Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

CRA as a product security regime complementing NIS 2 • While NIS 2 focuses on organisational security obligations, the CRA imposes product level cyber - security requirements. • CRA obligations apply to the entire life cycle of PDEs, including vulnerability reporting. • Important and critical PDE manufacturers face heightened conformity assessment obligations, which may feed into broader NIS 2 or DORA com - pliance. Cybersecurity Act and certification as a connecting layer • ENISA-led certification schemes under the Cyber - security Act support compliance with both NIS 2 and CRA. • Belgium’s CyFun® certification serves as an opera - tional tool for demonstrating NIS 2 conformity. AI Act interactions • High-risk AI systems deployed by NIS 2 entities or financial institutions must meet cybersecurity requirements aligned with ENISA standards. • The AI Act’s security provisions complement, rather than replace, NIS 2 and DORA obligations. The AI Act focuses on specific risks associated with AI systems (eg, data governance, robust - ness), whereas NIS 2 and DORA provide broader, sector-specific cybersecurity obligations, creating a layered, non-conflicting compliance framework. 1.3 Cybersecurity Regulators Belgium’s cybersecurity enforcement framework is built around several federal authorities with comple - mentary mandates. These bodies supervise com - pliance with key cybersecurity laws, including the NIS 2 Act, the Cybersecurity Act, DORA, the Criti - cal Infrastructures Act and sector-specific security requirements. Their roles, powers and operational capabilities, including incident response functions, are summarised below. Centre for Cybersecurity Belgium (CCB) Mandate The CCB is Belgium’s central cybersecurity authority, reporting to the Federal Prime Minister. It designs, co- ordinates and oversees national cybersecurity strat -

egy, and leads implementation of the NIS 2 Act. It also serves as Belgium’s national point of contact for EU cybersecurity bodies. Supervisory and enforcement powers • Monitors and enforces NIS 2 compliance for essential and important entities. • Conducts on-site and remote inspections, and may request policies, logs, risk management evidence and technical documentation. • Issues binding mitigation measures and corrective orders. • Imposes administrative sanctions in co-operation with sectoral authorities. • Co-ordinates national-level response to major cyber incidents. Investigative tools • Access to threat intelligence via its Cyber Threat Research and Intelligence Sharing (CyTRIS) unit. • Technical analysis of incident notifications. • Structured co-operation with law enforcement, intelligence services and the NCCN. • Authority to request information and forensic data The CCB hosts Belgium’s national Computer Emer - gency Response Team (CERT.be), providing 24/7 monitoring, triage and incident co-ordination. CERT.be collaborates with sectoral Computer Security Incident Response Teams (CSIRTs) and EU-level networks. Sectoral Competent Authorities Under the NIS 2 Act Sector-specific authorities work alongside the CCB to supervise cybersecurity obligations within their respective domains. They hold regulatory, investiga - tive and enforcement powers tailored to sector risks. Energy sector: Federal Public Service Economy Mandate • Oversight of cybersecurity obligations for electric - ity, gas and petroleum operators designated under NIS 2. Powers • Sectoral audits and compliance reviews. from regulated entities. Incident response role

37 CHAMBERS.COM

Powered by