Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

Belgian supervisory practice reflects the EU level reg - ulatory technical standards (RTS/ITS), including those on contractual requirements, subcontracting, classifi - cation of incidents, and RoI harmonisation. 3.3 Key Operational Resilience Obligations Financial entities must implement a management body-owned ICT risk management framework addressing identification, protection, detection, response and recovery. Financial entities must classify ICT-related incidents using EU harmonised materiality thresholds. If they determine that an ICT incident is “major” based on factors like impact on clients, transactions, data and duration, they must report the major incident within the following strict timelines. • Initial notification: as soon as possible, no later than four hours after classifying an incident as “major”, and in any case within 24 hours of detec - tion. • Intermediate report: within 72 hours after the initial notification. • Final report: within one month after the latest inter - mediate report. Financial entities must also notify clients where major incidents materially affect the financial interests or the continuity of services provided to them. DORA intro - duces a voluntary notification mechanism for “sig - nificant cyber threats”, enabling authorities to share threat information horizontally across the sector. For financial entities in Belgium that are subject to DORA, incident reports are submitted to the NBB or FSMA, as applicable. These authorities subsequently transmit the reports to the CCB, ensuring alignment with the Belgian NIS 2 notification framework. 3.4 Operational Resilience Enforcement The NBB and FSMA supervise compliance by financial entities with DORA’s ICT risk management and third- party oversight requirements. National supervisory measures may include remedial actions, heightened supervision and administrative fines for breaches of DORA obligations.

In parallel, the European Supervisory Authorities (EBA, EIOPA and ESMA) designate certain ICT service pro - viders as Critical ICT Third Party Providers (CTPPs). For each designated CTPP, one of the ESAs acts as the Lead Overseer. The Lead Overseer’s enforcement and oversight tools include requesting information, conducting investigations and on-site inspections, issuing recommendations, performing ongoing over - sight activities, and imposing periodic penalty pay - ments to ensure the CTPP’s compliance with DORA’s DORA does not impose general EU data localisation requirements; however, it requires transparency and risk mitigation for all locations in which data is pro - cessed or stored. Where ICT services involve personal data, the GDPR’s rules on international data transfers (Chapter V) apply, including obligations to ensure that the transferred data remains protected via adequacy decisions, Standard Contractual Clauses or Binding Corporate Rules, and that Transfer Impact Assess - ments are performed, where required. operational resilience requirements. 3.5 International Data Transfers Financial entities should integrate GDPR transfer risk assessments into their DORA third-party risk manage - ment processes. Contractual arrangements should specify data processing locations and set out notifi - cation and approval mechanisms for the relocation of data or services to third countries. 3.6 Threat-Led Penetration Testing Under Articles 26–27 of DORA, certain “significant” financial entities must conduct threat-led penetra - tion testing (TLPT) every three years. The EU TLPT Regulatory Technical Standards, effective July 2025, align with the EU’s Threat Intelligence Based Ethical Red Teaming (TIBER EU) framework, which Belgium implements through the NBB’s TIBER BE programme. TIBER BE co-ordinates intelligence-led red team test - ing of entities’ critical or important functions using realistic cyber-attack scenarios. Co-operation from ICT service providers may be required where they are identified as CTPPs for the systems in scope.

43 CHAMBERS.COM

Powered by