Not a Relaxation of Standards, but a Framework

The Inspection Service of the Belgian Cybersecurity Center (CCB) has unveiled a “remediation plan” for the many entities that risk failing to meet the required security level by the deadline.

As attacks increase, the CCB is responding with a general communication—akin to a “roadmap”—for Belgian NIS2 critical entities regarding their mandatory compliance assessment scheduled for April 18, 2027.

By April 18, 2027, NIS2 essential entities that are unable to demonstrate implementation of the cybersecurity measures required by the NIS2 law, CyFun (available on the CCB website), must submit a compliance plan.

This compliance plan must include:

  • evidence of compliance with NIS2 cybersecurity measures equivalent to CyFun’s “Significant” assurance level;
  • a description of the measures planned to achieve a level of assurance equivalent to CyFun’s “Essential” level by April 18, 2028 (this approach applies to all three available compliance assessment pathways);
  • CyFun certification or verification by an accredited conformity assessment body (CAB);
  • ISO/IEC 27001 certification by an accredited conformity assessment body (CAB);
  • conformity assessment conducted directly by the CCB’s inspection service.

No Relaxation of the Legal Text

The CCB emphasizes that this communication does not in any way alter the legal obligations or deadlines set by the Belgian NIS2 law and its Royal Decree.

Furthermore, no compliance plan is required from NIS2 essential entities that can demonstrate, by April 18, 2027, that they already comply with NIS2 cybersecurity measures equivalent to CyFun’s “Essential” assurance level, or cybersecurity measures that have been duly verified and are equivalent to a lower CyFun assurance level based on their risk analysis.

The CCB emphasizes that this administrative directive in no way constitutes a relaxation of the law or its deadlines for legal enforceability. This communication is primarily intended to provide guidance for operators who are behind schedule in order to avoid sudden compliance failures.