Cybersecurity 2026

BELGIUM Trends and Developments Contributed by: Stéphanie De Smedt, Loyens & Loeff

to be used by its affiliates. In such case, the NIS 2 services continue to be provided by the NIS 2 service provider and not by the contracting entity. The scope of “managed IT services” activities and their application in an intra-group context therefore remains a delicate and debated topic in Belgium in 2026. • NIS 2 in M&A: NIS 2 has become an important point of attention in M&A transactions in Belgium, notably as the NIS 2 qualification of an entity that undergoes a change of control may change. While NIS 2 applicability does not automatically trans - fer to the acquirer of an in-scope entity, both the calculation of size thresholds and the identifica - tion of in-scope activities may change after an acquisition. For example, depending on the service provided by the NIS 2 entity, an increase in size (because the acquiring group is much larger than the seller group) may trigger a post-closing quali - fication as an “Essential” rather than “Important” entity. Intra-group IT arrangements (see “managed IT services”, as discussed above) may trigger (or “de-trigger”) NIS 2 applicability. A re-assessment of NIS 2 applicability post-M&A (and, even better, as part of due diligence in order to assess potential additional cost/financial implications) is therefore highly advisable. • Civil and criminal liability of the management board: Article 31, Section 1 of the NIS 2 Law provides that management bodies are liable for breaches of cybersecurity measures. The CCB refers to the general principles of liability under Bel - gian law. The liability of legal entities is, in principle, engaged through the actions of their representative organs, as provided by Article 2:49 of the Com - panies and Associations Code. In addition, civil liability of members of management or supervisory bodies may also be engaged under the theory of cumulative liability, pursuant to Articles 2:56 to 2:58 of the Companies and Associations Code, where the fault is tortious and clearly exceeds what a prudent and diligent director would have done under the same circumstances. Regarding criminal liability, the CCB explicitly notes that the NIS 2 Law does not exclude criminal liability of either legal or natural persons. • Content of management training: while the NIS 2 Law requires members of management bod -

ies to receive cybersecurity training, the CCB has clarified in interviews that there are no mandatory training centres, certificates or prescribed content or methods for the delivery of such training. The CCB’s FAQ, however, does specify the objective of such training: “ The purpose of training members of the management body is to enable them to prop- erly perform the duties assigned to them under the law, ie, to approve cybersecurity risk-management measures and to supervise their implementation. There is no prescribed content or duration; both are left to the discretion of the entity.“ The CCB further distinguishes between ”Important” and “Essential” entities, implying that training expectations may vary depending on the entity’s NIS 2 classification. Accordingly, each organisation is responsible for determining the scope, format and duration of the management training, ensuring that members of management are adequately equipped to fulfil their supervisory and decision-making responsibilities under NIS 2. Cybersecurity Measures to Gain a Competitive Edge in the Supply Chain Cybersecurity is no longer evaluated solely within the boundaries of an organisation’s own systems: it is assessed across the entire value chain. Indeed, sup - ply chains have become one of the most common vectors for cyber incidents, and the NIS 2 Directive requires in-scope entities to implement specific cyber - security measures to manage their supply chains. As a result, in-scope organisations impose obligations on their suppliers, including those not directly subject to NIS 2, which are now increasingly indirectly impacted by this legislation. Many suppliers have understood that they can gain a strategic advantage by embedding cybersecurity into their operations. By adopting robust security prac - tices, they strengthen client and partner trust, increase operational resilience, and position themselves as more competitive players in the market. This trust translates into tangible commercial value. Customers are more likely to work with suppliers who can demon - strate effective management of third-party risks, par - ticularly when services are business-critical or involve sensitive data. In competitive tenders, credible cyber - security governance can serve as a clear differentia -

53 CHAMBERS.COM

Powered by