Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

• managing CSIRT operations; and • ensuring alignment with EU cybersecurity frame - works. The CCB represents Belgium in the NIS Cooperation Group, the CSIRT Network and the European Cyber Crisis Liaison Organisation Network (EU CyCLONe). The NCCN supports the CCB in national cyber crisis management, risk preparedness and handling inci - dents with cross-sector or national level impact. Sectoral regulators continue to enforce sector-specific obligations, with enhanced collaboration mechanisms introduced under NIS 2 to ensure coherent national supervision and co-ordinated incident response. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Belgium applies DORA as the primary regulatory framework governing the operational resilience of financial entities. DORA has applied since 17 January 2025 and covers a broad range of regulated financial entities established in Belgium or operating through Belgian or other EU branches, including: • credit institutions; • insurers and reinsurers; • investment firms; • payment and e-money institutions; • crypto-asset service providers; • trading venues and market infrastructures; • Institutions for Occupational Retirement Provision (IORPs); and • various intermediaries. DORA also applies indirectly to third-party ICT service providers that supply ICT services to financial enti - ties. An ICT provider that is designated as “critical” by the European Supervisory Authorities becomes sub - ject to direct EU level oversight and must establish an EU legal presence, even if headquartered outside the European Union. In this way, DORA has a limited but significant extraterritorial impact on non-EU criti -

cal ICT service providers that support the EU financial sector. The NBB and the FSMA serve as the competent authorities responsible for supervising DORA imple - mentation by financial entities. Where DORA applies as a sector-specific lex specialis, its requirements pre - vail over horizontal obligations under the NIS 2 Act. 3.2 ICT Service Provider Contractual Requirements DORA imposes detailed contractual, governance and oversight obligations on financial entities engaging third-party ICT service providers. “ICT service pro - viders” are broadly defined to include providers of cloud computing, data centres, hosting and storage, cybersecurity services, network services, managed IT services, software, data analytics, back-up and recov - ery solutions, and related support and maintenance. Financial entities within scope of DORA must main - tain a comprehensive Register of Information (RoI) covering all third-party ICT arrangements. Contracts supporting “critical or important functions” must meet specific minimum standards, including: • a detailed description of the services, including the business functions supported; • identification of all locations where data is pro - cessed and services are performed, with advance notification of any changes; • clear service levels and performance metrics; • information security, business continuity and inci - dent response obligations, including: (a) full audit, inspection and access rights for the financial entity, its auditors and competent authorities; (b) robust subcontracting and chain outsourcing provisions, including transparency, consent mechanisms and flow down of obligations; (c) support for digital operational resilience test - ing, including participation in threat-led pen - etration tests when applicable; and (d) exit, transition and data portability arrange - ments, including return and deletion obliga - tions.

42 CHAMBERS.COM

Powered by