Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

Treatment of Early Warnings The CCB treats early warnings as situational aware - ness tools, not enforcement triggers. It recognises that information may be incomplete or subject to change, and typically does not penalise entities for corrections or updates. Instead, the CCB encourages swift report - ing to prevent potential incident escalation. Obligation to Inform Recipients and the Public If an incident is likely to adversely affect service recipi - ents, the entity must: • notify recipients without undue delay; • provide actionable guidance on protective steps; and • communicate any mitigation actions the entity has taken. In cases of broader public risk, the CCB may require public disclosure. Multi-Agency and Parallel Reporting Obligations Depending on the nature of the incident, additional reporting requirements may apply, as follows. • GDPR: personal data breaches must be reported to the DPA within 72 hours, and possibly to affect - ed individuals if a high risk exists. • DORA: financial entities must follow DORA’s inci - dent classification and reporting model, submitting notifications to the NBB or FSMA. • Critical Infrastructure Act: operators designated as critical infrastructure may need to provide addi - tional reports to the NCCN. • Medical Devices Regulation: cyber incidents involving medical devices may trigger reporting to the Federal Agency for Medicines and Health Prod - ucts (FAMHP) if they cause or have the potential to cause death, serious deterioration of health, or serious public health threats. 2.4 State Responsibilities and Obligations The CCB is responsible for overseeing all aspects of NIS 2 implementation in Belgium, including: • co-ordinating and supervising essential and impor - tant entities; • monitoring national cybersecurity readiness;

The CCB shares information with relevant sectoral authorities and, for essential entities, with the NCCN, which co-ordinates national level crisis management. Sector-specific oversight bodies include: • BIPT for electronic communications and digital infrastructure; • FPS Economy for digital services and online plat - forms; • FPS Public Health for healthcare operators; • transport authorities covering rail, air, road and maritime sectors; and • the NBB and FSMA for financial services. Required Content of Notifications Regulators expect the following elements, tailored to the maturity of the investigation. Early warning (24 hours) • High-level description of the incident. • Suspected origin or cause. • Early assessment of impact on regulated services. • Confirmed technical facts and system details; • Identification of impacted assets and service dependencies; • Updated severity assessment; • Implemented containment measures and additional mitigation steps. Final report (one month) • Full forensic and root cause analysis. • Comprehensive timeline of the incident and response measures. • Detailed impact assessment for services, custom - ers and third parties. • Long-term security improvements and recom - mended preventative measures. • Potential cross-border effects. Incident notification (72 hours) The CCB has released a “NIS 2 Quickstart Guide” and provides a library of template policies (eg, for risk management and incident handling) to help organisa - tions standardise their internal procedures. The CCB is also expected to issue unified templates to stand - ardise reporting across sectors.

41 CHAMBERS.COM

Powered by