Cybersecurity 2026

BELGIUM Trends and Developments Contributed by: Stéphanie De Smedt, Loyens & Loeff

Introduction Cybercrime has significantly increased in recent years, with a growing number of ransomware attacks, increasingly sophisticated phishing campaigns, and major data breaches affecting both private companies and public institutions. As a result, cybersecurity has become a key strategic concern in Belgium for both the public and private sectors. The regulatory landscape in this area remains under construction, with certain legislation already in force and other requirements set to apply in the coming years, as follows. • Following the transposition of EU Directive 2022/2555 (the “NIS 2 Directive”) into Belgian law at the end of 2024, many entities are still investing considerable resources to achieve NIS 2 compli - ance. From 2026, entities that have opted for the “Basic” or “Important” frameworks will be required to have their initial self-assessments verified by a “Trusted NIS Provider” and approved by the Centre for Cybersecurity Belgium (CCB). • Belgium is expected to transpose EU Directive 2022/2555 (the “CER Directive”) in 2026 – a pro - cess that should have been completed by October 2024. • While EU Regulation 2024/2847 (the “Cyber Resil - ience Act”, or CRA) will generally apply from 11 December 2027, its Article 14 will become appli - cable as of 11 September 2026, and its Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. An analysis of some of these topics and developments follows. CCB Publishes Second Version of the NIS 2 FAQ In 2025, the CCB released a second version of its FAQ, clarifying several key aspects of the Belgian NIS 2 implementation act (the “NIS 2 Law”). The main points clarified by the CCB include the fol - lowing. • Ancillary activities may trigger NIS 2 applicability: a company whose principal activity falls outside the scope of the (exhaustively listed) NIS 2 sectors but that engages, even marginally, in activities listed in

the annexes to the NIS 2 Law will be considered “in-scope”. The primary or ancillary nature of the activities do not, as such, matter for NIS 2 appli - cability to be triggered. In such cases, the size calculations for the applicability assessment will encompass the entire entity, and not merely the activities deemed to be “in-scope”. • Application of NIS 2 to groups of companies: the size thresholds for determining NIS 2 applicability are to be calculated on a group level, taking into account the employees and financials of partnered and linked enterprises. Conversely, the relevant in-scope activities should be assessed for each legal entity individually. When assessing the scope of NIS 2 within a group of companies, every legal entity must analyse, on its own, whether its activi - ties and services bring it within the scope of NIS 2. The mere sharing of data, networks or infor - mation systems within a corporate group does not, in itself, determine or alter the applicability of NIS 2. However, it is possible for a NIS 2 entity to be subject to several pieces of transposition legislation and competent supervisory authorities throughout the EU. This is the case when, within the same group, entities are established in multiple EU member states and are not subject to the main establishment criteria (which apply only to certain entities providing digital services). • Intra-group provision of managed IT services or cloud services: although highly criticised for this position, the CCB takes the view that entities providing IT management or cloud services to affili - ates (ie, in a purely intra-group situation) fall within the scope of activities covered by NIS 2 (provided that the size thresholds are also met at group level). Even where the main operational activities of a group have no relation at all to NIS 2 in-scope activities, NIS 2 applicability may therefore be trig - gered purely by the way in which a group is struc - tured internally (namely by centralising intra-group IT management within one entity). Conversely, the CCB notes that the situation differs when multiple organisations within the same group share data, networks or systems and distribute costs, with - out any entity actually acting as a managed ser - vice provider for the others. The same reasoning applies if an entity enters into a contract with a NIS 2 service provider and allows this contract/service

52 CHAMBERS.COM

Powered by