Cybersecurity 2026

BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP

Product Recall, Withdrawal and Corrective Measures When cybersecurity risks cannot be mitigated through patches or updates, authorities may require PDE man -

• up to EUR10 million or 2% of global annual turno - ver for violations involving technical documenta - tion, reporting failures or conformity assessment obligations; and • periodic penalty payments for ongoing non-com - pliance, ensuring that entities cannot indefinitely delay corrective actions. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Belgium adopts a multi-layered approach to cyber - security certification that combines national, EU-wide and sector-specific frameworks. Together, these cre - ate both voluntary and mandatory obligations depend - ing on the product, service or sector concerned, and increasingly influence procurement, supply chain assurance and market access for companies operat - ing in Belgium. National Framework: CyberFundamentals (CyFun®) Belgium’s flagship national scheme is CyFun®, man - aged by the CCB, which also serves as the National Cybersecurity Certification Authority. CyFun® is designed to raise cybersecurity maturity across Bel - gian organisations and support compliance with the Belgian NIS 2 Act. CyFun® offers four levels: • small (entry-level guidance); • basic; • important; and • essential. Basic and Important require independent verification, whereas Essential requires full certification by an accredited and CCB-authorised Conformity Assess - ment Body (CAB). CyFun® is not legally mandatory but is widely used because it provides for the pre - sumption of conformity with NIS 2 requirements. EU Level Schemes Under the Cybersecurity Act At the EU level, certification follows the Cybersecu - rity Act (Regulation (EU) 2019/881), which establishes

ufacturers, importers or distributors to: • withdraw the PDE from the market; • recall the PDE from customers; or

• implement other appropriate corrective measures. Market surveillance authorities may also require inse - cure product functionality to be disabled where nec - essary. Enforcement and Penalty Structures The CRA establishes a unified EU-wide enforcement and market surveillance framework aimed at ensur - ing consistent oversight of cybersecurity requirements for PDEs across all EU member states. Enforcement operates under the EU’s horizontal market surveil - lance architecture (Regulation (EU) 2019/1020), with each EU member state designating its own competent authorities. In Belgium, CRA supervision is carried out by the CCB and the Federal Public Service Economy, which together perform the roles of market surveillance authority and enforcement body within the national context. Competent authorities – whether Belgian or EU level – are empowered to undertake a broad range of super - visory actions, including: • conducting inspections; • requesting and reviewing technical documentation; and • ordering corrective or risk mitigating measures where a PDE presents cybersecurity deficiencies or non-compliance with essential requirements. In addition, the CRA introduces a harmonised penalty framework, setting the following maximum adminis - trative fines: • up to EUR15 million or 2.5% of global annual turn - over (whichever is higher) for breaches of essential cybersecurity requirements;

46 CHAMBERS.COM

Powered by