Cybersecurity 2026

BELGIUM Trends and Developments Contributed by: Stéphanie De Smedt, Loyens & Loeff

and subsequently at least every four years. These assessments should consider interdependencies and relevant national and EU evaluations. • Resilience measures and planning: entities must develop, maintain and execute a resilience plan, incorporating technical, organisational and security measures that are proportionate to the risks identi - fied. • Reporting of incidents: significant incidents should be reported to the relevant authorities within 24 hours, with a detailed follow-up report submitted within a month if applicable. • Co-operation and information exchange: the CER Directive encourages close collaboration with competent authorities and requires the sharing of essential information to align internal resilience efforts with external protective measures. • Personnel screening: in compliance with national legislation and data protection requirements, enti - ties may perform background checks on specific categories of personnel. • Continuity and staff security: operational continu - ity measures, personnel security and training are typically included as part of the entity’s overall resilience strategy. Entities providing essential services in six or more EU member states are subject to special compliance pro - cedures due to their European significance. In accordance with the draft CER implementation law, a number of additional provisions will apply in Belgium compared to the general framework set out in the CER Directive. • Resilience exercises and plan updates: critical enti - ties are required to periodically carry out exercises to evaluate their resilience plans and update them based on lessons learned. Royal or ministerial decrees may set sector-specific schedules for these exercises, and define the participation of relevant government bodies. • Sector-specific plan content and reporting: authori - ties in each sector may specify mandatory ele - ments of resilience plans and require additional reporting or information from critical entities. • Enhanced co-operation principle: a general expec - tation of collaboration between critical entities and

competent authorities to align internal resilience efforts with broader external protection measures. • Sanctions framework: (a) Administrative sanctions: fines range from EUR500 to EUR125,000, doubling if a second offence occurs within three years of a prior final sanction. Suspensions of payment may be permitted under certain conditions. (b) Criminal sanctions: penalties include imprison - ment from eight days up to one year and/or fines of between EUR26 and EUR10,000 (to be multiplied with an indexation factor of eight), with harsher consequences for repeat offend - ers. • Governance and compliance deadlines: enforce - ment is primarily managed by sectoral authorities, in contrast to the more centralised approach under NIS 2 (led by the CCB). Critical entities are expect - ed to meet their initial obligations within six months of their explicit designation under the CER law. Conclusion – Key Points to Keep in Mind Belgium is rapidly advancing its cybersecurity and critical infrastructure regulatory framework, aligning closely with EU directives. Organisations must recognise that compliance is not optional; it is a strategic necessity affecting internal operations as well as supply chain relationships and market competitiveness. The CCB’s latest NIS 2 FAQ provides useful clarifica - tions. The CyFun® framework has emerged as a major tool in Belgium (as well as in certain other EU jurisdictions) for achieving structured, auditable and EU-recognised compliance. Its adoption helps organisations demon - strate adherence to NIS 2 standards while also facili - tating cross-border recognition and audit processes. The CER Directive is expected to be transposed in Belgium in 2026, and requires organisations to pre - pare for sector-specific obligations, resilience plan - ning, reporting and co-operation with authorities. The introduction of sanctions underscores the importance of proactive compliance.

55 CHAMBERS.COM

Powered by