Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Belgium continues to strengthen its national cyberse - curity framework through a combination of strategic policy initiatives and a rapidly evolving body of legisla - tion. The country’s overarching policy blueprint is the National Cybersecurity Strategy 2.0 (2021–2025), led by the Centre for Cybersecurity Belgium (CCB). This strategy aims to position Belgium among the least cyber-vulnerable countries in Europe by: • reinforcing trust in digital services; • improving the capabilities of users and system administrators; • enhancing the protection of vital companies; • increasing the effectiveness of incident detection and response; and • deepening collaboration across the public, private and academic sectors. The CCB plays a central role in co-ordinating imple - mentation, supported by sectoral authorities and the National Crisis Center (NCCN). An updated cyberse - curity strategy for the period 2025–2030 has been announced but not yet published. The National Cyber - security Strategy 3.0 is expected to build on the foun - dations of the previous Strategy, with an emphasis on improving national detection capabilities in order to strengthen overall resilience. Belgium’s legislative landscape has undergone signifi - cant development as part of this broader policy effort. The most consequential reform is the transposition of the EU NIS 2 Directive through the Belgian Act of 26 April 2024, which entered into force on 18 Octo - ber 2024. This law considerably broadens the scope of cybersecurity regulation in Belgium by classifying organisations as “essential” or “important” entities based on the nature of their services and their size, and by imposing detailed cybersecurity risk manage - ment, governance, supply chain oversight and inci - dent notification requirements. Registration of in- scope entities through the CCB’s Safeonweb@Work portal became mandatory as of 18 October 2024.

Parallel regulatory developments apply to the finan - cial sector. The EU Digital Operational Resilience Act (DORA), effective since January 2025, establishes a harmonised framework for ICT risk management, major incident reporting, operational resilience testing and the oversight of Critical Third Party ICT Service Providers. In Belgium, supervision is exercised by the National Bank of Belgium (NBB) and the Financial Services and Markets Authority (FSMA). While many financial institutions also fall within the scope of NIS 2, DORA operates as a lex specialis for the sector. Incident reporting under DORA is made directly to the NBB or FSMA, which then ensures co-ordination with the CCB as needed. Another important component of the EU cybersecurity framework with direct relevance for companies doing business in Belgium is the Cyber Resilience Act (CRA) (Regulation (EU) 2024/2847). This horizontal regulation applies to products with digital elements (eg, connect - ed devices) placed on the EU market. It introduces secure by design obligations, detailed requirements for vulnerability management and incident reporting, and market surveillance mechanisms. While the CRA entered into force in December 2024, its substantive obligations will become fully applicable in December 2027, with certain intermediary obligations taking effect in September 2026, such as reporting actively exploited vulnerabilities. Belgium also continues to develop its national cyber - security certification framework under the EU Cyber - security Act. The CCB, acting as Belgium’s National Cybersecurity Certification Authority, has created the CyberFundamentals (CyFun®) Framework, which offers a structured set of controls aligned with widely recognised international standards. The framework provides a presumption of conformity for NIS 2 pur - poses when verified or certified by an authorised Conformity Assessment Body. Therefore, achieving CyFun® certification/verification (or ISO 27001, if aligned with CyFun®) means an entity is presumed to have implemented the necessary, proportionate and adequate cybersecurity measures required by the NIS 2 Directive in Belgium. A new version of the framework, CyFun® 2025, introduces enhanced gov - ernance provisions, clearer control formulations and

34 CHAMBERS.COM

Powered by