Cybersecurity 2026

BELGIUM Trends and Developments Contributed by: Stéphanie De Smedt, Loyens & Loeff

Transposition of CER Directive into Belgian Law The law transposing the Critical Entities Resilience Directive into Belgian law is expected in 2026. This rep - resents a significant step toward completing the long- overdue transposition, which was initially required by 17 October 2024. This new legislation will replace the Critical Infrastructures Directive (2008/114/EC) and its 2011 Belgian transposition law. The sectors covered by the CER Directive are similar to NIS 2, although the list is not identical: • energy; • transport; • banking; • financial market infrastructures; • digital infrastructures; • drinking water; • wastewater management; • central public administration; • space; and • food. Whereas NIS 2 focuses on the cybersecurity of net - works, information systems and data, the CER Direc - tive adopts a broader approach aimed at the over - all resilience of critical entities. It addresses all risks (physical, natural, human or cyber) that could disrupt the provision of essential services. The two laws are thus complementary: NIS 2 governs digital security, while CER ensures the operational continuity and robustness of critical infrastructures. Entities designated as “critical” under CER will gener - ally also be considered “essential” under NIS 2. For sectors subject to detailed European regulatory regimes (notably banking, financial market infrastruc - tures and digital infrastructures), certain CER provi - sions may not apply when equivalent sector-specific obligations exist. Companies’ principal obligations under the CER Directive are as follows. • Threat and risk assessment: critical entities are required to carry out a comprehensive risk assess - ment within nine months of being designated,

tor, especially where price or functionality alone would not suffice. What was once a distinguishing feature of the most security-conscious organisations is rapidly becoming a baseline expectation across the market. CyFun® 2025 as a Major Framework in Belgium Since the entry into force of the NIS 2 Directive in Bel - gium, many organisations have adopted the Belgian CyFun® framework. CyFun® is a structured framework providing: • a standardised approach for risk assessment and cybersecurity controls aligned with Belgian and EU legal requirements; • modular frameworks (“Basic”, “Important”, “Essen - tial”) allowing organisations to calibrate security measures according to size, criticality and sector; and • a documentation and verification process facilitat - ing audits by “Trusted NIS Providers” and approval by the CCB. The key advantage of CyFun® lies in providing a com - mon language for authorities, auditors and organisa - tions, reducing ambiguity about what constitutes sat - isfactory NIS 2 compliance. It is designed to: • systematically assess vulnerabilities and risks in information systems; • define corrective and preventative action plans for identified weaknesses; and • provide clear, traceable reporting for regulatory inspections and audits. It is important to note that CyFun® certification also grants a legal presumption of compliance with the Belgian NIS 2 Law. Although developed at a national level in Belgium, CyFun® is designed for recognition and use at a broader EU level. Romania has already officially adopted the framework, and several other EU mem - ber states, including France, acknowledge CyFun®’s value and are exploring integration or full adoption.

54 CHAMBERS.COM

Powered by