Post

NIS2 Readiness Checklist for Belgian SMEs

NIS2 Readiness Checklist for Belgian SMEs

Why this checklist matters

NIS2 is in force in Belgium since 18 October 2024. The Law of 26 April 2024 and its supporting Royal Decree of 9 June 2024 established a framework for cybersecurity of networks and information systems. This checklist helps you understand what entities are in scope and what practical steps to take.

The checklist focuses on organisations that must comply. If you operate essential or important services, or if you supply them, this checklist provides a practical starting point for understanding your obligations.

This post explains what NIS2 requires based on official Belgian guidance from the CCB (Centre for Cybersecurity Belgium). You can download a detailed checklist to use as a working document.

Gilberto Torres, Founder of Gforce NetworksSecurity, Privacy & Governance. Based in Belgium. DPO experience from work at Essensium and Mind OSS, with 15+ years in IT leadership. This post does not constitute legal advice. For specific requirements, consult the CCB or your own legal counsel.

Quick summary

If you are an essential or important entity under NIS2, you must:

  1. Understand your scope under the law
  2. Register with the CCB by the applicable deadline if required
  3. Establish risk-based security measures appropriate to your organisation
  4. Document your security approach
  5. Report significant incidents according to CCB timelines

This checklist guides you through each step.

Who is in scope?

NIS2 applies to essential entities and important entities. The size rule is: organisations must be at least medium-sized enterprises, with some exceptions. The CCB can also identify entities directly.

Small and micro enterprises are generally outside the direct scope, unless an exception applies or the CCB identifies them. Check the CCB website for your specific sector: https://atwork.safeonweb.be/nis2

Your size category matters. If you are a small or micro enterprise, verify with the CCB whether you are directly in scope. Many are not. If you are a medium-sized or larger organisation providing services listed in the law, you likely are in scope.

Registration with the CCB

If you are essential or important, you must register with the CCB if you have not already. The registration deadline passed on 18 March 2025. If you missed that date, register immediately through Safeonweb@Work.

Incident reporting for essential entities

Essential entities must report significant incidents to the CCB. A significant incident causes or is likely to cause serious disruption, financial loss, or significant material, personal or non-material damage to others.

The timeline is strict:

  • Early warning: Without undue delay, within 24 hours of becoming aware of the incident
  • Incident notification: Within 72 hours
  • Final report: No later than one month after your incident notification

Report to the national CSIRT at the CCB: https://ccb.belgium.be/cert/report-incident/nis2-notifications-howto

Conformity assessment and certification

Essential entities must undergo regular mandatory conformity assessments. If your organisation chooses to use a conformity assessment route, you can opt for CyFun certification or ISO/IEC 27001 certification. Both are recognised paths, though they are not mandatory.

CyFun is a framework owned by the CCB with assurance levels: Small, Basic, Important, and Essential. A CyFun label can be obtained using an existing ISO/IEC 27001 certificate with the correct scope.

If you pursue certification, essential entities opting for CyFun or ISO 27001 must obtain it no later than 18 April 2027.

Important entities are not subject to regular mandatory conformity assessment, but may voluntarily choose to follow the essential regime.

Supply chain security

NIS2 requires you to secure your supply chain. Suppliers may face security obligations through contractual requirements. The CCB recommends suppliers meet CyFun Basic. As a NIS2 entity, you can impose a certain CyFun level contractually on your suppliers.

Practical steps: a checklist

Use this checklist to build a practical security programme:

Foundation (establish first)

  1. Verify your scope with the CCB if you are unsure whether you are essential, important, or outside scope
  2. If in scope, ensure you are registered with the CCB
  3. Create an asset inventory: list all systems, data stores, and services critical to your operations
  4. Establish a risk register: document identified threats, impacts, likelihoods, and current controls
  5. Document your incident response plan with roles, escalation, and the CCB reporting timeline

Controls (implement based on your risks)

  1. Implement access controls: restrict who can access sensitive systems based on job role
  2. Segment your network to limit damage if a system is compromised
  3. Encrypt sensitive data at rest (databases, files) and in transit (TLS for communications)
  4. Deploy endpoint security (antivirus, patch management) on all devices
  5. Establish backup and recovery procedures to restore operations after an incident

Governance (formalize and review)

  1. Document security policies: information security policy, incident response procedures, access control procedures
  2. Engage senior management in security oversight: regular reporting, budget allocation, risk decisions
  3. Conduct regular security testing: vulnerability scans, penetration testing, security configuration reviews
  4. Track security metrics: how quickly you detect incidents, how quickly you respond, whether your controls are effective
  5. Provide cybersecurity training to employees on phishing, secure practices, and your organisation’s incident response procedures

Getting help

The checklist is practical but not one-size-fits-all. Your organisation’s size, sector, and risk profile will determine which items take priority and how aggressively to implement them.

Start with the foundation items. They apply to every organisation. Then address controls based on your actual risks. Adjust the pace to your capacity.

Downloadable checklist

You can download a printable checklist: nis2-readiness-checklist.pdf. Use this as a working document to track your progress.

Conclusion

NIS2 has been in force in Belgium since October 2024. If your organisation is essential or important, compliance is not optional. This checklist provides a practical starting point.

The key is to start. Verify your scope with the CCB. Register if required. Build security controls based on your actual risks. Document what you have done. Report incidents correctly if they occur.

This is not easy, but it is achievable. Many Belgian organisations are already moving through this process. You can too.


References

  • CCB, The NIS2 Law: https://atwork.safeonweb.be/nis2
  • CCB, NIS2 incident notification: https://ccb.belgium.be/cert/report-incident/nis2-notifications-howto
  • CCB, CyberFundamentals Framework: https://atwork.safeonweb.be/tools-resources/cyberfundamentals-framework
  • NIS2 Directive (EU 2022/2555): https://eur-lex.europa.eu/eli/dir/2022/2555/oj
  • GDPR Article 33 (Breach notification): https://eur-lex.europa.eu/eli/reg/2016/679/oj

Word count: 820 words

This post is licensed under CC BY 4.0 by the author.