Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

nuity, incident handling, encryption, access control and vulnerability management; • ensure cybersecurity expertise within their man - agement bodies, including regular training and documented responsibilities for supervisory and oversight functions; • assess and manage supply chain risk, particularly where ICT service providers support the deliv - ery of essential or important services – the CCB recommends contractually requiring suppliers to meet cybersecurity certification standards such as CyFun® or equivalent; and • prepare for and comply with incident notification obligations, as outlined in 2.3 Incident Response and Notification Obligations . The CCB’s CyFun® Framework remains the primary national reference point for demonstrating compli - ance. Entities that obtain CyFun® or ISO/IEC 27001 certification benefit from a presumption of conformity with NIS 2 security requirements. 2.3 Incident Response and Notification Obligations Incident Classification and Thresholds Under the Belgian NIS 2 Act, incident reporting obliga - tions apply only to significant incidents – ie, those that have a substantial impact on the continuity or security of Annex I/II services and that: • cause or are likely to cause severe operational dis - ruption to essential or important services; • result in material financial loss for the entity; or • lead to considerable material, physical, personal or non-material damage. Mandatory Multi-Stage Notification Timeline The Belgian NIS 2 Act adopts a three-phase report - ing model that mirrors the requirements of the NIS 2 Directive. Reporting deadlines run from the moment the entity becomes aware of the significant incident. Early warning – within 24 hours Entities must notify the CCB: • without undue delay; and • within 24 hours of becoming aware of a significant incident.

The early warning aims to provide preliminary situ - ational awareness to the CCB. It may include sus - pected causes, early indicators of compromise, initial containment measures and any cross-border impli - cations. The CCB recognises that information at this stage is preliminary, and encourages early notification even when investigative findings remain incomplete. Incident notification – within 72 hours A more detailed incident notification must be submit - ted: • within 72 hours of awareness; or • within 24 hours for qualified trust service providers (as defined in Regulation (EU) 910/2014 on elec - tronic identification and trust services for electronic transactions in the internal market). The notification should include updated techni - cal details, the systems and services affected, the assessed or likely impact, known or suspected attack vectors, indicators of compromise, and measures tak - en or planned to contain the incident. For entities in the financial sector subject to DORA, notifications must be submitted to the NBB or the FSMA; these authorities then transmit the notification to the CCB. Final report – within one month A comprehensive final report must be submitted with - in one month after the detailed notification. The report must include a root cause analysis, a complete timeline from detection through recovery, a detailed impact and remediation analysis, and long- term mitigation measures. The CCB or relevant sec - toral authority may request additional interim updates. Notification Channels and Competent Authorities All notifications must be submitted through the CCB’s secure online reporting platform, accessible via Safeonweb@Work. The CCB functions as Belgium’s: • national CSIRT; • national cybersecurity authority; and • single point of contact for NIS 2 implementation.

40 CHAMBERS.COM

Powered by