Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

TLPT exercises performed in accordance with TIBER EU’s mandatory requirements may be recognised across borders by competent TLPT authorities. Financial entities in Belgium likely to be designated as “significant” should prepare by: • assessing their critical functions; • establishing relationships with qualified threat intel - ligence and red team providers; • updating contractual provisions to support TLPT participation; and • aligning internal teams with TIBER BE operational requirements. Belgium’s cyber-resilience framework is defined large - ly by directly applicable EU legislation – most notably the Cyber Resilience Act (CRA), which entered into force on 10 December 2024. As a horizontal regu - latory framework, the CRA establishes mandatory cybersecurity requirements for PDEs placed on the EU/Belgian market. The CRA applies irrespective of where the manufacturer of the PDE is located; non- EU entities placing PDEs on the Belgian market are fully in scope. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation The CRA requires cybersecurity to be embedded throughout the entire life cycle of a PDE, from initial design and development to post-market monitoring and end of support activities. The CRA complements, rather than replaces, sector- specific Belgian and EU regimes, such as the NIS 2 Act, the Cybersecurity Act and sectoral instruments governing telecoms, medical devices and financial services. Its scope is intentionally broad. PDEs include nearly any software or hardware product – such as consumer and industrial IoT devices, embedded systems, con - nected hardware, enterprise and standalone software – whose intended or foreseeable use involves a direct or indirect data connection to a device or network. Pure SaaS and cloud services are generally excluded

unless the service forms part of a PDE or is required for a PDE’s functioning. Cloud service providers may still fall under other regulatory frameworks such as NIS 2, and under DORA when providing ICT services to in-scope financial entities. The CCB will play a central role in co-ordination, market surveillance and enforcement support, work - ing alongside the Federal Public Service Economy and relevant EU bodies. It is expected to materially strengthen Belgium’s security posture by reducing systemic vulnerabilities in the digital products that underpin commercial operations and public services. 4.2 Key Obligations Under Legislation The CRA imposes a set of cybersecurity obligations on manufacturers, importers and distributors of PDEs placed on the EU/Belgian market, and (in limited cas - es) open source software stewards. These obligations focus on embedding cybersecurity into the design, development, distribution and maintenance of all PDEs placed on the Belgian market. Security by Design and Security by Default Requirements PDE manufacturers must ensure that cybersecurity is built into PDEs from the earliest stages of product conception. Key requirements include: • designing PDEs to reduce attack surfaces and prevent known vulnerabilities; • implementing secure architectures, appropriate encryption and protective technical controls; • ensuring secure configurations by default, such as disabling weak credentials and enabling secure update mechanisms; and • maintaining detailed technical documentation dem - onstrating compliance. Manufacturers must also implement processes for continuous improvement and adhere to “state of the art” security expectations throughout the product’s life cycle. Vulnerability Handling, Patching and Update Timelines The CRA introduces harmonised EU rules for vulner - ability management. Manufacturers of PDEs must:

44 CHAMBERS.COM

Powered by