BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP
Coordination Unit for Threat Analysis (CUTA) Mandate • CUTA assesses extremist and terrorist threats, including cyber-enabled threats. Though not a cybersecurity regulator, it forms part of Belgium’s broader national security architecture. Powers • Access to national intelligence sources and analyti - cal platforms. • Ability to issue threat warnings to public authorities and critical operators. National Security Council (NSC) Mandate • The NSC defines Belgium’s national security strat - egy and sets strategic priorities for cybersecurity, intelligence and critical infrastructure protection. Its role is primarily strategic rather than operational. 2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Belgium has implemented the NIS 2 Directive through the NIS 2 Act of 26 April 2024, which significantly expands the types of public and private entities sub - ject to cybersecurity oversight. The NIS 2 Act applies to the following organisations established in Belgium that provide services listed in Annex I (essential sectors) or Annex II (important sec - tors) within the EU: • essential entities are typically large operators in sectors such as energy, transport, banking, digital infrastructure and healthcare; and • important entities include medium-sized and large providers operating in sectors such as waste man - agement, manufacturing of key goods and (digital) services. Whether an entity falls within scope depends on the nature of the activity and whether it meets the applica - ble size criteria under Commission Recommendation
2003/361/EC, unless the Annex introduces a different size-based test. Belgium’s approach is intentionally broad. The CCB has clarified that the NIS 2 Act applies to the entirety of an in-scope organisation, not only the business unit performing the regulated service. Even where the regulated activity is ancillary, the NIS 2 Act may still apply unless the Annex expressly limits scope based on principal or ancillary activities. From a territorial standpoint, “establishment” requires stable and continuous operations in Belgium, includ - ing subsidiaries, branches or permanent installations. Operators designated as critical infrastructure under the Belgian Critical Infrastructures Act are automati - cally deemed essential entities under the NIS 2 Act. While the NIS 2 Act reduces many uncertainties that existed under the former NIS 1 regime, organisations must still engage in careful mapping of their services, supply chains and group structures to determine cov - erage. Despite extensive guidance from the CCB, the most persistent uncertainties and challenges concern: • determining sector applicability; • digital services classification, especially for hybrid providers whose digital services are ancillary rather than core; and • group level size calculations, especially across multinational structures. 2.2 Critical Infrastructure Cybersecurity Requirements Entities subject to the NIS 2 Act must implement a comprehensive, risk-based cybersecurity programme that aligns with the heightened obligations introduced under the NIS 2 Directive. Belgian law requires in- scope organisations to: • register with competent authorities, including completing onboarding via Safeonweb@Work and identifying the entity’s applicable sector classifica - tion; • adopt cybersecurity risk management measures that are effective and proportionate, addressing governance, operational security, business conti -
39 CHAMBERS.COM
Powered by FlippingBook