BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP
an EU‑wide framework for harmonised cybersecurity certification schemes. The first adopted scheme is the EUCC, formalised by Implementing Regulation (EU) 2024/482. The EUCC is based on the Common Criteria (ISO/IEC 15408) and the Common Evaluation Methodology (ISO/IEC 18045). It provides two assurance levels: Substantial and High, applicable to a wide range of ICT prod - ucts, including software, hardware and security com - ponents. EUCC certification is voluntary under the Cybersecurity Act, but may become mandatory where required by EU sectoral legislation or EU member state law, and procurement rules may also impose it. Two additional schemes, still under development, will have significant future impact. • The EUCS (cloud services) scheme is intended to certify cloud services at Basic, Substantial and High assurance levels. Its adoption has been repeatedly delayed due to political debate over so‑called “sovereignty” requirements, including whether high‑assurance cloud offerings must be operated exclusively under EU jurisdiction with EU‑only data residency and immunity from non‑EU laws. Once finalised, EUCS is expected to sig - nificantly influence cloud procurement practices across the EU (including in Belgium) where public sector and regulated sector buyers increasingly rely on EU‑level certification frameworks. • EU5G – work is progressing on 5G-related security requirements, but no binding EU scheme is yet in force. The proposed 2026 revision of the Cybersecurity Act aims to streamline certification, strengthen sup - ply chain protections, and enhance the role of the EU Agency for Cybersecurity (ENISA), likely making certification increasingly relevant for access to public sector markets. Mandatory Sector-Specific Schemes Some certification regimes are not voluntary and directly determine market access. • UNECE R155/R156 – automotive cybersecurity and software updates. Mandatory for EU vehicle
type approval, manufacturers must implement and maintain certified Cybersecurity Management Systems (CSMS) and Software Update Manage - ment Systems (SUMS). Compliance is required for obtaining type approval and is effectively a prereq - uisite for selling vehicles in the EU. • RED Delegated Regulation (EU) 2022/30 – cyber - security for radio equipment. From 1 August 2025, internet‑connected radio and IoT devices placed on the EU market must comply with mandatory cybersecurity essential requirements covering net - work protection, privacy and fraud prevention, as part of CE marking. Interactions With Belgian Practice Organisations operating in Belgium typically use a combination of CyFun® (organisational maturity), EUCC (product assurance), RED compliance (IoT devices) and sectoral schemes, such as UNECE R155. NIS 2-regulated entities increasingly require suppliers to demonstrate certification, making these schemes important not only for regulatory compliance but also for staying competitive in procurement. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection Belgium’s cybersecurity and personal data breach notification obligations derive primarily from the GDPR and the Belgian Data Protection Act of 30 July 2018, which supplements the GDPR at national level. The DPA is the competent supervisory authority. The combined framework imposes robust expectations on organisations regarding technical and organisational security measures, risk management, vendor over - sight and timely incident reporting. This section outlines the core cybersecurity require - ments applicable when processing personal data in Belgium and provides an overview of the thresholds, timelines and content obligations for breach notifica - tions.
47 CHAMBERS.COM
Powered by FlippingBook