questions & Answers
- VLAIO, Hervorming kmo-portefeuille: vanaf 1 februari 2026 enkel nog advies voor cybersecurity
Do you know where you stand?
In a first conversation, we look at whether NIS2 applies to you, which CyFun level fits and which steps you take first. You do not need to know a technical solution yet.
Schedule an introductory meeting or email sales@jvit.be.
Would you first like a broader view of your IT, from cyber risks to backup and secure AI? Then request an Executive IT Scan , a 90-minute conversation.
JViT, Mommersbosweg 41, 3520 Zonhoven, 011 36 16 60
Our promise to you
The Extra Mile
Is Our Starting Point.
Think ahead. Take responsibility. Stay involved.
Find out what that commitment means for your company.