Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Cybersecurity services — Belgium

Command of the Belgian regulatory framework — Centre for Cyber Security Belgium, Data Protection Authority, NIS2 — for public and private organizations.

Last updatedAugust 22, 2026

The local regulatory framework

Belgium's cybersecurity framework is carried by the Centre for Cyber Security Belgium (CCB), the national cybersecurity authority, and by the Data Protection Authority (APD/GBA) for personal data protection. The NIS2 transposition law, adopted in 2024, broadens the scope of essential and important entities subject to risk management and incident notification obligations. The CCB also promotes the CyberFundamentals Framework, a set of security controls graded by an organization's maturity and criticality level, widely used as an operational compliance tool.

Concrete obligations

Compliance with the 2024 NIS2 transposition law for identified essential and important entities

GDPR compliance under the oversight of the Data Protection Authority (APD/GBA)

Implementation of the CCB's CyberFundamentals Framework as a baseline of graded security controls

Notification of significant security incidents to the CCB within the timeframes required by NIS2

Priority sectors

Public sectorIndustryFinance

Delivery modalities

Engagement model

Direct engagement

Operational framework

CCB CyberFundamentals Framework

Languages

French, Dutch, English

Local FAQ

What is the national cybersecurity authority in Belgium?

The Centre for Cyber Security Belgium (CCB), which drives the national strategy and the NIS2 transposition.

What is the CyberFundamentals Framework?

A set of graded security controls developed by the CCB, allowing organizations to structure their compliance according to their maturity and criticality level.

Which entities are covered by Belgium's 2024 NIS2 law?

Entities identified as essential or important based on the sector and size criteria set by the national transposition. This topic has its own dedicated page on this site.

Which authority oversees data protection in Belgium?

The Data Protection Authority (APD/GBA), which enforces GDPR.

How does the CyberFundamentals Framework relate to NIS2?

It serves as an operational tool for entities subject to NIS2 to demonstrate and structure compliance with risk management requirements.

What services are most requested in Belgium?

Security audits, GRC compliance aligned with the CyberFundamentals Framework, and penetration testing for essential and important entities.

How does an engagement in Belgium typically start?

With an initial scoping phase to determine the entity's status under NIS2 and the targeted CyberFundamentals control level.

Get in touch