Customer area
FR NL EN

NIS2 in Belgium: is your SME affected?

Backlit laptop keyboard glowing in the dark, symbolising business cybersecurity

Since it came into force in Belgium, the European NIS2 directive has created a lot of confusion among SMEs: some think they're covered when they aren't, others believe they're safe when a client or partner is about to impose cybersecurity requirements on them by contract. Here's a jargon-free look at who is actually covered by NIS2 in Belgium, what obligations follow from it, and why the question is worth asking even if your company has fewer than 10 employees.

NIS2, in brief

NIS2 (Network and Information Security 2) is a European directive transposed into Belgian law by the act of 26 April 2024, in force since 18 October 2024. Its goal: to raise the cybersecurity level of organisations considered important for the functioning of society and the economy, building on an earlier NIS directive deemed too limited. In Belgium, the Centre for Cybersecurity Belgium (CCB) oversees its implementation, through the Safeonweb@Work platform.

Who is directly covered?

NIS2 applies to organisations active in 18 sectors considered critical: energy, healthcare, transport, water, financial services, digital infrastructure, public administration, space, waste management, chemicals, food, manufacturing of medical devices, and more. Within these sectors, two levels of obligation apply depending on the organisation's size:

  • "Important" entity: 50 or more employees, or more than €10 million in annual turnover, in one of the 18 covered sectors.
  • "Essential" entity: 250 or more employees, or more than €50 million in turnover, in one of the 11 highly critical sectors (energy, healthcare, transport, finance, digital infrastructure, public administration...).

Below these thresholds, a company generally falls outside the direct scope of NIS2 — except for a few providers that are always covered regardless of size (notably DNS providers, domain name registries and trust service providers).

What if your SME doesn't tick any of these boxes?

This is exactly where many Belgian SME owners get it wrong by assuming the topic doesn't concern them. NIS2 requires essential and important entities to secure their entire supply chain, including their IT suppliers and subcontractors. In practice, a hospital, a municipality, a bank or a telecom operator subject to NIS2 will progressively demand cybersecurity guarantees from its providers — web agency, custom-application developer, IT maintenance firm: security questionnaires, specific contract clauses, sometimes even certification against the CyberFundamentals (CyFun) framework recommended by the CCB.

In other words: even without a direct legal obligation, an SME can find NIS2-style requirements imposed by an important client, on pain of losing the contract. Better to anticipate the question than to discover it in the middle of a tender.

The concrete obligations for covered entities

For organisations directly subject to NIS2, the main obligations are:

  • cybersecurity governance owned by leadership, trained and accountable in the event of failures;
  • documented risk management, reassessed regularly rather than as a one-off exercise;
  • notification of significant incidents to the CCB in three stages: early warning within 24h, an initial report within 72h, a final report within one month;
  • concrete technical and organisational measures (backups, access management, encryption, a continuity plan).

Essential entities must also demonstrate their compliance to the CCB by 18 April 2026. Fines for non-compliance can reach €10 million or 2% of global turnover for essential entities, and €7 million or 1.4% for important entities — since exact timelines and modalities may still evolve, it's worth checking the current regulation with the CCB before making any decision.

What can you do right now?

Whether or not your SME is directly covered, a few reflexes are worth adopting:

  • check your status against the sector and size criteria above, and register on Safeonweb@Work if you're covered;
  • if you work for clients who are themselves subject to NIS2 (public sector, healthcare, finance, energy...), anticipate their future security requirements rather than discovering them in a tender document;
  • even without a legal obligation, solid IT security — reliable backups, controlled access, monitoring — remains an increasingly decisive sales argument as clients grow stricter on this point.

At Gigaweb, we support Belgian SMEs across their entire IT infrastructure — from the initial diagnosis to putting concrete security measures in place — so they can confidently meet their clients' requirements, whether or not they're directly subject to NIS2.

Share:
Gigaweb